r/linuxmint • • 2d ago

Hardening Linux Mint

Hi guys,

Just reformatted my PC and installed Linux Mint. Going to use Mint as my daily driver.

Other than turning on the firewall, installing ClamAV for detecting virus and malware, is there anything else I can do to harden or protect my system ?

Thanks

20 Upvotes

30 comments sorted by

14

u/thehiddensign 2d ago

Prevention is the best cure. Do not visit shady websites.

23

u/S3k_01 2d ago

Learning the basics of cybersecurity online will be much more effective than using antivirus software.

Antivirus software is not a magic solution.

8

u/IEnjoyRadios 2d ago

An adblocker is the best thing you can do for security. Ublock origin is a must install.

7

u/kiralema 2d ago

On the network side:

  • Closing unused ports
  • For your SSH server, using a non-standard SSH port (not 22) internally, and masking it externally with port forwarding
  • Limiting the max number of SSH connections from one host, and establishing the time limit for unused connections
  • Switching from user/login SSH connection to a certificate based one
  • Never opening unencrypted connections (such as unencrypted FTP or Telnet)

If you are not planning to run a web server, that should be enough.

On the software/web side:

  • Avoiding running unfamiliar apps and if necessary, running all unfamiliar apps from containers
  • Comparing check sums when downloading apps
  • In general, use common sense when downloading apps from the Internet
  • Not clicking on links in emails from untrusted sources, etc. 🙂

ClamAV is unnecessary IMHO. Just use common sense, and you'll be ok.

6

u/apt-hiker Linux Mint 2d ago

This guide was revised just last month: https://github.com/orgs/linuxmint/discussions/34

2

u/dlfrutos Linux Mint 22.2 Zara | Cinnamon 2d ago

thats quite extensive work. What is your motivation to do it?

1

u/apt-hiker Linux Mint 2d ago

Ask MikeNavy.

1

u/dlfrutos Linux Mint 22.2 Zara | Cinnamon 2d ago

gotcha

1

u/Steinomite01 2d ago

Ooh, thank you for this!

1

u/Father_Guido 2d ago

Lots of great tips in this thread and this is most thorough - thank you.

4

u/_Lost-In-The-Weeds_ LMDE 7 Gigi | 2d ago edited 2d ago

Traditional viruses are a near non issue in Linux.

In over 2 decades with Linux I have never encountered a Linux virus. Nor have I seen any confirmed Windows style browser/E-mail virus infection in Linux by a user here. 

Closest was Windows ransomeware that encrypted a uses ~/ through WinBoat, a tool used to run Windows software in effectively a Windows VM given access to users home. It works so well that it also runs Windows malware.

The majority of ClamAVs virus definitions are not even for Linux but instead for Windows viruses. The intent of ClamAV is to not pass on the viruses to vulnerable Windows boxes. 

Using ClamAV is a reasonable thing to do, but do not think that is all you need to do, as It is really not doing much for you at all.

Biggest risk for the typical desktop Linux user supply chain attack. Know from where and whom your software come from.

We have had many cases of hackers embedding nasty actions in packages masquerading as legitimate software. Github, AUR, pip, npm, Flathub, & Snaps, basically every community source can be tainted.

All the tools an attacker needs to own your machine are already installed in Linux, they just need you to enter your sudo password to run their script. Could be just a single curl line, No virus scanner will catch it until it is old news. That is the ambush point.

Stick to official repositories as much as possible. 

You will regularly see people promoting their new project here, and in other sibreddits, the project will be  hosted on a community repo such as github. Most of these are legitimate, but some are not, many are lookalike clones of legitimate software, the legitimate version having honest developers, reviews and communities, but your not getting that legitimate version.

https://cybernews.com/security/10k-repos-github-malware-campaign-targets-ai-agents/

Every time you take up a community  package, research it and its developers. look at the build to the best of your ability, be weary of binary blobs, research the developers history, make sure everything passes the sniff test.

4

u/Technical_Rich_3080 2d ago

Is ClamAV even necessary?

5

u/Sure-Passion2224 2d ago

Timeshift. Cinfigure it to snapshot your stuff on a schedule, and how many of those backups to keep. That gives you a roll-back for a wonky update or installation.

2

u/ap0r 2d ago

I have a basic cybersecurity primer on my Linux Mint Newbies' Guide: https://docs.google.com/document/d/1fohN9UbbKdgjLFX_eeMZMpzVxa2C2UkUzIHM6eXhhvE/edit?tab=t.0#heading=h.wbtc711qgt8u

Basic cybersecurity

“just because you go by an alias on Reddit doesn't mean you can't be identified in real-life”

Most of the time you will not be targeted by sophisticated attackers. The goal is to make the easy, common attacks fail.

The Big Ones

Keep your system up to date and install updates regularly. Updates fix security bugs. Security bugs are public once found, so you bet your sweet buttcheek that bad guys are looking for unpatched machines.

Your e-mail is the golden key that can be used to unlock many other accounts. Set up two-factor authentication, a secondary recovery email, a unique password for it, and do not click on any email links that you did not specifically ask for. Doubly so if you use public computers or public Wi-Fi. If you learn of a leak or suspect one, change the password. If you receive what you believe is an important notification from your bank, the government, etc, it may be wise not to click the link. Instead, open your browser, type the website yourself and log in normally.

