OS Security Panorama 2026: Linux, Windows, macOS, BSD
This comparison now covers three distinct scopes, evaluated on criteria adapted to each OS family.
Linux production comparison table (2026)
| Score | Property & Rights | Firewall |
|---|---|---|
| 3 | Advanced immutable · rollback · structured rights | Active restrictive policy by default |
| 2 | Solid Unix rights + proper sudo | Active standard configuration |
| 1 | Basic few structural mechanisms | Installed but inactive |
| 0 | Weak | Absent |
🖱️ Click a filter button above to keep only the matching rows — e.g. SELinux or Immutable. Click All to reset.
| Distribution | Level | MAC | FW | Rights | Kernel | Type |
|---|---|---|---|---|---|---|
| Fedora Workstation | High Security | SELinux enforcing | 3 | 2 | Moderate | Semi-annual point release |
| Fedora Silverblue | High Security | SELinux enforcing | 3 | 3 | Moderate | Immutable · ostree |
| openSUSE Tumbleweed | High Security | SELinux enforcing | 3 | 3 | Moderate | Rolling release |
| openSUSE Leap 16.0 | High Security | SELinux enforcing | 3 | 3 | Moderate | LTS-like · SLES 16 |
| openSUSE MicroOS | High Security | SELinux enforcing | 3 | 3 | Moderate | Immutable · transactional |
| Ubuntu LTS | Medium Security | AppArmor enforcing | 1 | 2 | Low-moderate | LTS (5–10 years) |
| Rocky Linux 9 | High Security | SELinux enforcing | 3 | 2 | Moderate | Enterprise · RHEL-compat. |
| Debian Stable | Medium Security | AppArmor partial | 0 | 2 | Weak | Stable · long cycle |
| Arch Linux | Low Security by default | None | 0 | 1 | Very low | Rolling · minimalistic |
| Qubes OS | Maximum Security | Xen · compartmentalization | 3 | 3 | High | Compartmentalized desktop |
| NixOS | High Security | None (experimental) | 2 | 3 | High | Declarative · generations |
| Ubuntu Core | Medium Security | AppArmor (snaps) | 1 | 3 | Moderate | Immutable · snaps only |
| Flatcar Linux | High Security | SELinux enforcing | 2 | 3 | High | Immutable · containers |
| Kali Linux | Isolated pentest | None | 0 | 1 | Weak | Pentest · specialized |
Linux production profiles
🖱️ Each card below has three tabs — Overview · Tech specs · Verdict. Click a tab to reveal the detailed analysis.
Fedora Workstation is one of the strongest desktop bases by default: SELinux enforcing, firewalld active and Wayland. This is not a rolling release — a new major version is released about every six months, with about thirteen months of support per version.
Each version receives updates via the Bodhi system before being validated, ensuring some stability without the full freeze of an LTS.
- TypeSemi-annual point release (~13 months support per version)
- MACSELinux enforcing, deny-by-default
- Firewallfirewalld active by default
- Property & RightsClassic DAC, sudo/polkit, Wayland reduces some GUI vectors
- Kernel HardeningPrudent settings present
- UpdatesSemi-annual, ~13 months support
- App IsolationFlatpak + desktop sandbox
Very good modern Linux desktop for strong security without an immutable model. Short support cycle to monitor.
Silverblue takes Fedora Workstation's security with an immutable root (read-only), greatly reducing the persistence of a local compromise.
The most consistent choice for a hardened desktop when accepting the ostree/Flatpak workflow.
- TypeImmutable, transactional (ostree)
- MACSELinux enforcing
- Firewallfirewalld active
- Property & RightsRead-only system, simple rollback
- Kernel HardeningSame base as Fedora Workstation
- UpdatesAtomic, reversible (rollback)
- App IsolationFlatpak privileged — host/app separation
Excellent for developers or advanced users wanting a hardened and resilient desktop.
Tumbleweed combines SELinux enforcing, active firewalld and Btrfs/Snapper snapshots for easy rollback. Since snapshot 20250211, SELinux is active in enforcing mode by default.
Suitable for advanced users wanting fast fixes without losing structural guardrails. A true rolling release: no frozen version.
- TypeRolling release (true rolling, no frozen version)
- MACSELinux enforcing since snapshot 20250211
- Firewallfirewalld active
- Property & RightsBtrfs + Snapper, practical rollback
- Kernel HardeningPrudent settings, no major singularity
- UpdatesVery fast — regular monitoring required
- App IsolationGood, not central to design
Very good serious rolling release with above‑average structural guardrails.
Leap 16.0 aims for a more predictable posture while keeping strong security components from the openSUSE ecosystem. SELinux enforcing by default.
AppArmor is not available in the Agama installer for a fresh installation — only SELinux. Migrations from Leap 15.6 keep AppArmor by default.
- TypeStable / long cycle (support until 2031)
- MACSELinux enforcing (default on new install)
- AppArmorAbsent from Agama installer · manual activation post‑install
- Firewallfirewalld active
- Property & RightsBtrfs/Snapper, classic structure
- UpdatesMore predictable than rolling
- App IsolationGood, not immutable
Very consistent for modern infrastructure wanting robustness without rolling rhythm.
MicroOS pushes openSUSE's logic toward a transactional, low‑mutable base, greatly reducing system persistence.
It shines on edge, appliances and container hosts where minimal system surface is a goal.
- TypeImmutable, transactional
- MACSELinux enforcing
- Firewallfirewalld active
- Property & RightsTransactional read‑only system, rollback
- Kernel HardeningGood level, supported by transactional model
- UpdatesAtomic
- App IsolationVery favorable to containerized workloads
One of the most consistent models when reducing persistent surface is the goal.
Ubuntu LTS stands out for its long support and active AppArmor by default. Critical point: ufw is installed but NOT enabled by default. A freshly deployed Ubuntu server has no active network filtering without manual configuration.
Kernel hardening not very differentiating by default; security fixes are backported for 5 years (10 years with Ubuntu Pro ESM).
- TypeLTS — 5 years standard, 10 years with Ubuntu Pro ESM
- MACAppArmor active by default
- Firewallufw installed but INACTIVE — enable with
sudo ufw enable - Property & RightsClassic DAC, sudo, polkit
- Kernel HardeningNot a visible asset by default
- UpdatesLong support, systematic backporting
- App IsolationSnap confinement useful but partial
Pragmatic and reassuring base, must be complemented by enabling the firewall.
Rocky Linux 9 inherits a solid enterprise posture: SELinux enforcing, active firewalld, long cycle and DISA STIG compliance available.
A solid RHEL alternative for budget‑constrained critical infrastructures. Less desktop‑oriented.
- TypeStable, long cycle (10 years support)
- MACSELinux enforcing
- Firewallfirewalld active
- ComplianceDISA STIG available — used in government environments
- Kernel HardeningPrudent and consistent base
- UpdatesLong support and backporting
- App IsolationGood, less advanced than immutable systems
Very good server base for robust and predictable posture in Red Hat environments.
Debian Stable is impeccable on change management, but its native security is less prescriptive than Fedora or RHEL families. No firewall active by default.
AppArmor is partially present depending on installed profiles. Kernel hardening mostly left to the administrator.
- TypeStable, long cycle
- MACPartial AppArmor depending on profiles
- FirewallNo firewall enabled by default
- Property & RightsClassic Linux base, clean and controllable
- Kernel HardeningNot highlighted by default
- UpdatesFollowed but conservative (backporting)
- App IsolationNot highlighted by default
Excellent base to administer, but not the most demonstrative in native security without explicit hardening.
Arch Linux prioritizes freedom and total control. No MAC, no firewall, no kernel hardening by default.
Relevant for Linux experts wanting to configure everything manually. Unsuitable for production deployment without significant hardening work.
- TypeMinimalistic rolling release
- MACNone by default — AppArmor/SELinux must be installed manually
- FirewallNone active by default
- Property & RightsClassic Linux model, highly customizable
- Kernel HardeningAlmost entirely manual
- UpdatesVery fast (strict rolling)
- App IsolationTo be built according to needs
Very relevant for Linux experts, but a weak showcase of default security.
Qubes OS compartmentalizes usage into distinct VMs via Xen — a radically different model from classic Linux MAC. dom0 is completely offline. LUKS mandatory.
Isolation compensates some of the traditional sysctl criteria. Requires at least 16 GB RAM for comfortable use.
- TypeHighly compartmentalized desktop
- MACXen hypervisor isolation (dom0 offline)
- FirewallDomain segmentation — dom0 offline
- Property & RightsStrict separation between qubes
- EncryptionLUKS mandatory
- UpdatesVia templates (TemplateVMs)
- Minimum RAM16 GB for comfortable use
Top choice for high threat models. Not suitable for standard general‑purpose use.
NixOS stands out for its declarative structure and transactional generations. Neither SELinux nor AppArmor are fully supported or integrated by default. The unique /nix/store structure makes file labeling mechanisms difficult.
Kernel hardening can be declared, replayed and versioned with remarkable consistency — a strong differentiating asset.
- TypeDeclarative, close to immutable model
- MACNeither SELinux nor AppArmor integrated by default — experimental support only
- FirewallManageable declaratively via nftables
- Property & RightsVery strong structural control via configuration
- Kernel HardeningCan be declared and replayed reproducibly
- UpdatesTransactional, simple rollback
- App IsolationGood separation thanks to Nix model
Very relevant for experts wanting maximum configuration consistency. MAC considered absent by default.
Ubuntu Core pushes confinement and atomic updates through a system entirely built around snaps. AppArmor is applied to Snap confinement.
Minimal firewall depending on the image — must be explicitly validated. Kernel hardening level depends on image and device role.
- TypeImmutable, snaps only
- MACAppArmor applied to Snap confinement
- FirewallMinimal depending on image — check
- Property & RightsVery good structural separation
- Kernel HardeningIntermediate level, image‑dependent
- UpdatesAtomic
- App IsolationExcellent application‑side confinement
Good choice for appliance or edge, provided you validate the effective network policy.
Flatcar Linux is optimized as a minimal container host with little unnecessary surface and atomic updates. SELinux enforcing targeted at host/containers.
Kernel hardening very consistent for a minimal containerized host.
- TypeImmutable, container/Kubernetes oriented
- MACSELinux enforcing targeted at host/containers
- FirewallNetwork policies adapted to node role
- Property & RightsMinimal host, low‑mutable base
- Kernel HardeningVery consistent for minimal containerized host
- UpdatesAtomic, availability‑oriented
- App IsolationVery strong when workload containerized
Very good choice as Kubernetes host or secured edge. Not relevant for desktop use.
Kali Linux is designed for offensive auditing, not as a reference for native security. No active MAC, pre‑installed pentest services, high attack surface.
Reserved exclusively for a VM or isolated pentest‑dedicated environment.
- TypePentest distribution
- MACNo strong MAC by default
- FirewallAbsent / not a target by default
- Property & RightsClassic Linux base oriented toward lab
- Kernel HardeningNot an objective by default
- UpdatesGood cadence for pentest tooling
- App IsolationTo be provided via VM or dedicated lab
Reserved for a VM or isolated test environment. Never as a main system.
Experimental / targeted use distributions
| Distribution | Level | MAC | FW | Rights | Kernel | Type |
|---|---|---|---|---|---|---|
| Fedora Rawhide | Development | SELinux enforcing | 3 | 2 | Variable | Development branch |
| Debian Sid (Unstable) | Advanced use | Partial AppArmor | 0 | 1 | Weak | Rolling · unstable |
| Tails | Targeted use (anonymity) | Amnesic · forced Tor | 3 | 2 | Moderate | Live amnesic · Tor |
🖱️ Each card below has three tabs — Overview · Tech specs · Verdict. Click a tab to reveal the detailed analysis.
Fedora Rawhide is Fedora's active development branch, updated daily. It is used to prepare the next stable version. Packages can break without warning.
SELinux enforcing is present (same policy as Fedora), and firewalld is active — but the inherent instability of a development branch excludes it from any production use.
- TypeRolling development branch (daily)
- MACSELinux enforcing — same policy as Fedora
- Firewallfirewalld active
- StabilityNot guaranteed — packages can break at any time
- UpdatesDaily, not tested by Bodhi
- Recommended useTesting, development, QA — never in production
Useful for testing upcoming Fedora versions or contributing to QA. Never in production.
Debian Sid is the unstable branch of Debian — a true rolling release. Counter‑intuitively, security fixes often arrive with a longer delay than Debian Stable, because they first go through unstable before being backported to stable.
No firewall by default (like Debian Stable). Partial AppArmor. The Debian security team does not provide official support for Sid.
- TypeRolling release (unstable branch)
- MACPartial AppArmor depending on profiles
- FirewallNone active by default
- Security supportNot officially covered by the Debian security team
- UpdatesFast for new features, less for targeted fixes
- Recommended useDebian development, packaging, testing — not in production
Useful for Debian developers and packagers. Security is objectively less guaranteed than Debian Stable.
Tails is an amnesic Live OS: all traffic goes through Tor, and RAM is erased at shutdown. The host machine is considered potentially compromised.
Designed for specific profiles (journalists, whistleblowers, lawyers, activists) requiring anonymity and anti‑forensics. Not a daily OS.
- TypeLive USB amnesic (RAM only by default)
- MACNo classic Linux MAC — security through isolation and amnesia
- NetworkAll traffic via Tor — mandatory and non‑bypassable
- PersistenceOptional encrypted persistent volume (LUKS)
- Forensic resistanceRAM erased at shutdown
- UpdatesRegular — critical to apply
- Recommended useJournalists, whistleblowers, lawyers, activists — targeted use only
The undisputed reference for anonymity and anti‑forensics. Unsuitable as a main OS or server.
Other OS: Windows, macOS, BSD
| OS | Level | Access Control (MAC equiv.) | Firewall | Encryption | System Hardening | Source |
|---|---|---|---|---|---|---|
| Windows 11 24H2 | Medium-High | MIC active · WDAC optional | Active by default | BitLocker (clean install + MS Account) | HVCI / VBS (hardware-dependent) | Closed (Microsoft) |
| macOS 15 Sequoia | High | SIP + Gatekeeper + App Sandbox | Disabled by default | FileVault (optional) | KASLR · Secure Enclave · KPP | Closed (Apple) |
| FreeBSD 14 | High | Jails · MAC framework optional | Absent by default | FDE optional (geli/ZFS) | sysctl + ASLR + optional W^X | Open (BSD License) |
| OpenBSD 7.8 | Security reference | pledge + unveil (native) | pf active by default | FDE optional (since 7.3) | W^X · ASLR · RETGUARD · SSP | Open (BSD License) |
Section III Analysis
• BitLocker automatically enabled on a clean install with a Microsoft account on TPM 2.0 hardware.
• Weak point: opaque source code, telemetry difficult to fully disable.
• WDAC (MAC equivalent) exists but its default configuration is less restrictive than SELinux in enforcing mode.
• Gatekeeper controls unsigned binaries.
• TCC manages access permissions to sensitive resources.
• Notable weakness: application firewall disabled by default (bugs in macOS 15.0, fixed in 15.1).
• FileVault is optional, not enforced during installation.
• Closed source → independent audit impossible.
• pledge(2) and unveil(2) reduce exploitation surface even after compromise.
• pf active by default.
• RETGUARD protects return addresses.
• Kernel relinked at each boot.
• Exceptional record: only two remote holes in over 25 years.
• Open source, fully auditable.
• pf (inherited from OpenBSD) is available but not enabled by default.
• Integrated ZFS provides encryption and data integrity.
• CVE-2025-15576 (Feb 2026): flaw in jail subsystem allowing processes from distinct jails to bypass restrictions via nullfs — fixed in FreeBSD 14.3 and 13.5.
• Default security lower than OpenBSD, but FreeBSD excels as server or network appliance with explicit configuration.
🖱️ Each card below has three tabs — Overview · Tech specs · Verdict. Click a tab to reveal the detailed analysis.
Windows 11 24H2 marks a significant improvement: BitLocker is automatically enabled on a clean install with a Microsoft account, on any TPM 2.0 hardware. Windows Defender Firewall is active by default with a restrictive inbound policy.
Important limitations: WDAC is not enabled by default for general public users (complex to deploy). MIC (Mandatory Integrity Control) is always active. Telemetry and attack surface remain high. Source code is not auditable.
- TypePoint release (annual update + monthly Patch Tuesday)
- MAC equiv.MIC always active · WDAC available but not enabled by default
- FirewallWindows Defender Firewall active by default
- EncryptionBitLocker automatic on clean install + MS account (24H2)
- HardeningHVCI, VBS, Secure Boot — hardware‑dependent
- UpdatesPatch Tuesday + hotpatching (24H2+)
- TelemetryHigh by default — must be reduced manually
- SourceClosed — not independently auditable
Real progress with 24H2. Attack surface and telemetry remain structural weak points.
macOS 15 offers a generally solid default security posture: SIP (System Integrity Protection) active and hard to disable on Apple Silicon, Gatekeeper for application verification, and an excellent App Sandbox for Mac App Store applications.
