Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Subgraph (operating system)

From Wikipedia, the free encyclopedia
Linux distribution
Subgraph OS
OS familyLinux (Unix-like)
Working stateDiscontinued[1]
Source modelOpen source
Final preview2017.09.22[2] / 22 September 2017; 8 years ago (2017-09-22)
Repositorygithub.com/orgs/subgraph/repositories
Kernel typeMonolithic (Linux)
UserlandGNU
Influenced byTails,Qubes OS
Default
user interface
GNOME 3
LicenseGPLv3+
Official websitesubgraph.com

Subgraph OS was aDebian-based project designed to be resistant to surveillance and interference by sophisticated adversaries over the Internet.[3][4][5][6][7][8] It has been mentioned byEdward Snowden as showing future potential.[9]

Subgraph OS was designed to be locked down, with a reduced attack surface, to increase the difficulty to carry out certain classes of attack against it. This was accomplished through system hardening and a proactive, ongoing focus on security and attack resistance. Subgraph OS also placed emphasis on ensuring the integrity of installed software packages throughdeterministic compilation.

The last update of the project's blog was in September 2017,[10] and all of itsGitHub repositories haven't seen activity since 2020.[11]

Features

[edit]

Some of Subgraph OS's notable features included:

  • Linux kernel hardened with the grsecurity andPaX patchset.[12]
  • Linux namespaces andxpra for application containment.
  • Mandatory file system encryption during installation usingLUKS.
  • Configurable firewall rules to automatically ensure that network connections for installed applications are made using theTor anonymity network. Default settings ensure that each application's communication is transmitted via an independent circuit on the network.
  • GNOME Shell integration for the OZ virtualization client,[13] which runs apps inside a secure Linux container, targeting ease-of-use by everyday users.[14]

Security

[edit]

Subgraph OS'ssandbox containers have been critiqued as inferior toQubes OS'svirtualization. An attacker can trick a Subgraph user to run a malicious unsandboxed script via the defaultNautilus file manager or in the terminal. It is also possible to run malicious code containing.desktop files (which are used to launch applications). Malware can also bypass Subgraph OS'sapplication firewall. Also, by design, Subgraph does not isolate thenetwork stack like Qubes OS.[15]

See also

[edit]

References

[edit]
  1. ^"DistroWatch.com: Subgraph OS".DistroWatch.com. 2023-01-30. Retrieved2023-10-13.
  2. ^"Subgraph OS September 2017 ISO Availability".subgraph.com. Retrieved22 September 2017.
  3. ^"Subgraph: This Security-Focused Distro Is Malware's Worst Nightmare".Linux.com. 2018-01-26. Retrieved2023-10-13.
  4. ^"DistroWatch.com: Put the fun back into computing. Use Linux, BSD".DistroWatch.com. 2017-01-30. Retrieved2023-10-13.
  5. ^updated, Mayank SharmaContributions from Brian Turner last (May 9, 2022)."Best Linux distro for privacy and security of 2023".TechRadar.{{cite web}}:|last= has generic name (help)
  6. ^"Subgraph announces security conscious OS" – via www.wired.co.uk.
  7. ^"Secure Your Online Privacy With These Linux Distributions".It's FOSS. February 22, 2017.
  8. ^"Subgraph OS, a new security-centric desktop distribution [LWN.net]".lwn.net.
  9. ^Styles, Kirsty (16 March 2016)."Subgraph will be Snowden's OS of choice – but it's not quite ready for humans yet". The Next Web. Retrieved7 July 2016.
  10. ^"Subgraph - Blog".subgraph.com. Retrieved2023-08-03.
  11. ^"Subgraph".GitHub. Retrieved2023-08-03.
  12. ^"Hardening".subgraph.com. Retrieved2023-08-03.
  13. ^"subgraph/oz: OZ: a sandboxing system targeting everyday workstation applications".GitHub. Retrieved2023-10-13.
  14. ^"GitHub - OZ: a sandboxing system targeting everyday workstation applications". Subgraph. Retrieved6 October 2016.
  15. ^"Breaking the Security Model of Subgraph OS | Micah Lee's Blog".micahflee.com. Retrieved2017-04-25.

External links

[edit]
Retrieved from "https://en.wikipedia.org/w/index.php?title=Subgraph_(operating_system)&oldid=1287374019"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp