• 0 Posts
  • 34 Comments
Joined 1 year ago
cake
Cake day: August 10th, 2024

help-circle


  • Totally agree.

    And here OP proves perfectly how Windows Updates have done a ton of collective damage to security by being a terrible experience.

    Software MUST be always updated.

    but then it breaks or the design team needed to justify its salary again or…

    Then the problem lies with the software. Not updating it is not a solution despite Debian propaganda (/hj)


  • You can have FDE binded to the TMP and then inside that encrypted volume an encrypted home.

    By doing that you only need to input your login password and get better security than the meme setup and other suggestions.

    You would need, iirc (I am typing this from memory):

    • A TPM.
    • systemd-cryptenroll
    • Some PAM config for fscrypt or similar.

    I know the steps but for NixOS only lmao.

















  • There’s a dedicated 10th circle in hell for this people. As someone who runs a root-on-tmpfs system, PLEASE document which dirs your application is using.

    It is a total pain, specially with non standar ones.

    But tbf there are a lot of Linux devs who neither have read a single line of any Linux standard API.

    XDG_DIR, Portals, Secrets, D-Bus, the Desktop file spec, Appstream… are there for you to read. 🥰