3 ms·
At the end of the day, you do you, but my experience with SElinux is that using it on the desktop is vastly overkill. At a high level, the essence of SElinux i
by Galanwe 1y ago
At the end of the day, you do you, but my experience with SElinux is that using it on the desktop is vastly overkill.
At a high level, the essence of SElinux is to limit the possibilities of exploitation and escalation by carefully specifying which process can access which resources in which context. Now that makes sense for a server opened to the www, or a host shared with untrusted users. But Omarchy is a _sole developer_ focused flavor of Arch Linux, think your typical dev laptop. There's no service exposed there, you most likely can't even listen on the internet behind your typical home router. The realistic threats that you face is your laptop being stolen (which is why LUKS is a default) or your laptop sitting unlocked (which is why hypridle & hyprlock are a default).
Of course there's always the tails of a compromised software, but it's much more unlikely.
- hollerith 1y ago>using [SELinux] on the desktop is vastly overkill. The ChromeOS project disagrees with you: ChromeOS uses SELinux to help sandbox the browser. And Android uses it to help sandbox apps if the AI assistant I use is not making stuff up.