4 ms·
Are there distros that have these 'fixes' built in? Alpine Linux?
by byproxy 7y ago
Are there distros that have these 'fixes' built in? Alpine Linux?
- lykr0n 7y agoAlpine is far from a desktop distro
- yjftsjthsd-h 7y agoWhy? I've got it on a laptop and it's fine
- keshavit 7y agoI agree that it's good for the desktop (I would have used it if Void Linux didn't exist) but that isn't really it's goal.
- yjftsjthsd-h 7y agoThat's fair. I'm happy to agree that desktop was never Alpine's main goal, having initially targeted network appliances and growing a lot after being picked up for Docker images.
- mehrdadn 7y agoAren't so many packages on it out-of-date? Though I'm not sure that makes it "not-a-distro", but still...
- yjftsjthsd-h 7y agoNot that I've noticed (when following the latest release), and I doubt that it's worse than Debian.
- mehrdadn 7y agoI just looked at their package repos and it seems it's gotten better at least for GCC and Clang. It used to be pretty bad. See my older discussion here: https://news.ycombinator.com/item?id=18731913 https://news.ycombinator.com/item?id=18731913
- boudin 7y agoThis short post doesn't talk about a lot of things that are happening like wayland to address X security issues or flatpak for sandoxing. The way it's written looks more like marketing than anything else... If you want to build your own hardened apps and kernel, you can look into Gentoo
- madaidan 7y ago> like wayland to address X security issues The post does mention X's security issues. We are discussing switching to wayland but XFCE doesn't support it yet. If we don't switch to wayland, I might add X sandboxing via a nested X server such as Xpra to sandbox-app-launcher. It's already on the TODO list. > flatpak for sandoxing Flatpak is not a good sandbox. It fully trusts the applications and the permissions are far too vague to be meaningful. For example, many applications come with "filesystem=home" which means read-write access to the entire home directory so to escape, they just need to write to .bashrc. We're using sandbox-app-launcher instead. > The way it's written looks more like marketing than anything else Sorry for talking about our recent projects then?
- est31 7y agoChrome OS is a very secure Linux distro. While the base system is very restricted, they also support Linux sandboxes, making it secure for you to use the computer both for online banking and for downloading random code from the internet. Check out the talk "Linux for Chromebooks: Secure Development": https://www.youtube.com/watch?v=pRlh8LX4kQI https://www.youtube.com/watch?v=pRlh8LX4kQI
- danieldk 7y agoIt is interesting that Fedora Silverblue wasn't mentioned in the discussion at all. It aims for having an immutable root filesystem with transactional updates. Like Fedora, it uses SELinux to isolate processes with security policies. It aims to be a minimal base system, where users install applications through (ideally) sandboxed Flatpaks and do development in containers [1]. Fedora has also been historically more proactive than upstreams to enable hardening features. Another good example (as mentioned by a sibling) is ChromeOS. It, of course, has privacy problems, but ChromiumOS is available in source form AFAIK. [1] I know, containers != security.