halezinflames

joined 1 week ago
[–] halezinflames@lemmus.org 2 points 5 hours ago (1 children)

100%, I love dogs but I love cats more

[–] halezinflames@lemmus.org 1 points 5 hours ago

Hell even Ron Paul would've been a marked improvement because as crazy as that dude was, he stood on business with the anti war thing

[–] halezinflames@lemmus.org 3 points 5 hours ago (2 children)
[–] halezinflames@lemmus.org 1 points 5 hours ago* (last edited 5 hours ago)

Yeah the real point was that those systems have things in place we could stand to learn from, to do better, and continue to keep people protected. It's a learning lesson we could stand to be more careful.

I'm cynical of it mostly due to the way people respond when you suggest it in cases like the AUR malware. Speaking of mobile permissions I'm impressed with Voyager (my Lemmy client), it asked for literally nothing!

[–] halezinflames@lemmus.org 1 points 6 hours ago* (last edited 6 hours ago)

It's really hard to quantify an answer to that final question, because realistically, any OS connected to the internet leaves itself more vulnerable than any OS air gapped, so that's already inherently a tradeoff. If I go purely on a purity test? TempleOS. It's not daily driveable, but it technically wins due to the fact that Terry did not code any network support at all into it.

You're definitely right about the convenience tradeoffs, but some of that shit is just blatantly egregious, particularly with Arch and the AUR, yet Linuxtubers still swear by it and still tell new converts they don't need to be careful, which is ignorance at best and negligence at worst. Even worse are the ones that openly advocate you use an LLM to figure this stuff out. That kind of mindset toward new users hurts us more than many realize.

SecureBlue doesn't claim to be the most secure option, its whole model is trying to strike a balance between security and convenience. It's just that a lot of distros are so far behind that their ideas seem extreme. I ran a Lynis audit on my Fedora system recently and I got a 77/100 score. That's probably enough for the average person, and that was after downloading their sysctl rules from their github, commenting out about 3 or 4 options that I didn't really need, and importing them all into my configuration.

[–] halezinflames@lemmus.org 5 points 6 hours ago (3 children)

Do people even still use Facebook or has it completely been taken over by bots at this point?

[–] halezinflames@lemmus.org 2 points 6 hours ago

Twitter being Twitter once again

[–] halezinflames@lemmus.org 18 points 6 hours ago (6 children)

I wonder how the Repubs I used to hear praise Trump for being "anti war" feel now that he's shown his whole ass

[–] halezinflames@lemmus.org 2 points 6 hours ago

Yeah you had some very good suggestions though, much appreciated :)

[–] halezinflames@lemmus.org 1 points 6 hours ago* (last edited 6 hours ago) (3 children)

Many desktop Linux distros have poor security defaults. Fedora even disables the restrictions on ptrace by default, which is strange considering the browser sandbox needs ptrace restrictions in order to function properly. Debian and Ubuntu default to apparmor which is very insecure (remember crackarmor?) and Arch has basically no security ootb and the AUR is essentially NEEDED in order to use it for most things, despite how unvetted and messy it is. Kali is not for daily driving, for the record.

I implore you to read SecureBlue's documentation which is where the bulk of my knowledge has been from. Even Android is not as secure as it could be, there is a reason that GrapheneOS, the pinnacle of Android security, doesn't even consider their build of Android secure enough.

[–] halezinflames@lemmus.org 1 points 6 hours ago* (last edited 6 hours ago) (2 children)

Well, it's more so that I wished the open source community wasn't as averse to implementing a security model that wasn't heavily reliant on the systems being obscure. Security through obscurity is a horrid way to do such things, but it seems like that's the way things were done before I got here.

It would be nice to see the vision of the SecureBlue project come through elsewhere in the desktop Linux world, but any time someone so much as hints at fixing the flagrant security issues of something like the AUR, all they get is dismissal and knuckle dragging in response. I'm not a blind shill for corporate products by any means, I just would like for the community to quit treating security as an afterthought, because it's truly needed if we want to keep the new converts safe from the looming threats that are coming day after day.

Acknowledging the successes of projects that just so happen to not be community driven isn't shilling inherently and I'm a little perturbed at that conclusion you immediately jumped to.

[–] halezinflames@lemmus.org 2 points 7 hours ago (2 children)

At the moment I've settled on Fedora with cherrypicked SecureBlue hardening, to me that is a lot more balanced for my needs. Tails is something I've dabbled with, but I'm not sure I need total anonymity, I basically never use Tor for anything but it's nice to have something like that on hand just in case the need arises.

Qubes is definitely an interesting project though as well, my last ex girlfriend daily drove it and somehow managed to get gaming working on it, and I wish she was still around to teach me how she did it.

view more: next ›