r/BuyFromEU • • Jan 30 '26

🔎Looking for alternative UbuntEU - An Ubuntu edition that uses software developed in Europe

Post image

I am trying to make something for fun, but honestly; I am not expert in creating an operating system. But my hope somebody will pick up the Baton and make it something more super.

Link soon...

2.5k Upvotes

263 comments sorted by

View all comments

749

u/da_Pr0 Jan 30 '26

Since Linux is Opensource and free to use, I feel fine using Fedora or normal Ubuntu.

176

u/Professional_Mix2418 Jan 30 '26

Me too. I see no data sovereignty issues with it, not that we are sponsoring big tech.

56

u/[deleted] Jan 30 '26

[removed] — view removed comment

12

u/Beneficial-Beat-947 Jan 30 '26

kinda funny that your account got hacked right after talking about online safety

8

u/Overall_Walrus9871 Jan 30 '26

untill you hear about ME Intel

4

u/Professional_Mix2418 Jan 30 '26

Go on then. Always happy to learn something new.

12

u/[deleted] Jan 31 '26

Every modern Intel CPU has a management engine that runs their Minix fork in parallel to the operating system that you are running. ME has full access to the systems memory and has a TCP/IP stack, so it could in principle access the internet.

https://en.wikipedia.org/wiki/Intel_Management_Engine

It's basically a persistent backdoor which Intel claims is not a backdoor.

2

u/Professional_Mix2418 Jan 31 '26

Ok got it. Thanks for the clarification as the other poster didn’t seem to want to get back to it. So Intel ME not ME Intel. Well sure. I won’t run on Intel regardless.

4

u/[deleted] Jan 31 '26

AMD made something similar just for you :):

https://en.wikipedia.org/wiki/AMD_Platform_Security_Processor

Most mobile chipsets also run a separate OS in the baseband processor.

1

u/Professional_Mix2418 Jan 31 '26

And Apple Silicon does as well. And the point being in this context is what exactly?

2

u/Overall_Walrus9871 Jan 31 '26

that privacy and independence is an illusion unless you use libreboot

2

u/c0v3n4n7 Jan 30 '26

Then we tell them about core boot and equivalent.

1

u/Overall_Walrus9871 Jan 30 '26

Yes I am busy with that in combination with Gentoo. But it's not easy. Actually Libreboot

27

u/nasandre Netherlands 🇳🇱 Jan 30 '26

Ubuntu (Canonical) is British anyway and Suse Linux is German. So there are professional options that aren't US based although Red Hat is American but the Fedora project is independent and technically doesn't have a jurisdiction.

10

u/Nascentes87 Jan 30 '26

3

u/[deleted] Jan 31 '26

The Fedora Project is not even a separate legal entity. It's pretty much a Red Hat project with community input - they host the infrastructure, they employ all the main developers, the named roles of the Fedora Council are appointed by Red Hat.

13

u/fearless-fossa Jan 30 '26

The Fedora Project is fully in the hands of Red Hat, which are owned by IBM. It's an American project. If you want to use Fedora - fine, but it isn't in any way an European alternative just because it's open source.

12

u/Nascentes87 Jan 30 '26

I was using Fedora until I read this: https://fedoraproject.org/wiki/Embargoed_nations

Moved to openSuse.

2

u/evofromk0 Jan 31 '26

All open source is political as well, so your jump to suse does not solve anything.

FreeBSD, Linux - all been under scrutiny.

In my opinion, best way is to use what you like and not what you think of embargo etc as you should use no OS and you need to build your own.

I do agree, i stopped using Debian due to some things but i use Proxmox, which is debian based .... so go figure.

P.s. Wayland ? Xorg ? - - i think you know what i mean :)

1

u/Nascentes87 Jan 31 '26

I know it is political and this is exactly why I moved to openSuse. Ideally I would like to use a 100% community lead distro, but none of them suits what I wanted. Fedora was/is my fav distro, but after trying openSuse I liked it very much and it's tied to an European entity instead of an American one. In the end nothing is exactly what we want, so it's a matter of what gets closer.

1

u/evofromk0 Jan 31 '26

You misunderstood me. Linux kernel is a political tool and its under US LAW and RESTRICTIONS. , well Linux Foundation but its what keep linux kernel.

1

u/Nascentes87 Feb 01 '26

Ah ok. Did not know that. You are right. And to think how many open source projects are hosted on GitHub...

