MAS

Privacy and security options

These are the toggles on the installer's privacy screen. All are on by default.

Option What it does
DNS-over-TLS Encrypts your DNS lookups
MAC randomization Uses a different network hardware address each boot
nftables default-deny Firewall that blocks incoming connections unless allowed
Disable mDNS/Avahi Stops the system announcing itself on the local network
Unattended security updates Installs security fixes automatically
Cloudflare NTP Sets the clock from Cloudflare's time server (time.cloudflare.com)
zram swap Compressed swap in RAM instead of swap on disk
earlyoom Frees memory before the system freezes when RAM runs out
AppArmor enforced Confines programs with Debian's AppArmor profiles
btrfs snapshots Sets up snapper so you can roll back

Sandboxing (optional)

Off by default. It installs firejail so you can run apps in a sandbox, for example firejail firefox-esr. You can add it later.

Snapshots

sudo snapper -c root list          # see snapshots
sudo snapper -c root create        # make one now
sudo snapper -c root rollback N    # go back to snapshot N, then reboot

Test a rollback on a fresh install before you depend on it.