I’m neither a privacy nor a linux guru, but I’m working on improving familiarity with the first, and have played around with a few of the second. Specifically, I’ve got a couple of live boot disks of Kali and Tails, Manjaro is on my current laptop (though it will probably not be on my next one), and a few VPSs I run are all on ubuntu.
I was a little surprised to not see any mention of Kali or Ubuntu on the OS pages - either good or bad. I know Kali is kind of purpose specific for pen testing, but are there specific security concerns about Ubuntu? I was planning on putting Kubuntu on my kid’s desktop since his hard drive crashed, and I am trying to spin up a privacy focused Matrix hosting SaaS on my VPSs, so now I’m a little concerned that maybe I’ve built it to run on a distro that is suboptimal?
The only issue I could find within their criteria is for ubuntu lts releases being “frozen”, making it harder to do bug fixes. Nothing about their normal releases. Its strange they don’t mention ubuntu in linux distros given the two mentions the site search brings up.
Kali is an offensive security distro that is about breaking security of other systems. It’s not secure in of itself. In fact it defaults to root user to make tool use easier, and at least in the Backtrack days the root password was by default “toor”. This is anything but ideal for security.
Ubuntu is fine, but the community has a long memory wrt the Amazon privacy concern. Trust is easy to lose and hard to regain. Also the LTS distros like the site says, receive security updates less often, and what’s worse, often better security is a feature that won’t be backported to LTS distros. This might include better encryption algorithms for SSH, or some privacy enhancing feature. So I get why rolling release is preferred. Ubuntu has short term releases too but it’s a bit of a hassle to upgrade every 6 months.
“Technically, when you search for something in Dash, your computer makes a secure HTTPS connection to productsearch.ubuntu.com, sending along your search query and your IP address. If it returns Amazon products to display, your computer then insecurely loads the product images from Amazon’s server over HTTP.”
So amazon, and anyone watching your traffic, gets your ip address and can clearly see the search results. I’m sure glad Canonical encrypted your connection to their “secure” proxy server