# Which OS for private secure internet browsing PC?

**URL:** https://discuss.privacyguides.net/t/which-os-for-private-secure-internet-browsing-pc/21387
**Category:** Questions
**Tags:** os
**Created:** 2024-10-09T18:28:52Z
**Posts:** 75

## Post 1 by @Preppy2723 — 2024-10-09T18:28:53Z

Hi All,

I’ve bought a new mini PC that I’m going to use specifically for internet browsing. I’m looking for a simple hardened OS that will provide good security and privacy by default. I will only be using a browser to “browse” and save files while connected to VPN. Nothing else. Looking for something that is easy to use and requires little or no configuration. I don’t need anything as extreme as tails, qubesOS etc.

Would something like [SecureBlue](https://github.com/secureblue/secureblue) be a good choice? or do you have any other recommendations that may fit the bill?

Many Thanks

---

## Post 2 by @anon48875053 — 2024-10-09T19:30:11Z

> **[Aeon](https://aeondesktop.github.io/)**

---

## Post 3 by @sha123 — 2024-10-09T22:18:02Z

What does Aeon do better or worse compared to Fedora Silverblue? How good is KDE support as of now?

---

## Post 4 by @ikelatomig — 2024-10-10T02:18:18Z

Maybe using something like ChromeOS Flex ?

I understand it’s Google. But it just works the way you want only problem Google and mandatory Google account sign in.

---

## Post 6 by @HushedWave — 2024-10-10T06:26:46Z

Currently I use Tails in Boxes… Would Whonix be a better bet in Secureblue?

Also watcha mean by layering Whonix? Wouldnt you shove it in VirtualBox or Boxes/Virt? :thinking:

---

## Post 7 by @anon80779245 — 2024-10-10T06:55:07Z

Please check [Privacy Guides reccomendation.](https://www.privacyguides.org/en/desktop/)

---

## Post 9 by @anon80779245 — 2024-10-10T07:29:55Z

You can use Arch and do manually install so you only have what’s strictly needed for you.

But you can’t have an easy to use/ no setup AND hardened setup.

---

## Post 11 by @anon48875053 — 2024-10-10T08:44:21Z

I haven’t properly tried Silverblue in quite some time.

One of the pros of Aeon is that it only supports and focuses on GNOME, but if you use KDE, then this is a con.

There is also openSUSE Kalpa, but it’s very far behind Aeon, and the reason why is KDE.

---

## Post 12 by @Preppy2723 — 2024-10-10T09:56:36Z

Thanks for everyone’s input so far.

To clarify I don’t need total anonymity and want fast uploads/downloads so I’m discounting anything using Tor.

I’m decided on going with either Secureblue or Kicksecure.

Which of the two choices would be better for installing directly to SSD, and using out of the box (other than configuring VPN)?

> [@Anon47486929](#):
>
> OP has disqualified tails and qubes, and would probably not like Kicksecure too, since there are similar frictions.

Could you explain what you mean by frictions in KS ?

Basically I’m a linux noob so there’s no point in using anything where it requires knowledge and know-how to make secure, because I wouldn’t know where to start!

---

## Post 14 by @anon48875053 — 2024-10-10T11:03:18Z

Here are some quotes from the founder of Aeon:

> Technically ostree is a burden that slows a system down more you pile atop it.. and a very painful proposition for infrastructure, mirrors, et al
> 
> I don’t think any popular distro can afford to embrace ostree the way SB has
> 
> I do not think we share one line of common code in all that makes SB different from Fedora or Aeon different from TW
> 
> So suggesting there is any technical similarities at all is downright silly
> 
> We don’t even have our own flatpaks like Fedora does (which is probably why people keep citing broken flatpaks on Fedora.. flathub has better ones)
> 
> Philosophically - Silverblue falls into the same trap as KDE and many other FOSS projects fall into - thinking that “customising everthing” is a valid usecase
> 
> Aeon prioritises getting things right and getting out of the way, rather than focusing on letting people tinker instead of using their system
> 
> For us, immutability is a route to ensuring your system keeps working
> 
> For SB it’s an excuse to try different ways of breaking your system/trying out new toys
> 
> Wildly different mindsets
> 
> This is why features like rebasing and composability/determinism are mostly irrelevant to Aeon
> 
> It aims to be an OS you shouldn’t need to heavily play with, just one to use.. you can’t say that about Silverblue, NixOS, Tumbleweed and many other distros out there

* * *

> Those distros use immutability as part of a story about customisation
> 
> I think heavy customisation is already better done in traditional distros built for it - the community who wants that is well served by Tumbleweed
> 
> Aeon doesn’t want to be messing around with rebasing and stuff like Silverblue or spinning up hundreds of different flavours like Universal Blue
> 
> We want to get it right and use our immutability to keep it right, working and self healing
> 
> Installing anything via transactional-update should be a last resort done sparingly for edge cases and quirks we can’t handle for everyone together

* * *

> Comparing Aeon to Silverblue is a bit like comparing a family car to a Battle Tank
> 
> Sure they’re both vehicles, and have wheels, and drive
> 
> But there really isn’t any commonality, no technical relationship, and there’s no intention by Aeon to walk in Silverblues footsteps
> 
> We’re walking our own path and do almost everything differently, from our update stack to flatpaks being user installed not system wide

---

## Post 15 by @TartlyUnderwear — 2024-10-10T11:04:58Z

Why haven’t you simply referred to the recommendations on PG?

PG does not recommend Secureblue - it recommends Fedora Workstation, which is the OG Fedora and the easiest to use as someone new to Linux. Don’t go for Silverblue or any other Fedora variant.

---

## Post 16 by @anon48875053 — 2024-10-10T11:06:42Z

Have you even tried Aeon or secureblue?

---

## Post 17 by @TartlyUnderwear — 2024-10-10T11:08:46Z

Have you read the thread on secureblue and why PG voted to not recommend it?

---

## Post 19 by @TartlyUnderwear — 2024-10-10T11:33:39Z

OP is brand new to Linux and you want to recommend an atomic distro?

---

## Post 21 by @Preppy2723 — 2024-10-10T12:55:33Z

> [@TartlyUnderwear](#):
>
> PG does not recommend Secureblue - it recommends Fedora Workstation, which is the OG Fedora and the easiest to use as someone new to Linux. Don’t go for Silverblue or any other Fedora variant.

I may be missing something here, but they have an Atomic Distributions section of which the first listing is Fedora Atomic Desktops, and I thought Silverblue is one of those, so does that mean that PG recommends Silverblue?

And my understanding is that Secureblue is adding some hardening. I could just use Silverblue ootb which seems valid because I don’t really understand what Secureblue really does and what benefits it brings me. Also it doesn’t seem widely adopted at present, and to me numbers of users / number of stars on github etc count as a good gauge of how good something is.

> [@Anon47486929](#):
>
> Kicksecure brings in some friction like:
> 
> 1. It’s based on debian, and is a traditional Linux system. This means it requires maintenance and command line. Plus it’s debian stable, so not exactly cutting edge. Complete opposite of fedora atomic based distros.
> 2. Updating firmware is hard. (They might have made it easier? Not sure.)
> 3. It makes a lot of opinionated choices, especially when it comes to password managers, browsers, etc. A normal user would have to fiddle stuff around a lot to suit their preference, most of which would be command line again.
> 4. It’s too locked down sometimes. (Which is excellent for some threat models, not much for others)

Out of interest, how are those issues different on Secureblue. i.e why does SB not require maintenance and command line? You mean opinionated choices like certain browsers, password managers etc are installed by default whereas SB comes with no preinstalled apps? If it’s locked down, could that be good for me if all I want to do is use a browser and not fiddle about with it?

Tbh I really just need to make a choice and get on with it, as for a noob like me, most of the the debate / info goes over my head anyway :dizzy_face:

---

## Post 22 by @anon48875053 — 2024-10-10T12:57:48Z

> [@Preppy2723](#):
>
> I may be missing something here, but they have an Atomic Distributions section of which the first listing is Fedora Atomic Desktops, and I thought Silverblue is one of those, so does that mean that PG recommends Silverblue?

Yes.

---

## Post 23 by @null — 2024-10-10T13:23:22Z

If you’ve never used Linux before, don’t go with any hardened OS, you’re shooting yourself in the foot and will probably quit in a week.

Go with something like Linux mint. Super easy and never break randomly on you. And learn how Linux works first.

