OS Tier List
So I saw political compass memes a while ago and started making one, but then I started taking it too seriously and eventually turned it into a tier list. Idk if it makes sense to share it here, but idk where else to share such a thing. I also made a browser tier list, but idk where to share that either.
This whole thing is a png export of a pure svg image. For some of the logos, I had to make them either from scratch or by using gimp and inkscape to convert a png into an svg (imperfect but good enough).
Hopefully this is all formatted properly.
::: spoiler OS Tier List S-Tier (reasonably secure operating system):
- Qubes OS
Advanced (complicated setup and configuration):
- Gentoo Linux
- Guix System
- Slackware Linux
- Linux From Scratch (LFS)
- Mobile NixOS
- NixOS
- Whonix
- Predator-OS
- Linux Kodachi
- Gentoo FreeBSD
Enhanced (optimized security and minimalism):
- Alpine Linux
- Hyperbola GNU/Linux-libre
- Chimera Linux
- EasyOS
- postmarketOS
- Tails
- Kicksecure
- NetHydra
- ParrotOS
- OpenBSD
- GrapheneOS
- Secureblue
Minimal (maximally mini resource use):
- Tiny Core Linux
- LibreCMC
- Void Linux
- Puppy Linux
- AsteroidOS
- Slitaz
- 4MLinux
- OpenWrt
- DragonFly BSD
- FreeBSD
- NetBSD
Indie & BSD (independent distros and BSD systems):
- PCLinuxOS
- Dynebolic
- KaOS
- Mageia
- LuneOS
- Solus
- AerynOS
- GNOME OS
- KDE Linux
- GhostBSD
Arch (reasonably fresh and arch-based):
- SystemRescue
- Parabola GNU/Linux-libre
- pearOS
- EndeavourOS
- Nemo Mobile
- Arch Linux Arm
- BlackArch Linux
- Archhurd
- Archcraft
- Nyarch
- Ageless Arch
- Arch Linux
- CachyOS
- Garuda Linux
Debian (reasonably stable and debian-based):
- Flora Linux-libre
- Genuen
- Devuan GNU+Linux
- Loc-OS
- antiX
- MX Linux
- Maemo Leste
- Mobian
- EmmabuntΓΌs
- Linux Mint Debian Edition (LMDE)
- Ageless Linux
- Debian
- KNOPPIX
- PikaOS Linux
- RetroPie
- LibreElec
- Vanilla OS
Corpo-ish (corporation-created and/or dependent):
- Replicant
- Uruk GNU/Linux-libre
- Trisquel GNU/Linux
- AnduinOS
- Linux Lite
- UBports
- Xubuntu
- Lubuntu
- Kubuntu
- Linux Mint
- KDE neon
- Fedora
- Asahi Linux
- Bazzite
- Nobara Linux
- Rocky Linux
- AlmaLinux
- openSUSE
Corporate (corporation-owned and/or controlled):
- /e/OS
- Sailfish OS
- PureOS
- Manjaro Linux
- Raspberry Pi OS
- OSMC
- Kali Linux
- Zorin OS
- Tuxedo OS
- Pop!_OS
- elementary OS
- Ubuntu
- Proxmox
- SteamOS
- CentOS Stream
- Red Hat Enterprise Linux (RHEL)
- CloudLinux OS
- SUSE Linux Enterprise
- Unraid
Dubious (questionable and/or suspicious):
- Waydroid
- Artix Linux
- Omarchy
- OpenMandriva
Borderline (possibly dangerous and best to avoid):
- LineageOS
MALWARE (actively dangerous and harmful to use):
- android
- chromeOS
- Apple Operating Systems (macOS, iOS, etc.)
- Windows
- Red Star OS :::
183 replies
This is not a tier list. This is a chart. possibly even an infographic. It resembles a teir list, but that doesn't make it one.
From wiki/Tier_list
...
Idk if it matters, but here's how I see the tiers:
Qubes OS: S-Tier Advanced: A+ Enhanced: A Minimal: B+ Indie & BSD: B Arch: C+ Debian: C Corpo-ish: D+ Corporate: D Dubious: F Borderline: F- Malware: -F
That doesn't mean I exclusively use distros from the top tiers. I can't yet run Qubes OS on a linux phone, but if and when I'm ever able I will absolutely do that. For now, distros like postmarketOS and PureOS are good enough for me, for the phones. OSMC is good for the Vero and devices like it. Generally, the trend is that the higher up in the list you go, the more there is to learn in order to make the best use of the distro selected.
I was getting ready to argue with your interpretation but then I noticed you're the op π
π (random mini-rant: omg it's so much more difficult to respond on fedi than platforms like matrix where i would typically emoji-react without much thought, whereas here i am contemplating the proper way to respond or whether to respond at all, since mbin doesn't support reacts without making a whole new comment π)
Those tiers are weird
as am i
Complicated setup and configuration to best thing to have? Then tiers that just say arch, debian.
And maximally mini
I kinda think so, yeah. Qubes OS is top-tier in my eyes, and is pretty sophisticated (and quite complicated to understand when first starting out with it). From there, Whonix is wonderful (qubes-whonix is the perfect combo), and the other advanced distros are known for their extensive customizibility/configurability (which also makes them pretty complex/complicated). With great power comes great responsibility (to read and learn lots of stuff).
There's not much to differentiate those distros in my view. Lots of flavours of arch and debian. I see them all similarly. Some users might prefer something like pearOS for an arch-based distro which is styled very similarly to apple operating systems, while some other users might prefer an arch distro like CachyOS which is meant to be optimally performant. But I still see those as comparably arch. Similar with the debian row. The ones which sprout from those rows are the ones which are optimized for security, otherwise they're all just flavours.
lol yeah ^^' See, one of the things is that all of the text has to fit and line up pretty much perfectly, and I'd wanted to keep that one simple and (hopefully) easy to understand. Also, idk, it felt kinda cute. "maximally mini" idk lol
[citation needed]
If you consider the fact that for some devices it's available in an unofficial capacity and people choose to run it but also that it still uses Google servers for things like NTP and that there is no guarantee that it's completely de-googled. It's understandable... Not to mention that they have an actual risk of stagnation if Google continues to close source more parts of the AOSP...
