OS Security Panorama 2026: Linux, Windows, macOS, BSD

 This comparison now covers three distinct scopes, evaluated on criteria adapted to each OS family.

3D illustration of MAC security battle: SELinux, AppArmor, WDAC, pledge and unveil
14 production Linux distributions : evaluation on 7 consistent criteria (v3 corrections included).
3 experimental or specialized Linux distributions : Fedora Rawhide, Debian Sid, Tails — with explicit warnings.
4 other OS : Windows 11 24H2, macOS 15 Sequoia, FreeBSD 14, OpenBSD 7.8 — adapted criteria, comparability discussed.
Linux production
14
Linux experimental
3
Other OS
4
Criteria / OS
7

Linux production comparison table (2026)

v3 corrections: Fedora Workstation reclassified as semi-annual point release (not rolling). NixOS corrected: no active MAC by default (neither SELinux nor AppArmor fully integrated).
ScoreProperty & RightsFirewall
3Advanced immutable · rollback · structured rightsActive restrictive policy by default
2Solid Unix rights + proper sudoActive standard configuration
1Basic few structural mechanismsInstalled but inactive
0WeakAbsent
Filters:

🖱️ Click a filter button above to keep only the matching rows — e.g. SELinux or Immutable. Click All to reset.

DistributionLevelMACFWRightsKernelType
Fedora Workstation High Security SELinux enforcing 3 2 Moderate Semi-annual point release
Fedora Silverblue High Security SELinux enforcing 3 3 Moderate Immutable · ostree
openSUSE Tumbleweed High Security SELinux enforcing 3 3 Moderate Rolling release
openSUSE Leap 16.0 High Security SELinux enforcing 3 3 Moderate LTS-like · SLES 16
openSUSE MicroOS High Security SELinux enforcing 3 3 Moderate Immutable · transactional
Ubuntu LTS Medium Security AppArmor enforcing 1 2 Low-moderate LTS (5–10 years)
Rocky Linux 9 High Security SELinux enforcing 3 2 Moderate Enterprise · RHEL-compat.
Debian Stable Medium Security AppArmor partial 0 2 Weak Stable · long cycle
Arch Linux Low Security by default None 0 1 Very low Rolling · minimalistic
Qubes OS Maximum Security Xen · compartmentalization 3 3 High Compartmentalized desktop
NixOS High Security None (experimental) 2 3 High Declarative · generations
Ubuntu Core Medium Security AppArmor (snaps) 1 3 Moderate Immutable · snaps only
Flatcar Linux High Security SELinux enforcing 2 3 High Immutable · containers
Kali Linux Isolated pentest None 0 1 Weak Pentest · specialized

Linux production profiles

🖱️ Each card below has three tabs — Overview · Tech specs · Verdict. Click a tab to reveal the detailed analysis.

FW
Fedora Workstation
Point release ~6 months • modern desktop • native security
High Security
MAC (SELinux)
95
Firewall
90
Property & Rights
82
Kernel Hardening
72
Updates
88
App Isolation
80
Attack Surface
85

Fedora Workstation is one of the strongest desktop bases by default: SELinux enforcing, firewalld active and Wayland. This is not a rolling release — a new major version is released about every six months, with about thirteen months of support per version.

Each version receives updates via the Bodhi system before being validated, ensuring some stability without the full freeze of an LTS.

  • TypeSemi-annual point release (~13 months support per version)
  • MACSELinux enforcing, deny-by-default
  • Firewallfirewalld active by default
  • Property & RightsClassic DAC, sudo/polkit, Wayland reduces some GUI vectors
  • Kernel HardeningPrudent settings present
  • UpdatesSemi-annual, ~13 months support
  • App IsolationFlatpak + desktop sandbox

Very good modern Linux desktop for strong security without an immutable model. Short support cycle to monitor.

SELinux enforcingfirewalld activeNative WaylandFast fixes~13 months supportNo LTSMajor upgrade every 6 months
FS
Fedora Silverblue
Immutable • ostree • transactional desktop
High Security
MAC (SELinux)
95
Firewall
90
Property & Rights
92
Kernel Hardening
74
Updates
90
App Isolation
92
Attack Surface
90

Silverblue takes Fedora Workstation's security with an immutable root (read-only), greatly reducing the persistence of a local compromise.

