Advanced Security Linux Mint Cinnamon Wayland setup

Last updated
Jun 1, 2026
How it's used?
For work or educational use
Operating system
Linux
Other operating system
Linux Mint 22.3 Zena Cinnamon Wayland
On-device encryption
Other full-disk drive encryption software
Log-in security
    • Biometrics (Windows Hello PIN, TouchID, Face, Iris, Fingerprint)
Security updates
Allow security updates and latest features
Update channels
Allow stable updates only
User Access Control
N/A - Linux / Mac / Other operating system
Smart App Control
N/A - Linux / Mac / Other operating system
Network firewall
Enabled
About WiFi router
TP-Link triband with IPv6 disabled, We use the three WIFI-networks seperately. The 2.4 Ghz is used for IoT-devices and guest (SPI-, NAT, ARP-filtering and intrusion detection enabled). The two 5 Ghz networks are for my wife and I (each uses his/her own) with additionally IP-MAC binding and MAC filtering enabled. I have set the e-mail log message level to critical events (acting as a rudimentary NIDS). The 5Ghz network has eternal lease time while 2.4 Ghz has short lease time (8 hours) and network partitioning enabled.
Real-time security
Non root user using build-in Linux sandboxing (AppArmor, Firejail, Flatpak) as extra protection layer.
Firewall security
Built-in Firewall for Mac/Linux
About custom security
Periodic malware scanners
When I receive files from others I scan them with Virus Total. My half yearly data backups to external USB are scanned with Microsoft Defender :cool:
Malware sample testing
I do not participate in malware testing
Environment for malware testing
None
Browser(s) and extensions
Brave-Origin with Brave adShield disabled and my two vibe coded security extensions. Using uBlockOriginLite with custom rules, added Kees1958 on ChatGPT's advice for blocking over 80% of the tracking requests!. For annoying websites I enable Brave adShield on-demand (in aggressive mode with Brave's adblock, AdGuard's URL parm, Easylist cookie and Fanboy/uBo annoyances filters enabled).
Secure DNS
  1. NextDNS in the Router with OISD and telemetry blocklists enabled (for IOT devices), allowing only common TopLevelDomains to connect.
  2. We use Quad9 as default DNS (at OS-level) for our Laptops and smartphones (to bypas router TLD firewall restrictions)
  3. Cloudflare Zero Trust Free plan (with malware protection) is used as DOH in browser with custom block page..
Desktop VPN
Proton VPN free for Linux on-demand (out of home). At home I have little use for VPN because our IP and IP location are changed regularly :-).
Password manager
Build-in (OS and Browser)
Maintenance tools
None
File and Photo backup
  • FreeFileSync quick on-demand backups to a partition on my internal SSD to which sandboxed utilities, desktop accessoires and applications have no access to.
  • The half yearly full backup saves to an external USB-SSD which is checked (afterwards) by Microsoft Defender on my wife's laptop (which has triple USB protection).
Subscriptions
    • None
System recovery
TimeShift (to another partition on 1 TB SSD)
Risk factors
    • Browsing to popular websites
    • Working from home
    • Making audio/video calls
    • Opening email attachments
    • Buying from online stores, entering banks card details
    • Logging into my bank account
    • Streaming audio/video content from trusted sites or paid subscriptions
Computer specs
AMD Ryzen 7 (5700U) laptop with 1 TB SSD and 16GB RAM
Notable changes
To many :)

After jumping back and forth, I finally decided for:
  • Changed from ControlD free to Cloudflare free ZT
  • Replaced 7-zip (unsandboxed) with PeaZip in Flatpak
  • Moved from LibreOffice in Flatpak to LibreOffice in Firejail
  • Moved from Thunderbird to Evolution (both in Flatpak sandbox)
  • Moved from Xfce desktop with X11 to Cinnamon desktop with Wayland
What I'm looking for?

Looking for maximum feedback.

Yes, although that doesn't prevent new inactive search engines from being added.
Only Edge has a policy that prevents such automatic additions.
I used this policy successfully in 2024 to ensure that only DDG appeared in the search engine list.
It worked perfectly.

If any forum members are interested, just ask.
and this one
 
Last edited:
I ended up with chrome://flags and switch, these flags are mostly experimental and more you tweak them more you 're unique in fingerprinting, now i just use templates in a json and use regular chromium : ON DEBIAN
Capture d’écran du 2026-06-16 17-29-15.png
 
I ended up with chrome://flags and switch, these flags are mostly experimental and more you tweak them more you 're unique in fingerprinting, now i just use templates in a json and use regular chromium : ON DEBIAN
View attachment 298230
Thanks for joining, care to explain your mysterious nickname? I think the 64 is your year of birth, but now Idea what 7Oz stands for :-)

7 oz stands for 7 ounces, a unit of measurement in the US Customary System that can refer to either weight (for solids) or volume (for liquids),
Common items that weigh or contain approximately 7 oz include a medium apple, a medium cooked chicken breast, a small can of soda, or a standard smartphone.
 
Thanks for joining, care to explain your mysterious nickname? I think the 64 is your year of birth, but now Idea what 7Oz stands for :-)

7 oz stands for 7 ounces, a unit of measurement in the US Customary System that can refer to either weight (for solids) or volume (for liquids),
Common items that weigh or contain approximately 7 oz include a medium apple, a medium cooked chicken breast, a small can of soda, or a standard smartphone.
You're most Welcome
You just find a new Thread to create if not already!!!;)

Ah you give two bad answers, some hints :
64 refer to something in my avatar (soup), and the second one is from India.(solid)
Good Luck!!!