this post was submitted on 04 Jul 2023
49 points (98.0% liked)

Linux

45534 readers
1302 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 5 years ago
MODERATORS
 

For my phone, I use Graphene OS. What would be the best desktop Linux option to match the level of security and privacy that GOS provides?

top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 30 points 1 year ago (4 children)

Tails in proxmox in tails running on pure ramdrive system with no longterm storage, cpu, bios, mac serials overwritten with FFFFFFF, TPM chip desoldered or lasered off CPU, connected to TOR viato mullvad paid with crypto, through VPN running left behind sanitized device hidden in a library, through second sanitized vpn device connected to private insecure wifi in poor residential area with no cameras, after abolishing the state

[–] [email protected] 4 points 1 year ago

Truly a person of refined taste.

[–] [email protected] 2 points 1 year ago (1 children)

Only two layers of sanitizers? Gosh might as well just put your social security number out there

[–] [email protected] 3 points 1 year ago

Read my instructions to the end, always abolish the state before you start. This makes social security numbers powerless, look, 663 342 934. Nothing happened.

[–] [email protected] 1 points 1 year ago

Reading this comment made me die.

On a related note, being dead is the most secure way to use a distro.

load more comments (1 replies)
[–] [email protected] 21 points 1 year ago

QubesOS for security, Tails for privacy. These are both very extreme options though and most likely overkill for the average person

[–] [email protected] 16 points 1 year ago (2 children)

Pretty much any distro that isn't Ubuntu. Are you asking for privacy or security? Those are very different.

For security, I'd stick to more complete distros like Fedora instead of more diy distros like NixOS or Arch. They're great to learn and tinker with, but distros like Fedora have security experts adding mitigations and security stuff in the distro by default, whereas most users of Arch or something would have to manually look up those things and keep up to date on the latest security. So basically, none of them lol.

Using more hardcore security distros like QubesOS is not very realistic as a daily driver. You'll see Linux nerds name drop it and claim they know what they're talking about, but none of them will actually dailt drive it because it's a very painful experience. Just stick with flatpaks as much as you can for pretty solid security.

[–] gobbling871 4 points 1 year ago (6 children)

What security stuff/mitigations are added on Fedora that are not on Ubuntu?

[–] [email protected] 9 points 1 year ago (1 children)

Ubuntu is bad privacy-wise because it has opt-out telemetry. The telemetry is not very invasive though and I wouldn't really call it a privacy risk. There are other reasons to prefer other distros over Ubuntu though

[–] gobbling871 6 points 1 year ago (2 children)

Not making a case for Ubuntu but even Fedora has opt-out telemetry.

[–] [email protected] 5 points 1 year ago

You're right. This only counts users though whereas Ubuntu collects information about your system

[–] [email protected] 1 points 1 year ago

Counting users based on their ip VS selling user search queries to amazon (i know it got changed to opt-in, but that's a massive stain on their reputation as far as I'm concerned)

[–] [email protected] 2 points 1 year ago* (last edited 1 year ago) (1 children)

Looks like they do add quite a bit security features. Having SELinux installed and working out of the box being the biggest. https://fedoraproject.org/wiki/Security_Features

[–] gobbling871 1 points 1 year ago (1 children)

My question is simple: Which of these security features are not enabled/present in Ubuntu that give Fedora an advantage?

SELinux has a functional equivalent called Apparmor that is also enabled out of the box in most distros.

[–] [email protected] 3 points 1 year ago (4 children)

Selinux is more secure then app armor, but more difficult to use. Ubuntu is also pretty secure, I'm just not as familiar with it. I mentioned it for the privacy but, since it used to have some Amazon bloat crapped bundled and telemetry built in.

load more comments (4 replies)
load more comments (4 replies)
[–] [email protected] 1 points 1 year ago

What's wrong with Ubuntu?

[–] [email protected] 6 points 1 year ago

If you look through this thread, you may notice that almost everything is biased towards personal preference(s). I recommend you research for those aspects of security AND privacy that interest you and select the tools, distros that you prefer. The beauty of Linux lies in its variety. Use what pleases you and serves your needs.

[–] [email protected] 5 points 1 year ago (3 children)

Nix OS, Guix or Vanilla OS for sandboxing I guess. But basically everything but Ubuntu is pretty good for privacy, it’s a big part of free software philosophy.

load more comments (3 replies)
[–] [email protected] 4 points 1 year ago

Qubes on Whonix

[–] [email protected] 4 points 1 year ago* (last edited 1 year ago) (1 children)

Depends on what you mean for security/privacy. You can use Tails or whatever and have everything encrypted and then just be logging into your Facebook account on Chrome without an ad blocker.

Most Linux distros are secure enough for the average person who isn’t being targeted by some crazy state level actor. If you’re particularly concerned stick with a distro that has a security team like Debian. As for privacy that has more to do with the sites you browse and have accounts with but obviously avoid Google (I just use Firefox instead of Chrome) use an adblocker like ublock origin, along with maybe something like decentraleyes.

[–] Synthead 2 points 1 year ago

Chrome phones home a lot. It's not a good idea to use it if you care about privacy. Firefox even has metrics enabled by default, although you can turn them off.

[–] [email protected] 4 points 1 year ago

Try Tails, you don't even gotta install it. Keep it on a flash drive and just plug it into your computer whenever you wanna use it.

[–] [email protected] 3 points 1 year ago
[–] [email protected] 2 points 1 year ago* (last edited 1 year ago)

The best for privacy are: Tails, that runs on live-cd; Whonix, which you run in vms; Qubes, which is an os that runs all your user programs inside vms (running whonix inside qubes is the most powerful privacy setup).

[–] [email protected] 2 points 1 year ago

How does Void Linux rate on the security and privacy front compared to the top recommendations in this thread?

[–] gobbling871 1 points 1 year ago

A GOS emulator?

[–] GustavoM 1 points 1 year ago* (last edited 1 year ago)

How many privacy/security are we talking about? Because if you want to go "full ham" on both, then any minimal install + docker + lynx as your main (and only) access to the internet (with "nobody" set as the main user) + a rpi 4 (with openwrt) serving as "middleman" routing access from your router to it, and to your PC. Oh, and using only dumb phones and avoiding any wireless-related stuff.

[–] [email protected] 1 points 1 year ago (1 children)

my impression is that grapheneos is only private and secure compared to regular android. likewise, any linux distro is going to be secure and private when compared to windows.

[–] chockblock 1 points 1 year ago

Sure, but graphene OS just has some really thoughtful privacy focused features, and I'm looking for a Linux distro that would have similar features if there is such a thing.

One thing I love about graphene is by default, the MAC address is randomized for every single connection. Also, the Bluetooth can be set to time out and turn off after a certain period of not being used.

load more comments
view more: next ›