So, although it could be safe to use now with some modifications, especially in microg and removing any calls to google, it might not be the case in the near future.
Very good points, but I wanna add that since MicroG does make connections to google, I don't see MicroG as usable either and would place it alongside LineageOS as borderline malware. Phoning home to a nefarious surveillance advertising corporation with bad history is not acceptable to me. The main issue I have with /e/OS (besides being android) is that it has MicroG installed and enabled by default, requiring the user to disable it in order to complete the degoogling of the device*. And it's also annoying that it cannot be removed. There should be 100% degoogled murena devices which do not ship with that shit installed. Though I'd much prefer to see new Fairphones shipped with postmarketOS as an option, and bonus points for optionally shipping without a cellular modem.
HOPEFULLY. The Fairphone 6+ picks up the work that The Mighty Cat has been doing and adds the missing pieces so that pmOS is a viable option.
"Possibly" denotes the fact that it depends on the user's sensibilities.
LineageOS is not degoogled and will connect to google unless properly firewalled, which afaik cannot be done properly on-device. And as another user pointed out, android is under google's control and doesn't look like it will last indefinitely. I feel that android itself is a dead-end. Projects like GrapheneOS will have to do a hard fork away from android one day, or they will cease to exist as an option.
But anyway, LineageOS is googled android, and google is a nefarious surveillance advertising corporation. So LineageOS is borderline malware in my eyes.
Feel free to disagree of course. I don't really care either way. You do you.
Did you forget about Clonezilla, Fedora Silverblue and their other variants?
My personal S-tier is Debian stable.
I'd figured that all of the various flavours of Fedora would be represented by the single Fedora logo in the Red Hat group. I do have Secureblue in a special "Secure Fedora" group in the Enhanced row, since it's more independent from Red Hat than Fedora itself.
As for Clonezilla, where would you place it? And where would one find an svg of the logo? I did leave out distros for which I could not find an svg logo (except for the few I was able to make myself).
Valid β€οΈ
Oh, but you have variants of Ubuntu. Do you have them, because there are technically not part of Canonical? This, I would understand.
For me, CloneZilla is a sysadmin tool. Wouldn't have guessed that they don't have a SVG version of their logo.
Yeah, that's my reasoning for including them and for the row they occupy.
I'm not saying they don't have an svg logo, just that I hadn't come across it when searching for as many operating system logos as I could find. I had started with distros I've used and then worked my way through popular distros. Clonezilla had seemed more of a tool and less of a distro so I hadn't spent much time searching for its logo. If i were to add it, I'd probably want it in the debian row, which is already quite full.
Why do people that make stuff like this not just label the logos?? Am I supposed to know the logo for every damn OS ever made? I appreciate you tried to solve this with a list that is just a big wall of text with no good way to connect back to the image, but it still sucks overall.
Thank you!
Beyond 5 logos, this graph is useless to me
Serious reply: That's understandable. Fun reply: Imagine how useless the emoji version would be to you :p
One problem is that some of the distro names are so long that I'd either have to shrink the text for all names or do it selectively, neither of which feels good to me, so I opted to just not list the names in the image itself (at least not yet). Another thing is that it took so long to align all the other text in the image, and it would devour my time to try adding all of the distro names. Yet another thing, I'm pretty sure I'd have to shrink all of the logos in order to properly fit the distro names, and even slightly altering the size of any logo would mean that I'd have to spend a lot of time realligning them. Did I mention that I made this in a text editor?
Nice. It would be good to put the distro name beneath each logo, for people who donβt recognise the logos.
I did include a full list in the original post, organized by row, and placed in a spoilered text-box thing. I had decided not to include the names under the logos because I would have obsessed so much longer if I'd have attempted to do that. As it is, I'd been obsessing with this project for several weeks. Why? idk
Ok, but where is TempleOS?
lol, where's the svg version of the logo? :p
An idiot admires complexity, a genius admires simplicity.
I prefer the term "fool" for this use-case. Similar to this π³οΈββ§οΈ meme:
Thats a direct quote from the creator of TempleOS
Waydroid is just a container of a slightly modified LineageOS. Why is LineageOS dangerous?
LineageOS is not degoogled and will connect to google unless properly firewalled, which afaik cannot be done properly on-device. Waydroid is basically a containerized LineageOS which can at least be firewalled from the host os, but that's sub-optimal, which is why I have it one notch above LineageOS.
Doesn't LinegeOS needs MicroG to have Play Services? I guess it still retains Google DNS, NTP and SUPL.
Yes, the google connectivity is the connectivity stuff like dns and ntp, and yes I think it lacks Play Services and MicroG by default. I just don't like google connectivity built-in without an easy way to disable it. That's why I like that projects like /e/OS exist as an easy way for people to get degoogled android (though I prefer linux over android for myself).
Be aware that /e/os just replace Google with their servers. So you must trust them.
Yeah, similar to GrapheneOS in that regard, swapping out google servers for their own for network connectivity checking and related stuff. Though, if you don't disable MicroG then there are some connections to google, but thankfully MicroG can be completely disabled without issue.
Like I said in another comment somewhere, I trust /e/OS for my parents cuz they want and need something that's familiar and will work without issues, and I want them to not be pulled into the google/apple blackholes of oblivion. Everything they want and more is available to them through fully FOSS apps from F-Droid, and they have VoLTE, VoWiFi, and the rest of "the basics" fully functioning. I do hope linux mobile will be ready to replace things like /e/OS one day, for people like them.
Greatest piece of ragebait I've ever seen on Lemmy so far, well done. I'll take it personal, therefore, have my downvote.
same
What makes Artix dubious? Genuinely curious because I use it and want to know if I there's a reason I should reconsider that.
This repo, made in response to another repo, has this bit:
When attempting to click the link to see for myself, I still find that the artix forums are inaccessible, and so I can't see for myself. I remember seeing something mentioned on a reddit post or forum somewhere about the same sort of thing, which makes me think it's true. So I placed Artix in the Dubious row to represent my unwillingness to recommend it.
Gross. I'll check out the link you shared. Might be just the push I need to finally move to Void.
Thanks!
Also check out Chimera Linux, it's a brilliant project. The lead dev is trans, the package management philosophy is very similar to Void, but with Alpine's APK instead of XBPS, and Dinit is a damn good init system. Here be dragons, but it remains one of my favorite distros.
