OpenBSD hardening Ottimizzazioni (2/4) securelevel (/etc/rc.securelevel) 2 Highly secure mode - all effects of securelevel 1 - raw disk devices are always read-only whether mounted or not - settimeofday(2) and clock_settime(2) may not set the time back- wards or close to overflow - pfctl(8) may no longer alter filter or nat rules - the ddb.console and ddb.panic sysctl(8) variables may not be raised ddb.panic=0 (not use ddb kernel debugger and reboot)