Page MenuHomePhabricator

securityProject
ActivePublic

Members (1)

Watchers

  • This project does not have any watchers.
  • View All

Details

Description

Security enhancements.

Recent Activity

Jan 19 2023

Patrick updated the task description for T135: find packages without security support / consider installation of debian-security-support by default.
Jan 19 2023, 10:58 AM · bash, Whonix, research, user documentation, security, usability
Patrick removed a project from T135: find packages without security support / consider installation of debian-security-support by default: Debian version 8 codename Jessie.
Jan 19 2023, 10:57 AM · bash, Whonix, research, user documentation, security, usability

Jan 12 2021

Patrick added a comment to T533: iptables block network access until sdwdate succeeded.

I am not sure sdwdate-gui would be a strong enough notification if networking was actually blocked if sdwdate did not succeed yet.

Jan 12 2021, 7:51 AM · Whonix, usability, whonix-ws-firewall, whonix-gw-firewall, iptables, python, security, enhancement, sdwdate-gui, sdwdate
Patrick updated the task description for T533: iptables block network access until sdwdate succeeded.
Jan 12 2021, 3:53 AM · Whonix, usability, whonix-ws-firewall, whonix-gw-firewall, iptables, python, security, enhancement, sdwdate-gui, sdwdate

Aug 13 2020

Patrick updated the task description for T540: Advanced Attacks Meta Ticket.
Aug 13 2020, 8:33 AM · VirtualBox, KVM, Qubes, security, research, Whonix
Patrick closed T542: Keyboard/Mouse Fingerprinting Defense as Resolved.

Shipping kloak in Whonix stable for a few releases already.

Aug 13 2020, 8:32 AM · security, Whonix
Patrick closed T542: Keyboard/Mouse Fingerprinting Defense, a subtask of T540: Advanced Attacks Meta Ticket, as Resolved.
Aug 13 2020, 8:32 AM · VirtualBox, KVM, Qubes, security, research, Whonix

Aug 12 2020

HulaHoop closed T530: CPU-induced latency Covert Channel Countermeasures as Invalid.

After running a bunch of tcp ping tests, the conclusion is this attack
is not really effective against TCP like ICMP. The latency is much lower
for TCP pings and though it slightly decreases with cpu stress it is not
consistent. Reloading pages in TBB with cpu stress
on/off does not impact latency readings while doing so with tc
attached has massive latency foot prints - implying it will ironically make such attacks much easier in addition to degrading performance.

Aug 12 2020, 4:30 PM · virtualizer, VMware, VirtualBox, KVM, Qubes, security, Whonix, research
HulaHoop closed T530: CPU-induced latency Covert Channel Countermeasures, a subtask of T540: Advanced Attacks Meta Ticket, as Invalid.
Aug 12 2020, 4:30 PM · VirtualBox, KVM, Qubes, security, research, Whonix

Aug 7 2020

HulaHoop added a comment to T530: CPU-induced latency Covert Channel Countermeasures.

Cyrus recommends adding delays per packet to disrupt inter-packet patterns that remain. The command can be fine tuned as such:

Aug 7 2020, 4:54 PM · virtualizer, VMware, VirtualBox, KVM, Qubes, security, Whonix, research

Aug 1 2020

HulaHoop added a comment to T530: CPU-induced latency Covert Channel Countermeasures.

The good news is I think I've figured out the equivalent tc-netem command looking the slot parameter in the manual:

Aug 1 2020, 3:42 PM · virtualizer, VMware, VirtualBox, KVM, Qubes, security, Whonix, research

May 30 2020

HulaHoop added a comment to T530: CPU-induced latency Covert Channel Countermeasures.

Ticket above closed and convo moved to tails-dev.