The most consistent choice for a hardened desktop when accepting the ostree/Flatpak workflow.

  • TypeImmutable, transactional (ostree)
  • MACSELinux enforcing
  • Firewallfirewalld active
  • Property & RightsRead-only system, simple rollback
  • Kernel HardeningSame base as Fedora Workstation
  • UpdatesAtomic, reversible (rollback)
  • App IsolationFlatpak privileged — host/app separation

Excellent for developers or advanced users wanting a hardened and resilient desktop.

Immutable ostreeFast rollbackSELinux enforcingBetter posture than WorkstationSpecific workflowLess flexible outside Flatpak
TW
openSUSE Tumbleweed
Rolling release • Btrfs/Snapper • high responsiveness
High Security
MAC (SELinux)
95
Firewall
90
Property & Rights
86
Kernel Hardening
74
Updates
92
App Isolation
76
Attack Surface
84

Tumbleweed combines SELinux enforcing, active firewalld and Btrfs/Snapper snapshots for easy rollback. Since snapshot 20250211, SELinux is active in enforcing mode by default.

Suitable for advanced users wanting fast fixes without losing structural guardrails. A true rolling release: no frozen version.

  • TypeRolling release (true rolling, no frozen version)
  • MACSELinux enforcing since snapshot 20250211
  • Firewallfirewalld active
  • Property & RightsBtrfs + Snapper, practical rollback
  • Kernel HardeningPrudent settings, no major singularity
  • UpdatesVery fast — regular monitoring required
  • App IsolationGood, not central to design

Very good serious rolling release with above‑average structural guardrails.

SELinux enforcingBtrfs snapshotsImmediate fixesHigh cadenceRegular monitoring required
LP
openSUSE Leap 16.0
LTS-like • SLES base • infrastructure · support until 2031
High Security
MAC (SELinux)
95
Firewall
90
Property & Rights
84
Kernel Hardening
74
Updates
84
App Isolation
70
Attack Surface
86

Leap 16.0 aims for a more predictable posture while keeping strong security components from the openSUSE ecosystem. SELinux enforcing by default.

AppArmor is not available in the Agama installer for a fresh installation — only SELinux. Migrations from Leap 15.6 keep AppArmor by default.

  • TypeStable / long cycle (support until 2031)
  • MACSELinux enforcing (default on new install)
  • AppArmorAbsent from Agama installer · manual activation post‑install
  • Firewallfirewalld active
  • Property & RightsBtrfs/Snapper, classic structure
  • UpdatesMore predictable than rolling
  • App IsolationGood, not immutable

Very consistent for modern infrastructure wanting robustness without rolling rhythm.

StableSELinux enforcingSupport until 2031Good infra profileAppArmor absent from installerLess agile than rolling
MO
openSUSE MicroOS
Immutable • transactional • edge / containers
High Security
MAC (SELinux)
95
Firewall
90
Property & Rights
94
Kernel Hardening
76
Updates
90
App Isolation
94
Attack Surface
91

MicroOS pushes openSUSE's logic toward a transactional, low‑mutable base, greatly reducing system persistence.

It shines on edge, appliances and container hosts where minimal system surface is a goal.

  • TypeImmutable, transactional
  • MACSELinux enforcing
  • Firewallfirewalld active
  • Property & RightsTransactional read‑only system, rollback
  • Kernel HardeningGood level, supported by transactional model
  • UpdatesAtomic
  • App IsolationVery favorable to containerized workloads

One of the most consistent models when reducing persistent surface is the goal.

ImmutableNative rollbackExcellent for containersNot desktop‑orientedSpecific workflow
UL
Ubuntu LTS
LTS • general public and server • 10 years support (Pro)
Medium Security
MAC (AppArmor)
78
Firewall
55
Property & Rights
74
Kernel Hardening
58
Updates
90
App Isolation
72
Attack Surface
68

Ubuntu LTS stands out for its long support and active AppArmor by default. Critical point: ufw is installed but NOT enabled by default. A freshly deployed Ubuntu server has no active network filtering without manual configuration.

