security: NixOS systemd hardening regression — restore baseline isolation #51
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
flake.nix:204-223(the installed config) force-disables every hardening flag thebitspire-atm.nixmodule sets sanely:Combined with the Electron renderer running
--no-sandbox(also in flake.nix), if the renderer is ever compromised (XSS via a dependency, Vue templating XSS, etc.) there is currently zero filesystem isolation between renderer and the rest of the system. Thebitspireuser is still unprivileged, but post-compromise the attacker can read/var/lib/bitspire/.env(the nsec stopgap), write anywhere the bitspire user has perms, and access all/dev/tty*and/dev/video*.The override comment cites "Electron sandbox needs unprivileged user namespaces" — true in general, but worth investigating whether:
--sandboxflag (the renderer sandbox, distinct from systemd'sNoNewPrivileges) can be enabled on top of more conservative systemd flags.SystemCallFilter,CapabilityBoundingSet,RestrictAddressFamilies, and read-only/usrcan be combined with the unprivileged-user-namespace requirement.NoNewPrivileges=truewhile still allowing the Chromium sandbox by settingkernel.unprivileged_userns_clone=1and running the renderer with appropriate capability sets.Goal
Find a configuration that satisfies BOTH:
--no-sandbox)./var/lib/bitspire/.env, write outside its sandbox, or escalate.If a full solution isn't reachable, document the trade-off explicitly and add compensating controls:
nftablesegress (only relay + LNbits HTTP)CapabilityBoundingSetAcceptance
--no-sandbox) OR documented why infeasible.ProtectSystem=strict+ProtectHome=true+PrivateTmp=truerestored.NoNewPrivileges=truerestored unless a documented blocker is found./var/lib/bitspire/.envunreadable from the renderer process namespace.References
aiolabs/lnbits#18(bunker) will eventually move the nsec off-disk entirely; this issue is the defence-in-depth that matters until then.