Pantherina

@Pantherina@feddit.de

This profile is from a federated server and may be incomplete. Browse more on the original instance.

Switching to Debian on my gaming pc

Hello everyone - I have been wanting to ditch windows on my gaming pc for a while now, and since I have recently finished a large project, I now have the free time to switch. I am relatively comfortable with Debian having used it for a while on my web server as well as school laptop, but I am concerned about using it on my...

Pantherina,

Debian is very manual in like everything. But Linux Mint uses Cinnamon which uses X11 for a loong time and that is pretty bad for anything modern with Graphics Cards

Pantherina,

Thanks. But is not using user namespaces just as bad as having no isolation, or can bubblewrap-suid or even Browsers isolate anyways?

Because thats what makes me curious, does removing them for security make the system less secure?

Pantherina,

So basically all laptop users can safely use it.

Crazy how PC users rely on such a steady power supply. Arent there small UPS devices for a few seconds with auto shutdown?

Pantherina,

Thanks. Bcachefs is for SSD-HDDs isnt it?

Pantherina, (edited )

Then disable the updates lol. This is done in the background and includes all the security patches so you dont even see any of it, not a single popup.

We are not talking about backported security fixes, but literally no updates for an entire month.

Pantherina,

Proprietary UEFI BIOS is, but for a secure system with local manipulation prevention it can be needed. Also secureboot is a security measurement against malware so no, its simply the best we have.

Look at Coreboot if you want a secure modern system

  • novacustom
  • 3mdeb
  • starlabs
  • system76
Pantherina,

Okay I went more the ProtonUpQt + Bottles + oversea way

Librewolf but like... for chromium?

My main browser is Librewolf but I keep a chromium browser just in case. Previously used brave but their flatpak is shit. Ungoogled chromium seems ok but it looks like they don’t change much from upstream chromium. Any good chromium browsers which harden their browsers like librewolf does for more privacy?

Pantherina,

They load google Javascript right? Does that proof “your account data” is sent to Google or Facebook (hate these hide-away company names)

I think this is not true. Mozilla doesnt send user accounts to these sites.

Even though the plain existence of these javascript tracking scripts is absurd. But dont spread fake news please

Pantherina,

Automatic openings? Like default Webbrowser? Also dont use Appimages, just dont.

Depending on the Distro I recommend using Firefox or Brave, add their signed repo and call it a day.

Pantherina,

You havent looked at the repo. And we are talking about different sandboxes here.

The browsers sandbox websites, this is broken if the entire browser is sandboxed as you need to remove that capability to do so.

My bash script pulls in the official brave repo and gpg key, fix the access permissions and that is it. Brave has no documentation on how to use their repo without dnf so this is needed.

The repo has gpg verification enabled and the system will update the browser.

Please dont spread misinformation if you havent even looked at the “random bash script” that does not handle the updatingô

Pantherina, (edited )

No default browser works normally but no idea how to set that in Hyprland.

I highly advise against Appimages. Flatpak is only useful if you dont trust the app which is a valid opinion, but poorly then the browser cant sandbox websites on its own. So native packages are the best option for security it you trust the browser.

Perfect would be to have the browser isolated and also using its sandbox to isolate websites from each other. I dont know if this works though, on Android it does (not with Firefox poorly as they didnt implement it)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #