30
Try Immutable Mode with openSUSE Leap 16.1 RC
(news.opensuse.org)
openSUSE is an open, free and secure operating system for PC, laptops, servers and ARM devices. Managing your emails, browsing the web, watching online streams, playing games, serving websites or doing office work never felt this empowering. And best part? It's not only backed by one of the leaders in open source industry, but also driven by lively community.
The root filesystem is mounted as read-only. Attackers can't write to or modify it.
No, the root system being read only is not a security benefit. Attackers (with root or a root exploit) can remount as read only, or remove the immutable bits on files.
In addition to that, thinks like /var usually contain persistent state which can be written to, even on an immutable system
Now, an attackers changes to the root filesystem would probably be overwritten on the next image upgrade. Although better is impermeance, where the root filesystem is generated from config files on boot (NixOS can do this). That is better because now the system is wiped every boot, however it runs into some of the same issues: an attacker with root can modify the update mechanism, or the persistent config files.
While I would say that an immutable system offers practical security benefits, in that most existing Linux malware probably is designed for an orthodox system, it doesn't offer theoretical security benefits. It's just security by obscurity that will probably wane if/when immutable distros get more popular.
I can't get into a discussion about something I know too little about it. But, it has a reduced attack surface. Do you agree on that?
Some immutable distros like talos linux, have an extremely stripped down installation of linux with just what ia needed to run kubernetes.
However most immutable distros have something akin to the standard base of a normal linux distro.
And even then, the Linux kernel, is now one of the biggest attack surfaces, infintely more of a threat than having a package on the host. Most packages on the host, since they aren't setuid, can't really do anything malicious.
Flatpak sandboxing is interesting but not as strong as I would like, and not unique to immutable distros. In additiom to that, flatpak and docker have very little supply chain security compared to the traditional distro model of packaging, so the result is that we are trading this invincible supply chain (Debian/RedHat enterprise linux (but NOT fedora or bazzite or other less stable distros/Ubuntu were not affected by xz utils backdoor) for weak sandboxing, which is not something I'm very happy about.
Security makes a lot of trade offs between other elements of security, and features and peformance.