Releases: Obscurix/Obscurix
Releases · Obscurix/Obscurix
Obscurix v0.3.1-alpha
Obscurix v0.3.1.
This is alpha software. Don't rely on it for strong anonymity yet.
Changelog:
- Xpra is used for X11 sandboxing to isolate X windows from each other
- Other sandboxing improvements
- Removed more setuid/setgid bits from binaries to reduce attack surface
- Updated Tor Browser to 9.0.2
- Updated everything else
- Disabled memdisk as it's broken with linux-hardened due to CONFIG_DEVMEM=n
- Minor bug fixes/improvements
SHA512:
1fcb19807290d4c46f03f4e78a373f080c5ebc6ae569a557a8447044b81b82e9a80b45033ec02601178ddce9f03ab97aec25bbb5be68987e469010c91e9bc3e6 Obscurix-0.3.1-x86_64.iso
Obscurix v0.3-alpha
Obscurix v0.3.
This is alpha software. Don't rely on it for strong anonymity yet.
Changelog:
- Now uses linux-hardened instead of the vanilla kernel
- Stronger sandboxing (seccomp, stricter rules etc.)
- Added a delay of 5 seconds between failed login attempts to try to stall bruteforce attempts
- I2P/Freenet sandboxes and AppArmor profiles
- Removed the
installi2p
andinstallfreenet
scripts. I2P/Freenet are now installed in the build script. - Disabled PXE to reduce attack surface.
- Added a hardened GPG configuration file
- Configured GPG and time sync for stream isolation
- Fixed the thunderbird user.js
- Installed the thunderbird enigmail extension by default
- Added an error when trying to use
su
orsudo
without therootpw
boot parameter - Mounted /tmp, /dev/shm, /var, /boot and /home with stricter mount options such as
nosuid
,nodev
andnoexec
- Added
oops=panic
as a boot parameter for better security - Installed veracrypt and checksec by default
- Set the default rootfs size to 3G so Freenet works reliably
- Pacman now uses scurl to prevent https downgrade attacks
- Added an update checker
- Minor bug fixes/improvements
Obscurix v0.2-alpha
Obscurix v0.2.
This is alpha software. Don't rely on it for strong anonymity yet.
Changelog:
- Fix ip6tables and pacman mirrors
- Added scurl for secure file downloading
- Added onioncircuits to view Tor circuits
- Installed electrum, keepassxc and youtube-dl by default
- Improved/added more sandboxing and AppArmor profiles (for Tor, I2P, Zeronet, onion-grater etc.)
- Enabled ALSA by default for audio although the AppArmor profiles do not yet grant audio access
- Disabled broken cjdns sandboxing
- Made sudo always ask for a password for better security
- Fixed iptables to allow Freenet/I2P traffic properly
- Updated Zeronet to 0.7.1
- Updated Tor Browser to 8.5.5
- Installed kloak to anonymize keystrokes
- Minor bug fixes/improvements
- Started signing commits
Obscurix v0.1-alpha
Initial release of Obscurix.
This is alpha software. Don't rely on it for strong anonymity yet.