It's not just a distro. RedHat used to host quite a bit of free software projects. The mailing lists that used to be now just bounce. Sourceware has been abandoned for GitLab. But I'm not sure if everything else has succesfully migrated away. It would've meant something really good if IBM would just continue to provide services for free software, but I'm not seeing them do that so I guess that means pretty much the exact opposite.
> Security from websites, installable software, physical access?
All those would be important, but don't let the perfect be the enemy of the good. We could start from the Vulnerability Of The Year: supply chain attacks.
Being able to visit a web page, open a PDF or download an inspect a git repo made by someone you don't know without the web page, PDF or git repo's being able to completely pwn the entire machine including the bootloader and the firmware for all the hardware subsystems.
Desktop Linux is very bad at that, but some distros are much better than others, and Fedora is approximately the best outside of Qubes and Secureblue, which approximately no one uses.
Untrustworthy blog reposts Twitter message from some person?
According to the tweet screenshot, IBM fires AI people! Hmm ...
Great opportunity to migrate to NixOS for those needing to decision a migration path.
It's not just a distro. RedHat used to host quite a bit of free software projects. The mailing lists that used to be now just bounce. Sourceware has been abandoned for GitLab. But I'm not sure if everything else has succesfully migrated away. It would've meant something really good if IBM would just continue to provide services for free software, but I'm not seeing them do that so I guess that means pretty much the exact opposite.
I'll stick with Fedora and RHEL.
From what I can tell NixOS still has no support for AppArmor or SELinux.
Semi-related: https://news.ycombinator.com/item?id=49841563
France as well: https://news.ycombinator.com/item?id=49842480
Last time I evaluated NixOS (Mar 2021) the project didn't care a whit about desktop security. Has that changed?
Fedora at least tries relatively consistently—and has been for decades.
What exactly do you mean by desktop security? Security from websites, installable software, physical access?
> Security from websites, installable software, physical access?
All those would be important, but don't let the perfect be the enemy of the good. We could start from the Vulnerability Of The Year: supply chain attacks.
Being able to visit a web page, open a PDF or download an inspect a git repo made by someone you don't know without the web page, PDF or git repo's being able to completely pwn the entire machine including the bootloader and the firmware for all the hardware subsystems.
Desktop Linux is very bad at that, but some distros are much better than others, and Fedora is approximately the best outside of Qubes and Secureblue, which approximately no one uses.
I'll wait until AI has translated all the nix scripts to a more user friendly language, thank you.