Skip to content
DnsLister Forum

Where domain hunters compare notes

Who else runs a hardened version of CachyOS?

Who of you runs a hardened version of CachyOS?

I hardened my CachyOS laptops basically the same way I did with my BlackArch machines:

  1. cachyos-hardened-lto Kernel
  2. IOMMU activated
  3. LUKS2 FDE
  4. secure and attested boot with my own keys rolled out, bound to TPM2 with a PIN and PCRS 0+7
  5. USB firewalling with USBGuard
  6. Firejail containment for Firefox, mupdf and a PDF/office file cleaning pipeline
  7. project directories encrypted with CryFS and Rclone crypt
  8. device bound OpenSSH keys in TPM2
  9. DNS over TLS
  10. Yubikeys as GnuPG smartcards and for FIDO2 passkeys
  11. Passwords et al in pass
  12. Wireguard and Tor Onion Services for phoning home.

Anyone running a similar setup? Other/better configurations? Something I overlooked?

submitted by /u/0xKaishakunin to r/cachyos
[link] [comments]

Source: r/cachyos · by /u/0xKaishakunin

Leave a Reply

Your email address will not be published. Required fields are marked *