diff --git a/hardening/README.md b/hardening/README.md index 9cb222ac..9537f08a 100644 --- a/hardening/README.md +++ b/hardening/README.md @@ -10,6 +10,17 @@ 1. Accessing the network when they don't need to. 1. Accessing hardware devices they don't need. +## Current Status + +1. **System Level**: + - [ ] AppArmor + - [ ] Kernel & System Hardening +1. **Per-App Level**: + - Nixpak (Bubblewrap) + - [x] QQ + - [ ] Firefox (Nvidia GPU support issue) + - [ ] Firejail (risk? not enabled yet) + ## Kernel Hardening - NixOS Kernel Config: