Field Notes

source

Kicksecure security features documentation

Comparison with others. About.

Two Kicksecure wiki pages providing a comprehensive feature-by-feature comparison against upstream Debian and an overview of the project’s design philosophy.

The comparison page catalogs dozens of hardening features Kicksecure applies by default that Debian does not, organized across five categories: account and privilege management (user-sysmaint-split, permission lockdown, libpam-tmpdir), package and binary hardening (SUID disabler, minimal default packages, HTTPS APT sources, security-misc), network security (Tor-routed updates, tirdad TCP ISN randomization, sdwdate secure time, no open ports, Bluetooth hardening, hardened SSH), encryption and data protection (strong entropy, FDE by default, ram-wipe, crash artifact reduction), and system hardening (kernel hardening via KSPP-aligned sysctl settings, strict CPU vulnerability mitigations, kernel module blacklisting, recovery mode lockdown). Build integrity features include a digital signature policy at all development stages and a Warrant canary.

The about page describes Kicksecure as a hardened Debian implementing the Securing Debian Manual by default, supplemented with original research. It is available as an ISO for bare metal, as VM images for multiple hypervisors, and as a live mode with anti-forensic properties. Kicksecure 18 is based on Debian 13 (Trixie) and serves as the base for Whonix.

These are primary-source project documentation maintained by the Kicksecure/Whonix team. The comparison is inherently self-referential and should be read alongside independent assessments.

Built on 2 sources (2 external).

Working out connections…