Securing a Debian installation for general home usage

Village

Debian comes with several harden packages, designed to make a computer more secure. My needs are very simple: word processing and Web browsing. I do not run any special servers, do not use SSH, telnet, etc. The only software that should use the Internet, that I know of, is iceweasel and apt.

  • Is there a way to ensure that only these two pieces of software can access the Internet?
  • Are any of the harden packages suitable for these needs?
jofel

In a default user installation, there is only ssh as server application installed which you can simply uninstall via aptitude remove openssh-server or via any other package manager you use.

Restricting network access for applications is difficult. {{ EDIT: However, there is now Leopard Flower developed which seems to provides the features you need (per-process firewall, interactive user interface). }} See Per process firewall? for more information about the topic. Without using complicate solutions, you can only restrict network access to special users via the iptables owner module.

As normal user you do not need any harden-* packages. They either conflict on unsafe packages, which you probably have not installed anyway, or install security packages which are for normal systems too complicated to configure and maintain - like network intrusion systems.

Collected from the Internet

Please contact [email protected] to delete if infringement.

edited at
0

Comments

0 comments
Login to comment

Related

From Dev

Pyinstaller installation in DebIan Linux

From Dev

Debian package, installation of dependencies

From Dev

Securing bolt cms installation for production

From Dev

MySQL application runs slow after general usage

From Dev

Nginx installation errors in debian 8.3

From Dev

Partition scheme for installation of Debian

From Dev

Virtualbox Ubuntu Installation, general troubleshooting (installation hangs)

From Dev

Debian package, installation of dependencies

From Dev

Securing bolt cms installation for production

From Dev

Securing my home network and computer while still allowing SSH

From Dev

Debian - unattended installation

From Dev

VMware terminology & home usage

From Dev

Debian 8 Jessie UEFI Installation

From Dev

Encrypting home folder in Debian

From Dev

Setup Debian Mirrors after Installation

From Dev

Root home is not /root on my debian?

From Dev

Python-swiftclient: what is the general usage procedure?

From Dev

nginx installation failed in Debian Stretch

From Dev

Gnome Installation Issue Debian

From Dev

Cannot start Devuan/Debian installation

From Dev

Error during Nodejs installation on Debian

From Dev

Debian does not boot after installation

From Dev

Debian USB installation

From Dev

Fresh GitLab Installation gives error 500 on home page (Plesk, Debian 9)

From Dev

Debian default installation package list?

From Dev

Debian version usage statistics

From Dev

Creating a portable debian installation

From Dev

Installation of Docker on Debian 8

From Dev

Proper Redux usage general questions