May 30 2020, 2:33 PM · virtualizer, VMware, VirtualBox, KVM, Qubes, security, Whonix, research

Mar 22 2020

Patrick updated the task description for T942: Whonix Host Firewall for Whonix Host.
Mar 22 2020, 5:15 PM · Whonix 15, security, Whonix-Host, Whonix

Mar 21 2020

Patrick renamed T942: Whonix Host Firewall for Whonix Host from polish Whonix Host Firewall for Whonix Host to Whonix Host Firewall for Whonix Host.
Mar 21 2020, 10:44 AM · Whonix 15, security, Whonix-Host, Whonix
Patrick added a project to T942: Whonix Host Firewall for Whonix Host: Whonix 15.
Mar 21 2020, 10:39 AM · Whonix 15, security, Whonix-Host, Whonix
Patrick updated the task description for T942: Whonix Host Firewall for Whonix Host.
Mar 21 2020, 10:34 AM · Whonix 15, security, Whonix-Host, Whonix

Jan 7 2020

HulaHoop added a comment to T552: Packaging USBKill.

An interesting product that triggers a system wipe if the cable is pulled:

Jan 7 2020, 4:51 PM · Whonix-Host, security, Whonix

Dec 24 2019

madaidan added a comment to T943: make /boot and /lib/modules unreadable even for root.

Any attempted access of /boot would be logged the same way anyway although it might be good to use that to stop it from showing up in aa-logprof.

Dec 24 2019, 4:07 PM · security, apparmor-profile-everything, Whonix
Patrick closed T943: make /boot and /lib/modules unreadable even for root as Resolved.

Would an audit denyrule for /boot be useful for the sake of audit?

Dec 24 2019, 3:49 PM · security, apparmor-profile-everything, Whonix
madaidan added a comment to T943: make /boot and /lib/modules unreadable even for root.

/boot isn't allowed in init-systemd anyway so we don't need to add it to dangerous-files. Apparmor denies access to files that aren't explicitly allowed. The only reason we need to blacklist /lib/modules and not /boot is because we give access to all libraries.

Dec 24 2019, 3:37 PM · security, apparmor-profile-everything, Whonix
Patrick added a comment to T943: make /boot and /lib/modules unreadable even for root.

Still need to add /boot to https://github.com/Whonix/apparmor-profile-everything/blob/master/etc/apparmor.d/abstractions/dangerous-files? Currently cannot find it there.

Dec 24 2019, 11:17 AM · security, apparmor-profile-everything, Whonix

Dec 23 2019

madaidan added a comment to T943: make /boot and /lib/modules unreadable even for root.

/boot/ is already unreadable.

Dec 23 2019, 8:27 PM · security, apparmor-profile-everything, Whonix

Dec 7 2019

Patrick renamed T943: make /boot and /lib/modules unreadable even for root from make /boot unreadable even for root to make /boot and /lib/modules unreadable even for root.
Dec 7 2019, 8:14 AM · security, apparmor-profile-everything, Whonix
Patrick triaged T943: make /boot and /lib/modules unreadable even for root as Normal priority.
Dec 7 2019, 8:13 AM · security, apparmor-profile-everything, Whonix

Dec 5 2019

Patrick updated the task description for T941: lock down interpreters / compilers (interpreter lock) (compiler lock).
Dec 5 2019, 3:16 PM · Whonix, security
Patrick updated the task description for T941: lock down interpreters / compilers (interpreter lock) (compiler lock).
Dec 5 2019, 3:12 PM · Whonix, security
Patrick renamed T941: lock down interpreters / compilers (interpreter lock) (compiler lock) from lock down interpreters (interpreter lock) to lock down interpreters / compilers (interpreter lock) (compiler lock).
Dec 5 2019, 3:12 PM · Whonix, security
Patrick updated the task description for T941: lock down interpreters / compilers (interpreter lock) (compiler lock).
Dec 5 2019, 3:07 PM · Whonix, security
Patrick triaged T942: Whonix Host Firewall for Whonix Host as Normal priority.
Dec 5 2019, 3:04 PM · Whonix 15, security, Whonix-Host, Whonix
Patrick renamed T941: lock down interpreters / compilers (interpreter lock) (compiler lock) from lock down interpreters to lock down interpreters (interpreter lock).
Dec 5 2019, 2:51 PM · Whonix, security
Patrick triaged T941: lock down interpreters / compilers (interpreter lock) (compiler lock) as Normal priority.
Dec 5 2019, 2:51 PM · Whonix, security
Patrick updated the task description for T940: grub boot password.
Dec 5 2019, 2:35 PM · security, Whonix, Whonix-Host
Patrick triaged T940: grub boot password as Normal priority.
Dec 5 2019, 2:22 PM · security, Whonix, Whonix-Host

