[-] pheusie@programming.dev 2 points 6 months ago* (last edited 6 months ago)

Even if it's subjective and reliant on the used hardware, if we had enough of these reports, they would become very valuable as patterns would inevitably show up.

But, I'm afraid we're past the point in which you can reliably and vividly recollect the whole experience ๐Ÿ˜….

[-] pheusie@programming.dev 2 points 6 months ago

I tried ~10 distros and then did a prolonged test of about 2 months for each of the 2 distros that were the closest to being perfect out of the box

Oh wow, that's some serious dedication. Have you ever written out your experience?

[-] pheusie@programming.dev 1 points 6 months ago* (last edited 6 months ago)

Sorry to say, but there's a lot questionable stuff found within your comment. But I will try to limit the discussion around some of the more egregious ones.

Hate to keep litigating this around here, but the shift alone is enough. Explaining to people WTF an immutable filesystem is, is a sure way to frustrate them into giving up, despite whatever comms finesse you might THINK you have.

I don't understand what's so hard to understand about (some) core system files being read-only, i.e. you can't change/modify it. Can you help me understand why that would cause so much frustration?

Counterpoint: STOP SUGGESTING IMMUTABLE DISTROS TO NEW USERS

Countering the counterpoint with an anecdote: I cold turkey switched from Windows to Fedora Silverblue almost 4 years ago. Beginner-friendly derivatives like Bazzite (or other uBlue images) weren't even around back then. And, somehow, I managed. And there are many other testimonials that point out something similar, especially with many^[Please, consider going over to the Bazzite subreddit and see it for yourself.] newbies appreciating Bazzite. Are you ignoring this empirical evidence? If so, on what basis?

there is ZERO benefit

Come on, you know that's not true. Perhaps you intended to write: "I suppose there is ZERO benefit to me (and others like me)". Though, if you genuinely don't know any, then please consider going over this (lengthy) blog post by Colin Walters, a key figure in the past and current development of Fedora Atomic and Fedora CoreOS. It's not a very efficient writing for educating oneself on this topic, but it's the best I know.

[-] pheusie@programming.dev 2 points 6 months ago

Yet another very lengthy comment. I hope you will find it worth reading.


Wow, that's very insightful. Thank you for the effort!

If you allow me, I wish to provide some feedback and -if applicable- give pointers on how some of that translates to Linux.

Iโ€™m closer to the average user than someone who has built a fortress.

That's probably true, but you're definitely upholding excellent practices. Most people I know don't even practice a fraction of that ๐Ÿ˜…. So mad props for that!

FWIW, I will assume for now that you haven't delved into Windows Registry (or stuff like HotCakeX) for the sake of hardening. Which, to be clear, is absolutely fine. But is worth noting for the eventual mapping to a suitable distro.

I use Firefox with ublock, ghostery, and privacy badger. I use the free tier of proton vpn.

You can just continue doing these.

I run avast daily and malwarebytes weekly.

Unfortunately, I'm not aware on how we would translate this responsibly. This could be on me, though. Granted, the situation on Linux is different from how it is at Windows. Anyhow, as a non-expert, the furthest I came would boil down to:

  • ClamAV as the first layer of reactive anti-malware. AFAIK, this is your only free^[To be clear, it seemed to me that you would prefer this. Which is why I specifically targeted gratis options. But please let me know if you're willing to shell out.] option for real time protection^[Note that this might not be setup correctly OOTB. Consider checking out this entry within its documentation.].
  • Unfortunately, ClamAV is plagued by a tendency to output many false positives. Perhaps even moreso than most of its kind^[This is actually widely reported. See e.g. this reddit thread or see this discussion on the Linux Mint forum]. So, you'd naturally want a second opinion to verify its claims. Which, often comes in the form of relegating it to something more accurate. Enter VirusTotal. If this only happens occasionally, then the web app might suffice. But feel free to look into Lenspect for a dedicated app with a GUI, that functionally does the same. Or, if you're more interested in ease^[Labeling a terminal-based tool as the easier option might seem counter intuitive at first, but makes sense when you notice that it can scan folders. Which, makes it possible to move all flagged files (by ClamAV or otherwise) to a folder in which they can all be scanned in one go] of use and/or function, the more powerful VirusTotal CLI.
  • As for your weekly Malwarebytes, a couple of options do exist, but it's questionable to what degree they're effective. Though, there's somewhat of an exception: Kaspersky's Virus Removal Tool for Linux (KVRT) is pretty legit. But I would only recommend that if you trust Kaspersky (or, rather, trust that they're not compromised due to politics).

I think that I should already be close to best practices but Iโ€™m not sure how changing OS will affect that.

It will ๐Ÿ˜œ. Look into the others comments for a healthy amount of pointers on this.

Iโ€™m not really worried about being targeted for anything.

I'm glad to hear that. It would otherwise complicate things a lot.

I donโ€™t think that I really do much risky beyond the occasional torrent or downloading a patch for a game.

You should be fine as long as they're from trusted sources.

I get games primarily from gog

Unrelated to the rest of my commentary, but this is an excellent choice! You got great taste.

donโ€™t open strange emails or click strange links, and use a password manager to generate secure passwords

Keep this up ๐Ÿ‘.

One of the things that Iโ€™m most unsure about is keeping everything updated. Microsoft manages keeping everything updated for the most part on Windows

So, the gist is that as long as you're installing stuff from a repository, then upgrading your whole system should be a pretty straightforward, streamlined and seamless experience. Heck, it can even be automated if you want. The following is worth pointing out, though:

  • If your notion of "updated" means that the latest ('stable'^[This can sometimes be a convoluted term as it means different things depending on the context. Here, I use it to mean production-ready as per the developer of said software.]) release is found on your system, then this will affect your choice of distro. By contrast, there are distros that update in leaps. So, instead of going from versions 1 -> 2 -> 3 -> 4 -> 5 -> 6 -> 7 -> 8 (and so on, and so forth) , it does 1 (long pause^[In which it basically freezes and skips any version in between. Security updates are backported, though. So, you're not necessarily unsafe/insecure and/or at risk.]) -> 3 (long pause) -> 6 (long pause) (and so on, and so forth).
  • Automated background updates do exist, but I'd only recommend those on systems that do that OOTB. If however, you're fine with (or perhaps even prefer) pressing a button after a prompt for updates, then note that that's more widely available.

and the last time I needed to find a driver anywhere except from Microsoft it came on a 3.5" floppy.

So, if that was your experience on Windows, then I'm somewhat optimistic that you'd be more than fine on Linux. FWIW, drivers and whatnot are mostly found within the Linux kernel itself. Thus, making Linux a very smooth experience; your drivers simply receive the updates whenever an update to the kernel has been applied. Though, while rare, exceptions do exist. And they're quite notorious:

  • Nvidia used to be pretty bad in this regard, probably the result of a bad relationship. But, it has become a lot better in recent years. Still, I would recommend a distro that specifically handles Nvidia updates (about) as gracefully as they come. So, please mention it if you're on Nvidia.
  • Broadcom's wireless drivers. Tough luck. Thankfully, some distros have put in significant efforts to make this work. So, again, the specific distro could matter.
  • There are perhaps others, but these were the first that came to my mind.

I use my computer primarily for single player gaming, discord, and fediverse sites. I need a spreadsheet and word processer, I use open office for that right now.

Nothing out of the ordinary. Most of those translate pretty easily to Linux:


I do financial and work related things on a different device.

Good job on compartmentalizing your activities across multiple devices!


Fam, as this has become an absolute unit of a comment, please feel free to dismiss as you feel like and only engage with the parts you want. If you've come this far, then I'd like to express my appreciation: Thank you!

[-] pheusie@programming.dev 0 points 6 months ago* (last edited 6 months ago)

what software do people pirate in linux?

It's a great piece of software. As such, I wouldn't want to harm them. Hence, I won't give you any pointers. Sorry not sorry.

[-] pheusie@programming.dev 1 points 7 months ago

It's Xfce's default file manager. I guess that means that OP is actually using Zorin OS Lite.

[-] pheusie@programming.dev 1 points 7 months ago

My priorities:

  • Secure. Unlike popular belief, the fact that the worlds infrastructure basically runs on Linux does not imply that your average Desktop Linux distro enjoys the same level of scrutiny when it comes to its security. Hence, the security-conscious should carefully pick a distro that can handle their threat model. Or, at least harden it to their liking.
  • Stateless. Conventionally, you will be met with a (relatively) minimal system after installation. After which you're expected to configure it to your liking and go smooth sailing afterwards. Occasionally, you might (un)install stuff and/or modify settings; but nothing out of the ordinary, really. While applying some of these changes might seem trivial, they (kinda) lead your system to accumulate cruft. This cruft might seem innocuous, but it's exactly why your system seems so fresh after a reinstall. Foregoing this altogether is referred to as going stateless. This is done by declaring a desired state and 'flushing' all changes that have not been declared. Many other benefits are associated with this, but I digress...

The above^[So, without even going into release cadence etc.] already dictates the use of NixOS with the impermanence and nix-mineral modules.

[-] pheusie@programming.dev 1 points 7 months ago

They do not have centralized configuration as far as I am aware so they do not go as far as Nix.

Which is why it's (only) their ambition ๐Ÿ˜œ. But thanks for prompting me to clarify!

Furthermore, their wording would suggest that configuration is not part of what's declared. Which -at best- would make it relatively light on how declarative it is.

view more: โ€น prev next โ€บ

pheusie

0 post score
0 comment score
joined 7 months ago