DaDesktop is developed and maintained entirely in-house by NobleProg Tech. Any issues are resolved by our dedicated internal team comprising Security Ops, Developers, and DevOps specialists. Access to the core DaDesktop system is restricted exclusively to NP Tech staff.
NobleProg holds full access and rights to utilize and modify all source code.
Redundancy and Failure Recovery
Trainers and users have the option to replicate the entire real-time desktop environment via the 'remote replica' feature.
During experimentation, automatic snapshots of the desktop can be enabled. Should a crash occur, the system can instantly restore the last stable version.
Servers are hosted in redundant data centers. In the event of a data center failure, alternative facilities with low-latency connectivity remain available to ensure continuity.
The DaDesktop infrastructure leverages multiple data centers located globally, all adhering to rigorous physical and IT security standards.
DaDesktop utilizes QEMU/KVM for creating and running virtual machines. As both QEMU and KVM are native components of the Linux operating system, security updates are streamlined and rapid, eliminating reliance on third-party dependencies. QEMU/KVM boasts an exceptional security and performance track record, surpassing many commercial solutions.
At NobleProg, a zero-trust policy is implemented
Access to NobleProg and DaDesktop systems is restricted to NP Tech staff with pre-registered IP addresses. IP table firewall rules are enforced to block unauthorized access via SSH and other ports.
Two-Factor Authentication and password protection secure each system. Consequently, an attacker possessing only a password cannot gain access, as their IP would not be whitelisted and they would lack the required One-Time Password.
In DaDesktop courses, each desktop network is isolated from other desktops and public internet access.
All NobleProg staff use a Multi-Factor Authentication (MFA) system to log in to NobleProg or DaDesktop systems. Access rights are revoked immediately upon an employee's departure to prevent unauthorized access.
Linux Hardening
DaDesktop server systems are optimized by installing only essential packages on a custom, stripped-down version of Ubuntu maintained by NobleProg. This approach reduces complexity and overhead, resulting in fewer security vulnerabilities due to fewer running packages and services. The standard installation footprint for each DaDesktop server node is typically only 250MB.
SSH access to the 'root' account is disabled.
The DaDesktop infrastructure is based on the latest stable version of Ubuntu Linux, with automatic upgrades and patching to mitigate the risk of zero-day vulnerabilities.
Servers are continuously monitored for known vulnerabilities.
Unused packages and files are regularly removed.
NobleProg retains access to all source code used in the project. In the event of a vulnerability where a patch is unavailable, the NobleProg security team can implement a fix immediately.
Systems are updated automatically via unattended-upgrades.
Any connections from our servers to the dark web are monitored and can be automatically blocked.
Monitoring
NobleProg monitors all servers, including those hosting DaDesktop, generating alerts for any issues requiring attention. These alerts are diligently followed up and resolved. Regular reviews of alerts and issues are conducted to ensure comprehensive resolution and prevent recurrence.
All DaDesktop servers and trainer/participant machines are monitored for CPU, memory, and network activity. Additionally, DaDesktop nodes and the underlying system are checked for CVEs, which trigger flags in the monitoring system for review. While security updates are typically applied automatically, any exceptions are manually patched, or additional mitigating measures are implemented as needed.
Automatic recordings are captured for Fresh Start machines during courses, allowing Trainers to verify any issues during preparation. Optional recordings of the Trainer machine and Training Room can also be enabled during sessions. This feature is fully controllable via the UI and can be disabled if not required.
DaDesktop Operating System Templates are updated every few weeks, incorporating the latest security updates.