Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Customized ISO distribution of SD Application and Monitor servers #1532

Closed
msheiny opened this issue Jan 25, 2017 · 1 comment
Closed

Customized ISO distribution of SD Application and Monitor servers #1532

msheiny opened this issue Jan 25, 2017 · 1 comment

Comments

@msheiny
Copy link
Contributor

msheiny commented Jan 25, 2017

Since we are already tightly controlling the OS experience through ansible policies on first playbook install I think we should invest more time to move some of the logic upfront during the install process. We should maintain our own spin of Ubuntu with baked in:

  • SecureDrop GPG key and repos already in place
  • Basic security hardening tasks in place
  • Strip out all non essential software for SD
  • Automate as much of the install process as possible
  • bad-ass ASCII art and customized ISO bootup logos

You could also make the argument (though I'm not really) that the gap between vanilla Ubuntu install and SD install is a vulnerable time for exploitation. We have no idea where administrators will stage these servers. It could have been set up in a relatively insecure network and then moved to an isolated location for the SD installation piece. In other words, this would close the gap of exposure between Vanilla Ubuntu and hardened SD configuration.

Now when I say maintain our own distro ... I mean take the stock upstream Ubuntu/Debian and sprinkle in our bits. I don't advocate that FPF gets in the OS shipping business and I feel there is a distinction here with what I'm proposing.

@eloquence
Copy link
Member

Given the effort and complexity, we're unlikely to implement this; in any event, we'll want to consider server OS alternatives first (#5517). Closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants