It’s sorrowful some people choose to hate, complain, ridicule, and block everything that does not fit their choice…

With just a single idea shared, a lone message posted in a community, with your finite priceless time and experience invested, you may get banned instantly, and permanently, instead of actually learning and discover together…


The single message that resulted in my immediate permanent ban:

Message

It’s not Linux, but your distribution, or you, what makes it “unsafe”.
There are numerous options to harden your Linux environment, and it’s relatively trivial to keep it safer if you ever want it, or actually stop blaming and complaining.

For example, to limit the access for root or custom group hwaccess, without much fuss but to give you an idea, for the most popular distros as Debian-based:

  1. Add a Udev rule:
# /etc/udev/rules.d/90-hwaccess.rules

KERNEL=="mem",        GROUP="hwaccess", MODE="0660"
SUBSYSTEM=="spidev",  GROUP="hwaccess", MODE="0660"
SUBSYSTEM=="i2c-dev", GROUP="hwaccess", MODE="0660"
  1. Set at boot:
setfacl -Rm 'g:hwaccess:rwX' -- \
    /sys/kernel/debug/ec \
    /sys/bus/pci/devices/*/config;

You may then setup SELinux, AppArmor, and secure it via SecureBoot’s shim, too.
Yet, you chose to effortlessly complain instead…

  • Harvey656
    link
    fedilink
    arrow-up
    7
    ·
    1 month ago

    Linux gives userspace access to /dev/mem /dev/spidev I²C/SMBus EC registers and PCI config space which is terrible for safety.

    I might be ignorant, but isnt that information technically different per distro?

    • ArtworkBanned from communityOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 month ago

      Of course it is! Thank you! And hence mentioned it in the comment, too!

      • Harvey656
        link
        fedilink
        arrow-up
        5
        arrow-down
        1
        ·
        1 month ago

        There’s been a ton of antis recently spreading straight up misinformation.

        Saw one recently saying anticheats dont work on linux because the apps can’t run root. Which is massively wrong. Weirdos.

        • A404@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          6
          ·
          1 month ago

          just wait until they find out that you have to literally use a exploit to load your own kernel drivers on windows