---

## Post 25 by @Astatine — 2024-10-10T14:15:44Z

Just a question out of pure curiousity: Why not just use [Brace](https://gitlab.com/divested/brace), created by the [DivestOS](https://divestos.org) developer, with Fedora Workstation?

Aside from that, especially if you don’t like the GNOME DE, I’m not sure what to recommend which offers what you’re looking for.

---

## Post 26 by @anon48875053 — 2024-10-10T14:28:39Z

> [@Astatine](#):
>
> Just a question out of pure curiousity: Why not just use [Brace](https://gitlab.com/divested/brace), created by the [DivestOS](https://divestos.org) developer, with Fedora Workstation?

Because immutable distributions are the future of Linux desktop.

Silverblue \> Workstation

Aeon \> Tumbleweed

---

## Post 27 by @ikelatomig — 2024-10-10T14:51:53Z

Is there an expected release date and why don’t SUSE use SELinux than AppArmor ?

Just curious.

---

## Post 28 by @anon48875053 — 2024-10-10T14:55:24Z

Aeon is using SELinux.

There is no release date, and it doesn’t really matter because the system is rock solid and you will not have to reinstall when Aeon is “released.”

---

## Post 29 by @Preppy2723 — 2024-10-10T14:58:15Z

Thanks for everyone’s input.

I’m going to try out Secureblue as per @Anon47486929 's recommendation. If I find myself struggling with it after a week or two then I’ll consider something more mainstream like Mint as per @null 's advice.

One other question regarding the chromium browser in SB. Would it be recommended to use any extensions such as ublock / privacy badger / decentraleyes etc etc. If it makes a difference, my router already has adguard home on it with some filtering lists.

---

## Post 30 by @anon48875053 — 2024-10-10T15:01:28Z

You could install uBO Lite.

---

## Post 31 by @Astatine — 2024-10-10T16:01:00Z

I completely agree, but the OP is not using it as their daily driver, and _just_ for internet browsing and saving files. I’d immediately suggest [openSUSE Aeon](https://aeondesktop.org) which perfectly fits into that category. However, since they asked about SecureBlue, I thought Brace would be a fine choice, since SecureBlue requires configuration.

---

## Post 32 by @username0990 — 2024-10-10T16:26:48Z

As far as I can see in the Linux world, there is not a consensus on how browsers should be installed on a system, and as a consequence there is a divergence of practices. At the center of this issue is the question of whether the security features of the browsers are compromised.

Firefox and Brave browsers have official flatpak packages. On the other hand, there are [reasonable arguments](https://discuss.privacyguides.net/t/does-flatpak-weaken-chromium-firefoxs-sandbox/13373) that their flatpak packages reduce or remove their security features. So why do the developers of those browsers release official flatpak packages? Either they don’t mind sacrificing security, or there are things that are not as important as claimed.

> [@Lukas](#):
>
> [https://aeondesktop.github.io/](https://aeondesktop.github.io/)

> [@Lukas](#):
>
> Because immutable distributions are the future of Linux desktop.
> 
> Silverblue \> Workstation
> 
> Aeon \> Tumbleweed

openSUSE Aeon recommended here includes Firefox’s flatpak package.

Let’s say we installed the browsers with the traditional package types and source tar files, SELinux does not contain policies restricting [user applications](https://discuss.privacyguides.net/t/in-line-with-the-pgs-recommendations-what-should-be-the-minimum-requirements-for-a-secure-arch-linux-installation/15972/27). Tor and Mullvad browsers are also recommended to be installed directly from the source archive, so they will also have unrestricted access to sensitive files etc. on the system.

> **[How to securely install the Firefox tar archive on Atomic desktops?](https://discussion.fedoraproject.org/t/how-to-securely-install-the-firefox-tar-archive-on-atomic-desktops/133321)**
>
> I am a big fan of Flatpak, but also highly support keeping RPM firefox until there are not only major fixes to flatpak, but also to firefox itself. In short, Flatpak issues: no exact drag&drop support (dragging a file into an “upload” box...

So how can immutable -and traditional- distributions be secure to use browsers?

@Lukas @Anon47486929

---

## Post 34 by @anon48875053 — 2024-10-10T17:44:47Z

I understand that Linux security doesn’t even come remotely close to Android’s, so I threat model accordingly and don’t care if flatpak versions are less secure.

I don’t even log in to my password manager on my PC, that’s how much I trust desktop OSs.

