scope:
- will be initially released for VMs (VirtualBox, maybe Qubes, maybe KVM)
- “sudo apt-get install kicksecure-cli” will be possible on bare metal Debian hosts, in other words installations of Debian can be easily converted into Kicksecure by installing the kicksecure-cli or other hardened debian package
- maybe later available as ISO for installation on hardware depending on community interest and support
hardening by default in Kicksecure version 1:
- install haveged by default for better entropy
- sdwdate rather than insecure NTP
- security-misc (Kernel Self Protection; Enhances Misc Security Settings)
- open-link-confirmation
- enable apparmor by default
- available apparmor profiles
- hopefully spectre / meltdown resistant by default
- SecBrowser ™: A Security-hardened, Non-anonymous Browser
- grub live boot menu entry
hardening by default in Kicksecure version 2:
usability by default:
- https://github.com/Whonix/shared-folder-help
- GitHub - Kicksecure/usability-misc: Misc usability improvements
desktop environment:
initially will be available most likely for:
- CLI only (console only, no desktop environment)
- XFCE
vision:
- computer security community is larger than computer anonymity community - we can work on a shared interest that is security
- we apply as many security settings by default
- we apply as much as default from System Hardening Checklist
- Kicksecure will be the base for Whonix (Whonix is applying most of above already anyhow)
development status:
- meta package “kicksecure-xfce” and “kicksecure-cli” exist - anon-meta-packages/control at master · Whonix/anon-meta-packages · GitHub
- most packages working (since reused from Whonix)
- build script ready (
--flavor kicksecure-xfce
/--flavor kicksecure-cli
) - builds successfully
- installation on Debian buster hosts using the
kicksecure-cli
package initially tested by developer, call for wider testing upcoming - VirtualBox ova downloads upcoming
initial homepage:
About me:
I am the founder and a maintainer of the Debian Linux and Tor based Whonix - Anonymous Operating System.
Questions:
Are you interested in Kicksecure? What do you think? What would you like to see? Any suggestions?