294

Remix of "This is fine" by David Revoy (@davidrevoy@framapiaf.org) − CC-BY 4.0

Context

all 40 comments
sorted by: hot top controversial new old
[-] khaleer@sopuli.xyz 7 points 12 hours ago

So, Haiku is the way now. (RIGHT?)

[-] khanh@lemmy.zip 2 points 8 hours ago

nope. maybe next year, lmfao

[-] provectus@lemmy.ml 24 points 20 hours ago

I do not understand the joke.

[-] basxto@discuss.tchncs.de 52 points 20 hours ago

David doesn’t want anything to do with the Linux Foundation anymore because they used AI generated art for an ad/promotion thing.

It had a blue cup with a tux on it in it and a big tux with a 35years head, which I put on Pepper’s cup. It also had a bunch of hallucinations in it

[-] rumschlumpel@feddit.org 16 points 13 hours ago

Linux the kernel =/= Linux Foundation. The LF is a very corporate organization with millions of donation money from industry sponsors.

[-] provectus@lemmy.ml 38 points 20 hours ago* (last edited 20 hours ago)

I kinda agree with him as an artist. It makes me sad to see people generate art with ai when they could've made a noobie drawing that will still be far much better than the ai one. Ai art can be so weird as well.

[-] MonkeMischief@lemmy.today 7 points 13 hours ago

Case in point: The online game "Kingdom of Loathing." I played that in like 2006 and the little martini stick dude still stands out.

[-] Jankatarch@lemmy.world 11 points 18 hours ago

After all these decades.
The year of the gnu hurd.

[-] provectus@lemmy.ml 3 points 7 hours ago

As the creator of the GNU Hurd community, I approve. Prepare everyone's old thinkpads or old dell laptops, and prepare some Ethernet cables.

[-] mrfriki@lemmy.world 16 points 22 hours ago

Hi Pepper! Everything's fine there?

[-] provectus@lemmy.ml 11 points 20 hours ago* (last edited 20 hours ago)

I played SuperTuxKart before. Is pepper a mascot somewhere, or is it a character for SuperTuxKart?

[-] basxto@discuss.tchncs.de 21 points 20 hours ago

It’s a comic https://www.peppercarrot.com/ licensed under a Creative Commons license and made with Krita

[-] halezinflames@lemmus.org 2 points 23 hours ago

Year of the Linux desktop when the years of neglecting security comes to bite them

[-] naught101@lemmy.world 25 points 22 hours ago
[-] halezinflames@lemmus.org 2 points 22 hours ago* (last edited 22 hours ago)

MacOS, iOS, GrapheneOS (and even then, Graphene doesn't believe themselves to be doing enough due to the fundamental limitations in AOSP)

There is one distro trying, and even they make it clear that they're bound by the limitations of the Linux desktop's security model at the moment (SecureBlue).

It is also technically possible to harden Windows to become nearly bulletproof but that usually requires third party software like ThreatLocker.

[-] waldfee@feddit.org 24 points 21 hours ago

MacOS, iOS

Do you have a source for that beyond shills and their marketing?

There most definitively are vulnerabilities and backdoors in these OSes. Whether or not we hear of them doesn't prove otherwise

[-] halezinflames@lemmus.org 1 points 21 hours ago

My source is primarily the GrapheneOS team's praises for how Apple handles iOS, particularly in Lockdown Mode. There was also a recent situation where they warned their users of "mercenary spyware" attacks.

It's also a position that many in the SecureBlue community would agree with, which is where I've learned the majority of my recent security stuff from.

[-] waldfee@feddit.org 10 points 19 hours ago

I mean it's commendable that Apple makes an effort to keep their users secure from third-party attackers (besides MDM software), but there's just no telling how much control and privacy violation is going on when they're keeping their source code secret. ("What do they have to hide? Clearly something.")

SecureBlue seems interesting, though most of their features look like security theater compared to the default

[-] halezinflames@lemmus.org 2 points 19 hours ago

Suppose this is a fair point. The stuff that is exposed seems to be quite helpful, such as already integrating features like Global Privacy Control long before Google.

As for SecureBlue... a lot of it seems quite extreme even for me but they're doing good work overall. I was maining their browser for a bit until I realized I was fighting against the current to make it usable for my use case and I felt kind of dirty doing all that to their excellent baseline. But I did grab their sysctl config, commented out 3 or 4 that I didn't need, and inserted it into my own. I like having more control, but I'll gladly take a more secure option if it doesn't affect usability significantly, so I cherrypick fixes liberally from their setup.

[-] onlinepersona@programming.dev 20 points 22 hours ago

A true turfblaster found in our midst.

[-] halezinflames@lemmus.org 4 points 22 hours ago

What is a turfblaster? I'm confused but maybe someone can explain that to me

[-] onlinepersona@programming.dev 2 points 13 hours ago* (last edited 13 hours ago)

Astroturfing. Pretending to be grassroots but just being a corporate shill to be for or promote corporate services and products.

Turfblaster is a word for someone who astroturfs.

[-] halezinflames@lemmus.org 1 points 13 hours ago* (last edited 13 hours ago)

Well, it's more so that I wished the open source community wasn't as averse to implementing a security model that wasn't heavily reliant on the systems being obscure. Security through obscurity is a horrid way to do such things, but it seems like that's the way things were done before I got here.

It would be nice to see the vision of the SecureBlue project come through elsewhere in the desktop Linux world, but any time someone so much as hints at fixing the flagrant security issues of something like the AUR, all they get is dismissal and knuckle dragging in response. I'm not a blind shill for corporate products by any means, I just would like for the community to quit treating security as an afterthought, because it's truly needed if we want to keep the new converts safe from the looming threats that are coming day after day.

Acknowledging the successes of projects that just so happen to not be community driven isn't shilling inherently and I'm a little perturbed at that conclusion you immediately jumped to.

[-] onlinepersona@programming.dev 2 points 12 hours ago

My bad then. I'm sorry I thought you were a shill, but those do come through here pretty often to dump their winblow and crApple dung.

As I said in another response, security is difficult to marry with convenience. You can see it on mobile operating systems where a flashlight app asks for network and storage permissions, and users just accept because they can't be bothered with even reading it.

I too recognise that there is a lot of room to improve, but I'm hopeful that with more attention, linux will become more secure. There will be more brainpower and money flowing into it.

[-] halezinflames@lemmus.org 1 points 12 hours ago* (last edited 12 hours ago)

Yeah the real point was that those systems have things in place we could stand to learn from, to do better, and continue to keep people protected. It's a learning lesson we could stand to be more careful.

I'm cynical of it mostly due to the way people respond when you suggest it in cases like the AUR malware. Speaking of mobile permissions I'm impressed with Voyager (my Lemmy client), it asked for literally nothing!

[-] sem@piefed.blahaj.zone 4 points 20 hours ago

Maybe it is someone who blasts astroturfing? Idk

[-] halezinflames@lemmus.org 4 points 20 hours ago* (last edited 20 hours ago)

I mean I guess following the messaging of one of the only explicitly security-focused Linux distros is considered "astro turfing" then? Hmm.

From their site directly:

secureblue is for those whose first priority is using Linux, and second priority is security. secureblue does not claim to be the most secure option available on the desktop. We are limited in that regard by the current state of desktop Linux standardization, tooling, and upstream security development. What we aim for instead is to be the most secure option for those who already intend to use Linux. As such, if security is your first priority, secureblue may not be the best option for you.

If security is your FIRST priority, they outright say their work is limited. So... that's where I'm getting it from.

[-] waldfee@feddit.org 6 points 19 hours ago

If security is your first priority you really just gotta stop using a networked computer, and even an airgapped one would be risky

[-] halezinflames@lemmus.org 2 points 19 hours ago

Yeah my primary aim is closer to something secure enough to be protected as long as I am careful, but still usable for modern stuff. My desktop setup has finally gotten to a place I like, but mobile has been really difficult for me, and I genuinely wish I had the privilege to get into the GrapheneOS world.

[-] MonkeMischief@lemmy.today 2 points 13 hours ago* (last edited 6 hours ago)

EDIT: erroneously deleted, but I suggested Qubes and Tails as possibilities. :)

[-] halezinflames@lemmus.org 2 points 13 hours ago

At the moment I've settled on Fedora with cherrypicked SecureBlue hardening, to me that is a lot more balanced for my needs. Tails is something I've dabbled with, but I'm not sure I need total anonymity, I basically never use Tor for anything but it's nice to have something like that on hand just in case the need arises.

Qubes is definitely an interesting project though as well, my last ex girlfriend daily drove it and somehow managed to get gaming working on it, and I wish she was still around to teach me how she did it.

[-] MonkeMischief@lemmy.today 2 points 13 hours ago

Haha cool thanks for the follow up!

I actually might have deleted my comment because I was like "Naaah they've probably thought of this already and I'm not contributing." 😅

[-] halezinflames@lemmus.org 2 points 13 hours ago

Yeah you had some very good suggestions though, much appreciated :)

[-] onlinepersona@programming.dev 1 points 13 hours ago

Linux is used in security contexts. What do you think Kali Linux is for? There's a linux distro that is literally a hypervisor to separate everything into VMs (Qubes). Fedora allows you to activate more security options like SELinux (which is also one way Android achieves more security BTW). And I could go on, but it seems you chose to be ignorant before making the claim linux was insecure.

Linux distros babe many flavors and eachallows a different focus.

[-] halezinflames@lemmus.org 1 points 13 hours ago* (last edited 13 hours ago)

Many desktop Linux distros have poor security defaults. Fedora even disables the restrictions on ptrace by default, which is strange considering the browser sandbox needs ptrace restrictions in order to function properly. Debian and Ubuntu default to apparmor which is very insecure (remember crackarmor?) and Arch has basically no security ootb and the AUR is essentially NEEDED in order to use it for most things, despite how unvetted and messy it is. Kali is not for daily driving, for the record.

I implore you to read SecureBlue's documentation which is where the bulk of my knowledge has been from. Even Android is not as secure as it could be, there is a reason that GrapheneOS, the pinnacle of Android security, doesn't even consider their build of Android secure enough.

[-] waldfee@feddit.org 2 points 9 hours ago

Fedora's choice to have ptrace_scope 0 sure is strange, it seems they had a discussion about it to revert it back to the upstream default of 1.

SEL being important was actually the main reason why in the light of recent kernel vulnerabilities I switched back to openSUSE, after being on Void for a while as inspired by this guide.

That the AUR is insecure lays basically in its name, I really don't get why people would use for anything but the most niche packages.

What Android is doing well compared to Linux is that it has proper per application compartmentalization, whereas *nix systems would require each program to be run by a different user to separate them, though Linux is also improving in that regard, for example through SEL or the flatpak sandbox.

[-] halezinflames@lemmus.org 1 points 3 hours ago

Yeah I pretty much chose to take matters into my own hands by importing some of the SecureBlue defaults (with a few modifications) into my config.

[-] onlinepersona@programming.dev 1 points 12 hours ago

Linux allows nearly endless customisation. But when making a desktop distro, you have to weigh convenience and security. You can be the most secure OS on the planet, but if nothing can run because of that, nobody will use it.

Go ahead and try to use Fedora with all security options activated. Give it a try and find out how much you like it. I bet that once you have to resolve your first SELinux issue that prevents you from running your favorite application, you'll start being more lax or drop it all together.

I think already know the answer to this, but which OS do you think is the most secure?

[-] halezinflames@lemmus.org 1 points 12 hours ago* (last edited 12 hours ago)

It's really hard to quantify an answer to that final question, because realistically, any OS connected to the internet leaves itself more vulnerable than any OS air gapped, so that's already inherently a tradeoff. If I go purely on a purity test? TempleOS. It's not daily driveable, but it technically wins due to the fact that Terry did not code any network support at all into it.

You're definitely right about the convenience tradeoffs, but some of that shit is just blatantly egregious, particularly with Arch and the AUR, yet Linuxtubers still swear by it and still tell new converts they don't need to be careful, which is ignorance at best and negligence at worst. Even worse are the ones that openly advocate you use an LLM to figure this stuff out. That kind of mindset toward new users hurts us more than many realize.

SecureBlue doesn't claim to be the most secure option, its whole model is trying to strike a balance between security and convenience. It's just that a lot of distros are so far behind that their ideas seem extreme. I ran a Lynis audit on my Fedora system recently and I got a 77/100 score. That's probably enough for the average person, and that was after downloading their sysctl rules from their github, commenting out about 3 or 4 options that I didn't really need, and importing them all into my configuration.

this post was submitted on 17 Aug 2026
294 points (100.0% liked)

linuxmemes

32519 readers
1020 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack users for any reason. This includes using blanket terms, like "every user of thing".
  • Don't get baited into back-and-forth insults. We are not animals.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry of any kind will not be tolerated. This is an LGBTQ+-friendly community -- if that is a problem for you, you should leave.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn, no politics, no trolling or ragebaiting.
  • Don't come looking for advice, this is not the right community.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, <loves / tolerates / hates> systemd, and wants to interject for a moment. You can stop now.
  • 5. 🇬🇧 Language/язык/Sprache
  • This is primarily an English-speaking community. 🇬🇧🇦🇺🇺🇸
  • Comments written in other languages are allowed.
  • The substance of a post should be comprehensible for people who only speak English.
  • Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
  • 6. (NEW!) Regarding public figuresWe all have our opinions, and certain public figures can be divisive. Keep in mind that this is a community for memes and light-hearted fun, not for airing grievances or leveling accusations.
  • Keep discussions polite and free of disparagement.
  • We are never in possession of all of the facts. Defamatory comments will not be tolerated.
  • Discussions that get too heated will be locked and offending comments removed.
  •  

    Please report posts and comments that break these rules!


    Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't remove France.

    founded 3 years ago
    MODERATORS