secure-os.org
All guidesQubes OSTailsWhonixHardened LinuxDisk encryptionThreat model

secure-os wrote

Linux Hardening in 2026: The Threat-Model-First Guide

Jun 12, 2026 in linux, hardening, sysctl — A practical Linux hardening guide built around threat models, not checklists. Covers sysctl, AppArmor, SELinux, kernel parameters, and verified boot — with clear explanations of what each measure actually protects against.

Read more…
📅 8 min read🛡️ Threat-model-first

Operating systems

Qubes, Tails & Whonix

Which secure OS fits which threat model — compartmentalisation vs amnesic vs Tor-routed.

Read the guides →

Encryption

Full disk encryption

LUKS, BitLocker, FileVault and VeraCrypt — what each protects, and what it does not.

Read the guide →

Hardening

Threat-model-first Linux

Practical hardening built around the adversary you actually face.

Read the guide →