So I saw political compass memes a while ago and started making one, but then I started taking it too seriously and eventually turned it into a tier list. Idk if it makes sense to share it here, but idk where else to share such a thing. I also made a browser tier list, but idk where to share that either.

This whole thing is a png export of a pure svg image. For some of the logos, I had to make them either from scratch or by using gimp and inkscape to convert a png into an svg (imperfect but good enough).

Hopefully this is all formatted properly.

OS Tier List

S-Tier (reasonably secure operating system):

  • Qubes OS

Advanced (complicated setup and configuration):

  • Gentoo Linux
  • Guix System
  • Slackware Linux
  • Linux From Scratch (LFS)
  • Mobile NixOS
  • NixOS
  • Whonix
  • Predator-OS
  • Linux Kodachi
  • Gentoo FreeBSD

Enhanced (optimized security and minimalism):

  • Alpine Linux
  • Hyperbola GNU/Linux-libre
  • Chimera Linux
  • EasyOS
  • postmarketOS
  • Tails
  • Kicksecure
  • NetHydra
  • ParrotOS
  • OpenBSD
  • GrapheneOS
  • Secureblue

Minimal (maximally mini resource use):

  • Tiny Core Linux
  • LibreCMC
  • Void Linux
  • Puppy Linux
  • AsteroidOS
  • Slitaz
  • 4MLinux
  • OpenWrt
  • DragonFly BSD
  • FreeBSD
  • NetBSD

Indie & BSD (independent distros and BSD systems):

  • PCLinuxOS
  • Dynebolic
  • KaOS
  • Mageia
  • LuneOS
  • Solus
  • AerynOS
  • GNOME OS
  • KDE Linux
  • GhostBSD

Arch (reasonably fresh and arch-based):

  • SystemRescue
  • Parabola GNU/Linux-libre
  • pearOS
  • EndeavourOS
  • Nemo Mobile
  • Arch Linux Arm
  • BlackArch Linux
  • Archhurd
  • Archcraft
  • Nyarch
  • Ageless Arch
  • Arch Linux
  • CachyOS
  • Garuda Linux

Debian (reasonably stable and debian-based):

  • Flora Linux-libre
  • Genuen
  • Devuan GNU+Linux
  • Loc-OS
  • antiX
  • MX Linux
  • Maemo Leste
  • Mobian
  • Emmabuntüs
  • Linux Mint Debian Edition (LMDE)
  • Ageless Linux
  • Debian
  • KNOPPIX
  • PikaOS Linux
  • RetroPie
  • LibreElec
  • Vanilla OS

Corpo-ish (corporation-created and/or dependent):

  • Replicant
  • Uruk GNU/Linux-libre
  • Trisquel GNU/Linux
  • AnduinOS
  • Linux Lite
  • UBports
  • Xubuntu
  • Lubuntu
  • Kubuntu
  • Linux Mint
  • KDE neon
  • Fedora
  • Asahi Linux
  • Bazzite
  • Nobara Linux
  • Rocky Linux
  • AlmaLinux
  • openSUSE

Corporate (corporation-owned and/or controlled):

  • /e/OS
  • Sailfish OS
  • PureOS
  • Manjaro Linux
  • Raspberry Pi OS
  • OSMC
  • Kali Linux
  • Zorin OS
  • Tuxedo OS
  • Pop!_OS
  • elementary OS
  • Ubuntu
  • Proxmox
  • SteamOS
  • CentOS Stream
  • Red Hat Enterprise Linux (RHEL)
  • CloudLinux OS
  • SUSE Linux Enterprise
  • Unraid

Dubious (questionable and/or suspicious):

  • Waydroid
  • Artix Linux
  • Omarchy
  • OpenMandriva

Borderline (possibly dangerous and best to avoid):

  • LineageOS

MALWARE (actively dangerous and harmful to use):

  • android
  • chromeOS
  • Apple Operating Systems (macOS, iOS, etc.)
  • Windows
  • Red Star OS
  • redsand@infosec.pub
    link
    fedilink
    arrow-up
    0
    ·
    20 days ago

    Would you believe gentoo, slack and LFS can be more secure than qubes in many use cases if you know what you’re doing? LFS you basically need to be a wizard but in theory it’s possible.

    • hirihit640@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      19 days ago

      In theory, any Linux OS can be more secure if you know what you’re doing. Just write all the software yourself and don’t write any bugs!

      • redsand@infosec.pub
        link
        fedilink
        arrow-up
        0
        ·
        19 days ago

        I more meant stripped down to just what you need for a given use case down to the library level. You only need to write software for LFS…

        • hirihit640@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          19 days ago

          Well you still need to run stuff on the computer. Like a browser. And if you want that to be secure as Qubes OS, you’d wrap the browser in a VM. To defend against usb attacks and networking attacks, you’d wrap those interfaces in a VM too, like Qubes does. Then have a way of routing the networking between the VMs. Etc etc. So it’s not just stripping things down. You have to build things up too, if you want to emulate Qubes.

