mirror of
https://github.com/privacyguides/privacyguides.org.git
synced 2025-04-27 18:46:23 -04:00
update: Tumbleweed logo and SELinux default (#2886)
Signed-off-by: fria <138676274+friadev@users.noreply.github.com> Signed-off-by: Daniel Gray <dngray@privacyguides.org>
This commit is contained in:
parent
f0308a3886
commit
5f93339323
@ -9,9 +9,9 @@ Our website generally uses the term “Linux” to describe **desktop** Linux di
|
||||
|
||||
[Our Linux Recommendations :material-arrow-right-drop-circle:](../desktop.md){ .md-button }
|
||||
|
||||
## Privacy Notes
|
||||
## Security Notes
|
||||
|
||||
There are some notable privacy concerns with Linux which you should be aware of. Despite these drawbacks, desktop Linux distributions are still great for most people who want to:
|
||||
There are some notable security concerns with Linux which you should be aware of. Despite these drawbacks, desktop Linux distributions are still great for most people who want to:
|
||||
|
||||
- Avoid telemetry that often comes with proprietary operating systems
|
||||
- Maintain [software freedom](https://gnu.org/philosophy/free-sw.en.html#four-freedoms)
|
||||
@ -51,7 +51,7 @@ We don’t believe holding packages back and applying interim patches is a good
|
||||
|
||||
Traditionally, Linux distributions update by sequentially updating the desired packages. Traditional updates such as those used in Fedora, Arch Linux, and Debian-based distributions can be less reliable if an error occurs while updating.
|
||||
|
||||
Atomic updating distributions, on the other hand, apply updates in full or not at all. On an atomic distribution, if an error occurs while updating (perhaps due to a power failure), nothing is changed on the system.
|
||||
Distros which use atomic updates, on the other hand, apply updates in full or not at all. On an atomic distribution, if an error occurs while updating (perhaps due to a power failure), nothing is changed on the system.
|
||||
|
||||
The atomic update method can achieve reliability with this model and is used for [distributions](../desktop.md#atomic-distributions) like Silverblue and NixOS. [Adam Šamalík](https://twitter.com/adsamalik) provides a presentation on how `rpm-ostree` works with Silverblue:
|
||||
|
||||
@ -84,7 +84,7 @@ We recommend **against** using the Linux-libre kernel, since it [removes securit
|
||||
|
||||
### Mandatory access control
|
||||
|
||||
Mandatory access control is a set of additional security controls which help to confine parts of the system such as apps and system services. The two common forms of mandatory access control found in Linux distributions are [SELinux](https://github.com/SELinuxProject) and [AppArmor](https://apparmor.net). While Fedora uses SELinux by default, Tumbleweed [defaults](https://en.opensuse.org/Portal:SELinux) to AppArmor in the installer, with an option to [choose](https://en.opensuse.org/Portal:SELinux/Setup) SELinux instead.
|
||||
Mandatory access control is a set of additional security controls which help to confine parts of the system such as apps and system services. The two common forms of mandatory access control found in Linux distributions are [SELinux](https://github.com/SELinuxProject) and [AppArmor](https://apparmor.net). Fedora and Tumbleweed use SELinux by default, with Tumbleweed offering an option in its installer to choose AppArmor instead.
|
||||
|
||||
SELinux on [Fedora](https://docs.fedoraproject.org/en-US/quick-docs/selinux-getting-started) confines Linux containers, virtual machines, and service daemons by default. AppArmor is used by the snap daemon for [sandboxing](https://snapcraft.io/docs/security-sandboxing) snaps which have [strict](https://snapcraft.io/docs/snap-confinement) confinement such as [Firefox](https://snapcraft.io/firefox). There is a community effort to confine more parts of the system in Fedora with the [ConfinedUsers](https://fedoraproject.org/wiki/SIGs/ConfinedUsers) special interest group.
|
||||
|
||||
@ -158,6 +158,6 @@ There are other system identifiers which you may wish to be careful about. You s
|
||||
|
||||
The Fedora Project [counts](https://fedoraproject.org/wiki/Changes/DNF_Better_Counting) how many unique systems access its mirrors by using a [`countme`](https://fedoraproject.org/wiki/Changes/DNF_Better_Counting#Detailed_Description) variable instead of a unique ID. Fedora does this to determine load and provision better servers for updates where necessary.
|
||||
|
||||
This [option](https://dnf.readthedocs.io/en/latest/conf_ref.html#options-for-both-main-and-repo) is currently off by default. We recommend adding `countme=false` to `/etc/dnf/dnf.conf` just in case it is enabled in the future. On systems that use `rpm-ostree` such as Silverblue, the countme option is disabled by masking the [rpm-ostree-countme](https://fedoramagazine.org/getting-better-at-counting-rpm-ostree-based-systems) timer.
|
||||
This [option](https://dnf.readthedocs.io/en/latest/conf_ref.html#options-for-both-main-and-repo) is currently off by default. We recommend adding `countme=false` to `/etc/dnf/dnf.conf` just in case it is enabled in the future. On systems that use `rpm-ostree` such as Silverblue, the `countme` option is disabled by masking the [rpm-ostree-countme](https://fedoramagazine.org/getting-better-at-counting-rpm-ostree-based-systems) timer.
|
||||
|
||||
openSUSE also uses a [unique ID](https://en.opensuse.org/openSUSE:Statistics) to count systems, which can be disabled by emptying the `/var/lib/zypp/AnonymousUniqueId` file.
