[-] pheusie@programming.dev 2 points 6 months ago

do you stick with the same distro across your PC, laptop, and server, or do you pick different ones based on the device and what you’re doing?

Definitely the latter.

constantly have to look up flags for different package managers.

FWIW, you don't have to choose the distro's package manager. While it makes sense in most cases, it's definitely not a requirement. And that's where the nix package manager comes in. Unbeknownst to some, you don't have to be on NixOS to access it, simply because it's probably already found in the repository of the distro you're using. So, frankly, you can even expect that it's well-supported.

I feel like NixOS might be the only distro that could realistically handle all these use cases

FWIW, containerfiles used in conjuction with bootc to boot your OS from, do allow differentiation within a single containerfile; i.e. specific changes are only applied for the designated target. This is accomplished by virtue of a single containerfile being able to produce many (very) different container images to boot from. So, in short, other avenues exist and bootc happens to be one I know. Note that bootc doesn't (necessarily) push you towards Fedora(-derivatives). Despite being very new (and perhaps somewhat experimental), Bootcrew does provide container images for other distros; some of which have already spawned multiple derivatives of their own. See e.g. Tartaria and XeniaOS.

but I’m a bit scared of the learning curve and the maintenance work it’d take to migrate everything over.

My 2 cents: if you're interested in NixOS, just start out with installing nix on any distro. And see where that takes you ;) !

[-] pheusie@programming.dev 4 points 6 months ago* (last edited 6 months ago)

I agree with this in general. But, I'd like to add that well-supported hardware (like a ThinkPad) may do equally well on Linux and perhaps even better.

[-] pheusie@programming.dev 2 points 6 months ago* (last edited 6 months ago)

Aight. I'll give you some more then 😜:

  • Don't expect real-time protection (Γ  la Windows Defender) on Linux. While decent options do exist^[Ironically, Microsoft Defender for Endpoint on Linux is one of the best out there.], the better ones come at a premium.
  • Though, related to the previous point, that's not necessarily a bad thing. The epitome of secure OSes, GrapheneOS (for mobile) and Qubes OS (for desktop), don't come pre-installed with one either. And I wouldn't be surprised if their respective maintainers would justify it by stating that proactive security is simply better than reactive security.
  • FWIW, Lynis is a battle-tested security tool used to audit the system. It doesn't work on Windows, but does on macOS, Linux and some other systems. It even goes as far as granting a numerical rating that represents how well the system performs on security and notes (point-by-point) what could be improved (and sometimes even how). While I would definitely not argue that it's the be-all and end-all, the numeral rating definitely makes it easy to compare distros at a glance.

There's perhaps more to go through, but I believe we should address the elephant in the room:

How much hardening did you even apply on your current/previous OS?

Like, if you've built a literal fortress, chances are that you'll have a hard time finding a suitable distro that provides similar protection OOTB. But, if you're just your average Joe and you just ran with how it came OOTB and at least didn't try to actively sabotage/compromise their system, then... chances are that a decent amount of mainstream distros will suit you fine. I kinda hinted at it in my previous comment, but a mainstream distro could be fine if you uphold best practices. So, in that scenario, the query shifts to:

Are you willing to adopt best practices?

If you're unsure whether you'll manage given your wants/needs out of the system, then that would (again) shift the question. This time we'd have to discuss the activities you engage in and 'decide' whether there are any distros out there that can handle those gracefully and responsibly.

Etc. Etc.


Warning: as you should be aware by now, and if you haven't yet, see the security entry on the (excellent) ArchWiki and the (infamous^[Madaidan used to be a security researcher on Whonix. Whonix is one of Linux' finest when it comes to privacy and security. Heck, it's involved in the preferred way to engage on the Tor network. It's even endorsed by Edward Snowden. So, by their efforts/contributions, Madaidan should have rightfully earned the required credentials and be regarded as somewhat of an authority on the subject matter. However, this article wasn't well-received. From what I saw, the community was mostly dismissive. Disappointingly so. Which..., unfortunately shows that there's a lot more circle jerking than what we'd all admit to. Anyhow..., FWIW, there was actually a slice of the community that did take it seriously. I'd characterize them as the security-conscious. Furthermore, note that Madaidan hasn't updated it for a couple of years now. So some of the writings have clearly become outdated. So, to be clear, the situation isn't as bleak as they described in their article.]) Linux entry on Madaidan's Insecurities, this can be a pretty ugly rabbit hole. I hope this doesn't discourage you, though.