            • hirihit640@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              0
              ·
              19 days ago

              Not sure what you mean by hardware segregation. If you mean, having multiple PCs, then that can actually be less secure. You now have to secure multiple devices against physical attacks, instead of just one. And you have to figure out how to transfer files securely between them.

              Im not really thinking general purpose either.

              What’s the setup you’re thinking about?

              • redsand@infosec.pub
                link
                fedilink
                arrow-up
                0
                ·
                19 days ago

                If you want anonymity not just security you can do whonix on hardware or I2P on a seprate host with a minimal headless install. I’m thinking more along the lines of a machine that only does a single job like a chat app client, a server, a word processor, CAD, etc… IRC, simplex and others don’t even need X or wayland.

                • keiko@fedia.ioOP
                  link
                  fedilink
                  arrow-up
                  0
                  ·
                  19 days ago

                  If the “one job” involves networking, then the machine is already doing more than one job, since it’s also managing network connection and firewalling. I’m not saying that such a thing can’t be very well-optimized for security, just that networking complicates things.

                • hirihit640@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  19 days ago

                  Qubes has Whonix templates to make it easy to dispose and recreate your Whonix VMs. And as the other reply said, handling networking is not trivial, tons of opportunity for user error if you try to do it yourself. If you want to give it a shot for fun, nothing wrong with that. Just don’t expect it to be as secure as Qubes, unless you are actually a security expert

            • keiko@fedia.ioOP
              link
              fedilink
              arrow-up
              0
              ·
              19 days ago

              I think you mean hardware isolation. By leveraging a type 1 hypervisor, Qubes OS does have hardware isolation, in addition to software-based isolation. For instance, physical devices like ethernet, wireless, and usb, are all capable of being isolated from the rest of the system (and from each other) and managed by dedicated service qubes. You can also have dedicated minimal templates for each service qube to reduce attack surface and increase efficiency of the service qubes. And then you can also configure the service qubes to be disposable, which is very nice.

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        0
        ·
        20 days ago

        Idk if it matters, but here’s how I see the tiers:

        Qubes OS: S-Tier Advanced: A+ Enhanced: A Minimal: B+ Indie & BSD: B Arch: C+ Debian: C Corpo-ish: D+ Corporate: D Dubious: F Borderline: F- Malware: -F

        That doesn’t mean I exclusively use distros from the top tiers. I can’t yet run Qubes OS on a linux phone, but if and when I’m ever able I will absolutely do that. For now, distros like postmarketOS and PureOS are good enough for me, for the phones. OSMC is good for the Vero and devices like it. Generally, the trend is that the higher up in the list you go, the more there is to learn in order to make the best use of the distro selected.

          • keiko@fedia.ioOP
            link
            fedilink
            arrow-up
            0
            ·
            20 days ago

            😇 (random mini-rant: omg it’s so much more difficult to respond on fedi than platforms like matrix where i would typically emoji-react without much thought, whereas here i am contemplating the proper way to respond or whether to respond at all, since mbin doesn’t support reacts without making a whole new comment 😖)

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      0
      ·
      20 days ago

      From wiki/Elementary_OS:

      The operating system, the desktop environment (called Pantheon), and accompanying applications are developed and maintained by elementary, Inc.

      From elementary.io:

      The elementary brand belongs to elementary, Inc., the company that guides and supports development of elementary products.

        • keiko@fedia.ioOP
          link
          fedilink
          arrow-up
          0
          ·
          19 days ago

          True. If I’d added another row or two, I could’ve shown more of a spectrum of corporate ownership and influence, but that would’ve messed up the rainbow and added more complexity than what I’d wanted. After all, it was supposed to be a light-hearted meme.

  • Sprossnix@slrpnk.net
    link
    fedilink
    arrow-up
    0
    ·
    20 days ago

    Nice list. I wanna comment, that it’s questionable whether Chimera Linux, EasyOS, Kicksecure and Secureblue genuinely offer enhanced security over the major distros. I guess it depends on ones thread model…

  • jonman364@sh.itjust.works
    link
    fedilink
    arrow-up
    0
    ·
    20 days ago

    I installed Omarchy on my laptop after seeing its helper scrips mentioned a lot in a Waybar config I was… getting inspiration from. Why does it fall under dubious on your list?

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      0
      ·
      20 days ago

      When researching the distro, I came across articles like this, this, and this detailing the many unpleasant aspects of the dev’s character, including racism and transmisia. So I placed Omarchy in the Dubious row to represent my unwillingness to recommend it.

