Considering checking out an #immutable #Linux distro that uses #distrobox, like #openSUSE #MicroOS or #VanillaOS, because I like the extra security and separation and atomic updates and so on they offer, it's a lot like the stuff I like about #GrapheneOS, but I'm not sure if they're actually any more secure, since new root OS components can still be installed, it just requires a reboot. Does anyone know?
Conversation
Notices
-
Embed this notice
novatorine 🏴🏳️⚧️ (anarchopunk_girl@kolektiva.social)'s status on Sunday, 30-Jul-2023 00:39:51 JST novatorine 🏴🏳️⚧️ -
Embed this notice
novatorine 🏴🏳️⚧️ (anarchopunk_girl@kolektiva.social)'s status on Sunday, 30-Jul-2023 03:04:47 JST novatorine 🏴🏳️⚧️ @karlggestd yeah the existence of the ability to modify the root system kind of undermines the security benefits of an immutable operating system especially since flatpak containers are not necessarily the most secure by default ( they come with access to the entire home directory by default which means they can modify your bashrc or whatever to gain root access)
-
Embed this notice
karlggest (karlggestd@mastodon.social)'s status on Sunday, 30-Jul-2023 03:04:48 JST karlggest @anarchopunk_girl
Well, you always can use translational-update, is it your doubt? -
Embed this notice
novatorine 🏴🏳️⚧️ (anarchopunk_girl@kolektiva.social)'s status on Tuesday, 01-Aug-2023 00:58:26 JST novatorine 🏴🏳️⚧️ @rwa yeah it isn't necessarily "about" security, but you do get more security as a side benefit of libostree-style immutability, although not microOS style btrfs-based immutability, as it turns out (see my latest post on the matter)
-
Embed this notice
rwa (rwa@scl.clttr.info)'s status on Tuesday, 01-Aug-2023 00:58:28 JST rwa @anarchopunk_girl hm, i have not digged that deep in the immuntable linux distro space - is the whole immutable approach about security at all?
From my point of view it's more about stability and availability (i.e. defined state after an update). I don't think it is "more secure" just by having a immutable root partition. Do i miss something?
-
Embed this notice