Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #187348 > unrolled thread

System hardening: adding hidepid to /proc?

Started byBrent Clark <brentgclarklist@gmail.com>
First post2017-09-28 10:30 +0200
Last post2017-09-30 17:10 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.debian.user


Contents

  System hardening: adding hidepid to /proc? Brent Clark <brentgclarklist@gmail.com> - 2017-09-28 10:30 +0200
    Re: System hardening: adding hidepid to /proc? Reco <recoverym4n@gmail.com> - 2017-09-30 17:10 +0200

#187348 — System hardening: adding hidepid to /proc?

FromBrent Clark <brentgclarklist@gmail.com>
Date2017-09-28 10:30 +0200
SubjectSystem hardening: adding hidepid to /proc?
Message-ID<uuCmK-6C9-29@gated-at.bofh.it>
Good day Guys

I came across this document:

https://linux-audit.com/linux-system-hardening-adding-hidepid-to-proc/

The idea is to increase security by hiding the display of running
processes, and their arguments, which belong to other users. This helps
avoid problems if users enter passwords on the command-line, and similar.

Its suggesting mount /proc with the option hidepid=2.

I would like to ask:

1) is it safe?

2) did you incur any issues?

3) what are your thoughts


The security audit tool, Lynis, also checks to see if /proc is mounted
hidepid?

[+] File systems
------------------------------------
  - Checking mount points

snippet

  - Testing /proc mount (hidepid)                             [ OK ]

Many thanks

Brent

P.s. I see its not suggested in the ''Securing Debian Manual"

[toc] | [next] | [standalone]


#187425

FromReco <recoverym4n@gmail.com>
Date2017-09-30 17:10 +0200
Message-ID<uvryV-5MV-19@gated-at.bofh.it>
In reply to#187348
	Hi.

On Thu, Sep 28, 2017 at 10:22:10AM +0200, Brent Clark wrote:
> Good day Guys
> 
> I came across this document:
> 
> https://linux-audit.com/linux-system-hardening-adding-hidepid-to-proc/
> 
> The idea is to increase security by hiding the display of running
> processes, and their arguments, which belong to other users. This helps
> avoid problems if users enter passwords on the command-line, and similar.
> 
> Its suggesting mount /proc with the option hidepid=2.
> 
> I would like to ask:
> 
> 1) is it safe?

Did not prevent boot for me (stretch, amd64, sysvinit).
Which means even if it breaks something - it should be possible to fix
without resorting to LiveCD booting and/or having console access.


> 2) did you incur any issues?

Nothing that catched my eye.


> 3) what are your thoughts

If that measure is your only defence against users that "enter passwords
on the commandline" (meaning actually that said users pass
usernames/passwords as commandline arguments so they are visible via
ps(1)) - you're doing it wrong as it's those commandline tools are
broken, not OS itself.
One should not tweak OS in such radical way without attempting to fix
those tools first. Or educating users. Or both.


> The security audit tool, Lynis, also checks to see if /proc is mounted
> hidepid?

I'm not familiar with this tool. Yet another thing I should research
once I have free time.

Reco

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web