When porting to Jessie we've tried to enable the
hidepid=2 hardening feature but we reverted it as it broke stuff (e.g. #8256). It seems one can make
gid=<gid>mount option for
- possibly some more services need to have
SupplementaryGroups=<gid>, e.g. polkitd; testing will tell
- add the
polkitduser to the
See https://wiki.debian.org/Hardening#Mounting_.2Fproc_with_hidepid for details and possibly more up-to-date info.