security-misc
security-misc copied to clipboard
Use systemd .mount files for stricter mount options and remove remount-secure
The only missing parts of this are the /tmp, /dev/shm and /run restrictions as systemd doesn't seem to like them:
dev-shm.mount: Cannot create mount unit for API file system /dev/shm
https://forums.whonix.org/t/re-mount-home-and-other-with-noexec-and-nosuid-among-other-useful-mount-options-for-better-security/7707/42
https://forums.whonix.org/t/re-mount-home-and-other-with-noexec-and-nosuid-among-other-useful-mount-options-for-better-security/7707/45
Stalled.