Finally, consider giving answers to the bold and cursive questions πŸ˜‰.

[-] pheusie@programming.dev 3 points 6 months ago

OP, I'll keep it short as you might have already moved on. Security on desktop Linux isn't great. The lack of widespread sandboxing is one of the main culprits. Good 'hygiene' should keep you safe. But, if you're (rightfully) more concerned, then I'd suggest looking into secureblue^[Note: this distro might be hard to get into if it's your first distro. Consider joining community channels for assistance.].

[-] pheusie@programming.dev 3 points 6 months ago

The way you present "immutable distros" make them look like state-of-the-art stateless systems (a la NixOS with the impermanence module).

As much as I'd wish (so-called) immutable distros were like that, almost none of them actually are^[It's basically the aforementioned NixOS. And, even then, only if you've set it up like that. Guix System might offer it as well, but I couldn't verify it the last time I looked into it.].

Fedora Atomic, which may or may not have surpassed NixOS in popularity by now, practically just locks down /usr. That's cute, but it means that the immutability doesn't prevent persistence of hardware in most of the filesystem.

Similarly, I could go over the other popular immutables to point out how their immutability doesn't do much to combat persistence. But I digress...

[-] pheusie@programming.dev 2 points 7 months ago* (last edited 7 months ago)

Thanks for the quick rely!

Maybe this is relevant for some

That is very tangible, indeed. And kudos for providing the only browser that aced the 'test'!

Also, pull requests attempting to improve the documentation are very much welcome. Would be great to get more contributors involved and one doesn't have to be deeply technical to write good docs.

Hehe 😜. I do admire your work, but don't get your hopes up πŸ˜….

Anyhow, I will add it to the list of Firefox(-based) browsers worth looking into. To be clear, I'm not a primary consumer of the product category. FWIW, I would install it on my system if I were*.

[-] pheusie@programming.dev 2 points 7 months ago* (last edited 7 months ago)

Yup.

After reading a ton of discussions and inevitably trying out many interesting text editors (including niche ones like Leo and Sam), I just had to give it to Doom Emacs. Been very happy with it ever since.

[-] pheusie@programming.dev 4 points 7 months ago

Thanks! I wonder who will reach the finish line first between Cinnamon and Xfce.

[-] pheusie@programming.dev 2 points 7 months ago

I was actually seriously considering to just write "Freedom" and call it a day. Apologies for making it more wordy than it has to be.

[-] pheusie@programming.dev 2 points 7 months ago

Not the one you asked, but here's my two cents.

Arch, by virtue of its DIY nature, has little to no defaults. As such, common security measures are not pre-configured either. Thankfully, it makes up for that with its excellent wiki entry on security. Unfortunately, I don't think most users ever seriously implement what's found within.

As for Debian, it actually does come with plenty of relatively sane defaults, including security. And Debian has shown to take security rather seriously. However, (most) Debian repositories are not great at providing up-to-date versions of the software they package:

  • The stable branch has outdated packages for the sake of providing a 'boring' (but reliable) experience. While security updates are backported, it is not the preferred way of keeping software safe and secure.
  • The testing branch is in a disturbing condition in which it holds software that is a bit more stable than the unstable branch. However, it does not enjoy the security updates backported to the stable branch. Nor does it immediately receive the security updates as they come to the unstable branch. A rather unsettling middle ground, if you will. Definitely not recommended for the security-conscious.
  • Finally, the unstable branch. Intuitively, this should provide the fix for the above problems. It should provide current software, which should mean that it receives updates as they're released, security included. But, anecdotally, the likes of Arch, Fedora and openSUSE seem to be doing a better job at offering a (semi-)rolling release distro. But, please be my guest, and prove them wrong.
[-] pheusie@programming.dev 4 points 7 months ago* (last edited 7 months ago)

Glad to help out 😊!

Thankfully the model forces upon the system to keep a pristine copy around. Which enabled us to fix this rather easy :P .

[-] pheusie@programming.dev 5 points 7 months ago* (last edited 7 months ago)

~~Did you try rpm-ostree reset ?~~


EDIT: The solution provided above 'could' perhaps work, but perhaps it's way too radical of a solution πŸ˜… ..., so I understand if you don't wanna go down that route. Instead, consider

sudo cp -a /usr/etc/containers/policy.json /etc/containers

as per this comment on github.

view more: β€Ή prev next β€Ί

pheusie

0 post score
0 comment score
joined 7 months ago