Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #187348 > unrolled thread
| Started by | Brent Clark <brentgclarklist@gmail.com> |
|---|---|
| First post | 2017-09-28 10:30 +0200 |
| Last post | 2017-09-30 17:10 +0200 |
| Articles | 2 — 2 participants |
Back to article view | Back to linux.debian.user
System hardening: adding hidepid to /proc? Brent Clark <brentgclarklist@gmail.com> - 2017-09-28 10:30 +0200
Re: System hardening: adding hidepid to /proc? Reco <recoverym4n@gmail.com> - 2017-09-30 17:10 +0200
| From | Brent Clark <brentgclarklist@gmail.com> |
|---|---|
| Date | 2017-09-28 10:30 +0200 |
| Subject | System hardening: adding hidepid to /proc? |
| Message-ID | <uuCmK-6C9-29@gated-at.bofh.it> |
Good day Guys I came across this document: https://linux-audit.com/linux-system-hardening-adding-hidepid-to-proc/ The idea is to increase security by hiding the display of running processes, and their arguments, which belong to other users. This helps avoid problems if users enter passwords on the command-line, and similar. Its suggesting mount /proc with the option hidepid=2. I would like to ask: 1) is it safe? 2) did you incur any issues? 3) what are your thoughts The security audit tool, Lynis, also checks to see if /proc is mounted hidepid? [+] File systems ------------------------------------ - Checking mount points snippet - Testing /proc mount (hidepid) [ OK ] Many thanks Brent P.s. I see its not suggested in the ''Securing Debian Manual"
[toc] | [next] | [standalone]
| From | Reco <recoverym4n@gmail.com> |
|---|---|
| Date | 2017-09-30 17:10 +0200 |
| Message-ID | <uvryV-5MV-19@gated-at.bofh.it> |
| In reply to | #187348 |
Hi. On Thu, Sep 28, 2017 at 10:22:10AM +0200, Brent Clark wrote: > Good day Guys > > I came across this document: > > https://linux-audit.com/linux-system-hardening-adding-hidepid-to-proc/ > > The idea is to increase security by hiding the display of running > processes, and their arguments, which belong to other users. This helps > avoid problems if users enter passwords on the command-line, and similar. > > Its suggesting mount /proc with the option hidepid=2. > > I would like to ask: > > 1) is it safe? Did not prevent boot for me (stretch, amd64, sysvinit). Which means even if it breaks something - it should be possible to fix without resorting to LiveCD booting and/or having console access. > 2) did you incur any issues? Nothing that catched my eye. > 3) what are your thoughts If that measure is your only defence against users that "enter passwords on the commandline" (meaning actually that said users pass usernames/passwords as commandline arguments so they are visible via ps(1)) - you're doing it wrong as it's those commandline tools are broken, not OS itself. One should not tweak OS in such radical way without attempting to fix those tools first. Or educating users. Or both. > The security audit tool, Lynis, also checks to see if /proc is mounted > hidepid? I'm not familiar with this tool. Yet another thing I should research once I have free time. Reco
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web