Skip to content

Split the security-misc into security-misc-shared, security-misc-desktop and security-misc-server #187

@monsieuremre

Description

@monsieuremre

Servers and workstations differ heavily, and there is no universal hardening that is also fine grained for both. A server is inherently a network. This package should prioritize workstations, as kicksecure is meant to be one. I do not support the idea of also being a server system. Firstly, some of hardening already eliminates the possibilty of kicksecure usage on specific server types, like a file sync or an email server might already face problems because of network hardening. They may have gone unnoticed, but this doesn't change the fact. The two reasonable options are:

  • Primarily good option: Forget about servers, do not try to keep support for them universally. This strips us of a very very big area of possible hardening options. If we want to support both, in terms of security, we will be the "jack of all trades, master of none". Nothing would be hardened to its full extend in this case.
  • Secondary, in my opinion the least favorable option, because of the unnecessary work it would require: Split this package in two. One package security-misc-desktop and one security-misc-server. At this point you can choose any other name you like.

But this has to be addressed in the near future, for the project to develop further.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions