Live data from Hacker News

Viewing profile — secureblue

secureblue

HN member
Joined
Fri, Dec 15, 2023, 9:54 PM UTC
HN karma
89
Public activity
18 items

About secureblue

No profile information was provided.

Recent public activity

  1. comment
    Comment #45045190

    secureblue creator here :) some corrections: > last I heard it wasn't out of Beta or whatever yet It is > But it uses containers rather than VMs It doesn't use plain containers for…

  2. story
  3. comment
    Comment #40136564

    We've been working hard to address feedback and make improvements over the last several months. Secureblue now has expanded hardening, improved documentation, and clearer scope. In…

  4. comment
  5. story
  6. story
  7. comment
    Comment #38668043

    FYI, both userns and non-userns variants are now available. https://github.com/secureblue/secureblue/commit/38999d4123aa...

  8. comment
    Comment #38661316

    Clearlinux has nothing comparable to this as far as I know: https://github.com/ublue-os/startingpoint And it's also mainly geared towards server use cases, whereas this project is …

  9. comment
    Comment #38660786

    Just changed it. Thanks for the feedback!

  10. comment
    Comment #38660690

    What is your distro doing that would make someone want to degoogle it? Certain users have expressed a preference towards Brave instead of Chromium because in their view Brave's "de…

  11. comment
    Comment #38660685

    Some people think that Brave is preferable to Chromium because they "degoogle" it.

  12. comment
    Comment #38660675

    Trading off possible kernel bugs against letting a whole LOT of userspace software run with real root privilege Only bubblewrap would run as root, but yes this is a fair critique a…

  13. comment
    Comment #38660351

    As a follow up to this, given that bubblewrap-suid without userns vs bubblewrap with userns is a tradeoff, I could make it so both variants are published. This would give users cho…

  14. comment
    Comment #38660202

    I'm just making a judgement call for myself. Any other project ontop of Fedora increases the attack vector with its own maintainers. Totally understandable. an ISO Small point of c…

  15. comment
    Comment #38660165

    Universal blue, the starting point for this project, is fedora based. https://universal-blue.org/ No other distro has the same level of immutable tooling or support for immutable v…

  16. comment
    Comment #38660149

    I'm a little concerned that degoogling would be necessary. I don't follow. The readme specifically says it's not in scope. How much of the user's privacy is this thing selling away…

  17. comment
    Comment #38659932

    Most of this can be done with Ansible. All of this can be done in several ways. Ansible, manually, a script, etc. Building it into an image just makes it more convenient. So why sh…

  18. story