[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology

Name
Options
Comment
Verification
4chan Pass users can bypass this verification. [Learn More] [Login]
File
  • Please read the Rules and FAQ before posting.
  • You may highlight syntax and preserve whitespace by using [code] tags.

08/21/20New boards added: /vrpg/, /vmg/, /vst/ and /vm/
05/04/17New trial board added: /bant/ - International/Random
10/04/16New board for 4chan Pass users: /vip/ - Very Important Posts
[Hide] [Show All]


[Advertise on 4chan]


File: 1750986818887997.png (929 KB, 736x1236)
929 KB
929 KB PNG
Do you set up apparmor/selinux/secureboot on your arch system?
>>
File: IMG_1055.jpg (934 KB, 2000x1487)
934 KB
934 KB JPG
How do i set up app armor on nix
>>
What's the usecase of Secure Boot?
>>
>>106993779
Bootkits
>>
>>106993779
Taking control way from the owner of the computer (real)
"Protecting users against the totally real danger of strangers sneaking into their home, installing a custom firmware or replacing boot.efi with a counterfeit" (fake)
>>
>>106993199
For both SELinux and AppArmor I cannot find enough tutorials and resources that are fast easy to digest.
Especially when it comes to more advanced uses like filtering D-Bus etc. and SELinux is a bit harder to compile policies into the system.
If I could have I would have setup a very tight SELinux/AppArmor profile on my computer to ensure nothing in the home dotfiles gets replaced by apps that shouldn't have access to each others configuration.
Secureboot, yes absolutely.
>>
>>106993889
It's either decking out SELinux/AppArmor or/and flatseal.
Or paying every year for sandboxie home so that I can sandbox apps away from each other.
So that I don't get pwned/infostealer incident by opening an infected meme image on discord/the web.
>>
>>106993199
>Do you set up apparmor/selinux/secureboot on your arch system?
Honestly, I'd love to. Yes secureboot is managable, but setting up selinux will give you terminal cancer, if you need/want the extra security of selinux, just use a distro, that has it by default. cia, nsa, android, opensuse and red hat use selinux, lol.
>>106993881
many people think secureboot is just for windows, but no it's just extra security, why do you complain? Another reason why I have it activated is, because I dual boot for some kernel malware games on windows.
>>
once secureboot is enforced and with no way of disabling it, say goodbye to running linux

>j-just run your own keys bro
very hard to do, most normies will never do it, and in many computers will brick your motherboard.
>>
File: 1730442158640864.jpg (448 KB, 1086x1080)
448 KB
448 KB JPG
>>106993199
No use case for that on personal computer
>>
>>106994822
just like hardware attest and other schizo delusions like pluton this isn't and will not happen
>>
>>106994204
youre not that important for secure boot to ever matter
>>
>>106995281
Nice try glowie
>>
File: 1755458005393654.png (70 KB, 448x274)
70 KB
70 KB PNG
>>106995296
>>
>>106995307
UKSA/Penal Colony issue
>>
>>106995307
lmao
>>
You don't need faparmor or sexlinux if you're not testing or using closed source/potential malware on your system
>>
>>106993881
Self-signed secure boot is a thing, you know.
>>
>>106995415
lmao

>>106994822
>j-just run your own keys bro
>>
>>106995437
not my fault you didn't do your research before buying
>>
>>106995415
iirc you actually have to sign the nvidia driver if you have secureboot activated on arch, not a problem with distros with a license
>>
>>106995281
true, but still SELinux is nice to have.
>>
>>106995459
and here comes the self sign cope
>>
microshart secure boot, never
>>
>>106995475
CachyOS automates this
https://wiki.cachyos.org/configuration/secure_boot_setup/



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.