It's pretty old and only affects openSUSE, the title is extremely misleading
https://cdn2.qualys.com/2025/06/17/suse15-pam-udisks-lpe.txt
31–40 of 287 posts
It's pretty old and only affects openSUSE, the title is extremely misleading
https://cdn2.qualys.com/2025/06/17/suse15-pam-udisks-lpe.txt
As someone who has been using linux quite happily on the desktop for more than 20 years now, I have to say it remains an eternal experiment, feature wise as well as security wise.
Earlier quoted context omitted.
What especially feels like an experiment is container technology.
how much harder is container escaping compared to vm escaping? i understand that containers are not truly meant to be security boundaries but they are often thought of and even used as such.
The answer heavily depends on your configuration. Unprivileged with a spartan syscall filter and a security profile is very different than privileged with the GPU bindmounted in (the latter amounts to a chroot and a separate user account).
Earlier quoted context omitted.
If you think Linux is an experiment, you should see the other OSes.
I'm pretty sure, that the BSD family is pretty mature and secure. Linux is just good enough for most people.
They are still missing something like capability based security like iOS and Android have where apps have to be granted access to use things like files or the camera. It may have been considered secure a couple decades ago, but they have fallen behind the competiton.
Earlier quoted context omitted.
how much harder is container escaping compared to vm escaping? i understand that containers are not truly meant to be security boundaries but they are often thought of and even used as such.
> how much harder is container escaping compared to vm escaping? The answer heavily depends on your configuration. Unprivileged with a spartan syscall filter and a security profile is very different than privileged with the GPU bindmounted in (the latter amounts to a chroot and a separate user account).
And yes, this will most likely be a mess.
Earlier quoted context omitted.
That's certainly an interesting standpoint. I use both privately and professionally and while I accept that security-wise (even with selinux) they feel lacking , feature-wise they far exceed Windows I use as my other is except in gaming experience. I wish I had something like GrapheneOS on desktops (yes I know about Qubes)
> I wish I had something like GrapheneOS on desktops (yes I know about Qubes) SecureBlue and Kicksecure are the closest equivalents.
Earlier quoted context omitted.
I'm pretty sure, that the BSD family is pretty mature and secure. Linux is just good enough for most people.
>is pretty mature and secure They are still missing something like capability based security like iOS and Android have where apps have to be granted access to use things like files or the camera. It may have been considered secure a couple decades ago, but they have fallen behind the competiton.
...like Capsicum?
Earlier quoted context omitted.
If you think Linux is an experiment, you should see the other OSes.
I'm pretty sure, that the BSD family is pretty mature and secure. Linux is just good enough for most people.
Take filesystems, the official filesystems are UFS(1/2) and ZFS. They have GEOM as LVM and LUKS and more.
That being said, the majority of money and development goes into Linux, which by itself may make it a better system (eventually).
Edit: Of course UFS is not deprecated.
Earlier quoted context omitted.
I'm pretty sure, that the BSD family is pretty mature and secure. Linux is just good enough for most people.
>is pretty mature and secure They are still missing something like capability based security like iOS and Android have where apps have to be granted access to use things like files or the camera. It may have been considered secure a couple decades ago, but they have fallen behind the competiton.