First i heard about mullvad now this??? Oh man artix was my go to distro (without systemd) if cachy implements the age verification bs.
Yeah, Mullvad Browser was at the top of my browser tier list, right under Tor Browser, until I came across the controversy. It made me realize that I shouldn't have corporate stuff go above the corporate row. Corporate doesn't necessarily mean bad, just that there are inherent risks in projects that are corporate owned/controlled.
I donβt get incorporating open source projects with the values of their developers.
Iβm personally moving from Mullvad VPN to Windscribe after the co-owner donation thing. But Mullvad VPN is a service. Mullvad browser is open source, it does not belong to Mullvad.
I also see the same concept applied to the European digital sovereignty movement, βOh this program is open source buuuuut itβs US basedβ no it is not. Open source is open source and nothing else.
Being open source doesn't negate their control over the project. Mullvad ultimately controls the project and the branding for it, as well as advertising for their vpn service within the browser by way of their addon. Some users will continue to use the browser, and that's fine. Some users will stop using the browser, and that's also fine. I understand both perspectives. I just can't recommend it anymore, like how I don't recommend anything coming from GAFAM. There are alternatives. There always are. Tor Browser remains the best browser anyway.
At the very least, there was this one person, using terms such as "pro - LGBT", as if being transphobic was a legitimate alternative:
Other than that, these people were really talking around and around, never actually saying much, which is quite typical jargon for bigoted individuals, because naming matters by their names would make them admit their bigotry.
@[email protected] Let me know if you'd like me to screenshot the whole thread (four pages)!
Thanks for the info and offer, but I'm not really interested in seeing more screenshots from that place. It bothers me that they restricted access to it in the first place, preventing people like me from seeing it directly, and I'd think that if it's a mischaracterization of the devs that they'd make it known rather than this.
Side note, I also find it concerning that fedi is similarly closing off access. I don't browse while being logged in, and that means I'm no longer able to browse fedi using any instance of mbin, since they're all restricted. Most instances of piefed are inaccessible now too, and the ones that aren't are still useless for accessing posts with more than 99 comments. I'd thought that lemmy was basically dead since a major update a year or so ago made all pages blank, but it seems that there are at least a few instances which are accessible again. I used to be hopeful about fedi but idk anymore.
γγγγγπβ€
Your efforts have not gone unnoticed. π©·
I've not been around fedi long enough to have experienced much of what you describe, but it's tiresome how gatekeepy and opaque some forums are... π
I kinda disappeared from fedi for a long time when I switched to using matrix, but I eventually started browsing again and only recently decided to actually interact. Idk how long this will last for me though, since I generally feel disconnected from this platform and its people. Most people really. I used to see these platforms as possibilities for finding people and building communities, but they all seem more like outlets than anything else. Some users meme, others rant or rage, and it feels like such an emptiness. idk, count this as one of my mini-rants. π©·
I think I've seen enough to know it's time to pack up and move along. Thanks for offering though!
Hang on let me find my OS so I can figure out how much i respect you /s
Neurodivergent brain likes this for some reason
π©·
And if this works, here's the light-mode themed version of the os tier list:
Absolute gold
lol sorry. idk how to spoiler uploads on mbin or if it's even possible.
God damn, Lemmy gets weirder and weirder every day
π
Have you visited any of the other platforms lately? Just sayin...
This might be the best looking and most comprehensive tier list of anything I've ever seen.
Although I have some concerns, mainly with the 3 bottom tiers, it's still more reasonable than most tier lists I've seen.
As for my concerns, perhaps someone will be able to answer some questions:
Google's Android is in the Malware row because google is a nefarious surveillance advertising corporation, and their android offering is known for having trackers/spyware built-in. From what I've read, Android Open Source Project (AOSP) is to Android as Chromium is to Chrome, in that it's not as infested with google trackers/spyware while still being generally googled in the way that it phones home for ntp and dns connectivity checks.
You are correct that android does not yet require age-verification, and I'm kinda surprised you're the only one to have pointed this out so far. I simply didn't feel like waiting to share this tier list meme thing and didn't want to make it seem as though apple is the only one implementing age-verification.
LineageOS is not degoogled and will connect to google unless properly firewalled, which afaik cannot be done properly on-device. LineageOS is googled android, and google is a nefarious surveillance advertising corporation. So LineageOS is borderline malware in my eyes.
In contrast, GrapheneOS is fully degoogled and is also maximally secured, which is why I placed it in a much higher rank. Though, it is ultimately still android, so it's not for me. Android is under google's control and doesn't look like it will last indefinitely. I feel that android itself is a dead-end. Projects like GrapheneOS will have to do a hard fork away from android one day, or they will cease to exist as an option.
Waydroid is basically a containerized LineageOS which can at least be firewalled from the host os, but that's sub-optimal, which is why I have it one notch above LineageOS.
I had tried Waydroid on my linux phone, and the OpenSnitch firewall running in the host linux system flagged multiple google connections that Waydroid was attempting to make upon starting. Basic connectivity stuff, but googled nonetheless. I hadn't seen any disclaimers on their site about it, but I also hadn't seen anything about LineageOS advertising itself as degoogled in the first place. I view degoogled android as generally acceptable (though it's not for me), but googled android is unacceptable (in my view). So I placed Waydroid in the Dubious row to represent my unwillingness to recommend it.
As for Artix Linux, this repo, made in response to another repo, has this bit:
When attempting to click the link to see for myself, I still find that the artix forums are inaccessible, and so I can't see for myself. I remember seeing something mentioned on a reddit post or forum somewhere about the same sort of thing, which makes me think it's true. So I placed Artix in the Dubious row to represent my unwillingness to recommend it.
The other two distros in the Dubious row are Omarchy and OpenMandriva.
When researching Omarchy, I came across articles like this, this, and this detailing the many unpleasant aspects of the dev's character, including racism and transmisia. So I placed Omarchy in the Dubious row to represent my unwillingness to recommend it.
When researching OpenMandriva, I came across lots of links referring to it as "the non-woke linux distro" and their forum, which was and is accessible, was what I'd expected to see. Basically "non-political" politics, which tends to mean anti-. It was an unpleasant place, and I think the intention is to make it unpleasant for the types of people they hate so as to keep them away. So I placed OpenMandriva in the Dubious row to represent my unwillingness to recommend it.
tyvm π©·
Wow, thanks for the in-depth explanations. I think I get it now.
You did mention 'political compass' in the description, but I'm guessing many people and I interpreted it a little differently, since the chart itself focuses on corpo vs non-corpo.
About LineageOS (and by extension Waydroid too) - maybe you could open issues about the connections to Google and point to the specific ones. Perhaps the devs would be entirely willing to change which servers LineageOS connects to by default. And if not, then maybe they'd explain why or how.
I was able to access the forum without any issues. Tl;dr - it looks like an off-topic discussion turned political; many mentions of neonazism, Marx, Lenin, and western propaganda. Then someone started throwing shit at an Alpine Linux dev, who happens to be trans. At first they didn't clearly state the 'issue', but I've been in many transphobic groups in the past, and I can tell you that's exactly what they meant. Later someone else said they were eating and upon seeing the dev's picture feel like vomiting. This is where I stopped reading, but the thread goes on for several more pages.
That's basically what it boils down to. The entire thread gives strong far-right and transphobic vibes, although not everyone participating demonstrated such views.
It should be noted that I have no idea who the people posting are. Some of their comments suggest they're Artix Linux devs, but I can't verify that right now. Maybe when I'm on a bigger screen later.
I don't really want to make an account on any code-hosting site since most (all?) of them require javascripts in the browser, and there aren't any which I trust. On top of that, LineageOS and Waydroid use microsoft's github, which is the worst.
Besides all of that, I don't have any use for android in my life and so there isn't really a reason for the devs to care about my opinions or perspectives on their projects which I'll never want to use anyway. And also, there are lots of posts on various forums about these issues, so I doubt that the devs of those projects are unaware. It's just that degoogling is not a project goal for LineageOS and Waydroid.
Regarding the Artix Linux forum:
Whether or not the devs themselves were participating, I don't feel comfortable recommending a distro if that's the state of the official community forum. I think new users who have questions about configuring or fixing things shouldn't have to deal with such hostile environments.
what is wrong with LineageOS and eOS for it to be put in "borderline"? + why does LFS, Secure Fedora, Secure Android all have their own sections? you can just merge them (DIY Distros, Hardened, for one).
LineageOS is not degoogled and will connect to google unless properly firewalled, which afaik cannot be done properly on-device. LineageOS is googled android, and google is a nefarious surveillance advertising corporation. So LineageOS is borderline malware in my eyes.
/e/OS is not in any of the gray rows that denote a failing grade. It is in the red "Corporate" row, because it is owned/controlled by a corporate entity, and it has a passing grade from me. I trust it for my parents and other "normal" people who need a phone that works without issues. MicroG is installed and enabled by default, but if it is disabled, then /e/OS becomes fully degoogled.Correction: /e/OS will be moved to the Dubious row for not being fully degoogled.
However, as I said in another comment:
Why does LFS have its own group? Honestly, it's mainly just so that the logo stands out better in the dark-mode version of this tier list. I also felt it made sense to single it out as special.
Why are there groups for Secure Fedora and Secure Android? Since there are already groups for Red Hat distros (which includes Fedora) and Android, I thought it made sense to make it obvious that the secure fedora/android distros were part of those other groups, similar to my reasoning for making a Secure Debian group. Those distros being optimally secured grants them higher rank than all the rest of the distros from those groups. All the other distros stay where they are because I don't see them as different enough to rise in the list. The secured ones, I do see as having reason to rise, and so they are placed higher, but I want it to be obvious that they are in fact Debian/Fedora/Android at their core.
So I've done a bit of research on this and I don't think what you say here is the most accurate.
LineageOS doesn't include any Google apps or services by default, nor does it include MicroG. (It does give an optional step to flash a GApps package in the official install guides, but this can be skipped no problem)
LineageOS does use proprietary Google BLOBs for AGPS services and wifi captive portal detection, both of which are anonymised by the nature of the protocols used. But more importantly, /e/ OS also uses these too, so /e/ shouldn't be ranked any higher than LineageOS is
On this point, I didn't suggest otherwise, and I don't disagree.
Looking into this here and here, I see that you are correct that /e/OS still has not fully degoogled:
So you are correct that I should drop /e/OS down to the Dubious row for advertising itself as degoogled and yet not being fully degoogled. Idk how GrapheneOS can manage their own servers for properly degoogling while /e/OS fails to do so.
Technically, disabling gps would effectively finalize the degoogling of /e/OS, as it currently exists. The questionable/suspicious aspect of this is that there isn't any documentation for how to finish the degoogling process that is accessibly presented to the user. I do find it annoying enough that clueless users won't know to disable MicroG in order to continue degoogling the phone, which is advertised as being already degoogled. Having to disable a useful feature like gps in order to finish the degoogling process is weird and bad and wrong to not inform the user in such a way that non-tech users understand.
I still find LineageOS to be borderline malware for having captive portal connectivity checks which /e/OS has properly degoogled. Unless something has changed in the last few years, Waydroid (containerized LineageOS) attempts to make connections to google upon starting up, which does not seem to be the case for /e/OS.
From another one of my comments in this thread:
And if I remember correctly, those connections were attempted every time I started Waydroid, not just the first time.
Well anyway, thanks for the info. Between this and the need to add CalyxOS into the list, I'll need a lot more time to move things around.
β€οΈ
They are not as secure as grapheneos, and they don't really care
Nor are most of the desktop Linux distros, compared to GrapheneOS, yet they are not downgraded for it.
Thanks but the vertical categories could be way clearer if the logos were not strictly left-aligned
Yeah, outlines like subway lines where each colour is visible the entire way would ne nice. Might be a bit thick in some places though.
I had initially considered that but ultimately decided it would be easier and more similar to other tier lists to keep it left-aligned. But yeah, I know it's a lot and might be too complicated to easily understand. Good enough for a meme though, I figure.
I think you have the skill to take this further, and make it interactive, clickable, explorable, even wiki'fied (or at least git'ified) to allow others to contribute too.
I noticed some were missing.
Well done for including as many as did already. Was joyous seeing Slitaz made the lislt. :) A fave of the small distros.
