30
Try Immutable Mode with openSUSE Leap 16.1 RC
(news.opensuse.org)
openSUSE is an open, free and secure operating system for PC, laptops, servers and ARM devices. Managing your emails, browsing the web, watching online streams, playing games, serving websites or doing office work never felt this empowering. And best part? It's not only backed by one of the leaders in open source industry, but also driven by lively community.
As someone that is not really interested in immutable distros, what is the use case here when btrfs covers the quick and easy rollback part already?
The root filesystem is mounted as read-only. Attackers can't write to or modify it.
Bingo.
I'd say use cases are home users sure but it would be even more appreciated in schools and offices. In those scenarios you're more likely to worry about security concerns than an end user accidentally borking something and having to revert.
Followup question, how do system files get patched if its mounted as RO?
Only the running system is read only, not everything. You simply boot into a new version when updating. If the new image fails, it boots into the old snapshot (i haven't seen this in practice on opensuse aeon because it did not yet break)
@illusionist
Reminds me of the old joke about Windows. "A new mouse position has been detected, please reboot your computer for this changes to take effect.."
@slazer2au
Thank you! Does that mean you have to reboot every time you update something?
Yes, or you just let it do automatically and don't even know that it updated in the background.
os wise. software is in a different partition.
No, the root system being read only is not a security benefit. Attackers (with root or a root exploit) can remount as read only, or remove the immutable bits on files.
In addition to that, thinks like /var usually contain persistent state which can be written to, even on an immutable system
Now, an attackers changes to the root filesystem would probably be overwritten on the next image upgrade. Although better is impermeance, where the root filesystem is generated from config files on boot (NixOS can do this). That is better because now the system is wiped every boot, however it runs into some of the same issues: an attacker with root can modify the update mechanism, or the persistent config files.
While I would say that an immutable system offers practical security benefits, in that most existing Linux malware probably is designed for an orthodox system, it doesn't offer theoretical security benefits. It's just security by obscurity that will probably wane if/when immutable distros get more popular.
I can't get into a discussion about something I know too little about it. But, it has a reduced attack surface. Do you agree on that?
Some immutable distros like talos linux, have an extremely stripped down installation of linux with just what ia needed to run kubernetes.
However most immutable distros have something akin to the standard base of a normal linux distro.
And even then, the Linux kernel, is now one of the biggest attack surfaces, infintely more of a threat than having a package on the host. Most packages on the host, since they aren't setuid, can't really do anything malicious.
Flatpak sandboxing is interesting but not as strong as I would like, and not unique to immutable distros. In additiom to that, flatpak and docker have very little supply chain security compared to the traditional distro model of packaging, so the result is that we are trading this invincible supply chain (Debian/RedHat enterprise linux (but NOT fedora or bazzite or other less stable distros/Ubuntu were not affected by xz utils backdoor) for weak sandboxing, which is not something I'm very happy about.
Security makes a lot of trade offs between other elements of security, and features and peformance.