Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #187348

System hardening: adding hidepid to /proc?

From Brent Clark <brentgclarklist@gmail.com>
Newsgroups linux.debian.user
Subject System hardening: adding hidepid to /proc?
Date 2017-09-28 10:30 +0200
Message-ID <uuCmK-6C9-29@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


Good day Guys

I came across this document:

https://linux-audit.com/linux-system-hardening-adding-hidepid-to-proc/

The idea is to increase security by hiding the display of running
processes, and their arguments, which belong to other users. This helps
avoid problems if users enter passwords on the command-line, and similar.

Its suggesting mount /proc with the option hidepid=2.

I would like to ask:

1) is it safe?

2) did you incur any issues?

3) what are your thoughts


The security audit tool, Lynis, also checks to see if /proc is mounted
hidepid?

[+] File systems
------------------------------------
  - Checking mount points

snippet

  - Testing /proc mount (hidepid)                             [ OK ]

Many thanks

Brent

P.s. I see its not suggested in the ''Securing Debian Manual"

Back to linux.debian.user | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

System hardening: adding hidepid to /proc? Brent Clark <brentgclarklist@gmail.com> - 2017-09-28 10:30 +0200
  Re: System hardening: adding hidepid to /proc? Reco <recoverym4n@gmail.com> - 2017-09-30 17:10 +0200

csiph-web