Privacy and security options
These are the toggles on the installer's privacy screen. All are on by default.
| Option | What it does |
|---|---|
| DNS-over-TLS | Encrypts your DNS lookups |
| MAC randomization | Uses a different network hardware address each boot |
| nftables default-deny | Firewall that blocks incoming connections unless allowed |
| Disable mDNS/Avahi | Stops the system announcing itself on the local network |
| Unattended security updates | Installs security fixes automatically |
| Cloudflare NTP | Sets the clock from Cloudflare's time server
(time.cloudflare.com) |
| zram swap | Compressed swap in RAM instead of swap on disk |
| earlyoom | Frees memory before the system freezes when RAM runs out |
| AppArmor enforced | Confines programs with Debian's AppArmor profiles |
| btrfs snapshots | Sets up snapper so you can roll back |
Sandboxing (optional)
Off by default. It installs firejail so you can run
apps in a sandbox, for example firejail firefox-esr. You
can add it later.
Snapshots
sudo snapper -c root list # see snapshots
sudo snapper -c root create # make one now
sudo snapper -c root rollback N # go back to snapshot N, then reboot
Test a rollback on a fresh install before you depend on it.