home.social

#secureblue — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #secureblue, aggregated by home.social.

fetched live
  1. Seeking suggestions for headless KVM/QEMU host. SELinux is a must, trying for secure as possible but MoBo lacks TPM2. Thinking between minimal Fedora Everything, or SecureBlue IoT. Any recs? Im aware no TPM2 is a security flaw, but new computers are $$$$.


    #KVM #VM #Fedora #Security #SecureBlue
  2. @tokyo_0

    A very popular option is #QubesOS for privacy. It's very popular among journalists and activists in dangerous situations. It was even endorsed by Edward Snowden IIRC.

    But I heard that many prefer #secureblue since its more user-friendly and makes a smoother daily driver, though I can't vouch too hard for this since I've never given it a go.

  3. @tokyo_0

    A very popular option is #QubesOS for privacy. It's very popular among journalists and activists in dangerous situations. It was even endorsed by Edward Snowden IIRC.

    But I heard that many prefer #secureblue since its more user-friendly and makes a smoother daily driver, though I can't vouch too hard for this since I've never given it a go.

  4. The notification system is ~13% of my total shell codebase... And it's not even ready yet (I'm also omitting the integrations of the system in the rest of the codebase).

    #ricing #linux #desktopshell #unixporn #material #materialdesign #shareyourdesktop #secureblue #niri #Quickshell

  5. I first need to check if I wasn't scammed, then I'll flash it with #secureblue 🔥

  6. secureblue @[email protected] now contains bazaar! I'm very happy to see consistent and good store among many bootc images, leaving the old PackageKit slow store behind! Shoutout to @kolunmi@kolunmi@hachyderm.io

    https://github.com/secureblue/secureblue/releases/tag/v4.8.1

    #bazaar #secureblue #bootc

  7. secureblue @[email protected] now contains bazaar! I'm very happy to see consistent and good store among many bootc images, leaving the old PackageKit slow store behind! Shoutout to @kolunmi@kolunmi@hachyderm.io

    https://github.com/secureblue/secureblue/releases/tag/v4.8.1

    #bazaar #secureblue #bootc

  8. What are my criteria for using systems apps and programs? 🤔 #privacy #security Well, when governments plan to #fud or censor a service, it is for me a big #SIGNAL to use that service. *Cough* #archiveToday. Everything about GrapheneOS is to embark on the grand #Odysee of becoming a #Linuxnerd. #secureblue, one has to be #brave to use certain services that are like #proton s in these #darkWeb times. With Tor and its hammer, we should look forward and #riseup to get up and stand up for our rights.

  9. What are my criteria for using systems apps and programs? 🤔 #privacy #security Well, when governments plan to #fud or censor a service, it is for me a big #SIGNAL to use that service. *Cough* #archiveToday. Everything about GrapheneOS is to embark on the grand #Odysee of becoming a #Linuxnerd. #secureblue, one has to be #brave to use certain services that are like #proton s in these #darkWeb times. With Tor and its hammer, we should look forward and #riseup to get up and stand up for our rights.

  10. @reflex @YaLTeR Yeah, the fact that you can just reboot to a different version of your OS is just so cool! I too don't use the vanilla Silverblue, but rather #secureblue, a distro based on that. Before switching to secureblue I used #ArchLinux (BTW), so an atomic desktop felt much more restrictive than #arch, but I got used to it eventually : )

  11. @reflex @YaLTeR Yeah, the fact that you can just reboot to a different version of your OS is just so cool! I too don't use the vanilla Silverblue, but rather #secureblue, a distro based on that. Before switching to secureblue I used #ArchLinux (BTW), so an atomic desktop felt much more restrictive than #arch, but I got used to it eventually : )

  12. My custom desktop shell I've been working on for several months now

    OS: #secureblue
    WM: #niri
    shell: #Quickshell

    repo: github.com/tpaau/dots

    Sorry for no alt, there's not much I can do here, hopefully @altbot will come up with something sensible.

