Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
secureblue
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
secureblue
1y ago
secureblue creator here :) some corrections: > last I heard it wasn't out of Beta or whatever yet It is > But it uses containers rather than VMs It doesn't use plain containers for app isolation. We ship the OS itself as a b
2.
▲
Secureblue: A security-focused desktop and server Linux operating system
(secureblue.dev)
4 points
by
secureblue
2y ago
|
0 comments
3.
▲
by
secureblue
2y ago
We've been working hard to address feedback and make improvements over the last several months. Secureblue now has expanded hardening, improved documentation, and clearer scope. Instructions are of course in the readme! :) https:
4.
▲
Secureblue: Hardened Fedora Atomic Images, F40 Release
(github.com)
3 points
by
secureblue
2y ago
|
1 comments
5.
▲
Wayblue: Fedora Atomic Images for Wayland Compositors
(github.com)
13 points
by
secureblue
3y ago
|
2 comments
6.
▲
by
secureblue
3y ago
FYI, both userns and non-userns variants are now available. https://github.com/secureblue/secureblue/commit/38999d4123aa...
7.
▲
by
secureblue
3y ago
Clearlinux has nothing comparable to this as far as I know: https://github.com/ublue-os/startingpoint And it's also mainly geared towards server use cases, whereas this project is mainly focused on desktop users.
8.
▲
by
secureblue
3y ago
Just changed it. Thanks for the feedback!
9.
▲
by
secureblue
3y ago
What is your distro doing that would make someone want to degoogle it? Certain users have expressed a preference towards Brave instead of Chromium because in their view Brave's "degoogling" of chromium is preferable. That l
10.
▲
by
secureblue
3y ago
Some people think that Brave is preferable to Chromium because they "degoogle" it.
11.
▲
by
secureblue
3y ago
Trading off possible kernel bugs against letting a whole LOT of userspace software run with real root privilege Only bubblewrap would run as root, but yes this is a fair critique as this is an opinionated tradeoff. I'm considering ad
12.
▲
by
secureblue
3y ago
As a follow up to this, given that bubblewrap-suid without userns vs bubblewrap with userns is a tradeoff, I could make it so both variants are published. This would give users choice between the two and be less opinionated. If this is want
13.
▲
by
secureblue
3y ago
I'm just making a judgement call for myself. Any other project ontop of Fedora increases the attack vector with its own maintainers. Totally understandable. an ISO Small point of correction: we're not publishing ISOs.
14.
▲
by
secureblue
3y ago
Universal blue, the starting point for this project, is fedora based. https://universal-blue.org/ No other distro has the same level of immutable tooling or support for immutable variants at this time. Also, Fedora has seli
15.
▲
by
secureblue
3y ago
I'm a little concerned that degoogling would be necessary. I don't follow. The readme specifically says it's not in scope. How much of the user's privacy is this thing selling away in the name of "security"?
16.
▲
by
secureblue
3y ago
Most of this can be done with Ansible. All of this can be done in several ways. Ansible, manually, a script, etc. Building it into an image just makes it more convenient. So why should I download images from a 3rd party outside of the Fe
17.
▲
Secureblue: Hardened Immutable Fedora Images
(github.com)
96 points
by
secureblue
3y ago
|
49 comments