---

## Post 35 by @Dkama — 2024-10-10T22:31:29Z

> [@Anon47486929](#):
>
> uses hardended chromium with vanadium patches

Except the ones that degoogle it. Because being spied on by Google and the government means you’re more secure. That’s where I noped out of it.

---

## Post 36 by @Preppy2723 — 2024-10-11T00:48:42Z

Ok so I’ve installed SB, followed the pre-install recommendations, and rebased as per the [readme](https://github.com/secureblue/secureblue?tab=readme-ov-file).

For the post install it says " After installation, yafti will open. Make sure to follow the steps listed carefully and read the directions closely."

Does anyone know if that was the screen that popped up that said welcome to Secureblue? I accidentally closed that window and now I’m not sure how to get it back up to follow the steps.

Otherwise all went smoothly :slight_smile:

Thanks

---

## Post 37 by @dumpster — 2024-10-11T02:38:59Z

Yes, that window you saw was yafti. run `ujust rerun-yafti` to access it.

---

## Post 38 by @username0990 — 2024-10-11T05:12:33Z

Thanks for the replies @Anon47486929 @Lukas

* * *

> [@Anon47486929](#):
>
> I can comment more on chromium. Chromium engine needs direct access to OS resources for it’s sandbox and process isolation to work as intended and thus it’s always better to layer it (directly install using rpm-ostree or equivalent) in atomic and install using package manager in traditional distros. Using chromium flatpaks is not how it’s supposed to be.
> 
> Now to make chromium derivatives work as flatpaks, the packagers use another, weaker sandbox called zypak. This is what Brave, Chrome, etc. use.

> [@Anon47486929](#):
>
> So ideally, you should be installing chromium browsers not as flatpaks, but by layering or direct installation.

I know these details because they are talked about on the link I posted.

> [@Anon47486929](#):
>
> This allows them to make flatpaks (and thus gain more share among users) with only slight damage to security. Why do they do this? For the same reason mobile applications tend to be present as both iOS and Android, in arch64 as well as universal apk - To capture people who stick to specific formats and types. Since they can do so with only minor damage to security, they ship “official” flatpaks.

I don’t know, but I think the developers should have informed the users about these things.

> [@Anon47486929](#):
>
> With regards to secureblue: They ship their own hardened chromium with vanadium patches as system browser, you ideally don’t need anything else (alongside UblockOrigin Lite)

Well, on secureblue hardened chromium or other browsers that users install are restricted by SELinux or not?

> [@Lukas](#):
>
> I don’t even log in to my password manager on my PC, that’s how much I trust desktop OSs.

Wow, I think you should make it clear in future Aeon recommendations that you don’t trust it enough to even be logged into your password manager. :slightly_smiling_face:

---

## Post 39 by @anon48875053 — 2024-10-11T05:35:08Z

> [@username0990](#):
>
> Wow, I think you should make it clear in future Aeon recommendations that you don’t trust it enough to even be logged into your password manager. :slightly_smiling_face:

The same goes for Windows and any other Linux distribution. MacOS is the only mainstream desktop OS that I would trust and log in to my password manager.

---

## Post 41 by @username0990 — 2024-10-11T07:34:06Z

> [@Anon47486929](#):
>
> No offense, but your link doesn’t talk anything. It’s a link to a forum question asked 1 day ago about Firefox with no responses. So I would prefer if we don’t imply that the link was useful in any way in knowing what your exact concerns are.

No offense, but that was not the only link I posted.

> [@Anon47486929](#):
>
> I think you have a misunderstanding about fedora security model. SELinux is a kernel level MAC that confines system process in fedora.

Actually, I am aware of that, but we know that they have been working on the userspace confinement for some time. [Secureblue - Atomic Fedora Hardening - #62 by RoyalOughtness](https://discuss.privacyguides.net/t/secureblue-immutable-fedora-hardening/16086/62)

> [@Anon47486929](#):
>
> If you are asking if non flatpak browser is confined, then I’d recommend you go through the fedora docs and secureblue hardening guide, and understand it from the primary source how applications are usually confined. That might also help dispel certain ideas that are incorrect about how fedora and it’s derivatives work. Secureblue does not write custom selinux policies, it merely enables flags already present in the kernel.

Yes, I have already commented on this in the secureblue [thread](https://discuss.privacyguides.net/t/secureblue-immutable-fedora-hardening/16086/76).

