Suggestion: remove 8 out of 10 recommended desktop OSes to prevent overchoice

This would actually benefit OP as there is basically no chance of getting community consesnus to remove all 8 desktop OS they are suggesting where there is a much higher chance if each one is considered individually.

You are right, that would probably be a better approach than my initial bulk deletion suggestion. However, for the time being, I don’t think I want to continue with pushing this idea.

If there are any strong candidates for deletion, I wouldn’t mind anyone creating a new thread independent of this one

I’m not informed enough to make a thread myself, but it seems like Arch could be removed given its supposed complexity, lack of additional benefits compared to other distros, and the issues with AUR packages when AUR is often seen as one of the reasons to use arch.

I could be wrong here since I’ve never used arch though.

As someone who frequently suffers from choice overload/choice paralysis here is my suggestion:

Don’t remove options to reduce choice paralysis, introduce personas instead.
Someone getting overwhelmed by the amount of choices is most likely someone wanting to make the switch to Linux, here is your first-timer persona. Keep the choices simple:

  • a more Windows-like desktop environment → Fedora KDE;
  • this one looks pretty → Fedora GNOME.

Keep the info on the other OSes as well for anyone who would want to consider more options, has a different threat model, or just learn more.

Preferably these would be two different pages, if everything was on the same page I would personally still read on past the first-timer options, get overwhelmed, and delay my switch, whereas is the firs-timer options are on a separate page that I can go back to I’d be more likely to pick whichever desktop environment seems nicer to me.

As an aside I couldn’t get my mom’s HP scanner to work on an immutable distro, so she is on Fedora Workstation now, for those 5 times a year she needs to print or scan something. But she much prefers GNOME as it is more like her phone than KDE.

I agree that it needs paring down, and additionally I believe there are some picks that should not be there.

Arch is a horrid recommendation for someone new to Linux. Besides Gentoo or LFS, it is the most difficult to set up for essentially no reason other than that’s how they want to do it. From a security perspective, this includes not even having a firewall unless you set it up yourself. The AUR is probably not something a security minded individual should be looking at, particularly a newcomer, and yes, Arch based distros are somewhat reliant on the AUR, despite the official repos. The AUR suffered a coordinated attack recently where hackers abused the system of how to take over maintaining dead projects and injected malware, as well as a few that were new. Not only is this possible, but packages are not reviewed at all by Arch or anyone but you, if you choose to and can read code. Arch is not a bad distro, there are a ton of distros I’d recommend to people that are not on this list because they don’t meet the criteria we have chosen to focus on. So Arch needs to go as a recommendation. It offers nothing for privacy or security that openSUSE wouldn’t.

Nix feels like it is there just to say “see, there are other types of technically atomic distros that aren’t immutable, isn’t atomic a cool concept?” Since it is not immutable, you’re not gaining the additional security from that, as you can still install malware just as easily. From a security perspective, their packaging system is really not much better than the AUR at the end of the day. Many packages are safe and official, but you have to pay attention constantly, and it is very easy to make Nix packages with a trivial review process. Similarly to Arch, why was it recommended from a privacy and security perspective? Reproducibility is cool and all, but not a privacy/security feature. It is probably the next hardest distro to set up after Arch, and feels alien compared to the main 3 distro families. So it is a bad recommendation regardless of skill, unless you specifically need its features. Additionally, the devs tend to be rather unprofessional and get caught up in weird drama on a regular basis. I can provide further info on this if needed. Again, like many Linux distros, Nix is good and has purpose for existing, but is bad as a blanket recommendation, especially for privacy and security and even more so for newbies. Plenty of Linux distros are cool and potentially something I’d use, but that doesn’t mean they belong here.

I don’t see the purpose of recommending KickSecure when we are generally against Debian based distros for the purposes of this forum’s blanket recommendation at least. It gets more updates than most Debian distros, but I don’t see what it offers over SecureBlue. I would personally remove it.

I recommend changing the default recommendation of Fedora Workstation to Fedora KDE. GNOME has its uses, but is very polarizing, and almost put me off from using Linux entirely. Maybe mention this as a side note.

Qubes/Whonix and TailsOS absolutely need to stay. If anyone is going to recommend them at any point, it would be a forum like this. I would personally consider rewriting the explanation though, Whonix + Qubes should not be separate even though they can be.

I like SecureBlue as a concept of a slight security upgrade, I have no daily driven it though. Does anyone have thoughts about usability?

I’m going to say openSUSE should stay. Btrfs + Snapper has saved my butt on CachyOS before. Having at least one rolling release is good, and I like that it has Secure Boot by default as well.

Speaking of which, I use CachyOS because it auto sets Snapper up, as well as Nvidia drivers, plus the performance optimizations. It is Arch but sets up the important things, including a firewall (yeesh Arch). Yet, I don’t think it belongs here due to modifying the kernel, being a smaller project, their own repos instead of Arch’s, access to the AUR in general, and gaming focus. That being said, maybe we should have a section for people with Nvidia GPUs? Unfortunately it is a real problem still and users should know their choices. As another more realistic example, Bazzite is not what we generally want to recommend over Fedora Kinoite, but if you have an Nvidia GPU you’re going to have a real bad time with Kinoite. I would rather give options from smaller forks that increase the chain of trust rather than have someone give up on Linux because they do not know why their monitor is flickering and they can’t play games or run video editors. And apparently we are fine with this due to KickSecure and SecureBlue getting recommendations. However, immediately talking about potential troubleshooting issues could be seen as off putting. I’m open to discussion about this.

The general overview is decent, but could use a few newbie friendly introductory sections such as explaining that Linux typically does not ship pre-installed on hardware, and you can install it yourself on x86 computers like basically any Windows PC or pre-2020 Apple computers.

How possible

Kicksecure supports a Live Mode which can improve both security and anti-forensics, even if you ran Kicksecure in a VM. I’m not sure if something similar is achievable on Secureblue but I don’t see any similar anti-forensic features or guidance in their documentation.

Well you can rule out a lot of them by saying they should have SELinux in enforcement operation :wink: that cuts the list down to Fedora and SUSE. This at least gives a distributor a mechanism to improve security posture of the baseline rather than being like “yolo security do it yourself”.

Unless the underlying platform is secure wouldn’t it be possible for persistent threat to just hide there? I don’t really think this feature makes a lot of sense. It kind of does in the VM/Whonix use case but I’m not so sure as a general purpose OS.

I think it is correct this is a non-actionable suggestion, because removing distros should be on a case-by-case basis like any other recommendation. As such I will close this thread as invalid. What we should see is:

  • Threads dedicated to removing a specific distro, with a reason why that one isn’t suitable, and/or
  • Threads suggesting specific new criteria be added, which may happen to eliminate multiple existing recommendations.

I also agree this is a non-issue, and change for the sake of change seems unnecessary to me. I am not seeing reasons to remove distros other than a desire to “clean up” that has no basis in technical criteria.

I would keep this in mind before opening distro removal threads :slight_smile:

Also by the way I personally think the best way to make things easier for newcomers is not to change our recommendations, but to write blog posts/articles explaining when our recommendations make sense to use in more detail, and if anyone would like to submit such an article feel free to do so :innocent: