

People really dislike it when you point this out, But the security model on Linux is lacking. Yes, we have things like apparmor and SELinux, but compare it to sandboxd on macOS. The windows sandbox isn’t perfect, but it’s really user-friendly, and it works in most cases. Linux doesn’t have a direct equivalent. We’ve made great strides with making immutable distros through things like flatpack, and snap, but something that they failed to do is implement a least privilege model that is as robust as sandboxd on macOS.
Hi to run into this problem. I have a Mac mini that I use as a bridge from my home network to my work laptop. Now, most workloads requiring horsepower, I will run in the cloud, but there are some workloads that I want to run locally. I can parsec into the Mac, but I can’t parsec into the Linux server I have. The state of media on Linux is not great, and there are understandable reasons as to why.