On 7/18/19 3:53 PM, Chris Laprise wrote:
Description:
------------
Qubes-VM-hardening
Leverage Qubes template non-persistence to fend off malware at VM
startup: Lock-down, quarantine and check contents of /rw private storage
that affect the execution environment.
* Acts at VM startup before private volume /rw mounts
* User: Protect /home desktop & shell startup executables
* Root: Quarantine all /rw configs & scripts, with whitelisting
* Re-deploy custom or default files to /rw on each boot
* SHA256 hash checking against unwanted changes
* Provides rescue shell on error or request
* Works with template-based AppVMs, sys-net and sys-vpn
Version 0.8.4 expands protection to the /home/user systemd directory,
and now hides its vms config directory on all VM startups (not just when
its enabled). Upgrading is recommended.
Github link - https://github.com/tasket/Qubes-VM-hardening
pardon my non-sysadmin query :
any chance of some real world examples? quite a few new terms there .
so install into Debian-9
but step 2 am already lost
eg how and where amd I "activating" vm-boot-protect in the templatevm ?
or during install there is going to appear a choice of which service to
start , then when one opens a TBAVM based on the specified Deb-9
template the protection work at that point ?
Can I install it in a fresh Deb-9 , and if its breaking things, just
delete the fresh Deb-9 template, or is it touching dom0 ?
I guess once installed there is no un-installing ?
--
You received this message because you are subscribed to the Google Groups
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/qubes-users/33117978-ed56-0e09-53fa-76331a057623%40riseup.net.