Advanced Plus Security Victor M Fedora 44 KDE Configuration

Last updated
Jun 6, 2026
Main use of this computer
For work or educational use
Operating system
Linux
On-device encryption
Other full-disk drive encryption software
Device sign-in security
    • Hardware security key
    • Account password
Security updates
Allow security updates
Update channels
Allow stable updates only
User Account Control (UAC)
Not applicable - not running Windows
Smart App Control
Not applicable / not available on this device
Network firewall
Enabled
Real-time protection
SELinux daemon & browser & user profiles
Systemd hardening
Firewall-cmd
Device firewall
Built-in Firewall for Mac/Linux
Custom security settings
SELinux daemon & browser & user profiles
Systemd hardening
Blacklisted unused network protocols
Firewall-cmd set to zone=drop
Seperate user_u confined account for daily use
Procedural security control forbids admin acc browser use.
Sudo command and logins require Yubikey
Browser policy foribds extensions
Browser policy disables javascript jit
Periodic malware scanners
clamav
Malware sample testing
I do not participate in malware testing
Environment for malware testing
n/a
Browsers and extensions
n/a
Secure DNS
quad9
Desktop VPN
ProtonVPN
Password and passkey manager
keepass
File and photo backups
file copy
Subscriptions
    • Google One Premium 2TB
System recovery
Clonezilla
Usage and exposure
    • Visiting familiar websites
    • Working from home
    • Making audio/video calls
    • Online shopping and card payments
Computer specs
Dell Latitude
Feedback preference

Detailed suggestions and alternatives welcome

I have switched from Firefox to Brave because of Chromium's stronger sandbox reputation. But Claude said it also has the highest concentration of hackers targeting it, because, well it is Chrome with it's massive user base. But I know my red team was targeting Firefox. So this is a change of scenery for them. And I should have done the right things like restricting extensions to none via policy, and disabling the much hacked javascript jit. And Brave is said to follow Chrome updates very closely, unlike Chromium. Leaping from the pan into the fire.
 
Last edited:
Asked ChatGPT about persistence techniques in Fedora and it spun out a 126 items list. A good part of it applies to the case whete the attacker gained root. ( I dearly hope not ) So I asked chat to generate a script to lock all the user mode persistence locations. And I applied it to my standard user account and it even backed up the existing and cleared out every location. Some ksmserverrc compllained that a spot was no longer writable when I logged in. But on the whole it is working. Good old chatgpt. The lockdown was simply preventing writing to user startup locations. ( the main thing was chattr +i, which makes that folder or file immutable). There are many folders and filies. ( remember Linux doesn't have a registry )
 
Last edited:

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top