this post was submitted on 29 Dec 2023
32 points (97.1% liked)

Arch Linux

7737 readers
2 users here now

The beloved lightweight distro

founded 4 years ago
MODERATORS
 

I have my firewall configured pretty restrictively. I am attempting to configure AppArmor but it seems to complicated.

How do you secure your desktop?

you are viewing a single comment's thread
view the rest of the comments
[–] cyanarchy@sh.itjust.works 3 points 10 months ago* (last edited 10 months ago) (1 children)

I know that almost nobody treats it this way but the number one rule of AUR is that it's pretty much all untrusted, by definition.

[–] driveway@lemmy.zip 1 points 10 months ago (1 children)

Same goes for any unofficial flatpak, right? And that is most of them.

[–] tty5@lemmy.world 1 points 10 months ago

In order from the most to the least secure:

  • distro repos: there is a process that is supposed to ensure no malicious changes make it through. Usually far enough behind recent code changes for new issues/code being compromised to be spotted
  • official package outside distro repos if packaging org has secure release workflow
  • building from source / official package on external repo if you know little about packaging org: malicious contributor or a compromised account is enough
  • unofficial package: like building from source, but you have to worry about package maintainer too