    • Envidon@feddit.nl
      link
      fedilink
      arrow-up
      0
      ·
      20 days ago

      Omarchy was getting a lot of attention when first released. The two major issues are that the guy that made it is very right wing (the term fascist was thrown around, I have not read up myself so do not now the details) and although it looks good it has a lot of technical issues, this blog post goed into more details if interested: https://マリウス.com/a-word-on-omarchy/

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      0
      ·
      19 days ago

      I had initially considered that but ultimately decided it would be easier and more similar to other tier lists to keep it left-aligned. But yeah, I know it’s a lot and might be too complicated to easily understand. Good enough for a meme though, I figure.

    • Tlaloc_Temporal@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      19 days ago

      Yeah, outlines like subway lines where each colour is visible the entire way would ne nice. Might be a bit thick in some places though.

  • keiko@fedia.ioOP
    link
    fedilink
    arrow-up
    0
    ·
    20 days ago

    And if this works, here’s the light-mode themed version of the os tier list:

    operating system tier list in light-mode theme (full description in main post)

  • 𝕸𝖔𝖘𝖘@infosec.pub
    link
    fedilink
    arrow-up
    0
    ·
    20 days ago

    I can’t see the image. It asks me log in on an instance where I do not have an account. So, I appreciate the text in the expand.

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      0
      ·
      19 days ago

      “Possibly” denotes the fact that it depends on the user’s sensibilities.

      LineageOS is not degoogled and will connect to google unless properly firewalled, which afaik cannot be done properly on-device. And as another user pointed out, android is under google’s control and doesn’t look like it will last indefinitely. I feel that android itself is a dead-end. Projects like GrapheneOS will have to do a hard fork away from android one day, or they will cease to exist as an option.

      But anyway, LineageOS is googled android, and google is a nefarious surveillance advertising corporation. So LineageOS is borderline malware in my eyes.

      Feel free to disagree of course. I don’t really care either way. You do you.

    • Solrac@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      19 days ago

      If you consider the fact that for some devices it’s available in an unofficial capacity and people choose to run it but also that it still uses Google servers for things like NTP and that there is no guarantee that it’s completely de-googled. It’s understandable… Not to mention that they have an actual risk of stagnation if Google continues to close source more parts of the AOSP…

      So, although it could be safe to use now with some modifications, especially in microg and removing any calls to google, it might not be the case in the near future.

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        0
        ·
        19 days ago

        Very good points, but I wanna add that since MicroG does make connections to google, I don’t see MicroG as usable either and would place it alongside LineageOS as borderline malware. Phoning home to a nefarious surveillance advertising corporation with bad history is not acceptable to me. The main issue I have with /e/OS (besides being android) is that it has MicroG installed and enabled by default, requiring the user to disable it in order to complete the degoogling of the device. And it’s also annoying that it cannot be removed. There should be 100% degoogled murena devices which do not ship with that shit installed. Though I’d much prefer to see new Fairphones shipped with postmarketOS as an option, and bonus points for optionally shipping without a cellular modem.

        • Solrac@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          19 days ago

          HOPEFULLY. The Fairphone 6+ picks up the work that The Mighty Cat has been doing. And adds the missing pieces so that pmOS is a viable option.

  • username_1@discuss.tchncs.de
    link
    fedilink
    arrow-up
    0
    ·
    20 days ago

    Tier 1; OS: Debian.
    Tier 2; Hmm: Red Hat, Arch, Gentoo.
    Tier 3; Shit: Android, Windows, TR-DOS.
    Tier 4; Is it even an OS: all others…

      • username_1@discuss.tchncs.de
        link
        fedilink
        arrow-up
        0
        ·
        20 days ago

        I meant OS. And the only OS here is Debian. You meant “Some obscure experimental piece of software most people never heard about”. And that’s NixOS, correct.

        • smiletolerantly@awful.systems
          link
          fedilink
          arrow-up
          0
          ·
          20 days ago

          Sorry, but calling the dumping ground for obsolete and outdated packages an “OS” goes a little too far in my opinion.

          “Smaller userbase yet more stable and more and better maintained packages” is not the insult you thought it was, I’m afraid…

          (/s, just in case, hope this is all still in good fun!)

          • username_1@discuss.tchncs.de
            link
            fedilink
            arrow-up
            0
            ·
            20 days ago

            Dumping ground? Have you tried to put something in the Debian repository? It is more difficult than shit over the pointy top of the Tutankhamun pyramid. Definitely not the dumping ground. Debian is stable like the frequency of seconds ticking.

            • smiletolerantly@awful.systems
              link
              fedilink
              arrow-up
              0
              ·
              20 days ago

              Yeah, that’s my point. I never got around to putting things in Debian repos or the AUR because shit seemed unnecessarily complicated. Now on NixOS, I happily help maintain a bunch of packages and modules. Because the packaging, build system, and OS are just sane, stable, and a joy to work with!