Nov 25 2019

Patrick updated the task description for T543: TCP ISNs and Temperature induced clock skews.
Nov 25 2019, 12:32 PM · C Code, security, Whonix

Nov 16 2019

Patrick updated the task description for T543: TCP ISNs and Temperature induced clock skews.
Nov 16 2019, 10:20 AM · C Code, security, Whonix
Patrick added a comment to T543: TCP ISNs and Temperature induced clock skews.
Nov 16 2019, 10:19 AM · C Code, security, Whonix
Patrick updated the task description for T543: TCP ISNs and Temperature induced clock skews.
Nov 16 2019, 10:18 AM · C Code, security, Whonix

Nov 6 2019

Patrick updated subscribers of T362: systemd SystemCallFilter= containment option seccomp hardening.
Nov 6 2019, 2:34 AM · enhancement, whonixcheck, msgcollector, sdwdate, onion-grater (Control Port Filter Proxy), security, Debian version 9 codename Stretch, systemd, Whonix
Patrick closed T362: systemd SystemCallFilter= containment option seccomp hardening as Resolved.

This was done. If not, please create specific tickets where it isn't done.

Nov 6 2019, 2:34 AM · enhancement, whonixcheck, msgcollector, sdwdate, onion-grater (Control Port Filter Proxy), security, Debian version 9 codename Stretch, systemd, Whonix

Oct 15 2019

HulaHoop added a comment to T530: CPU-induced latency Covert Channel Countermeasures.

https://redmine.tails.boum.org/code/issues/17156

Oct 15 2019, 7:26 PM · virtualizer, VMware, VirtualBox, KVM, Qubes, security, Whonix, research

Oct 13 2019

HulaHoop added a comment to T530: CPU-induced latency Covert Channel Countermeasures.

Analysis by Cyrus cited here for completion:

Oct 13 2019, 2:18 PM · virtualizer, VMware, VirtualBox, KVM, Qubes, security, Whonix, research

Oct 7 2019

HulaHoop added a comment to T543: TCP ISNs and Temperature induced clock skews.

An alternative proposal for editing ISNs without involving the kernel:

Oct 7 2019, 1:11 AM · C Code, security, Whonix

Oct 6 2019

HulaHoop added a comment to T530: CPU-induced latency Covert Channel Countermeasures.
Oct 6 2019, 8:53 PM · virtualizer, VMware, VirtualBox, KVM, Qubes, security, Whonix, research
Patrick closed T596: keep an eye on kloak anti keystroke deanonymization tool as Resolved.

Implemented for some time now.

Oct 6 2019, 7:54 PM · Whonix 16, security, Whonix
Patrick updated subscribers of T530: CPU-induced latency Covert Channel Countermeasures.
Oct 6 2019, 7:50 PM · virtualizer, VMware, VirtualBox, KVM, Qubes, security, Whonix, research
Patrick added a comment to T530: CPU-induced latency Covert Channel Countermeasures.

Reported build failures:

Oct 6 2019, 7:47 PM · virtualizer, VMware, VirtualBox, KVM, Qubes, security, Whonix, research
HulaHoop added a comment to T530: CPU-induced latency Covert Channel Countermeasures.

When an implementation is decided, let's decide if we can include this in security-misc for use on Linux hosts and Kicksecure. We would need some way in detecting the active NIC since on wireless systems wlan0 is the interface of choice and not eth0

Oct 6 2019, 7:01 PM · virtualizer, VMware, VirtualBox, KVM, Qubes, security, Whonix, research
HulaHoop added a comment to T530: CPU-induced latency Covert Channel Countermeasures.

tc-netem is a utility that is part of the iproute2 package in Debian. It leverages functionality already built into Linux and userspace utilities to simulate networks including packet delays and loss.

Oct 6 2019, 4:04 PM · virtualizer, VMware, VirtualBox, KVM, Qubes, security, Whonix, research

Apr 23 2019

Patrick updated the task description for T552: Packaging USBKill.
Apr 23 2019, 10:39 AM · Whonix-Host, security, Whonix
Patrick updated the task description for T552: Packaging USBKill.
Apr 23 2019, 10:38 AM · Whonix-Host, security, Whonix