http://secure45nbquibuw6thmenrfamhobdkkrllgxrtayn4sgmnexremexyd.onion/guides/linux-hardening.html
Both of these prevent many common TOCTOU races . fs.protected_fifos=2
fs.protected_regular=2 These prevent creating files in potentially
attacker-controlled environments , such as world-writable directories, to make data spoofing attacks more difficult. 2.3 Boot parameters Boot parameters pass settings to the kernel at boot using your bootloader.