@lemmingsareawesome@sh.itjust.works
2026-09-15 23:22 UTC
Replies (12)
-
@hexagonwin@lemmy.today 2026-09-15 23:46
don’t get software from random sites and use your package manager with distro provided repo only
-
@WeirdGoesPro@lemmy.dbzer0.com 2026-09-16 01:09
Pick a piracy site you can trust. It makes things easier.
-
@Semi_Hemi_Demigod@lemmy.world 2026-09-16 01:31
Take regular VM snapshots and never forget that exploits can breach the VM
-
@Sapphy@lemmy.ml 2026-09-16 03:47
You can just use a VM and an antivirus on Windows. Linux isn’t really necessary for your scenario
-
@Hakuso@scribe.disroot.org 2026-09-16 00:16
I have always kept everything airgapped, the best security is isolation. I download stuff to a tablet, with nothing of value or interest on it, dump it to the sd card, then move it to the offline systems with a USB card reader. Even my servers (mostly ARM SBCs with one RISC-V) were set up to work over a wired offline network. Also most of my pirated stuff is things I own that I yarred for the crack if it was more convenient than cracking it myself.
-
@MangoCats@feddit.it 2026-09-16 15:06
Mirror, keep a clean copy of your setup offline. Make periodic backups. If you ever get into an unpleasant state, nuke it and go back to one you like better.
-
@lemmyng@lemmy.dbzer0.com 2026-09-16 16:23
secureblue.dev/features
-
@mazzilius_marsti@lemmy.world 2026-09-16 16:48
compartmentalization top reasons why GrapheneOS is highly praised: ability to create different profiles with different encryption keys, and hardened codes. on Linux, the top choice is QuebeOS. But i tried it 4 times and still couldnt go with it. My laptop couldnt handle quebeos… The other choice is SecureBlue. I heard that is called the Graphene of Linux. They have hardened codes, secure browser and very strict secure defaults. The downside? You need to be able to use distrobox, flatpak, rpm-ostree, brew to maintain your apps. So in a way, it is the same compartmentalization, but a bit messy. If u cant deal with these 2, then maybe use TailOS to do your download. Not sure if it saves the data? Using VM is also great. But i think a “super VM” is the only answer and that is QuebeOS. You can literally control everything inside each VM.
-
@Clark@lemmy.ml 2026-09-16 16:57
Use Qubes OS. Do not update anything including Tor browser and the OS. Just install the new version as soon as it is released on Qubes OS website. Otherwise you will probably get a virus. I know this from experience, please take this into account
-
@Lettuceeatlettuce@lemmy.ml 2026-09-16 17:23
Idk what software you’re using, but most VM software has an easy way to take a snapshot of the VM state. If you’re about to download something risky, take a quick VM snapshot, so if it ends up being some kind of malware, you can just roll the VM back to its earlier state without issue, takes like 2 minutes. If you’re worried about malware spreading through your network, you need to isolate your devices. The most common way to do this is with VLANs, but I don’t know what your home network looks like, and if you just have a typical home setup with your ISP’s modem/router and all your devices plugged into it or on the default wireless network, you won’t be able to do that. You could also use something like UFW on Linux to only allow internet traffic and block any traffic inbound or outbound to your LAN network, isolating your PC from all other devices on your LAN. This isn’t great, because if your host is compromised, then your host-based firewall could also be compromised and the malware could then get out to the rest of your network. You could invert this and have all your other devices on LAN set to block all traffic from your specific PC, which would be more secure, but also a pain to configure, plus it assumes all the other devices are able to be configured in that way on your LAN. There are a bunch of other solutions, but it depends on your setup, your technical skill level, and your threat profile. If you’re just torrenting cracked games and random software, that’s somewhat risky, but not really that crazy if you are running it in a VM with rollback snapshots.
-
@TrollAccount69@lemmy.ml 2026-09-16 20:35
You could make backups and practice restoring from them so you can not lose everything when you screw up. You could learn not to screw up, which would go hand in hand with the above. You could switch to a mac and enable all the security and privacy stuff in macos (there’s quite a bit, it’s well documented and very extensive!). You could stop downloading from public sites and trackers and instead get on private trackers and use them exclusively.
-
@gandalfthewhite@lemmy.ml 2026-09-16 21:58
Honestly the biggest things are don’t run shit as root and don’t expose port 22. Especially don’t run things you downloaded from some website as root but in general just don’t run things as root. That’ll handle most problems that are likely to arise.