Received: from mail.w13.tutanota.de (mail.w13.tutanota.de [185.205.69.213]) by gbr-app-1.alpinelinux.org (Postfix) with ESMTPS id 5E05A225895 for <~alpine/users@lists.alpinelinux.org>; Wed, 18 Sep 2024 13:39:10 +0000 (UTC) Received: from tutadb.w10.tutanota.de (w10.api.tuta.com [IPv6:fd:ac::d:10]) by mail.w13.tutanota.de (Postfix) with ESMTP id EFEBA22996EA for <~alpine/users@lists.alpinelinux.org>; Wed, 18 Sep 2024 15:38:39 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; t=1726666719; s=s1; d=tuta.io; h=From:From:To:To:Subject:Subject:Content-Description:Content-ID:Content-Type:Content-Type:Content-Transfer-Encoding:Cc:Date:Date:In-Reply-To:MIME-Version:MIME-Version:Message-ID:Message-ID:Reply-To:References:Sender; bh=k9XJczgv0PR6GEX+OI4zSgU/1xNobRhSwN8lwcCFF30=; b=Knr5bH8nmHWB1RHaJ4AwWqqPTnzf1sxQylgaqusOziBKv1Z7IyhPomT4QNBJ1u3V fMKoKW3SYBepNrkGuXQuS3HLHdlrmQx3cF3NlPdS8R85yPy6lxO0XsBqm5mmeS6FUVJ ZPXCEQ5B5zfzu7U22YaCb3w+kr+FRqNamFqShEAItZBMlS2lYxavkpq4C8UeO4T9WAm oMXjIxIA5SWn+91P234oUSefAphYVctqi81tZMPgDTsGKanEMVaO7qGt6Fx+Xd4s5QV MAtYiFKp5tP/A0JXSdNW9eDmLrylhCo141K3jB0JhQZVvMYH848bg6ZIEdqSeAU3HsY wbkOMRR0Lg== Date: Wed, 18 Sep 2024 15:38:39 +0200 (CEST) From: kdmw.629@tuta.io To: ~alpine/users <~alpine/users@lists.alpinelinux.org> Message-ID: Subject: Discussion - Is Alpine Linux still a more secure Linux Distribution compared to its compatriots MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_Part_33086_747163815.1726666719971" ------=_Part_33086_747163815.1726666719971 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable One of the claims to fame for Alpine Linux has been its security. In Alpine= Linux About page it is mentioned that Alpine is a=20 "Linuxdistribution designed for power users who appreciate security, simpli= cityand resource efficiency."=20 In wider Linux Ecosystem Alpine is known for its focus on security. i.e. it= was among the very first distributions to enable PIE and Stack Smashing pr= evention flags for its packages. While other distros dithered Alpine Linux = forged ahead with security as one of its primary goal. But over the past fe= w years the situation has changed. Other distros, like Debian/Ubunutu/Fedor= a have come close if not surpassed Alpine Linux in terms of security. For e= xample Debian and Ubuntu now have started packaging most if not all of thei= r binaries with PIE, Stack Smashing prevention, full Relocation Read-Only (= RELRO) enabled, etc.=20 So the point of discussion is, does Alpine still offer in terms of security= that the other distros dont? Or have the other distros caught up with Alpi= ne Linux? Should Alpine be considered as more secure or equal secure compar= ed to its peers like Debian, Ubuntu, Fedora, etc?=20 I am not saying that Alpine Linux should not be chosen. Nor am I questionin= g anyone's choice of selecting Alpine Linux. Nor am I trying to say that Al= pine Linux is no longer relevant. It is a good distro with minimal footprin= t, fast execution, fast bootup and ability to build on top of its base inst= all.=C2=A0 I just want the community which builds Alpine Linux to say what = they think about security in Alpine Linux.=20 --=20 Aficionado ------=_Part_33086_747163815.1726666719971 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable
One of the claims to fame for Alpine Linux has been its s= ecurity. In Alpine Linux About page it is mentioned that Alpine is a
"Linux distribution designed for power users who appreciate security, simplicity and resource efficiency."

In wider Linux Ecosystem Alpine is known for its focus on security. = i.e. it was among the very first distributions to enable PIE and Stack Smas= hing prevention flags for its packages. While other distros dithered Alpine= Linux forged ahead with security as one of its primary goal. But over the = past few years the situation has changed. Other distros, like Debian/Ubunut= u/Fedora have come close if not surpassed Alpine Linux in terms of security= . For example Debian and Ubuntu now have started packaging most if not all = of their binaries with PIE, Stack Smashing prevention, full Relocation Read= -Only (RELRO) enabled, etc.

So the point of discussion is, does Alpine still offer in terms o= f security that the other distros dont? Or have the other distros caught up= with Alpine Linux? Should Alpine be considered as more secure or equal sec= ure compared to its peers like Debian, Ubuntu, Fedora, etc?

I am not saying that Alpine Linux = should not be chosen. Nor am I questioning anyone's choice of selecting Alp= ine Linux. Nor am I trying to say that Alpine Linux is no longer relevant. = It is a good distro with minimal footprint, fast execution, fast bootup and= ability to build on top of its base install.  I just want the communi= ty which builds Alpine Linux to say what they think about security in Alpin= e Linux.

--
Aficionado


------=_Part_33086_747163815.1726666719971--