logoalt Hacker News

iamnielstoday at 9:18 AM4 repliesview on HN

We need better OSes such that signing of software is not required to keep your computer safe.


Replies

drewfaxtoday at 1:24 PM

GrapheneOS is doing lot of things right in this regard. Robust permission system adopted from AOSP and hardening by default in every imaginable way. Things like hardened malloc, storage scopes are excellent security features. Malware cannot do much even with the default settings.

layer8today at 3:21 PM

With a file system driver like Veracrypt, if it’s malicious, the OS might keep your computer safe, but not your files that you store in that file system.

nixpulvistoday at 4:28 PM

Yes, I completely agree.

fsflovertoday at 2:51 PM

Qubes OS is such OS: it runs everything in VMs with strong hardware isolation. My daily driver, can't recommend it enough.