Plague OS

Discussion in 'all things UNIX' started by BoerenkoolMetWorst, Mar 10, 2022.

  1. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,875
    Location:
    Outer space
    Sounds like an interesting alternative to Subgraph OS which seems dead.
    https://git.arrr.cloud/whichdoc/plagueos

    Using VoidOS with hardened kernel and other features as hypervisor and different choices for Guest OS. Different install options according to ones IT expertise:
    • Cli-only (Minimal installation for advanced users)
    • Sway WM (Minimalist Window Manager (WM) for advanced users)
    • Gnome w/ Wayland (For novice users who desire gutted desktop environment)

    Current implemented features:

    • Full System Build
    • Hardened Memory Allocator system-wide LD_PRELOAD
    • Custom LUKS Encryption (AES256XTS+Argon2id KDF)
    • Blacklisted Kernel Modules
    • Blacklisted File Systems
    • Blacklisted Network Protocols
    • IPTables Packet Filtering
    • Hardened GRUB Boot Parameters
    • Rolled in Whonix's hide-hardware-info script (See here)
    • Increased Entropy with use of haveged and jitterentropy
    • Increased password hashing rounds
    • Full Wayland Environment options
    • Selection between WM, DE, or CLI-only
    • Hide Process IDs
    • Permission hardening + immutable configurations
    • UMASK 0077 to system-wide default
    • Secure fstab configuration (Bind for var and tmp)
    • Locked root account, admin account for elevated privileges
    • Use of doas over sudo
    • Generic Machine ID
    • Randomized MAC address for NIC
    • Memory erasure/poisoning
    • USBGuard Implementation
    • Import & Verification of Kicksecure & Whonix
    • Encrypted DNS with DNSCrypt by default
    • Hardened SSH configuration (SSH not installed on host by default)
    • All commits to contain PGP signatures
     
  2. Melionix

    Melionix Registered Member

    Joined:
    Jun 22, 2020
    Posts:
    111
    Location:
    Earth
    Did anyone try this? It looks interesting enough
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.