Replies (14)

Some of them make it easier to install in more secure manners too. Although verifying this is beyond my ability. Fedora, for example, allows different policies use by governments, etc. Requires user input the higher you go, in my experience. I just go with the best option that doesn't require me to touch things I don't understand. Most people probably just slap the default on
The hardware macOS runs on is far more secure than other laptop/desktop platforms and macOS is the only OS available for it which uses most of the hardware-based security features. The issue is you're completely hard locked on Apple then. Choosing a desktop OS today is a losing battle. Desktop OSes in general fall behind on adding security design / features that have been researched for decades. Linux distributions are incredibly behind on this and no one should be expected to configure things like SELinux to make it comfortable. Linux is a gigantic monolithic kernel written almost entirely in a memory unsafe language. It's good to have many vulns but having hundreds discovered over days will become unsustainable. A lot of the mobile OSes started development decades after the desktop, there was far more research on secure OS design by that point and so a better foundation to run on.
I'll get heat for this but I don't believe in the David vs. Goliath narrative people have for Linux as some sort of bastion against 'big tech'. It's one of the most used OS/kernels in the world, mostly by big tech and their employees motivate most of its development. It's only because it's open source. I think if people cared enough about competition they'd invest it into improving things like Qubes OS, Secureblue (a novel hardened Linux distribution) or a jump to newer OSes like making Redox OS more available to people.
I agree that macOS is pretty great in terms of security model, but that desktop is in general a mess … I’m more curious about your opinion for more limited tasks, and not day-to-day usage, like hardened limited-purpose servers, or to process sensitive data, and such. It is unfortunate we don’t have a lot of investment in this area.
pnk's avatar
pnk 3 days ago
Me too and I'm using an Apple trackpad over Bluetooth (because screen is far away) and I'm having and awful lag between my finger and the mouse pointer. Are you seeing anything like that?
The Xous distro that the Passport Prime uses has the right idea from a design standpoint. Microkernel, memory safe languages used throughout, mandatory sandboxing for apps. Xous is mostly designed for embedded systems. Obviously implementation is a different thing to rate compared to just the design. I also haven't looked into the hardware as much. I would take it as one of the better offerings the HWW market has right now. Secureblue has a server distro, hardened CoreOS. I would assume a lot of these bitcoin one-click server dashboard distros aren't as hardened to such an extent. Perhaps it's a room for improvement for these projects. A lot of defence corps sell their own OSes with the above as marketing, 'STOP OS' by BAE Systems comes to mind. Good luck being able to copy of it yourself though.
I have a hard time taking Passport Prime seriously after several of their claims and decisions. The idea makes sense, but at that point Betrusted seems like a better option