DaDesktop is developed by NobleProg Tech completely in-house, with maintenance and development handled internally. Any issues are addressed by our dedicated team of security operations, developers, and DevOps professionals. Only NP Tech personnel can access the core DaDesktop system.
NobleProg holds full access rights and permission to use and modify all source code.
Redundancy and Failure Recovery
Trainers and users can mirror the entire desktop in real time via the 'remote replica' feature.
While experimenting, you can enable automatic snapshots of a desktop. In the event of a crash, the system can restore the last working version.
Servers are kept in redundant data centres; if one fails, another is available with minimal latency.
The DaDesktop infrastructure makes use of several data centres situated worldwide, all protected by comprehensive physical and IT security policies.
DaDesktop uses QEMU/KVM to create and run virtual machines; both are built into the Linux operating system. Because they are integral components of Linux, security updates can be rolled out very easily and quickly – there’s zero reliance on third parties. QEMU/KVM boast a stellar security and performance record, outperforming even commercial solutions.
Zero-Trust Policy at NobleProg
Access to NobleProg and DaDesktop systems is granted only to NP Tech employees whose IP addresses are pre-registered. IP tables firewall rules are employed to block SSH and other ports for any unauthorised traffic.
Every system is secured with two-factor authentication and a password. Even if an attacker steals a password, they still cannot access the system because their IP isn’t whitelisted and they lack the one-time code.
During a DaDesktop course, each desktop network is isolated from other desktops and from public access.
All NobleProg staff use a multi-factor authentication system to log into NobleProg or DaDesktop. If a team member leaves, their access is immediately revoked to prevent any unauthorised access.
Linux Hardening
DaDesktop server nodes run on a custom, stripped-down Ubuntu version we build and maintain, containing only the necessary packages. This lean setup reduces complexity and overhead, resulting in fewer security holes and fewer active services. Typically, a DaDesktop server node uses only about 250 MB of disk space.
Direct root login over SSH has been disabled.
Our infrastructure relies on the latest stable Ubuntu Linux release and is regularly patched and upgraded automatically, thus lowering the risk of zero-day vulnerabilities.
Servers are continuously monitored for known vulnerabilities.
Any unused packages and files are taken out.
NobleProg has full access to every piece of source code in the project. Should a vulnerability emerge and no official fix be available, our security team can patch it right away.
Systems are updated automatically via unattended upgrades.
All outbound connections from our servers to the dark web are watched and can be blocked automatically.
Monitoring
NobleProg monitors all of its servers, including DaDesktop infrastructure. Alerts are created for any issues, followed up, and resolved. We periodically review alerts and issues to make sure each one is fully addressed and does not reappear.
We track CPU, memory, and network activity across all DaDesktop servers and the machines of trainers and participants. Furthermore, DaDesktop nodes and the core system are scanned for CVEs, which trigger alerts for inspection. Usually security patches are applied automatically, but if the monitoring system flags something unusual, we patch it manually or apply other mitigations.
Recordings of Fresh Start machines are automatically captured during courses, making it easy to review any issues when a trainer prepares a session. Optionally, recordings of the trainer’s machine and the Training Room can be made during a class. This is completely configurable through the UI and can be turned off if not needed.
DaDesktop operating system templates are refreshed about every two weeks, always with the latest security updates included.