Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Privacy
  3. my daily drive distro

my daily drive distro

Scheduled Pinned Locked Moved Privacy
4 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • chemicalwonka@discuss.tchncs.deC This user is from outside of this forum
    chemicalwonka@discuss.tchncs.deC This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #1

    my daily drive distro

    justenoughducks@feddit.nlJ 1 Reply Last reply
    0
    • System shared this topic on
    • chemicalwonka@discuss.tchncs.deC [email protected]

      my daily drive distro

      justenoughducks@feddit.nlJ This user is from outside of this forum
      justenoughducks@feddit.nlJ This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #2

      Do you know if you can still do everything with it? Like atomic already has its own limitations and quirks. I can imagine there are bigger limitations with this.

      Like can you install driver-level stuff like tablet drivers, GPU/CPU control, udev rules, etc... I guess I don't really know the implications of the extra hardening.

      chemicalwonka@discuss.tchncs.deC J 2 Replies Last reply
      0
      • justenoughducks@feddit.nlJ [email protected]

        Do you know if you can still do everything with it? Like atomic already has its own limitations and quirks. I can imagine there are bigger limitations with this.

        Like can you install driver-level stuff like tablet drivers, GPU/CPU control, udev rules, etc... I guess I don't really know the implications of the extra hardening.

        chemicalwonka@discuss.tchncs.deC This user is from outside of this forum
        chemicalwonka@discuss.tchncs.deC This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #3

        I use secureblue as host for my virtual machines

        1 Reply Last reply
        0
        • justenoughducks@feddit.nlJ [email protected]

          Do you know if you can still do everything with it? Like atomic already has its own limitations and quirks. I can imagine there are bigger limitations with this.

          Like can you install driver-level stuff like tablet drivers, GPU/CPU control, udev rules, etc... I guess I don't really know the implications of the extra hardening.

          J This user is from outside of this forum
          J This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #4

          Not the one you asked, but please allow me give my take on the matter.

          Do you know if you can still do everything with it? Like atomic already has its own limitations and quirks. I can imagine there are bigger limitations with this.

          Being derived from Fedora Atomic, already comes with its own set of limitations; like being limited in which kernel mods you can make use of (without reinventing the wheel), or how UKI is unsupported or how you should probably create your own image if you want to populate /usr. You can't even install software from any repository; e.g. installing the ProtonVPN RPM has been hit or miss for me.

          And, on top of this, secureblue's hardening does (strictly) limit this even further. Most impactful, so far, would be the inability to use sudo or anything like it. Instead, run0 is suggested. I'm 100% sure that run0 is better. However, I've had at least 1 occasion on which the software doesn't know how to properly interact in this setting. Ultimately, I'd have to give the blame on the software that doesn't properly support run0. And, perhaps, you could help address the issue by opening a bug report related to it. But it's definitely something to keep in mind.

          Finally, note on first setup you're walked through the many different additional hardening that can be reverted based on your needs. Just be aware of that fact.

          Like can you install driver-level stuff like tablet drivers

          Maybe. Depends on what exactly it is.

          GPU/CPU control

          I have.

          udev rules

          Shouldn't be a problem either.

          etc… I guess I don’t really know the implications of the extra hardening.

          If you're interested, I suppose the best course of action would be to find a secondary device of yours and setup it to your heart's content with secureblue. Whenever you face a roadblock, consider paying a visit to their discord server for support; they've been a great help so far. If, at some point, you find something you absolutely can't do, then you'd have to make up your mind on what you deem more important. Wish ya the best of luck!

          1 Reply Last reply
          0
          • System shared this topic on
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • World
          • Users
          • Groups