Edit: see response from OP.
Come again? What's wrong with Artix?In reading about it, I learned that the devs are apparently hateful and hostile to transgender people. When trying to see for myself, I found their forums gated, inaccessible to the public. So I placed Artix in the Dubious row to represent my unwillingness to recommend it.
Edited to add this:
This repo, made in response to another repo, has this bit:
Thanks for doing the research and informing me! πππ©·
Oh fuck!
What's wrong with waydroid?
LineageOS is not degoogled and will connect to google unless properly firewalled, which afaik cannot be done properly on-device. Waydroid is basically a containerized LineageOS which can at least be firewalled from the host os, but that's sub-optimal, which is why I have it one notch above LineageOS.
There are some weird picks here. Is replicant even maintained anymore? UBports and Asahi Linux in Corpo-ish? And what do you have against LineageOS?
From the Ageless Linux site:
It didn't have a logo so I made one based on the styling of the site. There used to be a site for Ageless Arch not long ago, and so I had made a logo for it based on what I'd made for Ageless Linux. The site seems to be offline now but I kept the logo in the list anyway.
UBPorts was created by a corporation and is an ubuntu distro. Asahi Linux is a Red Hat (Fedora) distro. I'd wanted corporate influence to be represented.
LineageOS is not degoogled and will connect to google unless properly firewalled, which afaik cannot be done properly on-device. Waydroid is basically a containerized LineageOS which can at least be firewalled from the host os, but that's sub-optimal, which is why I have it one notch above LineageOS.
Edit: Replicant is still technically maintained but has fallen very far behind.
true. I will adjust my comment. Good logo!
Lineage is not gegoogled? You have to install google services seperatly, when does it connect?
I suppose if corporate status is inherited that may be correct. in my opinion, its a bit too far removed to be corporate. Asahi linux is a purely volunteer distro, and ubuntu mobile was discontinued years ago, and is also purely volunteers-run nowadays.
I had tried Waydroid (containerized LineageOS) on my linux phone, and the OpenSnitch firewall running in the host linux system flagged multiple google connections that Waydroid was attempting to make upon starting. Basic connectivity stuff, but googled nonetheless. I hadn't seen any disclaimers on their site about it, but I also hadn't seen anything about LineageOS advertising itself as degoogled in the first place. I view degoogled android as generally acceptable (though it's not for me), but googled android is unacceptable (in my view).
That's why I called it "corpo-ish" :p (cuz I have no idea how else to describe the corporate relationship at play). But yeah, the corporate row is acceptable to me. They get a passing grade. I still use PureOS on my Librem 5 and OSMC on my Vero and have my parents setup with /e/OS on their Fairphones. Valid options all around.
I think this might be the most impressive/best one I've seen so far
tyvm β€οΈ I credit my unmedicated psychological disorders and the emptiness of my life which is sometimes randomly filled by projects like this that captivate me and don't really matter.
Honestly, same.
My SO said I constantly need to be tinkering or my mental state goes off the rails.
i dont use arch btw
neither do i :p
Is that the Knoppix logo? To my knowledge it's unmaintained (still offering kernel 2.6?) and last time I tried downloading it years ago the .iso contained a virus. That one is definitely dubious at best.
When I'd previously gone searching, I remember having seen some posts on reddit and forums about how Professor Klaus Knopper had paused development for a while but indicated that he'd eventually get back to it. I can't seem to find those posts at the moment, but I'm pretty sure that still holds true.
As for the problem of iso files containing malware, that seems unrelated to the actual distro itself and more to do with re-shares of it. Though people should definitely be aware of such problems, as well as the problem of running out-of-date or end-of-life distros. It's mainly in the list as a nod to its historical significance, with the hope that it gets a big update one day.
When I saw that, I was like "wait, is Knoppix still around?". A quick search revealed it hasn't been updated in some time.
Back in the 2000's Knoppix was a life saver more than once, but once other distros gained the ability to run live from the install media, I didn't really need Knoppix any longer.
Sad, knoppix was the goat for me back in 2004. Ran several scrap yard computers for months at a time from the live disk.
Sorry to point out a mistake but isn't CacheOS a gaming distro? As I understand the chart, it's not in that grouping but is right next to it
I did initially have CachyOS in the gaming group, but after looking a little closer, it appears to be a general-purpose distro optimized for performance, which happens to be useful for gaming. So it doesn't seem to be specifically made for gaming, which is why I pulled it out of that group but kept it right next to it (and next to the "popular" group, since it's one of the most popular distros).
Iβve used CachyOS for years, and this seems about right. +1
Many optimizations are definitely tailored to gaming, itβs gaming centric in origin, but its purpose and user-facing bits are more generalized than that.
Damn, did not realize there was a phone version of nixos.
The pink Linux Mint got me bugged for a moment lol
If you do an update on this, add calyx os (A custom rom to android), it's more safe than lineage os, but less safe than graphene is. And it does support a few more devices other than pixel.
I just got calyx's work profile set up and its really useful!
Ah, I remember seeing that CalyxOS came back from the hiatus recently.
Well, I'll have to obsess over how to add that one into the mix, since it will be somewhat disruptive pretty much regardless of where and how it's added. It's not really security-oriented, so it doesn't make sense for it to be in the Enhanced row with GrapheneOS. It's not the creation/product of a corporation, yet it is of android, so it would make sense for it to be basically right where Replicant is currently. If I add it there and move Replicant and the rest of the row to the right by one, that will shift the groups. So I'd probably want to move the "wildcard" of Unraid to the non-grouped bubble with OSMC and Kali Linux, in order to shift that row to the right by one to keep the groups lined up. But then I would also need to adjust the debian and arch rows. Probably would want to move VanillaOS to the left of EmmabuntΓΌs. Oh, but then idk about the gaming group. Technically, with the way the groups are shaped, Garuda Linux could be to the left of the main column of that group and still be connected but idk how good that would look. If, instead, I were to shift the gaming group entirely to the left by one, then it would be right next to the popular group, and due to the group shapes, they would overlap in such a way that could make it somewhat confusing as to where the gaming group truly ends.
So idk, but thank you for reminding me about CalyxOS
Tier 1; OS: Debian.
Tier 2; Hmm: Red Hat, Arch, Gentoo.
