Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions debian/security-misc.maintscript
Original file line number Diff line number Diff line change
Expand Up @@ -49,3 +49,6 @@ rm_conffile /etc/sysctl.d/30_security-misc.conf
rm_conffile /etc/sysctl.d/30_silent-kernel-printk.conf
rm_conffile /etc/sysctl.d/30_security-misc_kexec-disable.conf

## replaced with privacy conscious configurations for bluetooth
## not to hinder day to day usage
rm_conffile /bin/disabled-bluetooth-by-security-misc

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This isn't needed. There are no conf files in /bin/. rm_conffile is only useful for /etc because these files are treated in a special way by dpkg.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I did not know this. Makes sense.

30 changes: 30 additions & 0 deletions etc/bluetooth/30_security-misc.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
[General]
# How long to stay in pairable mode before going back to non-discoverable
# The value is in seconds. Default is 0.
# 0 = disable timer, i.e. stay pairable forever
PairableTimeout = 30

# How long to stay in discoverable mode before going back to non-discoverable
# The value is in seconds. Default is 180, i.e. 3 minutes.
# 0 = disable timer, i.e. stay discoverable forever
DiscoverableTimeout = 30

# Maximum number of controllers allowed to be exposed to the system.
# Default=0 (unlimited)
MaxControllers=1

# How long to keep temporary devices around
# The value is in seconds. Default is 30.
# 0 = disable timer, i.e. never keep temporary devices
TemporaryTimeout = 0

[Policy]
# AutoEnable defines option to enable all controllers when they are found.
# This includes adapters present on start as well as adapters that are plugged
# in later on. Defaults to 'true'.
AutoEnable=false

# network/on: A device will only accept advertising packets from peer
# devices that contain private addresses. It may not be compatible with some
# legacy devices since it requires the use of RPA(s) all the time.
Privacy=network/on
7 changes: 5 additions & 2 deletions etc/modprobe.d/30_security-misc.conf
Original file line number Diff line number Diff line change
Expand Up @@ -11,8 +11,11 @@ options nf_conntrack nf_conntrack_helper=0

## Disable bluetooth to reduce attack surface due to extended history of security vulnerabilities
## https://en.wikipedia.org/wiki/Bluetooth#History_of_security_concerns
install bluetooth /bin/disabled-bluetooth-by-security-misc
install btusb /bin/disabled-bluetooth-by-security-misc
#
## Now replaced by a privacy and security preserving default bluetooth configuration for better usability
#
# install bluetooth /bin/disabled-bluetooth-by-security-misc
# install btusb /bin/disabled-bluetooth-by-security-misc

## Disable thunderbolt and firewire modules to prevent some DMA attacks
install thunderbolt /bin/disabled-thunderbolt-by-security-misc
Expand Down
2 changes: 2 additions & 0 deletions usr/lib/NetworkManager/conf.d/99_ipv6-privacy.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
[connection]
ipv6.ip6-privacy=2
6 changes: 6 additions & 0 deletions usr/lib/NetworkManager/conf.d/99_randomize-mac.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
[device-mac-randomization]
wifi.scan-rand-mac-address=yes

[connection-mac-randomization]
ethernet.cloned-mac-address=random
wifi.cloned-mac-address=random
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
[Network]
IPv6PrivacyExtensions=kernel