|
||||
|
@ -1 +1,5 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" width="128" height="128" version="1.1" viewBox="0 0 33.867 33.867"><path fill="#35b9ab" stroke-width=".135" d="m25.988 9.0047c-1.556 0-3.0622 0.44692-4.403 1.2083-1.3076 0.74486-2.4498 1.7545-3.4594 2.8636-0.39726 0.43036-0.77796 0.89384-1.1587 1.3573-0.36415 0.44692-0.69521 0.91038-1.0428 1.3739-0.16552 0.23173-0.3476 0.48002-0.51312 0.71175-0.3476 0.48002-0.69521 0.9435-1.0759 1.3739-0.36415 0.39726-0.74486 0.77796-1.1256 1.1587-0.96004 0.94348-1.9863 1.8207-3.1284 2.5491-0.89384 0.56278-1.9532 1.109-3.0457 1.109-2.9297 0-5.5451-2.3173-5.5451-5.843 0-3.5256 2.516-5.4457 5.5451-5.4457 1.7545 0 3.294 0.74487 4.8002 2.0359l-0.81107 0.82762 3.9394 0.99315-1.0925-3.9064-0.87728 0.91038c-1.5393-1.3739-3.4429-2.4829-5.843-2.4829-3.9229 0-7.1506 2.8305-7.1506 7.1506 0 4.138 3.2277 7.1506 6.8527 7.1506 1.5062 0 2.9628-0.44692 4.2374-1.2083 1.1587-0.67865 2.1684-1.5724 3.0953-2.5491 0.31449-0.33105 0.61244-0.66209 0.91038-0.99315 0.39726-0.43036 0.76141-0.86072 1.0925-1.3573 0.14897-0.21517 0.28139-0.43036 0.43036-0.64555 0.26483-0.39726 0.51312-0.79452 0.79452-1.1752 0.52968-0.71175 1.0759-1.407 1.6553-2.069 0.99314-1.109 2.1188-2.1353 3.4263-2.8305 1.0428-0.56278 2.2015-0.86072 3.3932-0.86072 4.138 0 6.4555 2.8801 6.4555 6.5547 0 3.4263-2.218 6.2568-6.0416 6.2568-2.1849 0-4.1051-0.59589-6.1244-2.3339l0.9435-1.1421-4.0056-0.66209 1.4235 3.8072 0.79452-0.96004c1.9532 1.7711 4.0884 2.9297 6.8692 2.9297 4.6346 0 7.6638-3.5256 7.6638-7.9617-0.01655-4.6677-3.1449-7.8955-7.879-7.8955z"/></svg>
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!-- Created with Inkscape (http://www.inkscape.org/) -->
|
||||
<svg width="128" height="128" version="1.1" viewBox="0 0 128 128" xmlns="http://www.w3.org/2000/svg">
|
||||
<path transform="matrix(-.87465 0 0 .87465 120.75 8.0741)" d="m94.992-0.066849c18.715-0.044873 33.956 15.196 33.911 33.911-0.04486 18.715-15.321 33.989-34.036 34.034l-8.4141 0.020097 0.017864-0.002233c-6e-3 1.4e-5 -0.007498-1.3e-5 -0.013398 0h-0.002233c-7.6468 0.017388-14.32 0.032773-17.572 0.040195-0.009725 4.4623-0.040839 18.807-0.058059 25.984-0.044878 18.715-15.319 33.991-34.034 34.036-18.715 0.04487-33.956-15.196-33.911-33.911 0.044867-18.715 15.321-33.989 34.036-34.034 2.1936-0.00527 4.5166-0.010064 7.9407-0.017864 7.7782-0.017708 14.744-0.032937 18.041-0.040195 0.009726-4.4623 0.040848-18.807 0.058059-25.984 0.04487-18.715 15.321-33.991 34.036-34.036zm0.020097 8.0055c-1.103 0.0026456-2.187 0.081744-3.2535 0.2166v28.826h28.936c0.12707-1.0356 0.20064-2.0878 0.20321-3.1575 0.0345-14.39-11.496-25.92-25.885-25.885zm-11.259 2.5702c-8.739 4.2031-14.767 13.124-14.792 23.478-0.01718 7.1648-0.048059 21.454-0.058059 25.946 4.4917-0.0099 18.779-0.040849 25.943-0.058059 10.391-0.024925 19.338-6.0976 23.523-14.888h-34.617v-34.478zm-22.873 57.447c-4.4931 0.00995-18.781 0.040851-25.946 0.058059-10.529 0.025256-19.571 6.2614-23.681 15.241h34.474v34.264c8.9016-4.1421 15.07-13.146 15.095-23.619 0.01719-7.1648 0.048059-21.452 0.058059-25.943zm-23.157 23.3h-28.679c-0.10066 0.92285-0.15627 1.8597-0.15855 2.8092-0.034516 14.39 11.496 25.92 25.885 25.885 0.99889-0.00239 1.9828-0.06749 2.9521-0.17864v-28.516z" color="#000000" fill="#35b9ab" fill-rule="evenodd" stroke-linecap="square" style="-inkscape-stroke:none"/>
|
||||
</svg>
|
||||
|
Before Width: | Height: | Size: 1.5 KiB After Width: | Height: | Size: 1.7 KiB |
Loading…
x
Reference in New Issue
Block a user