> [@Secureblue - Atomic Fedora Hardening](https://discuss.privacyguides.net/t/secureblue-atomic-fedora-hardening/16086/76):
>
> IMHO, it could be clarified how other internet browsers (Brave, Firefox, Tor Browser, etc.) should be installed and whether [bubblejail](https://github.com/secureblue/secureblue/blob/c68039132a5bb3015597d2fef32d0e28e08cab36/FAQ.md#should-i-use-firejail) should be used for those browsers.

Eventually secureblue users will want to use other browsers. There’s a general recommendation in the secureblue you suggested to use bubblejail only if the flatpak package of the applications is not going to be installed. There is no mention of whether the hardened chromium browser uses bubblejail or not, nor whether it is necessary for browsers. If there is something missing here, it might be worth mentioning it.

---

## Post 42 by @Preppy2723 — 2024-10-11T07:37:22Z

> [@Anon47486929](#):
>
> You might be asking about bubblewrap, the application sandbox underlying flatpaks.

On that note, I chose the non userns version, which I know talked about bubblewrap. Does this mean bubblewrap will still work with flatpaks?

The reason I ask is because my browser of choice has been Librewolf and ideally I’d like to stay with it, but I’m guessing Chromium has been chosen in SB for a reason, so is it a bad idea to use Flatpak Librewolf instead of the bundled Chromium? I don’t really mind Chromium, I just like the familiarity of what I’m used to.

Thanks

---

## Post 43 by @Preppy2723 — 2024-10-11T07:39:53Z

> [@dumpster](#):
>
> Yes, that window you saw was yafti. run `ujust rerun-yafti` to access it.

Amazing, thank you!

---

## Post 44 by @RoyalOughtness — 2024-10-11T08:05:11Z

We just shipped [built-in content blocking](https://github.com/secureblue/secureblue/releases/tag/v3.3) using the same method GrapheneOS’s Vanadium uses (chromium’s subresource filter).

You can always install UBO-lite if you find it lacking (some ads will still show like youtube ads, unfortunately. which is also the case on Vanadium).

---

## Post 45 by @RoyalOughtness — 2024-10-11T08:11:35Z

> Either they don’t mind sacrificing security, or there are things that are not as important as claimed.

The former. Brave in particular. For example they have also opted to retain MV2 support. They are willing to sacrifice security for convenience / “privacy”.

> So how can immutable -and traditional- distributions be secure to use browsers?

The lack of userspace confinement for desktop linux apps is a fundamental flaw in desktop linux security. It’s not specific to browsers. The problem with browsers is that you unfortunately have to choose between:

1. a weak sandbox for chromium itself that also unfortunately breaks the browser’s robust internal sandboxing
2. no sandboxing for chromium but preserving chromium’s robust internal sandboxing

#1 seems like a terrible idea, #2 is less than ideal but highly preferable.

---

## Post 46 by @RoyalOughtness — 2024-10-11T08:13:10Z

We don’t exclude any vanadium patches that are relevant to the desktop. Please do not spread misinformation about secureblue :slight_smile:

---

## Post 47 by @Astatine — 2024-10-11T09:02:21Z

Librewolf might not last much [longer](https://discuss.privacyguides.net/t/which-browser-do-you-prefer-and-why/21269/28), unfortunately.

---

## Post 48 by @sha123 — 2024-10-11T09:39:55Z

> [@username0990](#):
>
> As far as I can see in the Linux world, there is not a consensus on how browsers should be installed on a system

Native packages and Snaps are fine. Flatpaks not. Flatpaks block the namespace+chroot/pivot\_root sandbox layer.

> [@username0990](#):
>
> Firefox and Brave browsers have official flatpak packages.

Brave recommends against using their own Flatpak version:

> [We currently recommend that users who are able to use our official package repositories do so instead of using the Flatpak.](https://brave.com/linux/#flatpak)

> [@username0990](#):
>
> SELinux does not contain policies restricting [user applications](https://discuss.privacyguides.net/t/in-line-with-the-pgs-recommendations-what-should-be-the-minimum-requirements-for-a-secure-arch-linux-installation/15972/27). Tor and Mullvad browsers are also recommended to be installed directly from the source archive, so they will also have unrestricted access to sensitive files etc. on the system.