Tier 3; Shit: Android, Windows, TR-DOS.
Tier 4; Is it even an OS: all others...
I don't how hoch you managed to accidentally type "Debian" while you were obviously trying to type NixOS.
I meant OS. And the only OS here is Debian. You meant "Some obscure experimental piece of software most people never heard about". And that's NixOS, correct.
Sorry, but calling the dumping ground for obsolete and outdated packages an "OS" goes a little too far in my opinion.
"Smaller userbase yet more stable and more and better maintained packages" is not the insult you thought it was, I'm afraid...
(/s, just in case, hope this is all still in good fun!)
Dumping ground? Have you tried to put something in the Debian repository? It is more difficult than shit over the pointy top of the Tutankhamun pyramid. Definitely not the dumping ground. Debian is stable like the frequency of seconds ticking.
Yeah, that's my point. I never got around to putting things in Debian repos or the AUR because shit seemed unnecessarily complicated. Now on NixOS, I happily help maintain a bunch of packages and modules. Because the packaging, build system, and OS are just sane, stable, and a joy to work with!
Why is elementaryOS corporate?
From wiki/Elementary_OS:
From elementary.io:
Most people don't think of that when they read 'corporate'. π€·ββοΈ
True. If I'd added another row or two, I could've shown more of a spectrum of corporate ownership and influence, but that would've messed up the rainbow and added more complexity than what I'd wanted. After all, it was supposed to be a light-hearted meme.
Mint is corpo-ish? That's new to me.
mint is based on ubuntu (except for the mint debian edition) which is probably why it is there
Ah that makes sense. I disagree but at least I get it now.
This was my reasoning, yes.
Whats wrong with artix
Way too few maintainers for how ambitious it is
While that can be a valid concern, that's not my reason for placing Artix in the Dubious row. See my other response here.
(can someone remind me how to properly format links to comments so they bring the user to the instance being used?)
This repo, made in response to another repo, has this bit:
When attempting to click the link to see for myself, I still find that the artix forums are inaccessible, and so I can't see for myself. I remember seeing something mentioned on a reddit post or forum somewhere about the same sort of thing, which makes me think it's true. So I placed Artix in the Dubious row to represent my unwillingness to recommend it.
Would you believe gentoo, slack and LFS can be more secure than qubes in many use cases if you know what you're doing? LFS you basically need to be a wizard but in theory it's possible.
In theory, any Linux OS can be more secure if you know what you're doing. Just write all the software yourself and don't write any bugs!
I more meant stripped down to just what you need for a given use case down to the library level. You only need to write software for LFS...
Well you still need to run stuff on the computer. Like a browser. And if you want that to be secure as Qubes OS, you'd wrap the browser in a VM. To defend against usb attacks and networking attacks, you'd wrap those interfaces in a VM too, like Qubes does. Then have a way of routing the networking between the VMs. Etc etc. So it's not just stripping things down. You have to build things up too, if you want to emulate Qubes.
Hardware segregation βΊ virtual. Im not really thinking general purpose either.
Not sure what you mean by hardware segregation. If you mean, having multiple PCs, then that can actually be less secure. You now have to secure multiple devices against physical attacks, instead of just one. And you have to figure out how to transfer files securely between them.
What's the setup you're thinking about?
If you want anonymity not just security you can do whonix on hardware or I2P on a seprate host with a minimal headless install. I'm thinking more along the lines of a machine that only does a single job like a chat app client, a server, a word processor, CAD, etc... IRC, simplex and others don't even need X or wayland.
Qubes has Whonix templates to make it easy to dispose and recreate your Whonix VMs. And as the other reply said, handling networking is not trivial, tons of opportunity for user error if you try to do it yourself. If you want to give it a shot for fun, nothing wrong with that. Just don't expect it to be as secure as Qubes, unless you are actually a security expert
If the "one job" involves networking, then the machine is already doing more than one job, since it's also managing network connection and firewalling. I'm not saying that such a thing can't be very well-optimized for security, just that networking complicates things.
I think you mean hardware isolation. By leveraging a type 1 hypervisor, Qubes OS does have hardware isolation, in addition to software-based isolation. For instance, physical devices like ethernet, wireless, and usb, are all capable of being isolated from the rest of the system (and from each other) and managed by dedicated service qubes. You can also have dedicated minimal templates for each service qube to reduce attack surface and increase efficiency of the service qubes. And then you can also configure the service qubes to be disposable, which is very nice.
All the isolation breaks with a xen 0day. I love qubes but it has its weknesses.
Well everything has weaknesses, and nothing is perfect. I still trust xen over linux and Qubes OS over any other operating system. It is "a reasonably secure operating system" and doesn't claim to be anything else. But you are definitely correct to point out that we should not put blind trust into something as if it cannot fail.
While I don't doubt that those options can be made very secure, I don't think they can reach the level of security offered by Qubes OS, as it's not just a linux distro but is actually a xen-based type 1 hypervisor. The core of Qubes OS is security by compartmentalization, which includes hardware and software isolation. Disposable service qubes based on minimal templates with only the necessary packages installed, all managed by a type 1 hypervisor, seems out of the scope for what can reasonably be accomplished in a linux distro, whether LFS, Gentoo, or Slackware Linux. But idk, I'm just a user, not a dev.
I can't see the image. It asks me log in on an instance where I do not have an account. So, I appreciate the text in the expand.
That's odd, but here's a link from a lemmy instance which should be accessible to you: https://lemy.lol/api/v3/image_proxy?url=https%3A%2F%2Fmedia.fedia.io%2F34%2F93%2F3493f198e0e6823a7b690c488d610936f769d46908f1514e139f8118801c95b0.png
Is that just a weird Kali logo or is it a modified kali distro lol?
If you're talking about the distro in the third row from the top, that's NetHydra, which is similar to Kali Linux but is not owned by a corporate entity. The full list of all distros is included in a spoilered text box thing in the main post.
Huh. Γere are more systemd-free distros ΓΎan I was aware of.