Kernel hardening not very differentiating by default; security fixes are backported for 5 years (10 years with Ubuntu Pro ESM).

  • TypeLTS — 5 years standard, 10 years with Ubuntu Pro ESM
  • MACAppArmor active by default
  • Firewallufw installed but INACTIVE — enable with sudo ufw enable
  • Property & RightsClassic DAC, sudo, polkit
  • Kernel HardeningNot a visible asset by default
  • UpdatesLong support, systematic backporting
  • App IsolationSnap confinement useful but partial

Pragmatic and reassuring base, must be complemented by enabling the firewall.

10 years support (Pro)Active AppArmorVast ecosystemLivepatch availableufw inactive by defaultKernel hardening not differentiating
RL
Rocky Linux 9
Enterprise • RHEL‑compatible • critical infrastructure
High Security
MAC (SELinux)
95
Firewall
90
Property & Rights
82
Kernel Hardening
72
Updates
84
App Isolation
68
Attack Surface
84

Rocky Linux 9 inherits a solid enterprise posture: SELinux enforcing, active firewalld, long cycle and DISA STIG compliance available.

A solid RHEL alternative for budget‑constrained critical infrastructures. Less desktop‑oriented.

  • TypeStable, long cycle (10 years support)
  • MACSELinux enforcing
  • Firewallfirewalld active
  • ComplianceDISA STIG available — used in government environments
  • Kernel HardeningPrudent and consistent base
  • UpdatesLong support and backporting
  • App IsolationGood, less advanced than immutable systems

Very good server base for robust and predictable posture in Red Hat environments.

SELinux enforcing10 years supportDISA STIGRHEL compatibleLess desktop‑orientedSlower innovation
DE
Debian Stable
Stable • universal • manual hardening advised
Medium Security
MAC (AppArmor)
60
Firewall
35
Property & Rights
78
Kernel Hardening
48
Updates
82
App Isolation
55
Attack Surface
60

Debian Stable is impeccable on change management, but its native security is less prescriptive than Fedora or RHEL families. No firewall active by default.

AppArmor is partially present depending on installed profiles. Kernel hardening mostly left to the administrator.

  • TypeStable, long cycle
  • MACPartial AppArmor depending on profiles
  • FirewallNo firewall enabled by default
  • Property & RightsClassic Linux base, clean and controllable
  • Kernel HardeningNot highlighted by default
  • UpdatesFollowed but conservative (backporting)
  • App IsolationNot highlighted by default

Excellent base to administer, but not the most demonstrative in native security without explicit hardening.

Great stabilityClean baseVery controllableNo firewall by defaultPartial AppArmorLittle prescriptive kernel hardening
AR
Arch Linux
Rolling • total control • security entirely to build
Low Security by default
MAC
20
Firewall
20
Property & Rights
60
Kernel Hardening
35
Updates
95
App Isolation
45
Attack Surface
42

Arch Linux prioritizes freedom and total control. No MAC, no firewall, no kernel hardening by default.

Relevant for Linux experts wanting to configure everything manually. Unsuitable for production deployment without significant hardening work.

  • TypeMinimalistic rolling release
  • MACNone by default — AppArmor/SELinux must be installed manually
  • FirewallNone active by default
  • Property & RightsClassic Linux model, highly customizable
  • Kernel HardeningAlmost entirely manual
  • UpdatesVery fast (strict rolling)
  • App IsolationTo be built according to needs

Very relevant for Linux experts, but a weak showcase of default security.

Total controlFast fixesFlexible ecosystemNo native guardrailsEntirely manual hardeningNot recommended for production
QB
Qubes OS
Maximum isolation • Xen • compartmentalized security
Maximum Security
MAC (Xen)
98
Firewall
95
Property & Rights
94
Kernel Hardening
86
Updates
75
App Isolation
100
Attack Surface
92

Qubes OS compartmentalizes usage into distinct VMs via Xen — a radically different model from classic Linux MAC. dom0 is completely offline. LUKS mandatory.

Isolation compensates some of the traditional sysctl criteria. Requires at least 16 GB RAM for comfortable use.

