Application Sandboxing
- AppBoxes & Flatpaks: AppBoxes (CLI and GUI) and Flatpaks are isolated with Bubblewrap or Firejail, providing lightweight namespace sandboxes that prevent unauthorized access to user data and system files.
- Other Executables: We use AppArmor and Firejail to restrict standard executables’ capabilities. This ensures they operate with the principle of least privilege.
Network Security
- Firewall Management: Nitrux includes Firewalld, which is managed via Cinderward, making it easy to configure traffic rules.
- VPN Support: NetworkManager comes pre-configured with plugins for OpenVPN, OpenConnect, and OpenFortiVPN.
- WireGuard: Nitrux supports WireGuard for high-performance encrypted tunnels, which are managed via Wirecloak or wg-quick, making it easy to select tunnels.
- Encrypted DNS: Nitrux uses dnscrypt-proxy by default, which encrypts DNS queries between your machine and the DNS resolver.
Filesystem Integrity
- Immutable Root: The system core is read-only by default to prevent tampering and ensure stability. However, users can still make persistent changes when needed.
Filesystem Encryption
- Full-disk Encryption: Our Calamares configuration uses Argon2id for LUKS2 key derivation when selecting encryption during the installation.
- F2FS Encryption: Support for creating encrypted directories using fscrypt for user accessible partitions.
Password Management
- KWallet: We use it to securely store and manage system credentials for apps requiring a keyring.
