So I saw political compass memes a while ago and started making one, but then I started taking it too seriously and eventually turned it into a tier list. Idk if it makes sense to share it here, but idk where else to share such a thing. I also made a browser tier list, but idk where to share that either.

This whole thing is a png export of a pure svg image. For some of the logos, I had to make them either from scratch or by using gimp and inkscape to convert a png into an svg (imperfect but good enough).

Hopefully this is all formatted properly.

OS Tier List

S-Tier (reasonably secure operating system):

  • Qubes OS

Advanced (complicated setup and configuration):

  • Gentoo Linux
  • Guix System
  • Slackware Linux
  • Linux From Scratch (LFS)
  • Mobile NixOS
  • NixOS
  • Whonix
  • Predator-OS
  • Linux Kodachi
  • Gentoo FreeBSD

Enhanced (optimized security and minimalism):

  • Alpine Linux
  • Hyperbola GNU/Linux-libre
  • Chimera Linux
  • EasyOS
  • postmarketOS
  • Tails
  • Kicksecure
  • NetHydra
  • ParrotOS
  • OpenBSD
  • GrapheneOS
  • Secureblue

Minimal (maximally mini resource use):

  • Tiny Core Linux
  • LibreCMC
  • Void Linux
  • Puppy Linux
  • AsteroidOS
  • Slitaz
  • 4MLinux
  • OpenWrt
  • DragonFly BSD
  • FreeBSD
  • NetBSD

Indie & BSD (independent distros and BSD systems):

  • PCLinuxOS
  • Dynebolic
  • KaOS
  • Mageia
  • LuneOS
  • Solus
  • AerynOS
  • GNOME OS
  • KDE Linux
  • GhostBSD

Arch (reasonably fresh and arch-based):

  • SystemRescue
  • Parabola GNU/Linux-libre
  • pearOS
  • EndeavourOS
  • Nemo Mobile
  • Arch Linux Arm
  • BlackArch Linux
  • Archhurd
  • Archcraft
  • Nyarch
  • Ageless Arch
  • Arch Linux
  • CachyOS
  • Garuda Linux

Debian (reasonably stable and debian-based):

  • Flora Linux-libre
  • Genuen
  • Devuan GNU+Linux
  • Loc-OS
  • antiX
  • MX Linux
  • Maemo Leste
  • Mobian
  • Emmabuntüs
  • Linux Mint Debian Edition (LMDE)
  • Ageless Linux
  • Debian
  • KNOPPIX
  • PikaOS Linux
  • RetroPie
  • LibreElec
  • Vanilla OS

Corpo-ish (corporation-created and/or dependent):

  • Replicant
  • Uruk GNU/Linux-libre
  • Trisquel GNU/Linux
  • AnduinOS
  • Linux Lite
  • UBports
  • Xubuntu
  • Lubuntu
  • Kubuntu
  • Linux Mint
  • KDE neon
  • Fedora
  • Asahi Linux
  • Bazzite
  • Nobara Linux
  • Rocky Linux
  • AlmaLinux
  • openSUSE

Corporate (corporation-owned and/or controlled):

  • /e/OS
  • Sailfish OS
  • PureOS
  • Manjaro Linux
  • Raspberry Pi OS
  • OSMC
  • Kali Linux
  • Zorin OS
  • Tuxedo OS
  • Pop!_OS
  • elementary OS
  • Ubuntu
  • Proxmox
  • SteamOS
  • CentOS Stream
  • Red Hat Enterprise Linux (RHEL)
  • CloudLinux OS
  • SUSE Linux Enterprise
  • Unraid

Dubious (questionable and/or suspicious):

  • Waydroid
  • Artix Linux
  • Omarchy
  • OpenMandriva

Borderline (possibly dangerous and best to avoid):

  • LineageOS

MALWARE (actively dangerous and harmful to use):

  • android
  • chromeOS
  • Apple Operating Systems (macOS, iOS, etc.)
  • Windows
  • Red Star OS
  • someone@lemmy.today
    link
    fedilink
    arrow-up
    1
    ·
    59 minutes ago

    Kodachi is listed as secure debian, advanced, next to kicksecure and whonix and these others. I’m somewhat surprised about the placement. Is Kodachi actually open source? Can I build it myself to make sure there is nothing malicious in the binaries?

    Also, from what I recall Kodachi is easy to use but just it was never clear that the binaries were open, right? It also connects to a server by default (for “vpn”) the users have to trust, but I’m not sure if they changed it? I looked at their webpage and they now include RiseUp VPN and other options but my guess is they still have an initial ping to the Kodachi VPN setup by default?

    Also Kali is corporate? I didn’t know that! This makes it seems like Kali is somehow more concerning than Parrot! Is it?

  • 𝕸𝖔𝖘𝖘@infosec.pub
    link
    fedilink
    arrow-up
    2
    ·
    7 hours ago

    I can’t see the image. It asks me log in on an instance where I do not have an account. So, I appreciate the text in the expand.

  • redsand@infosec.pub
    link
    fedilink
    arrow-up
    1
    ·
    7 hours ago

    Would you believe gentoo, slack and LFS can be more secure than qubes in many use cases if you know what you’re doing? LFS you basically need to be a wizard but in theory it’s possible.

    • hirihit640@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 hours ago

      In theory, any Linux OS can be more secure if you know what you’re doing. Just write all the software yourself and don’t write any bugs!

