[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Linux workstation security

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 12
Thread images: 3

File: 2.png (204KB, 578x736px) Image search: [Google]
2.png
204KB, 578x736px
I've been thinking about how to make an usable yet reasonably secure Linux desktop.

As base system, I'd choose Fedora, because it comes with Wayland (X is shit security-wise), SELinux and good defaults. If I had more advanced knowledge and time to learn so that I'd trust myself more than Red Hat to properly configure a Linux system, I'd use Hardened Gentoo because it comes with Grsecurity, which is arguably a better protection than SELinux or Apparmor alone.

I'd disable internet access for my regular user with iptables, and would instead use a separate user with internet access for browsing in another virtual terminal. I'd use Chromium because security-wise it's simply unmatched (it can be argued architectural/theory wise, but the best proof for people who don't believe it are CVE stats about remote code execution for both Firefox and Chrome), and I'd always run it sandboxed using firejail or something else. Usual ad and JS blocking add-ons are a must too.

This way, regular applications that might pose a security risk, like media parsers, don't have internet access so they are rendered more or less useless. The only part that is exposed to the internet is a sandboxed browser running as another user, so even if that gets exploited, your files are safe. The only way to defeat this is with a zero-day elevation of privilege, which I don't think is something 99.999% of people have to worry about.
>>
File: 1465472517298.png (3MB, 2000x2000px) Image search: [Google]
1465472517298.png
3MB, 2000x2000px
>>59322953
I'd just like to interject for a moment. What you're referring to as Linux, is in fact, GNU/Linux, or as I've recently taken to calling it, GNU plus Linux. Linux is not an operating system unto itself, but rather another free component of a fully functioning GNU system made useful by the GNU corelibs, shell utilities and vital system components comprising a full OS as defined by POSIX.

Many computer users run a modified version of the GNU system every day, without realizing it. Through a peculiar turn of events, the version of GNU which is widely used today is often called "Linux", and many of its users are not aware that it is basically the GNU system, developed by the GNU Project.

There really is a Linux, and these people are using it, but it is just a part of the system they use. Linux is the kernel: the program in the system that allocates the machine's resources to the other programs that you run. The kernel is an essential part of an operating system, but useless by itself; it can only function in the context of a complete operating system. Linux is normally used in combination with the GNU operating system: the whole system is basically GNU with Linux added, or GNU/Linux. All the so-called "Linux" distributions are really distributions of GNU/Linux.
>>
Install Slackware.
>>
>>59322953

>linux
>fedora
>systemd
>x86 cpu
>capable of packet switching
>cia
>nsa
>fbi
>secure
>>
>>59322953
I want to creampie Youmu.
>>
>>59322953
Why are you trying to re-invent Qubes poorly when it already exists?
>>
>>59323079
Should I pick something?
>>
>>59323111
that's gross, anon
>>
>>59323111
fucking pedo
>>
>>59323171
Qubes has a clunky UI and doesn't support graphic acceleration.
>>
>>59323806
She's over 60.
>>
>>59323259
>picking things
>2011
pick one
Thread posts: 12
Thread images: 3


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.