I all,
FOG and security is a concern to me either.
As I understand it securing FOG means securing TFTP, and that sounds somewhat like a dead-end. For sure some cutomization of the server's passwords, firewall, SSH conf, Web server conf and other confs I don't know would help, but FOG will remain unsecure in an unsecured environnement. As far as you can't control the devices on the subnet it will go down sooner or later.
I'm intending to go for some tests in the next months on a scalable fog architecture and I'll tell you if I got some clues, not a linux specialist neither. One move could be to shorten the live cycle of the server, reduce is output capacities to minimum and secure the image delivery, I mean ensure that distributed images and pxe images are not corrupted, may be by using FOG as a one way only cloning device and placing file rights as to. AppArmor profile could be some help too, maybe.
I'll focus on the basic security in my attemps as my main concern for now is using on a fixed unalterable DHCP's lan by testing some alleged "proxy DHCP" capabilities of dnsmasq 2.49. Would like to hear about that if some one knows over here.
Untill know tested a FOG server only in lab lan, good and efficient work, out of the box and ready to mass-clone but DRBL sounds more convenient in this situation. FOG server, to me, is more a head for a 10/100 controled devices lan, small closed cells like classrooms or labs. For a windows devices management on a big open LAN and AD I'd think RIS/WDS or some win embeded technology.