<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Hardening OTBR on Umair's Systems Notebook</title><link>https://umair-as.github.io/blog/series/hardening-otbr/</link><description>Recent content in Hardening OTBR on Umair's Systems Notebook</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 14 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://umair-as.github.io/blog/series/hardening-otbr/index.xml" rel="self" type="application/rss+xml"/><item><title>Hardening OTBR: Reading a 4.1 systemd-analyze Score</title><link>https://umair-as.github.io/blog/posts/otbr-systemd-hardening/</link><pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate><guid>https://umair-as.github.io/blog/posts/otbr-systemd-hardening/</guid><description>Part 1 got OTBR running as a non-root user with three capabilities. Part 2 covers the hardening block in the service file — what each directive does, why one had to be an exception, and how to use systemd-analyze security as a decision tool rather than a score to chase. Part 2 of 2.</description></item><item><title>Running OTBR as Non-Root: Finding the Capability Floor</title><link>https://umair-as.github.io/blog/posts/running-otbr-as-non-root/</link><pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate><guid>https://umair-as.github.io/blog/posts/running-otbr-as-non-root/</guid><description>OpenThread Border Router assumes it runs as root. Getting it down to a least-privilege non-root user means figuring out exactly what it needs — which turned out to be a source code problem, not a trial-and-error problem. Part 1 of 2.</description></item></channel></rss>