| ▲ | 0xfedcafe 7 days ago |
| Best systemd hardening is switching to OpenRC or runit |
|
| ▲ | mcpherrinm 7 days ago | parent | next [-] |
| Do you have any references for doing similar system hardening under either of those? |
| |
|
| ▲ | fsflover 7 days ago | parent | prev | next [-] |
| No, switching to Qubes OS is the real hardening. |
| |
|
| ▲ | gf000 7 days ago | parent | prev [-] |
| An unbootable system is indeed harder to exploit! /s |
| |
| ▲ | yjftsjthsd-h 7 days ago | parent [-] | | Why would OpenRC or runit be any less likely to boot? | | |
| ▲ | gf000 6 days ago | parent [-] | | My response was a joke to a low-effort comment, but in general - systemd is complex because it solves the complex problem of booting up a system, complete with error handling, logging, etc. Many of the alternatives simply ignore part of the problem space, making the simple case simpler, but the complex case impossible. |
|
|