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        4
        ·
        16 hours ago

        Idk if it matters, but here’s how I see the tiers:

        Qubes OS: S-Tier Advanced: A+ Enhanced: A Minimal: B+ Indie & BSD: B Arch: C+ Debian: C Corpo-ish: D+ Corporate: D Dubious: F Borderline: F- Malware: -F

        That doesn’t mean I exclusively use distros from the top tiers. I can’t yet run Qubes OS on a linux phone, but if and when I’m ever able I will absolutely do that. For now, distros like postmarketOS and PureOS are good enough for me, for the phones. OSMC is good for the Vero and devices like it. Generally, the trend is that the higher up in the list you go, the more there is to learn in order to make the best use of the distro selected.

          • keiko@fedia.ioOP
            link
            fedilink
            arrow-up
            3
            ·
            14 hours ago

            😇 (random mini-rant: omg it’s so much more difficult to respond on fedi than platforms like matrix where i would typically emoji-react without much thought, whereas here i am contemplating the proper way to respond or whether to respond at all, since mbin doesn’t support reacts without making a whole new comment 😖)

  • slemptastrophe@piefed.social
    link
    fedilink
    English
    arrow-up
    14
    ·
    16 hours ago

    What makes Artix dubious? Genuinely curious because I use it and want to know if I there’s a reason I should reconsider that.

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      7
      ·
      15 hours ago

      This repo, made in response to another repo, has this bit:

      Artix Linux | Developers are openly transphobic

      When attempting to click the link to see for myself, I still find that the artix forums are inaccessible, and so I can’t see for myself. I remember seeing something mentioned on a reddit post or forum somewhere about the same sort of thing, which makes me think it’s true. So I placed Artix in the Dubious row to represent my unwillingness to recommend it.

      • plsnerf7@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        5 hours ago

        First i heard about mullvad now this??? Oh man artix was my go to distro (without systemd) if cachy implements the age verification bs.

        • keiko@fedia.ioOP
          link
          fedilink
          arrow-up
          5
          ·
          21 hours ago

          Complicated setup and configuration to best thing to have?

          I kinda think so, yeah. Qubes OS is top-tier in my eyes, and is pretty sophisticated (and quite complicated to understand when first starting out with it). From there, Whonix is wonderful (qubes-whonix is the perfect combo), and the other advanced distros are known for their extensive customizibility/configurability (which also makes them pretty complex/complicated). With great power comes great responsibility (to read and learn lots of stuff).

          Then tiers that just say arch, debian.

          There’s not much to differentiate those distros in my view. Lots of flavours of arch and debian. I see them all similarly. Some users might prefer something like pearOS for an arch-based distro which is styled very similarly to apple operating systems, while some other users might prefer an arch distro like CachyOS which is meant to be optimally performant. But I still see those as comparably arch. Similar with the debian row. The ones which sprout from those rows are the ones which are optimized for security, otherwise they’re all just flavours.

          And maximally mini

          lol yeah ^^’ See, one of the things is that all of the text has to fit and line up pretty much perfectly, and I’d wanted to keep that one simple and (hopefully) easy to understand. Also, idk, it felt kinda cute. “maximally mini” idk lol

  • Natanox@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    6
    ·
    17 hours ago

    Is that the Knoppix logo? To my knowledge it’s unmaintained (still offering kernel 2.6?) and last time I tried downloading it years ago the .iso contained a virus. That one is definitely dubious at best.

    • toddestan@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      7 hours ago

      When I saw that, I was like “wait, is Knoppix still around?”. A quick search revealed it hasn’t been updated in some time.

      Back in the 2000’s Knoppix was a life saver more than once, but once other distros gained the ability to run live from the install media, I didn’t really need Knoppix any longer.

    • tehn00bi@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      15 hours ago

      Sad, knoppix was the goat for me back in 2004. Ran several scrap yard computers for months at a time from the live disk.

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      4
      ·
      16 hours ago

      When I’d previously gone searching, I remember having seen some posts on reddit and forums about how Professor Klaus Knopper had paused development for a while but indicated that he’d eventually get back to it. I can’t seem to find those posts at the moment, but I’m pretty sure that still holds true.

      As for the problem of iso files containing malware, that seems unrelated to the actual distro itself and more to do with re-shares of it. Though people should definitely be aware of such problems, as well as the problem of running out-of-date or end-of-life distros. It’s mainly in the list as a nod to its historical significance, with the hope that it gets a big update one day.

  • Digit@lemmy.today
    link
    fedilink
    English
    arrow-up
    5
    ·
    17 hours ago

    I think you have the skill to take this further, and make it interactive, clickable, explorable, even wiki’fied (or at least git’ified) to allow others to contribute too.

    I noticed some were missing.

    • BedrockLinux
    • CRUX
    • SLAX
    • Tin Hat
    • Hannah Montana
    • KISS
    • Carbs
    • Exherbo
    • … Okay, I’ll not exhaust this list with dozens more. ;)

    Well done for including as many as did already. Was joyous seeing Slitaz made the lislt. :) A fave of the small distros.

  • mlg@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    16 hours ago

    Is that just a weird Kali logo or is it a modified kali distro lol?

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      4
      ·
      16 hours ago

      If you’re talking about the distro in the third row from the top, that’s NetHydra, which is similar to Kali Linux but is not owned by a corporate entity. The full list of all distros is included in a spoilered text box thing in the main post.