Modern browsers have a multi-process architecture, with sandboxing around the important processes, for example renderer sandboxes, gpu sandbox, extension sandbox and so on. This way you can make these sandboxes much more tailored and thus stricter than you would be able to do around the browser as whole.

> [@username0990](#):
>
> So how can immutable -and traditional- distributions be secure to use browsers?

Install them _not_ as a flatpak. That’s independent of distros and doable on immutable ones, too.

---

## Post 49 by @username0990 — 2024-10-11T11:00:51Z

@sha123 You have already expressed these views in the hyperlinked threads I have attached to my posts and more. I have benefited a lot from your views in the past months, and you have helped me to search for more accurate information in other sources. I thank you for that.

Since this thread is more focused on distributions based on Fedora, I wanted to know if other browsers installed from traditional packages should be restricted by tools like bubblejail, firejail. As we can see the OP is considering using a browser based on Firefox not hardened Chromium.

By the way they wrote the same thing for the official snap package:  
[You can find Brave in the Snapcraft Store, but while it is maintained by Brave Software, it is not yet working as well as our native packages. We currently recommend that users who are able to use our official package repositories do so instead of using the Snap.](https://brave.com/linux/#snap)

---

## Post 51 by @Preppy2723 — 2024-10-11T12:52:37Z

> [@Anon47486929](#):
>
> Just ditch librewolf (reasons stated by others in the thread above). My opinion is staying with the native hardened chromium is definitely better.

:+1:

> [@RoyalOughtness](#):
>
> We just shipped built-in content blocking using the same method GrapheneOS’s Vanadium uses (chromium’s subresource filter).

That’s good to know, thanks :slight_smile:

Basically then I’m going to to follow all the post install recommendations, and use it as is (other than maybe adding uBO lite and my VPN app. Sounds like I don’t need to worry about additional sandboxing. I assume I should apply all updates as soon as they become available, and they are updates from Fedora, not SB - and they will all play nicely with SB tweaks?

---

## Post 52 by @Dkama — 2024-10-11T13:55:51Z

I am sorry if I got that wrong.  
There used to be a table with all the Vanadium patches and marking which were/weren’t included and why, no? I can’t seem to find it…

---

## Post 53 by @Preppy2723 — 2024-10-11T15:36:38Z

A bit of feedback for @RoyalOughtness from a linux noob’s perspective:

I think the post install documentation could be easier. I’m getting lost in the steps required

A few examples:  
ujust enroll-secure-boot-key

It rebooted to BIOS and I had to select options on a menu, I think I’ve done it right but not sure how to verify.

GRUB  
Is this a password required for modifying boot entries (order) in the BIOS? Not really sure what the expected result is. However I did notice the disk encryption password that I was having to enter on boot is now not coming up anymore for some reason?

I skipped the wheel section and went on to do bash lockdown and LUKS TPM2 sections.

When I now try to do the wheel section - adduser admin, I get the response  
User add : Permission denied  
User add : Cannot lock /etc/passwd - try again later

Maybe it’s because I didn’t do the list in order? Also it mentions about rolling back to a snapshot but wasn’t sure how to create one. Also in discovery software centre its not showing anything and saying not connected when I am.

Maybe it’s just a sign that if I can’t navigate through the post install instructions then I’m out of my depth (I know that’s the case really!)

---

## Post 54 by @Astatine — 2024-10-11T15:40:49Z

Why was the OP’s post flagged?

---

## Post 55 by @Preppy2723 — 2024-10-11T15:43:09Z

I had a message:

Your post was flagged as **spam** : the community feels it is an advertisement, something that is overly promotional in nature instead of being useful or relevant to the topic as expected.

Not sure what in relation to though

---

## Post 56 by @Astatine — 2024-10-11T15:44:01Z

In my humble opinion, you probably should’ve went with something easier to use, like [openSUSE Aeon](https://aeondesktop.org) for example which requires little to no maintenance and is quite fine for Linux beginners.

---

## Post 57 by @Astatine — 2024-10-11T15:45:12Z

Well, it certainly wasn’t spam. Perhaps someone accidentally flagged the post? I’m not sure, but it’s **certainly not an advertisement**.

---

## Post 58 by @Preppy2723 — 2024-10-11T15:51:01Z

> [@Astatine](#):
>
> In my humble opinion, you probably should’ve went with something easier to use, like [openSUSE Aeon](https://aeondesktop.org) for example which requires little to no maintenance and is quite fine for Linux beginners.