Notable weakness: the application firewall is disabled by default. macOS 15.0 also had significant firewall bugs fixed in 15.1. FileVault (disk encryption) is optional.
- TypeAnnual point release (Rapid Security Response between versions)
- MAC equiv.SIP protects system files · Gatekeeper verifies apps · App Sandbox
- FirewallApplication firewall DISABLED by default — known bugs in macOS 15.0
- EncryptionFileVault optional (offered but not forced)
- HardeningKASLR, KPP, Secure Enclave (Apple Silicon), Pointer Auth
- UpdatesRapid Security Response — targeted fixes without major release
- SourceClosed — XNU kernel partially open source
- TelemetryModerate
Good default posture on Apple Silicon, but the firewall disabled by default remains surprising for an OS of this category.
FreeBSD 14 offers very robust isolation mechanisms via Jails — the equivalent of kernel containers with strong isolation, predating Docker by decades. pf (the firewall inherited from OpenBSD) is available but not enabled by default.
CVE-2025-15576 (Feb 2026): a flaw in the jail subsystem allowed processes from distinct jails to bypass chroot restrictions via nullfs — fixed in FreeBSD 14.3 and 13.5.
- TypeStable, long cycle (quarterly releases)
- MAC equiv.Jails (excellent) · MAC framework available but not active by default
- Firewallpf/ipfw available but not active by default
- Encryptiongeli (FDE) or native ZFS encryption
- RightsClassic Unix model + Jails capabilities
- Kernel hardeningPrudent sysctl options, ASLR available
- SourceOpen (BSD License) — auditable
- Updatesfreebsd-update + portsnap
Excellent for servers and appliances with manual hardening. Default security remains lower than OpenBSD.
OpenBSD is universally recognized as the most secure system by default. Its unique pledge + unveil mechanism restricts system calls and file access of each process — integrated directly into the kernel and used by all base programs.
pf is active by default. W^X (Write XOR Execute) is applied systemically. RETGUARD protects return addresses. Disk encryption is guided since 7.3. Exceptional record: only two remote holes in over two decades.
- TypeStable, bi‑annual release (6‑month cycle)
- MAC equiv.pledge(2) + unveil(2) — restrict syscalls and filesystem access per process
- Firewallpf active by default — the best available firewall
- EncryptionGuided FDE since OpenBSD 7.3 (LUKS equivalent) · encrypted swap by default
- RightsSystemic W^X · doas (safer than sudo) · privilege separation everywhere
- HardeningASLR, RETGUARD, SSP, kernel relinking at each boot, ProPolice GCC
- Updatessyspatch for binary fixes · support for last 2 releases
- SourceOpen · regular audits by the OpenBSD team
The absolute reference for default security. Less suitable for general‑public desktop or environments requiring wide software compatibility.
Conclusion — Which OS for your profile?
Sources — Official sites of the systems presented
| Distribution / OS | Official site |
|---|---|
| Fedora Workstation | fedoraproject.org/workstation |
| Fedora Silverblue | fedoraproject.org/atomic-desktops/silverblue |
| openSUSE Tumbleweed | get.opensuse.org/tumbleweed |
| openSUSE Leap 16.0 | get.opensuse.org/leap |
| openSUSE MicroOS | get.opensuse.org/microos |
| Ubuntu LTS | ubuntu.com |
| Rocky Linux 9 | rockylinux.org |
| Debian Stable | debian.org |
| Arch Linux | archlinux.org |
| Qubes OS | qubes-os.org |
| NixOS | nixos.org |
| Ubuntu Core | ubuntu.com/core |
| Flatcar Linux | flatcar.org |
| Kali Linux | kali.org |
| Fedora Rawhide | fedoraproject.org/wiki/Releases/Rawhide |
| Debian Sid (Unstable) | debian.org/releases/sid |
| Tails | tails.net |
| Windows 11 24H2 | learn.microsoft.com/windows |
| macOS 15 Sequoia | apple.com/macos |
| FreeBSD 14 | freebsd.org |
| OpenBSD 7.8 | openbsd.org |
Recommended reading — SafeITExperts
Share your experience
What is your Lynis score before/after applying these checks? Share it in the comments or on social networks with #SafeITExperts.
👥 Comments
Comment on this article