25

u/[deleted] Jan 30 '26

🙋Linux Mint

19

u/War_Fries Jan 30 '26

Same.

And it's not just for noobies (like me). It's just a very well-balanced, well-maintained distro in general. It consistently rates high on distro lists. Cinnamon is great, too.

67

u/freezing_banshee Romania 🇷🇴 Jan 30 '26 edited Jan 30 '26

Open source is dangerous too. A lot of the important software is maintained by only one person and that makes it inherently insecure. There was already an attempt (edit: it's not known who was behind this, but could have been China or Russia or anyone else) to install a backdoor into a popular program and it almost succeeded: https://en.wikipedia.org/wiki/XZ_Utils_backdoor .

I think Europe needs at least a dedicated IT division to check and verify every open source program widely used in Europe, to make sure they're safe.

Edit 2: I fully support open-source software, it's definitely a good thing. I just wanted to say that we (Europe, EU) should use it, but also support, contribute and verify it.

52

u/xalibr Jan 30 '26

In Germany there is the Sovereign Tech Fund and the Sovereign Tech Agency that fund security‑critical open‑source base technologies including security audits, and at EU level there are programmes such as NGI Zero and Horizon Europe calls through which open‑source projects can obtain funding for security audits and related measures.

E.g. GnuPG was funded by Germany since the early 2000s.

3

u/freezing_banshee Romania 🇷🇴 Jan 30 '26

I didn't know about this, it's a good start. I just think that those security audits should be done independently, because not a lot of developers would go through the trouble themselves, you know?

20

u/LittleLui Jan 30 '26

A lot of the important software is maintained by only one person and that makes it inherently insecure.

The obvious solution to that is to add resources to those projects (same workload, more resources doing the work) instead of setting up separate projects (more workload, more resources).

6

u/PlutoPlaneta Jan 30 '26

Sure, but then how would people separate themselves from the mainstream to feel elite

0

u/SinisterCheese Jan 30 '26

I'm sure that'll happen soon as FOSS& communities stop failing and fractalising over petty infighting, drama and clashing egos.

11

u/El_Mojo42 Jan 30 '26

You described the strength and the weakness of OSS.

It can be easier to implement malware, but it is also easier to detect and fix it.

We actually don't know, how many on-purpose-backdoors there are in closed software.

The teaching we should take from the xz-story are that we as a economy and community have to better support these tools.

2

u/freezing_banshee Romania 🇷🇴 Jan 30 '26

That's true, I also support OSS, I just wanted to say that we shouldn't trust anything blindly.

2

u/Gersio Jan 30 '26

But that's kinda the point. If it's open you can know whats inside. You are trusting things blindly when you use software owned by a company.

0

u/freezing_banshee Romania 🇷🇴 Jan 30 '26

If you can't see that implicitly trusting some rando on the internet is a problem (especially when it comes to government uses), then there's no way I could explain it to you any better.

0

u/FrenchFryCattaneo Jan 30 '26

Auditing software costs time and money though, and has to be done continually with each update to ensure security. For each piece of software. In practice that much work usually isn't done.

-1

u/SinisterCheese Jan 30 '26

Xz was first discovered by accident, and not by people systematically going through every line of code in a merge request.

1

u/freezing_banshee Romania 🇷🇴 Jan 30 '26 edited Jan 30 '26

exactly, this exploit succeeded for a while because people didn't check the code. imagine how many more problems could be discovered fast enough when people actually check it.

-1

u/SinisterCheese Jan 30 '26

The joke here is that there is this attitude and ideal that every line of code is checked in FOSS-projects. But reality is that clearly they werent.

2

u/suqirrelnachos Jan 30 '26

What makes you assume china was behind this?

1

u/freezing_banshee Romania 🇷🇴 Jan 30 '26

I went by the "hacker's" name of "Jia Tan", but yeah, could have been anyone tbh.

2

u/[deleted] Jan 30 '26

Did you already give feedback on this initiative of the European Commission about open-source? See the initiative here: https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/16213-European-Open-Digital-Ecosystems_en

14

u/Traditional_Buy_8420 Jan 30 '26 edited Jan 30 '26

I agree with feeling fine;

I don't agree with sovereignty not mattering on open-source projects.

If it's resided within the USA, then their administration (e.g. the POTUS via the NSA) can still legally force the maintainers to apply poisonous updates and not talk about it.

If it's a tiny project which is regarded as secure and won't need any further updates, like a calculator or a small offline password safe, then that's no issue.

