mirror of
https://github.com/optim-enterprises-bv/secureblue.git
synced 2025-11-02 03:18:00 +00:00
fix: sudo timeout to 1min instead of 0min
This commit is contained in:
@@ -33,7 +33,7 @@ Hardening applied:
|
||||
- Installing Chromium instead of Firefox in the base image <sup>[Why chromium?](https://grapheneos.org/usage#web-browsing)</sup> <sup>[Why not flatpak chromium?](https://forum.vivaldi.net/post/669805)</sup>
|
||||
- Including a hardened chromium config that sets numerous hardened defaults <sup>[details](https://github.com/secureblue/secureblue/blob/live/config/files/usr/etc/chromium/policies/managed/hardening.json.readme.md)</sup> and disables JIT javascript <sup>[why?](https://microsoftedge.github.io/edgevr/posts/Super-Duper-Secure-Mode/#is-jit-worth-it)</sup>
|
||||
- Pushing upstream fedora to harden the build for all fedora users, including secureblue users ([for example, by enabling CFI](https://bugzilla.redhat.com/show_bug.cgi?id=2252874))
|
||||
- Require a password for sudo every time it's called
|
||||
- Reduce the sudo timeout to 1 minute
|
||||
- Disable passwordless sudo for `rpm-ostree install` <sup>[why?](https://github.com/rohanssrao/silverblue-privesc)
|
||||
- Brute force protection by locking user accounts for 24 hours after 50 failed login attempts, hardened password encryption and password quality suggestions
|
||||
- Installing chkrootkit, usbguard, and bubblejail
|
||||
|
||||
@@ -1 +1 @@
|
||||
Defaults timestamp_timeout = 0
|
||||
Defaults timestamp_timeout = 1
|
||||
Reference in New Issue
Block a user