  • TypeHighly compartmentalized desktop
  • MACXen hypervisor isolation (dom0 offline)
  • FirewallDomain segmentation — dom0 offline
  • Property & RightsStrict separation between qubes
  • EncryptionLUKS mandatory
  • UpdatesVia templates (TemplateVMs)
  • Minimum RAM16 GB for comfortable use

Top choice for high threat models. Not suitable for standard general‑purpose use.

Extreme isolationdom0 offlineLUKS mandatoryVery strong lateral resilience16 GB RAM minimumSteep learning curveHeavy updates
NX
NixOS
Declarative • generations • strong reproducibility
High Security
MAC (absent by default)
20
Firewall
76
Property & Rights
90
Kernel Hardening
84
Updates
86
App Isolation
90
Attack Surface
85

NixOS stands out for its declarative structure and transactional generations. Neither SELinux nor AppArmor are fully supported or integrated by default. The unique /nix/store structure makes file labeling mechanisms difficult.

Kernel hardening can be declared, replayed and versioned with remarkable consistency — a strong differentiating asset.

  • TypeDeclarative, close to immutable model
  • MACNeither SELinux nor AppArmor integrated by default — experimental support only
  • FirewallManageable declaratively via nftables
  • Property & RightsVery strong structural control via configuration
  • Kernel HardeningCan be declared and replayed reproducibly
  • UpdatesTransactional, simple rollback
  • App IsolationGood separation thanks to Nix model

Very relevant for experts wanting maximum configuration consistency. MAC considered absent by default.

DeclarativeClean rollbackStrong system consistencyReproducible kernel hardeningMAC absent by defaultReal learning curveSELinux/AppArmor experimental
UC
Ubuntu Core
Immutable • snaps only • IoT / embedded
Medium Security
MAC (AppArmor)
82
Firewall
50
Property & Rights
88
Kernel Hardening
68
Updates
88
App Isolation
94
Attack Surface
82

Ubuntu Core pushes confinement and atomic updates through a system entirely built around snaps. AppArmor is applied to Snap confinement.

Minimal firewall depending on the image — must be explicitly validated. Kernel hardening level depends on image and device role.

  • TypeImmutable, snaps only
  • MACAppArmor applied to Snap confinement
  • FirewallMinimal depending on image — check
  • Property & RightsVery good structural separation
  • Kernel HardeningIntermediate level, image‑dependent
  • UpdatesAtomic
  • App IsolationExcellent application‑side confinement

Good choice for appliance or edge, provided you validate the effective network policy.

ImmutableConfined snapsAtomic updatesFirewall to checkKernel level depends on usage
FL
Flatcar Linux
Immutable • containers • minimal host
High Security
MAC (SELinux)
94
Firewall
88
Property & Rights
85
Kernel Hardening
82
Updates
90
App Isolation
95
Attack Surface
90

Flatcar Linux is optimized as a minimal container host with little unnecessary surface and atomic updates. SELinux enforcing targeted at host/containers.

Kernel hardening very consistent for a minimal containerized host.

  • TypeImmutable, container/Kubernetes oriented
  • MACSELinux enforcing targeted at host/containers
  • FirewallNetwork policies adapted to node role
  • Property & RightsMinimal host, low‑mutable base
  • Kernel HardeningVery consistent for minimal containerized host
  • UpdatesAtomic, availability‑oriented
  • App IsolationVery strong when workload containerized

Very good choice as Kubernetes host or secured edge. Not relevant for desktop use.

ImmutableVery low useful surfaceSELinux enforcingExcellent for containersSpecialized useNot intended for desktop
KA
Kali Linux
Pentest • specialized use • never in production
Isolated pentest
MAC
25
Firewall
30
Property & Rights
50
Kernel Hardening
40
Updates
80
App Isolation
35
Attack Surface
30

Kali Linux is designed for offensive auditing, not as a reference for native security. No active MAC, pre‑installed pentest services, high attack surface.

Reserved exclusively for a VM or isolated pentest‑dedicated environment.

  • TypePentest distribution
  • MACNo strong MAC by default
  • FirewallAbsent / not a target by default
  • Property & RightsClassic Linux base oriented toward lab
  • Kernel HardeningNot an objective by default
  • UpdatesGood cadence for pentest tooling
  • App IsolationTo be provided via VM or dedicated lab

Reserved for a VM or isolated test environment. Never as a main system.

