Earlier quoted context omitted.
> Running applications as restricted users has been standard practice for decades ...as a way of preventing users from interfering with the system or other users in multi user systems. Running applications as a user different from yourself is an ugly hack we've started doing because we don't have actual control over what our applications can access, so things like ransomware are possible despite not having system lev…
Once you add backup in the picture, the local users are great. My main account can have all the ransomware it wants, all the backups are gong to stay intact, so I can restore the files. * in the real life, there is “sudo hole”, but this can be fixed within the current user concept.
EasyOS: An experimental Linux distribution designed from scratch for containers
91–94 of 94 posts
Re: EasyOS: An experimental Linux distribution designed from scratch for containers
#92Fedora Silverblue is already semi-production ready https://silverblue.fedoraproject.org https://fedoramagazine.org/what-is-silverblue/ https://docs.fedoraproject.org/en-US/fedora-silverblue/toolb...
Re: EasyOS: An experimental Linux distribution designed from scratch for containers
#93Earlier quoted context omitted.
Once you add backup in the picture, the local users are great. My main account can have all the ransomware it wants, all the backups are gong to stay intact, so I can restore the files. * in the real life, there is “sudo hole”, but this can be fixed within the current user concept.
I'd rather prevent ransomware from working in the first place. Local backups are hardly sufficient anyway.
I was under impression that even with zero days, using modern distribution and auto updates will minimize the amount of time the system is vulnerable, so for most of time, it will be sufficient.
Re: EasyOS: An experimental Linux distribution designed from scratch for containers
#94Earlier quoted context omitted.
Do you have a point to make about how this is better , or is this change for the sake of change?
GUI tools provide significantly better discoverability, for one. The file hierarchy is a mess to put it mildly.