Hey guys, first post here and on an alt, I hope I don’t get flamed. If there’s not enough info I’ll post another thread tomorrow.

Its been ~5-7 years since using Linux (Ubuntu/Kubuntu/Debian/Mint/Fedora/etc) as my daily driver. Windows since then for dev and games with kids, but now I have a laptop that can run my dev env in a VM.

I’m an advocate for privacy and security, but I’m also at the “config once, mostly work for a while” camp… I don’t like spending a ton of time fixing things. I don’t need Whonix or QubesOS-level compartmentalization (unless it runs Barbone’s now), but I tried OpenSuse Tumbleweed on a recommendation and the fine-tuning of flatpak controls seemed really nice. I’d love to be able to sandbox as much as possible without breaking things. Memory and exploit-hardened kernel/apps is a huge plus. Basically GrapheneOS as a Linux distro would be fantastic, even though it comes with its own issues.

Am I overthinking here? Should I commit to Debian, Fedora, or OpenSuse and learn to sandbox and harden properly (if so which has best docs and community)?

I forgot the copy-paste specs my laptop hardware info to my phone earlier, but its an HP Victus 15-fa0032dx

HP Victus 15.6" 144Hz FHD IPS Gaming Laptop (Intel i7-12650H 10-Core, 16GB DDR4, 512GB SSD, RTX 3050 Ti 4GB GDDR6), Backlit KYB, WiFi 6, BT 5.2, HD Webcam

I don’t use the Bluetooth or webcam, so those drivers aren’t necessary. Does Wayland work for this, and is that really necessary?

Sorry for the noob questions. Mid-30s guy with kids wanting to get this done this week if possible. Please excuse spelling and grammar mistakes.

SIDE NOTE: NOT AT ALL opposed to learning new systems, especially for security, as long as it doesn’t require hunting down obscure undocumented commands.

Thanks all

  • hauiA
    link
    English
    217 days ago

    Although I get the idea, going all in on the privacy would mean you can never log in with a single account you have since they bind it to your ip and you’ve lost. Also using vpns all the time or tor if possible/necessary. Imo, its far too much work to go full paranoia mode.

    So I‘m running debian stable with kde (dont do it on nvidia!) and pop os on a laptop. Firefox, adblock plus and pihole do most of the heavy lifting. Gaming, working and other activities on the same machine works well without vms. I do use vms in specific dev Environments though.

    For kids, an immutable distro sounds like a great idea. Good luck and have a nice day.

    • @FutureProofBackdoors@futurology.todayOP
      link
      fedilink
      English
      1
      edit-2
      17 days ago

      Thanks for the reply. Why no Debian stable with KDE… which part doesn’t play nicely with nvidia (Debian or KDE?)

      I already use VPNs/for for 99% of my daily browsing/activities on my personal PCs, is there a higher chance of account lockout with VPNs on linux besides a few services like Netflix?

      • hauiA
        link
        English
        117 days ago

        Debian stable is pretty much a meme since it prioritizes stability over everything else. So you get the oldest kernel and will get the latest features months after every other distro. Since kde has only recently gotten wayland+nvidia support, it is pretty janky on debian stable still. It just makes no sense imo for a desktop pc. Pop is way better.