    #linux #wayland #desktopshell #ricing #ricinglinux #unixporn #materialdesign #material #vim #neovim

  13. My custom desktop shell I've been working on for several months now

    OS: #secureblue
    WM: #niri
    shell: #Quickshell

    repo: github.com/tpaau/dots

    Sorry for no alt, there's not much I can do here, hopefully @altbot will come up with something sensible.

    #linux #wayland #desktopshell #ricing #ricinglinux #unixporn #materialdesign #material #vim #neovim

  14. @privacyguides On my phone I use Vanadium, the default one on #grapheneos, on my laptop I run Trivalent, which is a hardened Chromium fork maintained by the #secureblue team.

  15. I got a question at work here today about hardened Linuxes.
    Remembered SecureBlue and decided to install the KDE iso.
    And first impressions are really good. It includes a hardened browser and many, many tweaks.
    Most of all: with flatpak, homebrew and very good documentation I haven't found things that I can't do yet. Impressive!
    What I appreciate the most is that it makes you rethink about security and how to apply it in D2D.
    Check it out at secureblue.dev

    #secureblue

  16. I got a question at work here today about hardened Linuxes.
    Remembered SecureBlue and decided to install the KDE iso.
    And first impressions are really good. It includes a hardened browser and many, many tweaks.
    Most of all: with flatpak, homebrew and very good documentation I haven't found things that I can't do yet. Impressive!
    What I appreciate the most is that it makes you rethink about security and how to apply it in D2D.
    Check it out at secureblue.dev

    #secureblue

  17. Just installed #secureblue #linux on my old gaming laptop. Let's see if I can live with the limitations 🤞

  18. The feature-list of secureblue is a great resource to start your research about security concepts. secureblue.dev/features

    But do we really need a special GNU/Linux distribution that is secure? Let's go #SecureByDefault!

    #secureblue #linux #silverblue #fedora #cybersecurity #privacy

  19. The feature-list of secureblue is a great resource to start your research about security concepts. secureblue.dev/features

    But do we really need a special GNU/Linux distribution that is secure? Let's go #SecureByDefault!

    #secureblue #linux #silverblue #fedora #cybersecurity #privacy

  20. tails.net/doc/persistent_stora Wouldn't it be much more secure and easier to just include #Homebrew? #Linuxbrew for #Tails. And create a Brew version of #Dangerzone so people can just install it on the fly, and maybe other tools too, especially for example when they just want to use it live without persistence or even with? Brew's base installation appears to be 106 MB or something.

    stackoverflow.com/questions/69

    🤔 I mean #secureblue also has it pre-installed? Just thinking 🤷

  21. tails.net/doc/persistent_stora Wouldn't it be much more secure and easier to just include #Homebrew? #Linuxbrew for #Tails. And create a Brew version of #Dangerzone so people can just install it on the fly, and maybe other tools too, especially for example when they just want to use it live without persistence or even with? Brew's base installation appears to be 106 MB or something.

    stackoverflow.com/questions/69

    🤔 I mean #secureblue also has it pre-installed? Just thinking 🤷

  22. #tails should also implement like #secureblue #linuxbrew it might come handy just thinkin #tor

    Modern Package Management Features: Homebrew leverages modern distribution methods (like OCI artifacts and GitHub Packages), supports aggressive updates, and is integrating advanced security features such as SLSA build level 2 and sigstore integration. These features enhance both usability and security for end-users.

    (1/2)

  23. #tails should also implement like #secureblue #linuxbrew it might come handy just thinkin #tor

    Modern Package Management Features: Homebrew leverages modern distribution methods (like OCI artifacts and GitHub Packages), supports aggressive updates, and is integrating advanced security features such as SLSA build level 2 and sigstore integration. These features enhance both usability and security for end-users.

    (1/2)

  24. #silverblue #secureblue #fedora

    KeepasXC wörks when one installs the secureblue teams maintained version.

    Libreoffice works fine, onlyoffice don't which is no problem per se there are online alternatives.