WheΓΎer or not I agree wiΓΎ all of your opinions about categorization, ΓΎis is an interesting, ΓΎoughtful, and ΓΎought-provoking piece of work.
tyvm β€οΈ What had started as a random fun project ended up sucking me in, and I spent more and more time researching different distros to see how ΓΎey compared in my eyes. Γe systemd age-verification controversy is what had caused me to consider it a worΓΎwhile goal to be free from reliance on systemd, and I slowly discovered lots of such distros. I do really hope Qubes OS can move in ΓΎat direction eventually. And yes, I realize my views of ΓΎese distros is probably very different from ΓΎe views of most oΓΎers. NeverΓΎeless, random conversation-starting content <3
On this list, where would FreeDOS, Haiku and 9Front stand?
I overlooked FreeDOS and forgot about it even though it did come up when I had been looking for differrent operating systems to include. Reading the wiki page for it, I think I would place it in the Minimal row.
I had opted to ignore Haiku because it's been in a persistent state of alpha/beta for over a decade, but if I were to add it to the tier list, I think I'd place it in the Indie & BSD row.
I hadn't heard of 9Front until your comment, so I looked it up and read this article about it, and from my limited reading, I suppose I'd probably place it in the Indie & BSD row.
Kodachi is listed as secure debian, advanced, next to kicksecure and whonix and these others. I'm somewhat surprised about the placement. Is Kodachi actually open source? Can I build it myself to make sure there is nothing malicious in the binaries?
Also, from what I recall Kodachi is easy to use but just it was never clear that the binaries were open, right? It also connects to a server by default (for "vpn") the users have to trust, but I'm not sure if they changed it? I looked at their webpage and they now include RiseUp VPN and other options but my guess is they still have an initial ping to the Kodachi VPN setup by default?
Also Kali is corporate? I didn't know that! This makes it seems like Kali is somehow more concerning than Parrot! Is it?
Yeah, Qubes is cool, but then you need a second system/os to do "normal" stuff...
What "normal" stuff can't be done in a qube?
Stuff like games, video conferencing, screen sharing, android development, flashing ROMs, 3D CAD/slicing... if you care about dropped frames I would even put video playback on that list.
With a powerful enough processor and enough RAM, even modern games should be playable, excluding the ones requiring anti-cheat stuff i guess (I'm not a gamer so idk).
Video-conferencing is very much possible with things like matrix, as is screen-sharing (though that would be limited to the specific qube doing the screen-sharing, and you wouldn't want that in dom0 for obvious reasons).
Is android development not possible in a vm? idk why it wouldn't be. And idk about flashing ROMs but I was able to flash postmarketOS onto a Pinephone without issues.
3D CAD stuff would likely need a powerful processor and lots of RAM allocated to the specific qube doing the work, but it should be doable.
Video playback is perfectly fine as it is, no dropped frames at all. And I don't even bother giving any qubes more than the default 4GB RAM.
Well, maybe my hardware sucks or I have skill issues, but all of these are major hurdles. In the case of android/flashing, many things will reset the connection, which breaks the first qubes sharing command, and I can't share the "new" device (same device now in a different mode) b/c either I'm too slow or it only works for the first connection (and it's not in the right state after trying to re-share the device a second time due to a bus reset, or the like)...
Maybe that's more of an issue with android than Qubes OS, since flashing postmarketOS has absolutely no issues for me. idk. I also format usb drives and sd cards without issues. I'll add this to my list of reasons to not bother with android, lol.
Nice. Although, many of these Linux OSes are complying with Identity Verification laws. So... that automatically docks points from them for me.
If you're talking about the age-verification stuff, I actually did have a group for "Plans to Age-Verify" but decided to hide that since it made the image even more complicated and difficult to interpret than it already is. If/when any of the distros above the gray area do end up implementing age-verification in such a way that the user cannot simply ignore it, then they will be dropped to the gray area with the other operating systems which I cannot recommend.
Personally, them saying they will comply is enough for me. I moved from Linux Mint to Devuan due to this. Systemd is getting the Identity Verification stuff baked in and most Linux distros are complying, but Devuan EXPLCITLY refused to and they use SysVinit instead of systemd.
Yeah, that's valid. I'm interested in Alpine Linux and postmarketOS myself, but Devuan is a nice choice as well. Especially since Devuan and also Slackware Linux explicitly said they will refuse to comply with such laws. I liked the Slackware Linux response, which pointed out that such laws are actually unconstitutional in the states.
Valid. I just personally like Debian-based operating systems. Slackware Linux and Alpine Linux are not Debian-based. Devuan is. That is really why I chose them... they are the only Debian-based Linux OS without systemd that explicitly refused compliance.
I have tended to prefer Deiban-based distros too, I just recently found Alpine Linux and have been giving postmarketOS another chance on my Pinephone. But I haven't switched from PureOS on my Librem 5 yet, and I still rely on debian-minimal templates in Qubes OS (and a few Fedora templates too). I feel like I wanna go with Alpine Linux for qube templates but at the same time worry if it'll be too much work and time better spent going with Devuan but idk yet. It's nice that we still have options.
This guide was super helpl to me getting Guix installed/setup.
Why isn't CachyOS in the gaming bubble?
As I said in another comment:
I installed Omarchy on my laptop after seeing its helper scrips mentioned a lot in a Waybar config I was... getting inspiration from. Why does it fall under dubious on your list?
Omarchy was getting a lot of attention when first released. The two major issues are that the guy that made it is very right wing (the term fascist was thrown around, I have not read up myself so do not now the details) and although it looks good it has a lot of technical issues, this blog post goed into more details if interested: https://xn--gckvb8fzb.com/a-word-on-omarchy/
When researching the distro, I came across articles like this, this, and this detailing the many unpleasant aspects of the dev's character, including racism and transmisia. So I placed Omarchy in the Dubious row to represent my unwillingness to recommend it.
I think there is a lack of Void-based distros.
Although, why are Waydroid, Artix, Omarchy and LineageOS dubious, suspicious or borderline?
I made a really long comment answering those questions here.
I forgot how to properly link to comments in such a way that they will point to the comment on whichever instance is seeing them (idk how else to word that either), so I searched and found the link for your instance so it'll be accessible to you.
If you or anyone else understands what I'm talking about and know the answer, please remind me how to properly link stuff. <3
Edit: Oh yeah, and I suppose I can investigate Void-based distros to add to the list (I am a master-procrastinator and so it will likely take quite a while)
I've just read them and... Now all makes sense... π
Will you offer ΓΎe SVG source?