Complete pentest ecosystemReady‑to‑use toolsLive USB modeNo MACHigh attack surfaceNever as a main system

Experimental / targeted use distributions

Important: distributions in this section are not intended for production use. They appear here to complete the panorama, with explicit warnings on each card.
DistributionLevelMACFWRightsKernelType
Fedora Rawhide Development SELinux enforcing 3 2 Variable Development branch
Debian Sid (Unstable) Advanced use Partial AppArmor 0 1 Weak Rolling · unstable
Tails Targeted use (anonymity) Amnesic · forced Tor 3 2 Moderate Live amnesic · Tor

🖱️ Each card below has three tabs — Overview · Tech specs · Verdict. Click a tab to reveal the detailed analysis.

RH
Fedora Rawhide
Fedora development branch • rolling unstable • test only
Development
MAC (SELinux)
90
Firewall
88
Property & Rights
70
Kernel Hardening
68
Stability
15
App Isolation
72
Production suitability
8

Fedora Rawhide is Fedora's active development branch, updated daily. It is used to prepare the next stable version. Packages can break without warning.

SELinux enforcing is present (same policy as Fedora), and firewalld is active — but the inherent instability of a development branch excludes it from any production use.

  • TypeRolling development branch (daily)
  • MACSELinux enforcing — same policy as Fedora
  • Firewallfirewalld active
  • StabilityNot guaranteed — packages can break at any time
  • UpdatesDaily, not tested by Bodhi
  • Recommended useTesting, development, QA — never in production

Useful for testing upcoming Fedora versions or contributing to QA. Never in production.

SELinux enforcingNewest packagesUseful for testersCan break without warningNot officially supportedZero stability guarantee
DS
Debian Sid (Unstable)
Rolling release • unstable branch • security not guaranteed
Advanced use
MAC (AppArmor)
58
Firewall
30
Property & Rights
72
Kernel Hardening
46
Updates
72
App Isolation
52
Production suitability
30

Debian Sid is the unstable branch of Debian — a true rolling release. Counter‑intuitively, security fixes often arrive with a longer delay than Debian Stable, because they first go through unstable before being backported to stable.

No firewall by default (like Debian Stable). Partial AppArmor. The Debian security team does not provide official support for Sid.

  • TypeRolling release (unstable branch)
  • MACPartial AppArmor depending on profiles
  • FirewallNone active by default
  • Security supportNot officially covered by the Debian security team
  • UpdatesFast for new features, less for targeted fixes
  • Recommended useDebian development, packaging, testing — not in production

Useful for Debian developers and packagers. Security is objectively less guaranteed than Debian Stable.

Recent packagesUseful for Debian packagingFamiliar Debian baseSecurity not officially coveredNo firewallPartial AppArmorLess secure than Debian Stable
TL
Tails
Live USB amnesic • mandatory Tor • anti‑forensic
Targeted use (anonymity)
Network anonymity
96
RAM-only isolation
92
Firewall / Tor routing
94
Forensic resistance
95
Controlled persistence
88
Updates
80
Daily use
25

Tails is an amnesic Live OS: all traffic goes through Tor, and RAM is erased at shutdown. The host machine is considered potentially compromised.

Designed for specific profiles (journalists, whistleblowers, lawyers, activists) requiring anonymity and anti‑forensics. Not a daily OS.

  • TypeLive USB amnesic (RAM only by default)
  • MACNo classic Linux MAC — security through isolation and amnesia
  • NetworkAll traffic via Tor — mandatory and non‑bypassable
  • PersistenceOptional encrypted persistent volume (LUKS)
  • Forensic resistanceRAM erased at shutdown
  • UpdatesRegular — critical to apply
  • Recommended useJournalists, whistleblowers, lawyers, activists — targeted use only

The undisputed reference for anonymity and anti‑forensics. Unsuitable as a main OS or server.

