Who of you runs a hardened version of CachyOS?
I hardened my CachyOS laptops basically the same way I did with my BlackArch machines:
- cachyos-hardened-lto Kernel
- IOMMU activated
- LUKS2 FDE
- secure and attested boot with my own keys rolled out, bound to TPM2 with a PIN and PCRS 0+7
- USB firewalling with USBGuard
- Firejail containment for Firefox, mupdf and a PDF/office file cleaning pipeline
- project directories encrypted with CryFS and Rclone
crypt - device bound OpenSSH keys in TPM2
- DNS over TLS
- Yubikeys as GnuPG smartcards and for FIDO2 passkeys
- Passwords et al in
pass - Wireguard and Tor Onion Services for phoning home.
Anyone running a similar setup? Other/better configurations? Something I overlooked?
submitted by /u/0xKaishakunin to r/cachyos
[link] [comments]
Source: r/cachyos · by /u/0xKaishakunin