My plan was to eventually make a repo after eventually setting up my own server (if i can ever accopmlish such a ΓΎing), but I will probably share ΓΎe svg versions here soon-ish (i need to double-check ΓΎe original code for all ΓΎe svg files used to make sure i re-add any/all attribution ΓΎat was stripped out when making ΓΎis ΓΎing). (oh and also, i was 2 pixels in ΓΎickness off, wiΓΎ ΓΎe group at ΓΎe very bottom)
I ΓΎink GrapheneOS was ΓΎe only one which actually had attribution to a person who had created it, as opposed to ΓΎe oΓΎers which eiΓΎer had attribution for ΓΎe program which was used to create it or noΓΎing at all. Does it make sense to re-add ΓΎe attribution for ΓΎe grogram for each of ΓΎe (over 100) operating systems? Γis was someΓΎing which I'd figured I'd decide later, but I'm still not sure what to do.
Also worΓΎ noting ΓΎat I altered all of ΓΎe original svg logos to have ΓΎe same style, which involved removing lots of code (including all commas).
Yeah, I saw your caveat. Lord, ΓΎat's a lot of licenses to go ΓΎrough!
I doubt adding a comment, or comments, wiΓΎ attribution will have ΓΎat big of an impact, especially if you
.svgzit. You may never be able to upload it to a Threadiverse server -- I'm not sure if Piefed supports ΓΎem, eiΓΎer. Could you upload it to catbox.moe, or someΓΎing similar? Having it in a repos would be nice, too.I will certainly look into compression via gzip to try sharing here, after I double/triple-check ΓΎat I have all attributions from ΓΎe original svg files in place in my tier list. I do also want to add and rearrange a few ΓΎings before I'm ready to share, based on ΓΎe feedback I've gotten from some of ΓΎe comments here.
Idk about catbox.moe ΓΎough, as I've always had issues loading anyΓΎing from ΓΎat site when using tor. And I find ΓΎat weird, since it seems like a rude way of blocking access, raΓΎer ΓΎan a bug. Maybe I'm wrong, but it seems like a block as opposed to reject, leaving ΓΎe client waiting for a response while being ignored by ΓΎe server. Idk what else could explain ΓΎe consistent behaviour I experience.
As for a repo, if ΓΎat ever happens it will be my own. I just need to do a lot of ΓΎings to get to ΓΎe point where I can setup and manage my own server to host a repo. Ultimately ΓΎat's what I'd like to do, but until ΓΎen I don't have an easy way to share ΓΎings like ΓΎis.
(sorry for ΓΎe late reply)
I love catbox, but lately have been having trouble accessing it. I suspect, but have no evidence, ΓΎat it's related to my VPN because I rotated exit nodes recently and down detectors are not correlating my inability to access it. It makes me sad. :-(
Do you need to host your own server? You don't need to use github; you could create an account on gitlab or forge or someΓΎing.
It seems ΓΎat all of ΓΎe code-hosting sites require javascripts enabled in ΓΎe browser, and besides ΓΎat I also have trust issues. I don't feel comfortable setting up a repo on a site I can't trust.
Sourcehut (st.ht) is Javascript-free. At least mostly, if not entirely.
I've attempted to upload ΓΎe svg a few times wiΓΎ no success, using safest, safer, and safe modes in Tor Browser. Γere seems to be an issue wiΓΎ mbin regarding uploading svg images, and I'm not sure if ΓΎere's a fix or workaround. For ΓΎose who are curious, here's a screenshot of ΓΎe error message:
Gentoo freebsd exists?
Nice list. I wanna comment, that it's questionable whether Chimera Linux, EasyOS, Kicksecure and Secureblue genuinely offer enhanced security over the major distros. I guess it depends on ones thread model...
I'm just a user, not a dev, so idk besides what I've read. I know that Whonix is based on Kicksecure and seems to be designed to secure Debian as best as can reasonably be done. I do love qubes-whonix, so I figure Kicksecure is a reasonably secure option. Chimera looks to be an interesting blend of ideas and things while being an independent distro capable of forging its own path, and it seems to have security in mind. EasyOS seems like a Puppy Linux meant for optimized security while maintaining minimalism. Secureblue has optimized security as its goal. That's all just from what I've read about these distros. Those in particular are new/new-ish concepts for maximizing security in the linux space, and they all seem to be reasonable options.
For me, I continue to see Qubes OS as the ultimate secure operating system, and idk how anything else can come close in terms of security, with qubes-whonix being the absolute best combination. I do think it'd be better to eventually shift away from reliance on systemd, and it'd be nice if dom0 could be based on something like Alpine Linux instead of Fedora. It would also be nice to have something like Whonix based on something like Alpine Linux as well. Security-oriented minimal distros are really nice.
QuebeOS is cool. I tried it once and havent tried again.
I get that it is secure, but i feel like i need to rewire how my brain works. E.g. you dont open a Download folder, instead you spawn a File manager quebe and open Thunar
It's definitely not for everyone, but it's very good at what it sets out to do and be, for those who want or need such a thing. It compliments my ocd nicely, especially the concept of disposable qubes. It's just perfect for me. The optimal security also gives me peace of mind, a calm mind. It's lovely. But yeah, I understand that it's not for everyone. It's cool that you tried it though. Most people don't even know it exists.
What sicko has sat down and tried every one of these OS???
That said what's the spider one. I am an ignorant.
I haven't actually tried them all, not even most of them. The spider one is Slitaz. There's a spoilered list in the main post btw.
There's a ton of suggestions and stuff already, so don't want to add to the noise, but thanks for the work! Had no idea about Artix, and almost installed it because of dinit.
Just wanted to say, KaOS is systemd free, it's been using dinit for the init system for some time now. It does ship with some standalone systemd components like elogind, but so does Chimera. (also a really good project if anyone wants to check it out, quickly becoming my go-to recommend).
Oh tyvm for the info. I remember seeing progress on that front. Nice to see they did it. I shall add that to the small list of changes I plan to make. I will of course obsess over it for a while before considering the changes done. As is tradition ^^ Oh and no worries about commenting wherever. No such thing as noise if it's in a meme thread :p And thank you for the praise π©·
Finally....an os tier list we all can agree