Mandatory TorRAM erasedExcellent anonymityNo traces on hardwareNot a daily OSLimited performanceRequires dedicated USB stick

Other OS: Windows, macOS, BSD

Methodology — partial comparability: Windows and macOS are closed source systems; their security mechanisms cannot be independently audited. The criteria below are functional equivalents adapted to each OS. BSD (FreeBSD, OpenBSD) are open source and directly auditable. These OS are not directly comparable to Linux distributions on the same scale.
OSLevelAccess Control (MAC equiv.)FirewallEncryptionSystem HardeningSource
Windows 11 24H2 Medium-High MIC active · WDAC optional Active by default BitLocker (clean install + MS Account) HVCI / VBS (hardware-dependent) Closed (Microsoft)
macOS 15 Sequoia High SIP + Gatekeeper + App Sandbox Disabled by default FileVault (optional) KASLR · Secure Enclave · KPP Closed (Apple)
FreeBSD 14 High Jails · MAC framework optional Absent by default FDE optional (geli/ZFS) sysctl + ASLR + optional W^X Open (BSD License)
OpenBSD 7.8 Security reference pledge + unveil (native) pf active by default FDE optional (since 7.3) W^X · ASLR · RETGUARD · SSP Open (BSD License)

Section III Analysis

Windows 11 24H2
WDAC • BitLocker • HVCI • VBS
• HVCI, VBS and Secure Boot mandatory.
• BitLocker automatically enabled on a clean install with a Microsoft account on TPM 2.0 hardware.
• Weak point: opaque source code, telemetry difficult to fully disable.
• WDAC (MAC equivalent) exists but its default configuration is less restrictive than SELinux in enforcing mode.
macOS 15 Sequoia
SIP • Gatekeeper • App Sandbox • TCC
• SIP blocks any system file modification even with root rights.
• Gatekeeper controls unsigned binaries.
• TCC manages access permissions to sensitive resources.
• Notable weakness: application firewall disabled by default (bugs in macOS 15.0, fixed in 15.1).
• FileVault is optional, not enforced during installation.
• Closed source → independent audit impossible.
OpenBSD 7.8
pledge • unveil • W^X • pf • RETGUARD
• Security reference by default: only OS in this comparison applying W^X (Write XOR Execute) strictly and systemically for over 20 years.
• pledge(2) and unveil(2) reduce exploitation surface even after compromise.
• pf active by default.
• RETGUARD protects return addresses.
• Kernel relinked at each boot.
• Exceptional record: only two remote holes in over 25 years.
• Open source, fully auditable.
FreeBSD 14
Jails • pf • ZFS • geli • BSD License
• Jails : strong isolation (kernel containers predating Docker).
• pf (inherited from OpenBSD) is available but not enabled by default.
• Integrated ZFS provides encryption and data integrity.
• CVE-2025-15576 (Feb 2026): flaw in jail subsystem allowing processes from distinct jails to bypass restrictions via nullfs — fixed in FreeBSD 14.3 and 13.5.
• Default security lower than OpenBSD, but FreeBSD excels as server or network appliance with explicit configuration.

🖱️ Each card below has three tabs — Overview · Tech specs · Verdict. Click a tab to reveal the detailed analysis.

W11
Windows 11 24H2
Point release • HVCI • BitLocker default 24H2 • closed source
Medium-High
MAC equiv. (MIC/WDAC)
55
Firewall (Defender FW)
88
Encryption (BitLocker)
80
Rights & privileges (UAC)
70
System hardening
75
Updates
85
Attack Surface
50

Windows 11 24H2 marks a significant improvement: BitLocker is automatically enabled on a clean install with a Microsoft account, on any TPM 2.0 hardware. Windows Defender Firewall is active by default with a restrictive inbound policy.

Important limitations: WDAC is not enabled by default for general public users (complex to deploy). MIC (Mandatory Integrity Control) is always active. Telemetry and attack surface remain high. Source code is not auditable.

  • TypePoint release (annual update + monthly Patch Tuesday)
  • MAC equiv.MIC always active · WDAC available but not enabled by default
  • FirewallWindows Defender Firewall active by default
  • EncryptionBitLocker automatic on clean install + MS account (24H2)
  • HardeningHVCI, VBS, Secure Boot — hardware‑dependent
  • UpdatesPatch Tuesday + hotpatching (24H2+)
  • TelemetryHigh by default — must be reduced manually
  • SourceClosed — not independently auditable

Real progress with 24H2. Attack surface and telemetry remain structural weak points.