I may yet still give it a try. What does it mean by " Aeon is still in a **Release Candidate** stage!" ?

---

## Post 59 by @anon48875053 — 2024-10-11T15:51:35Z

It’s not officialy released, but it doesn’t matter because it works flawlessly.

---

## Post 60 by @Astatine — 2024-10-11T15:58:23Z

Yes, but it’s [pretty much](https://news.opensuse.org/2024/07/28/rc-image-released/) finished, according to them:

> RC3 may be the final Release Candidate before Aeon’s official release. There are no major structural changes planned to the core Aeon OS, just regular improvements as upstream versions develop and our community contributes to new features and packages.

---

## Post 61 by @Astatine — 2024-10-11T15:58:42Z

> [@Preppy2723](#):
>
> Aeon is still in a **Release Candidate** stage

Release Candidate is simply means that it is almost ready for official release and is only making minor changes and improvements. If you saw the above post, that means it could get released soon, maybe this year or next year. It’s fine to use right now, but if it was in Alpha—it would probably not be a recommendation.

---

## Post 62 by @Preppy2723 — 2024-10-11T15:59:22Z

Cool, thanks for clarifying

---

## Post 64 by @Preppy2723 — 2024-10-11T16:02:06Z

Out of interest is there anyone here associated with any of the suggested options in the thread other than Qoijjj ? (not that that would be a problem, just wondered)

---

## Post 65 by @Astatine — 2024-10-11T16:02:33Z

**The only** thing I should let you know is that its popularity is not like Ubuntu, openSUSE Tumbleweed or Leap, Fedora, etc. Thus, there won’t be many people to help you troubleshoot if you encounter issues.

Personally, I would use it anyway, and for your purposes there shouldn’t be any problems with it being in Release Candidate stage.

---

## Post 66 by @anon48875053 — 2024-10-11T16:02:38Z

Nope.

---

## Post 67 by @anon48875053 — 2024-10-11T16:04:10Z

> [@Astatine](#):
>
> Thus, there won’t be many people to help you troubleshoot if you encounter issues.

There are plenty of people that are willing to help, including the founder itself:

[https://matrix.to/#/#aeon:opensuse.org](https://matrix.to/#/#aeon:opensuse.org)

> **[Reddit - The heart of the internet](https://www.reddit.com/r/AeonDesktop/)**

---

## Post 68 by @Astatine — 2024-10-11T16:05:25Z

Not at all.

---

## Post 70 by @Preppy2723 — 2024-10-11T16:35:09Z

> [@Anon47486929](#):
>
> I just try to answer with exactly what OPs ask for, but alas, sometimes OPs don’t know if they want what they are asking for :frowning:

I agree and I’m sorry about that, sometimes the only way to know for sure is to try, nevertheless I am grateful for all the advice I have been given :wink:

---

## Post 71 by @RoyalOughtness — 2024-10-11T17:35:58Z

That’s not what that table was. It was a list of vanadium patches and their best-effort policy configuration that we were applying at _runtime_ to Fedora’s chromium.

We’ve long since moved to shipping our own chromium, which allows us to simply drop in Vanadium patches: [GitHub - secureblue/Trivalent: A security-focused, Chromium-based browser for desktop Linux inspired by Vanadium.](https://github.com/secureblue/hardened-chromium)

Also, even vanadium doesn’t just blindly “degoogle” like ungoogled-chromium does, which is a good thing. Some of the ungoogled-chromium patches are so tunnel visioned on removing google that they remove security functionality. For example, they disable browser time validation via a network synchronization service, which is used for cert validation and is a terrible idea to disable: [ungoogled-chromium/patches/core/ungoogled-chromium/disable-network-time-tracker.patch at 61b271f22b9efc91bfe3e69ee6f25f2dad87afa4 · ungoogled-software/ungoogled-chromium · GitHub](https://github.com/ungoogled-software/ungoogled-chromium/blob/61b271f22b9efc91bfe3e69ee6f25f2dad87afa4/patches/core/ungoogled-chromium/disable-network-time-tracker.patch)

---

## Post 72 by @RoyalOughtness — 2024-10-11T17:39:31Z

The postinstall steps for secureblue would need to be executed on Aeon as well in order to secure the system. secureblue is simply neatly documenting those steps for user convenience, they’re largely not unique to secureblue.

