I want to clarify my threat model because my original post may have placed too much emphasis on privacy.
I am not particularly concerned about advertising trackers, Big Tech, government surveillance, or remaining anonymous online. My main concern is protecting my computer and accounts from a targeted attacker—for example, a technically capable and hostile former partner attempting to compromise my device, email, passwords, or personal files.
My everyday needs are basic:
Web browsing and email
A VPN
LibreOffice
Opening normal documents and attachments
A system that does not require advanced Linux command-line knowledge
I understand that no operating system can protect me if I voluntarily enter my password into a phishing page or approve a malicious request. However, I would like a system that reduces the damage if I accidentally open a malicious link, attachment, or application.
I am looking for something more secure than a typical Linux Mint installation, but not nearly as complicated or restrictive as Qubes OS. I want something practical that can remain my everyday computer.
With this clarified threat model, what would you recommend?
Would Fedora Silverblue, Secureblue, Fedora Workstation, or another distribution provide the best balance of security and usability? Does an immutable system such as Silverblue meaningfully help against this kind of personal, targeted attack, or should I focus more on browser isolation, application sandboxing, full-disk encryption, hardware security keys, and good account security?
Chromebook or GrapheneOS are both Linux and could be a good option.
You should be fine using Fedora Linux, Chromium browser, and installing as little software as possible. Just stick to the browser and install a uBlock (or Brave) to prevent Malvertising
Grapheneos, ios, or macos, unless it’s a money thing, over desktop Linux. These do what you want much better than desktop linux and will provide more protection against targetted attacks. I think macos is most like what you want and you can exclusively install open source programs if you want.
Hold up, you already made this thread:
My advice is the same as it was in that thread. You can do this on mobile besides maybe Libreoffice, but you can use proton docs and sheets to write documents. Macos is also an option for desktop.
If you go with desktop Linux anyway, Ubuntu or Fedora. Ubuntu has the most resources and support but has slower updates, but they patch the type of vulnerabilities that were in the news quickly. If you want to minimize time in the terminal or configuring settings it’s the safest bet.
When you say “restrictive,” what do you mean? And what extra do you need? When I look at your basic needs and threat model, Qubes would be a perfect match. Qubes isn’t that hard to learn as many people make it sound.
Trivalent in a Fedora 44 VM if you just want security.
An alternative would be something like Fedora as a host and have Whonix and Kicksecure VMs in Live Mode depending on needs or if you want to use Tor or not, but I would use Qubes at that point.
In general, from the other thread, MacOS or GrapheneOS’ desktop mode likely offers you the most security, put simply. Comparatively, desktop Linux is widely considered inherently less secure.
If you still want to consider Linux distros outside of Qubes OS, Secureblue offers more security than most at the cost of convenience (depending on use). For more convenience, consider Fedora with Trivalent (and secureblue’s SELinux policy), as your browser is more likely to be a central attack surface.
In this case I wouldn’t limit yourself to Linux. Mac is the most secure desktop but I’m not sure if that’s an option for you. If you must use a PC, hardened Windows might be worth considering? It has garbage privacy but could have more security features and exploit mitigations than most if not all desktop Linux distros. I’m not sure if it’ll make a real difference for you but it’s something to look into.
Definitely learn about other aspects of security such as DNS blocking, email compartmentalization through aliasing, how to tell if you’re being phished, etc.
If you’re willing to deal with some less usability, secureblue might be the best compromise if you prefer Linux over Windows. You may run into some issues but you can probably get around them by asking for help in the secureblue Discord. Otherwise the main user-friendly recommendation is still Fedora Workstation or KDE. Regardless of which OS you choose, you may want to consider using a virtual machine for things like email and web browsing if you’re seriously at risk of being targeted by a skilled attacker.
Definitely put more time into focusing on the latter. AFAIK immutable/atomic distros don’t provide any inherent security benefit, they exist more for stability and preventing the user from accidentally breaking their system which can sometimes come at a cost to usability. If you’re not gonna go with secureblue, I’d recommend Fedora Workstation over Silverblue.
Based on the threat model it would seem social engineering mitigations, OSINT prevention by minimizing data, would be more important than the OS specific security.
Of course go ham with OS sec if you want, it doesn’t hurt.
Notably the enterprise/business edition windows is what has more security features like disk encryption, from what I’ve read.
If they’re worried about physical attacks other than theft (disk or even home folder encryption works here) I’d strongly recommend mobile or macos though. They’re much more sophisticated in protecting here. Though boot hijacking and hardware manipulation is specialized knowledge and not something most technically skilled people could pull off with limited time.
You caught me before my edit. I meant something like covertly adding a physical keylogger and recovering it later or hijacking the boot process via a USB vulernability is specialized knowledge and therefore possibly not what they need to be worried about, even if mobile and macos provide more protections here.
That’s fair, I’m just basing this recommendation off of what they say they’ll use:
I haven’t tested it myself but I don’t see why secureblue shouldn’t be able to do all of this without any issues. One of the main usability issues I found was with installing Electron apps, but if this user sticks to the browser (most Electron apps are available as web apps anyways) they should be fine.
With Windows 10 you needed Pro (or better) for full disk encryption. Windows 11 seems much weirder. From what I’ve read, Home supports basic full disk encryption if you sign in using a Microsoft account (which provides Microsoft with your decryption keys) but Pro (or better) supports all of BitLocker’s features, presumably including local full disk encryption? IIRC the benefit of Enterprise is having much greater control over permissions and policies, but it’s very expensive and only usable to IT folks.
If OP reads this, maybe consider getting Windows 11 Pro instead of Home to be safe (if you go the Windows route).
What are we talking about exactly?
Could the attacker get physical access to your devices?
What does technically capable mean? Is he just someone who is good with computers or someone who has the knowledge and resources to deliver spyware and if so, only cheap off-the-shelf spyware or more expensive/sophisticated spyware?
Agreed. For most cases of hostile former partners, that should have priority over OS optimization and even more so taking care of physical security. Also making sure that no spyware is already lingering, from the time the former partner still had physical access.
Atomic does barely nothing about security, and what SecureBlue does can also be applied to regular Fedora. They used the atomic version because it saved a lot of work.
Securing your local personal devices is a good step but you may be missing the big picture.
Have you already set freezes at the big 4 credit reporting agencies, secured your Bigtech, email, SSA and IRS accounts with MFA and set a sim security pin with your telco?