Firewall active by defaultAutomatic BitLocker (24H2)Reliable Patch TuesdayHVCI on compatible hardwareWDAC inactive by defaultHigh attack surfaceSignificant telemetryNon‑auditable source code
MOS
macOS 15 Sequoia
SIP · Gatekeeper · App Sandbox · Rapid Security Response
High
MAC equiv. (SIP+Gatekeeper+Sandbox)
88
Firewall (app firewall)
52
Encryption (FileVault)
72
Rights & privileges (SIP)
85
System hardening
82
Updates
88
Attack Surface
76

macOS 15 offers a generally solid default security posture: SIP (System Integrity Protection) active and hard to disable on Apple Silicon, Gatekeeper for application verification, and an excellent App Sandbox for Mac App Store applications.

Notable weakness: the application firewall is disabled by default. macOS 15.0 also had significant firewall bugs fixed in 15.1. FileVault (disk encryption) is optional.

  • TypeAnnual point release (Rapid Security Response between versions)
  • MAC equiv.SIP protects system files · Gatekeeper verifies apps · App Sandbox
  • FirewallApplication firewall DISABLED by default — known bugs in macOS 15.0
  • EncryptionFileVault optional (offered but not forced)
  • HardeningKASLR, KPP, Secure Enclave (Apple Silicon), Pointer Auth
  • UpdatesRapid Security Response — targeted fixes without major release
  • SourceClosed — XNU kernel partially open source
  • TelemetryModerate

Good default posture on Apple Silicon, but the firewall disabled by default remains surprising for an OS of this category.

Very robust SIPGatekeeper + NotarizationExcellent App SandboxRapid Security ResponseFirewall disabled by defaultFileVault optionalClosed sourceApple ecosystem dependency
FB
FreeBSD 14
Jails • pf • ZFS • BSD License • servers and appliances
High
MAC equiv. (Jails)
72
Firewall (pf/ipfw)
50
Encryption (geli)
60
Rights & privileges
80
System hardening
72
Updates
78
Attack Surface
80

FreeBSD 14 offers very robust isolation mechanisms via Jails — the equivalent of kernel containers with strong isolation, predating Docker by decades. pf (the firewall inherited from OpenBSD) is available but not enabled by default.

CVE-2025-15576 (Feb 2026): a flaw in the jail subsystem allowed processes from distinct jails to bypass chroot restrictions via nullfs — fixed in FreeBSD 14.3 and 13.5.

  • TypeStable, long cycle (quarterly releases)
  • MAC equiv.Jails (excellent) · MAC framework available but not active by default
  • Firewallpf/ipfw available but not active by default
  • Encryptiongeli (FDE) or native ZFS encryption
  • RightsClassic Unix model + Jails capabilities
  • Kernel hardeningPrudent sysctl options, ASLR available
  • SourceOpen (BSD License) — auditable
  • Updatesfreebsd-update + portsnap

Excellent for servers and appliances with manual hardening. Default security remains lower than OpenBSD.

Very robust Jailspf availableIntegrated ZFSAuditable source codeExcellent for serversFirewall inactive by defaultManual MAC frameworkLess secure by default than OpenBSD
OB
OpenBSD 7.8
pledge · unveil · pf · W^X · default security reference
Security reference
MAC equiv. (pledge/unveil)
96
Firewall (pf)
95
Encryption (FDE)
78
Rights & privileges (W^X+doas)
94
System hardening
97
Updates
72
Attack Surface
96

OpenBSD is universally recognized as the most secure system by default. Its unique pledge + unveil mechanism restricts system calls and file access of each process — integrated directly into the kernel and used by all base programs.

pf is active by default. W^X (Write XOR Execute) is applied systemically. RETGUARD protects return addresses. Disk encryption is guided since 7.3. Exceptional record: only two remote holes in over two decades.

