Kicksecure / security-misc

Kernel Hardening; Protect Linux User Accounts against Brute Force Attacks; Improve Entropy Collection; Strong Linux User Account Separation; Enhances Misc Security Settings - https://www.kicksecure.com/wiki/Security-misc
https://www.kicksecure.com/wiki/Impressum
Other
517 stars 51 forks source link

Disable some Intel PMT kernel modules #237

Closed raja-grewal closed 4 months ago

raja-grewal commented 4 months ago

Disable some Intel Platform Monitoring Technology Telemetry (PMT) kernel modules.

Disabling was first suggested in Issue https://github.com/Kicksecure/security-misc/issues/224.

Changes

Add some Intel PMT modules to the list of disabled kernel modules.

Create disabled-intelpmt-by-security-misc.

Mandatory Checklist

Terms of Service, Privacy Policy, Cookie Policy, E-Sign Consent, DMCA, Imprint

Optional Checklist

The following items are optional but might be requested in certain cases.

raja-grewal commented 4 months ago

https://forums.whonix.org/t/blacklist-more-kernel-modules-to-reduce-attack-surface/7989/38

adrelanos commented 4 months ago

Moved my comment to https://github.com/Kicksecure/security-misc/pull/236 where it belongs. It is a related discussion.

raja-grewal commented 4 months ago

As per the discussion at https://github.com/Kicksecure/security-misc/issues/224#issuecomment-2230729392.

For disabling Intel PMT, perhaps we should make it opt-in because I would imagine a large portion of users would prefer to have it preemptively disabled than risk any potential future revelations regarding what was actually being collected.