TP-Link triband with IPv6 disabled, We use the three WIFI-networks seperately. The 2.4 Ghz is used for IoT-devices and guest (SPI-, NAT, ARP-filtering and intrusion detection enabled). The two 5 Ghz networks are for my wife and I (each uses his/her own) with additionally IP-MAC binding and MAC filtering enabled. I have set the e-mail log message level to critical events (acting as a rudimentary NIDS). The 5Ghz network has eternal lease time while 2.4 Ghz has short lease time (8 hours) and network partitioning enabled.
Real-time security
Non root user using build-in Linux sandboxing (AppArmor, Firejail, Flatpak) as extra protection layer.
Firewall security
Built-in Firewall for Mac/Linux
About custom security
Using only official package sources from verified publishers and de-installed all unused accessoires and applications.
Installed fapolicyd denying normal users to execute something which does not come from above repositories
Mildly hardened Linux by disabling P2P, remote access, old TLS versions and enabling ASLR system wide.
Created additional Firejail profiles with firecfg and reduced Flatpak permissions with flatseal.
Added OpenSnitch outbound application firewall to compliment inbound GuFW.
FreeFileSync quick on-demand backups to a partition on my internal SSD to which sandboxed utilities, desktop accessoires and applications have no access to.
The half yearly full backup saves to an external USB-SSD which is checked (afterwards) by Microsoft Defender on my wife's laptop (which has triple USB protection).
Subscriptions
None
System recovery
TimeShift (to another partition on 1 TB SSD)
Risk factors
Browsing to popular websites
Working from home
Making audio/video calls
Opening email attachments
Buying from online stores, entering banks card details
Logging into my bank account
Streaming audio/video content from trusted sites or paid subscriptions
Computer specs
AMD Ryzen 7 (5700U) laptop with 1 TB SSD and 16GB RAM
Notable changes
To many
After jumping back and forth, I finally decided for:
Changed from ControlD free to Cloudflare free ZT
Replaced 7-zip (unsandboxed) with PeaZip in Flatpak
Moved from LibreOffice in Flatpak to LibreOffice in Firejail
Moved from Thunderbird to Evolution (both in Flatpak sandbox)
Moved from Xfce desktop with X11 to Cinnamon desktop with Wayland
Installed fapolicyd (simular to WDAC on Windows) application control (see post)
You always have 3 layers of download protection because you have the DownloadsRestrictions policy, even though it's set to 1, whereas I have it set to 4 (no FP):