Let me guess. Their kernel malware is going to come to Linux next?
Let me guess. Their kernel malware is going to come to Linux next?
MCU nerds if you didn’t like Infinity Bore
Many desktop Linux distros have poor security defaults. Fedora even disables the restrictions on ptrace by default, which is strange considering the browser sandbox needs ptrace restrictions in order to function properly. Debian and Ubuntu default to apparmor which is very insecure (remember crackarmor?) and Arch has basically no security ootb and the AUR is essentially NEEDED in order to use it for most things, despite how unvetted and messy it is. Kali is not for daily driving, for the record.
I implore you to read SecureBlue’s documentation which is where the bulk of my knowledge has been from. Even Android is not as secure as it could be, there is a reason that GrapheneOS, the pinnacle of Android security, doesn’t even consider their build of Android secure enough.
Well, it’s more so that I wished the open source community wasn’t as averse to implementing a security model that wasn’t heavily reliant on the systems being obscure. Security through obscurity is a horrid way to do such things, but it seems like that’s the way things were done before I got here.
It would be nice to see the vision of the SecureBlue project come through elsewhere in the desktop Linux world, but any time someone so much as hints at fixing the flagrant security issues of something like the AUR, all they get is dismissal and knuckle dragging in response. I’m not a blind shill for corporate products by any means, I just would like for the community to quit treating security as an afterthought, because it’s truly needed if we want to keep the new converts safe from the looming threats that are coming day after day.
Yeah my primary aim is closer to something secure enough to be protected as long as I am careful, but still usable for modern stuff. My desktop setup has finally gotten to a place I like, but mobile has been really difficult for me, and I genuinely wish I had the privilege to get into the GrapheneOS world.
I mean I guess following the messaging of one of the only explicitly security-focused Linux distros is considered “astro turfing” then? Hmm.
secureblue is for those whose first priority is using Linux, and second priority is security. secureblue does not claim to be the most secure option available on the desktop. We are limited in that regard by the current state of desktop Linux standardization, tooling, and upstream security development. What we aim for instead is to be the most secure option for those who already intend to use Linux. As such, if security is your first priority, secureblue may not be the best option for you.
If security is your FIRST priority, they outright say their work is limited. So… that’s where I’m getting it from.
My source is primarily the GrapheneOS team’s praises for how Apple handles iOS, particularly in Lockdown Mode. There was also a recent situation where they warned their users of “mercenary spyware” attacks.
It’s also a position that many in the SecureBlue community would agree with, which is where I’ve learned the majority of my recent security stuff from.
What is a turfblaster? I’m confused but maybe someone can explain that to me
MacOS, iOS, GrapheneOS (and even then, Graphene doesn’t believe themselves to be doing enough due to the fundamental limitations in AOSP)
There is one distro trying, and even they make it clear that they’re bound by the limitations of the Linux desktop’s security model at the moment (SecureBlue).
It is also technically possible to harden Windows to become nearly bulletproof but that usually requires third party software like ThreatLocker.
Year of the Linux desktop when the years of neglecting security comes to bite them
KDE wins again
If only they never caught on
Better software support??? There’s stuff I’m still struggling to replace and I’d rather native linux builds than have to go back for it.