I agree that it needs paring down, and additionally I believe there are some picks that should not be there.
Arch is a horrid recommendation for someone new to Linux. Besides Gentoo or LFS, it is the most difficult to set up for essentially no reason other than that’s how they want to do it. From a security perspective, this includes not even having a firewall unless you set it up yourself. The AUR is probably not something a security minded individual should be looking at, particularly a newcomer, and yes, Arch based distros are somewhat reliant on the AUR, despite the official repos. The AUR suffered a coordinated attack recently where hackers abused the system of how to take over maintaining dead projects and injected malware, as well as a few that were new. Not only is this possible, but packages are not reviewed at all by Arch or anyone but you, if you choose to and can read code. Arch is not a bad distro, there are a ton of distros I’d recommend to people that are not on this list because they don’t meet the criteria we have chosen to focus on. So Arch needs to go as a recommendation. It offers nothing for privacy or security that openSUSE wouldn’t.
Nix feels like it is there just to say “see, there are other types of technically atomic distros that aren’t immutable, isn’t atomic a cool concept?” Since it is not immutable, you’re not gaining the additional security from that, as you can still install malware just as easily. From a security perspective, their packaging system is really not much better than the AUR at the end of the day. Many packages are safe and official, but you have to pay attention constantly, and it is very easy to make Nix packages with a trivial review process. Similarly to Arch, why was it recommended from a privacy and security perspective? Reproducibility is cool and all, but not a privacy/security feature. It is probably the next hardest distro to set up after Arch, and feels alien compared to the main 3 distro families. So it is a bad recommendation regardless of skill, unless you specifically need its features. Additionally, the devs tend to be rather unprofessional and get caught up in weird drama on a regular basis. I can provide further info on this if needed. Again, like many Linux distros, Nix is good and has purpose for existing, but is bad as a blanket recommendation, especially for privacy and security and even more so for newbies. Plenty of Linux distros are cool and potentially something I’d use, but that doesn’t mean they belong here.
I don’t see the purpose of recommending KickSecure when we are generally against Debian based distros for the purposes of this forum’s blanket recommendation at least. It gets more updates than most Debian distros, but I don’t see what it offers over SecureBlue. I would personally remove it.
I recommend changing the default recommendation of Fedora Workstation to Fedora KDE. GNOME has its uses, but is very polarizing, and almost put me off from using Linux entirely. Maybe mention this as a side note.
Qubes/Whonix and TailsOS absolutely need to stay. If anyone is going to recommend them at any point, it would be a forum like this. I would personally consider rewriting the explanation though, Whonix + Qubes should not be separate even though they can be.
I like SecureBlue as a concept of a slight security upgrade, I have no daily driven it though. Does anyone have thoughts about usability?
I’m going to say openSUSE should stay. Btrfs + Snapper has saved my butt on CachyOS before. Having at least one rolling release is good, and I like that it has Secure Boot by default as well.
Speaking of which, I use CachyOS because it auto sets Snapper up, as well as Nvidia drivers, plus the performance optimizations. It is Arch but sets up the important things, including a firewall (yeesh Arch). Yet, I don’t think it belongs here due to modifying the kernel, being a smaller project, their own repos instead of Arch’s, access to the AUR in general, and gaming focus. That being said, maybe we should have a section for people with Nvidia GPUs? Unfortunately it is a real problem still and users should know their choices. As another more realistic example, Bazzite is not what we generally want to recommend over Fedora Kinoite, but if you have an Nvidia GPU you’re going to have a real bad time with Kinoite. I would rather give options from smaller forks that increase the chain of trust rather than have someone give up on Linux because they do not know why their monitor is flickering and they can’t play games or run video editors. And apparently we are fine with this due to KickSecure and SecureBlue getting recommendations. However, immediately talking about potential troubleshooting issues could be seen as off putting. I’m open to discussion about this.
The general overview is decent, but could use a few newbie friendly introductory sections such as explaining that Linux typically does not ship pre-installed on hardware, and you can install it yourself on x86 computers like basically any Windows PC or pre-2020 Apple computers.