CICADA.OS
● LIVE ·

Features

GrapheneOS is the north star for intent. This page lists what Cicada actually ships on a laptop — policy OS on Linux, not Android kernel sandboxing.

Exploit mitigations

RUNTIME
  • mallochardened_malloc (GrapheneOS tag) via ld.so.preload
  • Kernellinux-hardened boot entry + lockdown on that entry
  • Memoryinit_on_alloc / init_on_free on cmdline
  • CETibt + shstk where silicon supports it — not MTE

Permissions

SCOPES
  • DefaultUnknown apps: NETWORK/FILES deny
  • MIC/CAMPer-app deny + system software kill
  • PortalFILES=portal ≈ Downloads + picker
  • VPN-onlyHost net only while wg0 is up

AFU / coercion

LOCK
  • RebootAuto-reboot when locked (default 30 min)
  • USBUSBGuard blocks inserts while locked
  • DuressLUKS slot + session PAM path
  • WatchdogHardware AFU ceiling when present

Browser / network

HELIUM
  • JITOff via managed policy
  • TelemetryOff — sync, metrics, DoH theater cut
  • VPNWireGuard + nftables kill switch (opt-in)
  • MACRandomized; LLMNR/mDNS off

Will not claim

HARD GAPS