Plus, some of them you would _wish_ are available on Aeon, like the ease of nvidia configuration on secureblue/silverblue compared to aeon.

Aeon isn’t analogous to secureblue. It’s analagous to Silverblue. immutability/atomicity on its own isn’t a security feature.

If there was a hardened image of Aeon you were recommending, your post would make more sense. But this is apples and oranges. You’re comparing a hardened image of a major distro to an unhardened release of a different major distro, all of which would need similar postinstall steps executed to fully harden.

So, if you do go with opensuse Aeon, don’t forget to follow equivalent steps to secureblue’s postinstall steps after installing :slight_smile:

---

## Post 73 by @RoyalOughtness — 2024-10-11T17:45:56Z

> It rebooted to BIOS and I had to select options on a menu, I think I’ve done it right but not sure how to verify.

yeah we could add more details here, please open github issues for these documentation improvements

`mokutil --sb-state` btw

> Also it mentions about rolling back to a snapshot but wasn’t sure how to create one.

That should probably say “deployment”, but anyways you don’t have to do anything. every time you make any changes via rpm-ostree, a new deployment is generated and deployed which you then boot into next reboot. The old deployment isn’t removed, two deployments are always kept. Please browse the silverblue docs as this isn’t specific to secureblue and isn’t something we’ll be documenting.

> User add : Permission denied

`sudo` :slight_smile:

which should probably be added as well, although it is somewhat implied by the nature of the changes

also you can run `ujust audit-secureblue` to check for steps you may have missed.

And again, like I mentioned previously, these are all steps you would want to do equivalent steps for on openSUSE Aeon as well if you want to harden it. So using Aeon wouldn’t really change anything in this regard except that you would have to modify the secureblue postinstall steps to be compatible with Aeon.

---

## Post 74 by @Dkama — 2024-10-21T15:06:34Z

> [@RoyalOughtness](#):
>
> We don’t exclude any vanadium patches that are relevant to the desktop. Please do not spread misinformation about secureblue :slight_smile:

You may have deleted the page from github, but webarchive is forever (that is, if it’s not hacked yet again).  
[https://web.archive.org/web/20240711091023/https://github.com/secureblue/secureblue/blob/e33b73d9d3bceeb26eb40271d4aaae0ac37ff5ea/config/files/usr/etc/chromium/vanadium\_comparison.readme.md](https://web.archive.org/web/20240711091023/https://github.com/secureblue/secureblue/blob/e33b73d9d3bceeb26eb40271d4aaae0ac37ff5ea/config/files/usr/etc/chromium/vanadium_comparison.readme.md)

You say I spread misinformation and that all desktop-relevant patches were applied. But my “misinformation” is the factual observation that only 86 of the 135 ignored patches are marked as “Android only”.

Care to explain why?

And even if you have perfectly good explanations, would you care to appologize as well?

---

## Post 75 by @RoyalOughtness — 2024-10-21T18:12:54Z

> You may have deleted the page from github

Yes because it’s from before hardened-chromium even existed.

> You say I spread misinformation and that all desktop-relevant patches were applied.

Yes, you are spreading misinformation and you’re now doubling down. The page you’re linking is from before we were applying a single patch, because hardened-chromium didn’t exist yet.

> But my “misinformation” is the factual observation that only 86 of the 135 ignored patches are marked as “Android only”.

No, you are doubling down on misinformation. That page has nothing to do with hardened-chromium.

> Care to explain why?

Because they patched Java code that only runs on Android and were not replicable using policies (remember this is before hardened-chromium). They _do nothing_ on desktop. They have to be rewritten in cpp to have any effect, if they’re even relevant to begin with. Now that we have hardened-chromium, we can do so if needed.

But again, in your ignorance you’re pointing to a document that isn’t even about hardened-chromium. That’s a document describing drop-in policies, not patches.

> would you care to appologize as well?

Wow. You have spread misinformation, doubled down on your misinformation, refused to correct your own misunderstanding, and then to top it all off demanded an apology from me? And for what, helping educate you on the difference between policies and patches? The difference between drop-ins on top of an application vs building the application yourself?

You have been blocked. I hope you don’t treat the work of others with the same contempt, especially offline.
