From 2b47447f0b880ab4847c607ff725b3b10aba4f7c Mon Sep 17 00:00:00 2001 From: Ryan Yin Date: Fri, 6 Sep 2024 00:03:46 +0800 Subject: [PATCH] docs: nixos-hardening - current status --- hardening/README.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/hardening/README.md b/hardening/README.md index 9cb222ac..9537f08a 100644 --- a/hardening/README.md +++ b/hardening/README.md @@ -10,6 +10,17 @@ 1. Accessing the network when they don't need to. 1. Accessing hardware devices they don't need. +## Current Status + +1. **System Level**: + - [ ] AppArmor + - [ ] Kernel & System Hardening +1. **Per-App Level**: + - Nixpak (Bubblewrap) + - [x] QQ + - [ ] Firefox (Nvidia GPU support issue) + - [ ] Firejail (risk? not enabled yet) + ## Kernel Hardening - NixOS Kernel Config: