systemcheck Hardening

systemcheck attack surface reduction.
Contents
Rationale
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Rationale
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Systemcheck_Hardening#Rationale|Rationale]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Rationale](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Rationale)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Rationale](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Rationale)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Rationale]Rationale[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Although systemcheck
already has AppArmor and systemd hardening, some marginal security benefits are gained by reducing: the number of network connections, the amount of code running, and unnecessary functionality. This is not the default configuration, since that would come at the cost of decreased usability for the entire Kicksecure population.
Hardening Steps
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Hardening_Steps
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Systemcheck_Hardening#Hardening_Steps|Hardening Steps]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Hardening Steps](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Hardening_Steps)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Hardening Steps](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Hardening_Steps)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Hardening_Steps]Hardening Steps[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Prevent Autostart
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Autostart
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Systemcheck_Hardening#Prevent_Autostart|Prevent Autostart]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Prevent Autostart](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Autostart)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Prevent Autostart](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Autostart)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Autostart]Prevent Autostart[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
To prevent systemcheck
from automatically starting, run.
Click = Copy Copied to clipboard! sudo systemctl mask systemcheck
Prevent Kicksecure Warrant Canary Check and User Census Counting
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Kicksecure_Warrant_Canary_Check_and_User_Census_Counting
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Systemcheck_Hardening#Prevent_Kicksecure_Warrant_Canary_Check_and_User_Census_Counting|Prevent Kicksecure Warrant Canary Check and User Census Counting]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Prevent Kicksecure Warrant Canary Check and User Census Counting](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Kicksecure_Warrant_Canary_Check_and_User_Census_Counting)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Prevent Kicksecure Warrant Canary Check and User Census Counting](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Kicksecure_Warrant_Canary_Check_and_User_Census_Counting)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Kicksecure_Warrant_Canary_Check_and_User_Census_Counting]Prevent Kicksecure Warrant Canary Check and User Census Counting[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Refer to the following systemcheck chapters:
Prevent Polluting TransPort
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Polluting_TransPort
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Systemcheck_Hardening#Prevent_Polluting_TransPort|Prevent Polluting TransPort]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Prevent Polluting TransPort](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Polluting_TransPort)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Prevent Polluting TransPort](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Polluting_TransPort)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Polluting_TransPort]Prevent Polluting TransPort[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- This is only useful when running
systemcheck --leak-tests
. However, running this command with the TorTransPort
test disabled makes little sense; in that case it would be useful as a TorSocksPort
connectivity test.
Deactivate the TransPort
Test for better Stream Isolation.
Open file /etc/systemcheck.d/50_user.conf
in an editor with root rights.
Kicksecure
See Open File with Root Rights for detailed instructions on why to use
sudoedit
for better security and how to use it.
Note: Mousepad (or the chosen text editor) must be closed before running the sudoedit
command.
Click = Copy Copied to clipboard! sudoedit /etc/systemcheck.d/50_user.conf
Kicksecure for Qubes
NOTES:
- When using Kicksecure-Qubes, this needs to be done inside the Template.
Click = Copy Copied to clipboard! sudoedit /etc/systemcheck.d/50_user.conf
- After applying this change, shutdown the Template.
- All App Qubes based on the Template need to be restarted if they were already running.
- This is a general procedure required for Qubes and unspecific to Kicksecure for Qubes.
Others and Alternatives
- This is just an example. Other tools could achieve the same goal.
- If this example does not work for you or if you are not using Kicksecure, please refer to this link.
Click = Copy Copied to clipboard! sudoedit /etc/systemcheck.d/50_user.conf
Add the following content.
Click = Copy Copied to clipboard! SYSTEMCHECK_DISABLE_TRANS_PORT_TEST="1"
Save.
Prevent Running APT
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Running_APT
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Systemcheck_Hardening#Prevent_Running_APT|Prevent Running APT]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Prevent Running APT](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Running_APT)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Prevent Running APT](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Running_APT)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_Running_APT]Prevent Running APT[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
This prevents the running of APT by systemcheck.
Open file /etc/systemcheck.d/50_user.conf
in an editor with root rights.
Kicksecure
See Open File with Root Rights for detailed instructions on why to use
sudoedit
for better security and how to use it.
Note: Mousepad (or the chosen text editor) must be closed before running the sudoedit
command.
Click = Copy Copied to clipboard! sudoedit /etc/systemcheck.d/50_user.conf
Kicksecure for Qubes
NOTES:
- When using Kicksecure-Qubes, this needs to be done inside the Template.
Click = Copy Copied to clipboard! sudoedit /etc/systemcheck.d/50_user.conf
- After applying this change, shutdown the Template.
- All App Qubes based on the Template need to be restarted if they were already running.
- This is a general procedure required for Qubes and unspecific to Kicksecure for Qubes.
Others and Alternatives
- This is just an example. Other tools could achieve the same goal.
- If this example does not work for you or if you are not using Kicksecure, please refer to this link.
Click = Copy Copied to clipboard! sudoedit /etc/systemcheck.d/50_user.conf
Add the following content.
Click = Copy Copied to clipboard! systemcheck_skip_functions+=" check_operating_system "
Prevent torproject.org Connections
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_torproject.org_Connections
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Systemcheck_Hardening#Prevent_torproject.org_Connections|Prevent torproject.org Connections]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Prevent torproject.org Connections](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_torproject.org_Connections)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Prevent torproject.org Connections](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_torproject.org_Connections)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Prevent_torproject.org_Connections]Prevent torproject.org Connections[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Connections to The Tor Project are prevented by default, therefore no action is required.
systemcheck
only connects to torproject.org
if the command systemcheck --leak-tests
is manually run.
Footnotes
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Footnotes
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Systemcheck_Hardening#Footnotes|Footnotes]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Footnotes](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Footnotes)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Footnotes](https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Footnotes)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Systemcheck_Hardening?direction=prev&oldid=88084#Footnotes]Footnotes[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.


Copy as Wikitext

for Discourse, reddit, GitHub

Copy as Markdown

Copy as phpBB Click below ↴ = Open social URL with share data











We believe security software like Kicksecure needs to remain Open Source and independent. Would you help sustain and grow the project? Learn more about our 12 year success story and maybe DONATE!