    Security audit with lynis hangs at `Querying DNF…`

    Trivalent as a browser like Vanadium is very interesting. Sad tho that Librewolf doesn't work. I know I could probably run some software as ostree or something but I would rather not.

  25. #silverblue #secureblue #fedora

    KeepasXC wörks when one installs the secureblue teams maintained version.

    Libreoffice works fine, onlyoffice don't which is no problem per se there are online alternatives.

    Security audit with lynis hangs at `Querying DNF…`

    Trivalent as a browser like Vanadium is very interesting. Sad tho that Librewolf doesn't work. I know I could probably run some software as ostree or something but I would rather not.

  26. #silverblue #secureblue #fedora

    Of course one disables first

    brew analytics off

    Ok yt-dlp, lynis, htop, vim, chkrootkit, rkhunter, mat2(hangs though) can be installed via #brew #linuxbrew it's sad that dangerzone is missing there mhh… only for macos as a cask.

    Signal works after enabling flathub beta repos

    flatpak override --user --env=SIGNAL_PASSWORD_STORE=gnome-libsecret org.signal.Signal

    flatpak override --user --env=ELECTRON_OZONE_PLATFORM_HINT=auto org.signal.Signal

    Then it works

  27. #silverblue #secureblue #fedora

    Of course one disables first

    brew analytics off

    Ok yt-dlp, lynis, htop, vim, chkrootkit, rkhunter, mat2(hangs though) can be installed via #brew #linuxbrew it's sad that dangerzone is missing there mhh… only for macos as a cask.

    Signal works after enabling flathub beta repos

    flatpak override --user --env=SIGNAL_PASSWORD_STORE=gnome-libsecret org.signal.Signal

    flatpak override --user --env=ELECTRON_OZONE_PLATFORM_HINT=auto org.signal.Signal

    Then it works

  28. Btw, one can also install any Fedora Silverblue with a Secure Boot-compatible Ventoy stick and then, after installation, run the Secure Blue optimizations. Works like a charm! Now I have to figure out how everything else works. 🤣

    Best part: all by myself without help from anyone. ^^

    #Silverblue #secureblue #privacy #security #fedora

  29. Btw, one can also install any Fedora Silverblue with a Secure Boot-compatible Ventoy stick and then, after installation, run the Secure Blue optimizations. Works like a charm! Now I have to figure out how everything else works. 🤣

    Best part: all by myself without help from anyone. ^^

    #Silverblue #secureblue #privacy #security #fedora

  30. #secureblue rocks! 😎 👍

    Portable device with Secure Boot, Secure Blue, LUKS2—everything up to date. Atomic updates, GNOME Wayland, USBGuard, and everything works on an immutable Fedora base system. Everything else is either Flatpaks, Podman, brew or something similar. 🤩 What else could one want to have from a security and privacy perspective?

    secureblue.dev/features

    #silverblue #privacy #security #fedora

  31. #secureblue rocks! 😎 👍

    Portable device with Secure Boot, Secure Blue, LUKS2—everything up to date. Atomic updates, GNOME Wayland, USBGuard, and everything works on an immutable Fedora base system. Everything else is either Flatpaks, Podman, brew or something similar. 🤩 What else could one want to have from a security and privacy perspective?

    secureblue.dev/features

    #silverblue #privacy #security #fedora

  32. So I think I will revisit this project when stuff is a little more stable OR I become more fluent with rpm-ostree cause twice now, I have followed the post install instructions and ended up with no internet when trying to use Trivalent. #secureblue #trivalent

  33. So I think I will revisit this project when stuff is a little more stable OR I become more fluent with rpm-ostree cause twice now, I have followed the post install instructions and ended up with no internet when trying to use Trivalent. #secureblue #trivalent

  34. Somehow managed to break my install. Tried to revert to previous rpm-ostree rollback --reboot but that didn't fix my problem. Wiping and trying again. #secureblue

  35. Somehow managed to break my install. Tried to revert to previous rpm-ostree rollback --reboot but that didn't fix my problem. Wiping and trying again. #secureblue