Hardened. Locked down. Still fully alive.
A LAN-isolated, WAN-only hardening of Fedora Workstation 44. 40 modules layer defense across kernel, network, identity, integrity, firmware and browser โ LUKS2 encryption, SELinux enforcing, auditd, AIDE, USBGuard and a VPN killswitch โ in one reproducible-from-source ISO. Hardening is additive: Flatpak, NetworkManager, Firefox + uBO and a ready VSCodium + Claude Code workspace stay intact.
๐ x86_64 ยท UEFI + Secure Boot ยท TPM 2.0 โข GPL-3.0 โข reproducible from source
๐ Verify your download
A hardened OS is only as trustworthy as the file you booted. Always check the GPG signature and the checksum before writing the ISO to a USB stick.
Release signing key fingerprint:
1ACB FCE4 9687 FEBB 9101 0E52 F8E3 F11D 6962 256F
The signature proves the checksum file really came from NoID Privacy (not a tampered mirror or a compromised host); the checksum then proves the ISO is byte-for-byte intact. Both must pass.
๐ฐ What You Get
Defense layered across the whole stack โ on by default, with Snapper rollback for covered root-system state
Substantially reduces attack surface โ a pragmatic hardening tier, hardened by default while you stay in control. NoID, not ParaNoID: privacy + surveillance-resistance on any network you join, not state-level anonymity.
๐ค AI-Agent-Ready Workspace
Built for the people who live in a terminal + IDE + AI-agent loop โ opt-in, telemetry-off, local-AI capable
๐ How It Compares
A different optimum โ privacy, security, documented recovery boundaries and usability
| Feature | NoID Privacy WS 44 | secureblue | Kicksecure |
|---|---|---|---|
| Base | Fedora Workstation (mutable) | Fedora Atomic (immutable) | Debian (reconfigured) |
| Untrusted-LAN isolation | โ block-lan-out + ARP | โ | โ ๏ธ partial |
| File integrity (AIDE daily) | โ | โ | โ |
| Root-system rollback | โ Snapper; documented exceptions | โ ๏ธ image-mode | โ |
| AI-agent workspace | โ Claude Code + VSCodium | โ | โ |
| Default browser hardening | โ Firefox + arkenfox + uBO | โ Trivalent (Chromium) | โ ๏ธ Firefox-ESR |
| Hardened memory allocator | โ deliberate (Firefox-incompat) | โ hardened_malloc | โ deprecated upstream |
| Gaming (one-toggle) | โ Gaming-Mode | โ ๏ธ clunky | โ ๏ธ not oriented |
secureblue and Kicksecure are excellent, deeper on raw prevention primitives. NoID Privacy is the recovery-aware, auditable, AI-ready daily-driver with privacy co-equal to security โ and LAN-isolation + daily file-integrity that neither ships by default.
โ๏ธ Requirements
A modern UEFI + TPM 2.0 machine
Same speed. More privacy. Less heat. More free RAM.
Not for: ARM / Raspberry Pi ยท non-UEFI hardware ยท multi-user / family systems (LAN-iso blocks shared services) ยท enterprise AD / LDAP. Not a replacement for Tails / Whonix anonymity or Qubes VM-isolation.
๐ง Already inside the image: NoID Privacy for Linux
Workstation 44 ships with the NoID Privacy for Linux audit built in โ the same read-only, zero-dependency Bash auditor that also runs standalone on any distro (Fedora, Ubuntu, Debian, RHEL). On Workstation it runs out of the box; everywhere else it's one curl command.
Pre-installed on Workstation 44 (just run noid-privacy-linux.sh --ai). On any other distro โ one command:
โ Frequently Asked Questions
Is NoID Privacy Workstation 44 affiliated with Fedora or Red Hat?
No. It is an independent derivative built on Fedora Workstation 44 โ not affiliated with, endorsed by, or sponsored by the Fedora Project or Red Hat. "Fedora" is a registered trademark of Red Hat. NoID Privacy ships its own hardening, branding, apps and a reproducible-from-source kickstart recipe.
How is it different from secureblue or Kicksecure?
NoID Privacy balances privacy, security and daily usability. Snapper covers supported root-system state; it does not restore storage layout, LUKS provisioning, Secure Boot enrollment, firmware or /home, which need separate recovery.
Is NoID Privacy Workstation 44 really free?
Yes. The build code is GPL-3.0-or-later and the ISO is a free download. It ships zero OS telemetry, is reproducible from source, and keeps the entire disable-list in the open kickstart tree so you can audit every change yourself before installing.
Will the hardening break my daily-driver workflow?
Hardening is additive. GNOME 50, Flatpak, NetworkManager and Firefox + uBO stay intact; Bluetooth, camera, microphone and location are one-toggle opt-in; and an opt-in Gaming-Mode relaxes the two real blockers for Steam/Proton while SELinux stays enforcing.
Does it include the NoID Privacy for Linux audit tool?
Yes. The read-only NoID Privacy for Linux audit (noid-privacy-linux.sh --ai, 420+ checks across 42 sections) is built into the image and runs out of the box. The same single Bash file with zero dependencies also runs standalone on any other Linux distribution. Optional leak-tests contact third-party endpoints โ skippable with --skip.
๐ Complete Your Security Ecosystem
Workstation 44 is the hardened OS in a family that spans every platform. Same philosophy everywhere: You own your system.
Ready to harden your daily driver?
40 modules. LUKS2 + Secure Boot. Zero telemetry. Reproducible from source.
โฌ Download NoID Privacy Workstation 44