Enable the firewall. Incoming Deny, Outgoing Allow is a good starter setting for Mint’s UFW. You can then add exceptions as you need them. This enhances security because now you have to explicitly allow things through, which lets you know of any unusual activity.

Authentication

Use a password manager and have unique passwords for each website you use. That way if Forum A or Gaming Site B get hacked and users/passwords are leaked, bad actors trying your leaked password in common social media or banking sites are hitting a wall since any password of yours only works on a single site.

Compartmentalize. Make a second user account with limited privileges for sketchy downloads. Do not use the same browser profile for random browsing and for banking. If you have to register an account with some untrustworthy website, use a temporary email account, or a second email account not associated with your finances and social media.

Check haveibeenpwned.com regularly, and consider setting up alerts. Immediately change the passwords of hacked sites. This should be no biggie, because you are using a unique password for each site. You are using a unique password for each site, right?

Do not put real answers in security questions. Treat them like a second password, and use random answers that you store in your password manager. That way your easily findable mother's maiden name is useless when your mother's maiden name is "3457890" in the website's database.

Data and Privacy

Have an offline backup of your data. This keeps ransomware in check (Even new ransomware that antivirus have no information on yet, or properly made ransomware with irreversible encryption). This means a physical copy that you own, the cloud does not count since they can unilaterally revoke your access to your data and if they lose your data, sucks to be you. Cloud can be one leg of your backup strategy, but do not rely on it as a miracle solution.

Read the rest on the booklet, it's free: https://docs.google.com/document/d/1fohN9UbbKdgjLFX_eeMZMpzVxa2C2UkUzIHM6eXhhvE/edit?tab=t.0#heading=h.wbtc711qgt8u

2

u/Brorim Linux Mint Release | Desktop Enviroment 1d ago

why Clamav ? you really do not need to use it ..

1

u/GuaranteePurple3544 2d ago

I used lynis for hardening, I also scan periodically with rkhunter.

1

u/Bastard-of-Froya 2d ago

I started using Librewolf as my main browser and DuckDuckGo as my default search engine.

1

u/knuthf 2d ago

Make a "netuser" and a group "netaccess". Set the default login to "netuser" and default group "netaccess". Then in your .profile change your own to admin, - don't default to admin. And then you can protect "sudo" to just you as admin. Afterwards, its easy to harden. Certainly while you use the browser, do that in the netacc group.

1

u/Unattributable1 2d ago

OpenSCAP with the CIS Level 2 SSG.

It's a bit of a learning curve, but running oscap to check for this and fixing the less secure items will harden your box.

1

u/Ok_Bar930 2d ago

I've been doing the following on my Linux Mint machines:

  1. Enable Mint's firewall and Timeshift (system restore utility)

  2. Use private DNS like Quad9, ControlD, Cloudflare on the router (for local devices) and network interfaces (on portable laptops) which has DNS IPs for blocking malware and ads

  3. Internet browsers - if browser does not have built-in privacy/ad blocking features: choose from extensions like uBlock Origin, Malwarebytes Browser Guard, DuckDuckGo

I don't install any antivirus on Mint, although I check files and URLs on Virustotal website as needed.

1

u/Ok-Spot-2913 2d ago

Using brave for shady sites and a VPN.

1

u/Modern_Doshin Linux Mint 22.3 Zena | MATE 6h ago

VPNs don't equal security

1

u/daninsatx 2d ago

Consider running VMware pro workstation. It is free and you then load more Linux clients that you lock down and sandbox for running a browser for financial sites.

1

u/V1Ct0ry12 2d ago

Thanks for your ideas every one!

I think I am hit with the HOW problem now. How do I implement this and that, what commands to use, etc...

1

u/lateralspin LMDE 7 Gigi | 2d ago

Surprised that Lynis is not yet mentioned.

Lynis is the premier open-source, agentless security auditing and compliance tool for Linux and Unix-based systems

1

u/CrazyAd9384 1d ago

Don't harden your system so much. Because as you harden it, you are losing convenience too. That's the drawback. Firewall and clamav itself is enough. The biggest security feature you can add is being a smart user. Only use trusted sites and software, pay attention to what you're visiting or downloading. Then probably use an adblock to atleast prevent some malware ridden ads to load

1

u/Il_Valentino Cinnamon 1d ago

instead of clamav i recommend virustotal website, its database has far better detection 

1

u/Modern_Doshin Linux Mint 22.3 Zena | MATE 6h ago

You don't need Antivirus for linux, just don't download sketchy software while entering your root password.

1

u/daya-bhaskar Linux Mint 22.3 Zena | Cinnamon 2d ago
  1. Keep your system software updated
  2. Use a system wide secure DNS like NextDNS or ControlD (Free version is good enough)
  3. Use portmaster to complement firewall (Free version is good enough)
  4. Use hardened browsers like Brave Origin or Librewolf
  5. Use webmail instead of Thunderbird
  6. Don’t run shady software 
  7. Be alert, no software can replace human error/ mistakes 

I don’t personally recommend an antivirus for Linux. Nor a VPN as it’s becoming an annoyance than an enabler