If you don't know what kernel parameters are and what do they affect, it's likely safer to go with all the mitigations enabled by default :-|
Appreciate sharing the gist though!
If you don't know what kernel parameters are and what do they affect, it's likely safer to go with all the mitigations enabled by default :-|