  • TypeStable, bi‑annual release (6‑month cycle)
  • MAC equiv.pledge(2) + unveil(2) — restrict syscalls and filesystem access per process
  • Firewallpf active by default — the best available firewall
  • EncryptionGuided FDE since OpenBSD 7.3 (LUKS equivalent) · encrypted swap by default
  • RightsSystemic W^X · doas (safer than sudo) · privilege separation everywhere
  • HardeningASLR, RETGUARD, SSP, kernel relinking at each boot, ProPolice GCC
  • Updatessyspatch for binary fixes · support for last 2 releases
  • SourceOpen · regular audits by the OpenBSD team

The absolute reference for default security. Less suitable for general‑public desktop or environments requiring wide software compatibility.

pledge/unveil integrated everywherepf active by defaultSystemic W^XRETGUARDMaximum auditability2 remote holes in 25+ yearsLimited software support6‑month cycle (2 releases supported)Less suitable for general‑public desktopFew proprietary drivers

Conclusion — Which OS for your profile?

💻 Developer desktop
→ Fedora Workstation / Silverblue
Workstation for daily balance, Silverblue for an immutable and resilient posture.
🖥️ Linux LTS servers
→ Ubuntu LTS / Debian Stable
Ubuntu LTS for 10‑year support (Pro). Debian for total change control — manual hardening mandatory.
🏗️ Critical infrastructure
→ Rocky Linux 9 / openSUSE Leap 16.0
SELinux enforcing, long‑term support, enterprise or clear infrastructure orientation.
📦 Cloud / Edge / Containers
→ MicroOS / Flatcar / Ubuntu Core
Immutable variants: reduced persistence, standardized deployments, minimal surface.
🔐 Maximum security Linux
→ Qubes OS
Xen virtualization isolation. dom0 offline. LUKS mandatory. High threat model.
🕵️ Anonymity / Anti‑forensic
→ Tails
Live USB amnesic, mandatory Tor, RAM erased. For journalists, whistleblowers, lawyers.
🛡️ Absolute default security
→ OpenBSD 7.8
pledge/unveil everywhere, pf active, systemic W^X. World reference — less suitable for general‑public desktop.
🪟 Windows — general public
→ Windows 11 24H2
Active firewall, automatic BitLocker (clean install), HVCI. Enable WDAC for controlled environments.
🍎 macOS — Apple productivity
→ macOS 15 Sequoia
Robust SIP, Gatekeeper, excellent sandbox. Manually enable FileVault and application firewall.
🐡 Network server / Firewall
→ OpenBSD 7.8 / FreeBSD 14
Reference pf, powerful Jails (FreeBSD), pledge/unveil (OpenBSD). Preferred choice for network appliances.

Sources — Official sites of the systems presented

Distribution / OSOfficial site
Fedora Workstationfedoraproject.org/workstation
Fedora Silverbluefedoraproject.org/atomic-desktops/silverblue
openSUSE Tumbleweedget.opensuse.org/tumbleweed
openSUSE Leap 16.0get.opensuse.org/leap
openSUSE MicroOSget.opensuse.org/microos
Ubuntu LTSubuntu.com
Rocky Linux 9rockylinux.org
Debian Stabledebian.org
Arch Linuxarchlinux.org
Qubes OSqubes-os.org
NixOSnixos.org
Ubuntu Coreubuntu.com/core
Flatcar Linuxflatcar.org
Kali Linuxkali.org
Fedora Rawhidefedoraproject.org/wiki/Releases/Rawhide
Debian Sid (Unstable)debian.org/releases/sid
Tailstails.net
Windows 11 24H2learn.microsoft.com/windows
macOS 15 Sequoiaapple.com/macos
FreeBSD 14freebsd.org
OpenBSD 7.8openbsd.org

Recommended reading — SafeITExperts

Which distributions truly are secure out of the box — a critical review of default installs.
nftables, firewalld, ufw, Windows Defender Firewall: measured effectiveness of the firewalls scored in this panorama.
Silverblue, MicroOS, Flatcar: why the immutable model changes the security game — the « Immutable » column of our table.
The « Property & Rights » criterion in practice: properly configuring privilege elevation on Linux.

About the author

Marc is the lead editor of SafeITExperts, a bilingual technical blog (FR/EN) dedicated to cybersecurity, Linux and digital sovereignty.

Share your experience

What is your Lynis score before/after applying these checks? Share it in the comments or on social networks with #SafeITExperts.

👥 Comments

Comment on this article