Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #263357

Re: it would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...

From Albretch Mueller <lbrtchx@gmail.com>
Newsgroups linux.debian.user
Subject Re: it would be nice is Debian live includes the Wazuh unified XDR and SIEM protection framework ...
Date 2023-11-11 10:40 +0100
Message-ID <HySD7-4DZz-1@gated-at.bofh.it> (permalink)
References <HyKYV-4z9j-1@gated-at.bofh.it> <HyQKZ-4CK4-11@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 11/11/23, tomas@tuxteam.de <tomas@tuxteam.de> wrote:
> In which case you aren't the customer, but the cattle.

 Once we go into exposed mode (go online), we tacitly become all
cattle, don't we? What I am talking about is being more of an
unleashed cattle, a leashed one that is aware.

On 11/11/23, Marco <mm@dorfdsl.de> wrote:
> Am 11.11.2023 01:26 schrieb Albretch Mueller:
>
>>  the politics behind the "cloud trial" may not be compatible with
>> Debian, but I don't know if there is a way to work around such issues
>> or just use the other parts of it:
>
> Why can't you install it manually, maybe with a script?

 Yes, of course, you can always do so. I meant it would be best if
certain security issues are dealt on a hardware level. It may sound as
"paranoid", "crazy" to you, but I always go into exposed mode using a
Debian Live DVD, basically:

 1) boot up
 2) mount local drive (reset my home dir ...)
 3) mount USB pen with extra stuff I need
 4) customize my run by using dpkg to install packages from the USB pen drive
 5) unmount, remove pen drive
 6) physically plug in Internet enabling hardware
 7) install the drivers to be able to connect to the Internet ...
...
 (n-2)) disconnect yourself from the internet (software + hardware by
removing the wifi USB dongle or cable) ...
 (n-1)) run script to check which files were changed during your run and how
 n) shutdown

 Yes, it is cumbersome, but it is the only way I can access the
Internet with some reliability.

 It is not just about soft- and hardware level measures, "hackers" as
part of their modus operandi need "persistence". They would not spend
their while and expertise knowing well that by shutting down your
computer you would be effortlessly erasing all their cr@p, along with
all cookies and all of that and they are smart enough to realize that
they would risk exposing their rear end to the four winds. If they
continue doing such thing you will know the kinds of "legally
protected" hackers that would not mind such risk.

 lbrtchx

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

it would be nice is Debian live includes the Wazuh unified XDR and  SIEM protection framework ... Albretch Mueller <lbrtchx@gmail.com> - 2023-11-11 02:30 +0100
  Re: it would be nice is Debian live includes the Wazuh unified XDR  and SIEM protection framework ... <tomas@tuxteam.de> - 2023-11-11 07:30 +0100
  Re: it would be nice is Debian live includes the Wazuh unified XDR  and SIEM protection framework ... Marco <mm@dorfdsl.de> - 2023-11-11 08:40 +0100
    Re: it would be nice is Debian live includes the Wazuh unified XDR  and SIEM protection framework ... Albretch Mueller <lbrtchx@gmail.com> - 2023-11-11 10:40 +0100
      Re: it would be nice is Debian live includes the Wazuh unified XDR  and SIEM protection framework ... Michael Kjörling <2695bd53d63c@ewoof.net> - 2023-11-11 12:20 +0100

csiph-web