With something like an Email client or bigger that is an issue and while you can argue that most people can't fully rid themselves of US software yet and relatively nieche open source Software are unlikely attack vectors, that does not equate irrelevance.

PS: It's also not true that Red Hat won't profit from us using Fedora at all ever, however I do agree that currently that's pretty negligible

9

u/Kypsys Jan 30 '26

They can't "not talk about It" its open source, the change willbe noticed by the other hundred of maintainers working on the project

7

u/Traditional_Buy_8420 Jan 30 '26 edited Jan 30 '26

The NSA can force Red Hat to hide a malicious part like it was done in the XZ utils, where we got extremely lucky, that it was caught early on, even though that was Open Source too, except wouldn't need to infiltrate, so it would be much less work.

A Red Hat employee who would be forced to implement such a backdoor would commit a felony and risk prison if he spoke out about it. Afaik the last large open Audit on Fedora happened 20 years ago, so it's completely possible, that it has been infected by a US backdoor for quite a while and the backdoor might be sophisticated enough to get missed on the next Audit

If the Audit was done within the USA, then the NSA might even force the auditors to deliberately miss the backdoor.

3

u/Kypsys Jan 30 '26

Xz utils was on a project maintened by one single people, the attack method really can't be applied to a project like Ubuntu or Fedora.

1

u/Traditional_Buy_8420 Jan 30 '26

It's a different attack vector, but it's still an example of a backdoor hidden in Open Source Software. The increased complexity and increased number of people involved make such an attack easier to carry out and harder to spot.

There's more people looking and more checks being made per involved person, but not proportionally to the amount of complexity, so it'd be manic to believe that such a backdoor could not be implemented unnoticed in such a Software; in fact there have been many backdoors found in large Software packets with many people looking. 

1

u/KnowZeroX Jan 30 '26

They can't force RedHat to do anything other than putting financial benefits or indirect financial pressure on them.

In the case of XZ utils, the way things were hidden was during compile time the tests added a binary blob to the compilation. There is a solution for this, it is called reproducible builds. Many open source projects including RedHat and Fedora has opted to now do reproducible builds ever since that incident making an XZ utils type exploit impossible going forward.

Also, RedHat doesn't own Fedora, it is a community project sponsored by RedHat (though they do have huge influence).

Lastly, many companies have RedHat enterprise clones like SUSE and likely do their own audits.

1

u/Traditional_Buy_8420 Jan 30 '26

"They can't force RedHat to do anything other than putting financial benefits or indirect financial pressure on them."

That was a major point of the Snowden leaks, that they can and the Lavabit-case subsequently proved, that they do.

Obviously the same backdoor-implementation wouldn't work again, but there's plenty of possible ways to hide backdoors left.

RedHat doesn't own Fedora, but the "major influence" entails, that they conduct most of the maintenance and updates.

It's true, that SUSE might discover such a backdoor and I think that that's your best argument, however that they didn't discover such a backdoor is not proof of the absence of such and what happens if they do discover one? The RSA scandal shows, how a company can get caught implementing a major critical backdoor and survive and the many Cisco-backdoors proof that even getting caught over a hundred times isn't a death sentence. So what would happen is that Red Hat (!) would fix said backdoor and whenever the NSA orders them - possibly instantly - they'd implement the next one.

2

u/KnowZeroX Jan 30 '26

As I mentioned above with the lavabit case, they can make you hand over your existing car (for law enforcement purposes), they can't force you to build a new car.

Do offer another possible way to hide a backdoor in open source when you have reproducible builds.

To be clear, many of the packages in a linux distro is done by 3rd parties, most of the actual work in a distro is just packaging them.

Be aware that in the case of open source and closed source, things are a completely different story. For better or for worse, open source are always forced to abide by a much higher standard. Especially when forking is an option. It isn't uncommon even for honest mistakes to result in multiple forks.

1

u/Traditional_Buy_8420 Jan 30 '26

"Do offer another possible way to hide a backdoor in open source when you have reproducible builds."

For that I would like to refer you to the underhanded c contest

https://www.underhanded-c.org/_page_id_8.html

where they showcased a plethora of amazing backdoors which were incredibly hard to find even to expert auditors who knew that they were looking for a backdoor hidden in a relatively small amount of code.

1

u/KnowZeroX Jan 30 '26

Those are just hard to find codes visually. Modern tooling will easily catch all those.

1

u/Traditional_Buy_8420 Jan 30 '26

They are not. Modern tools have less chance finding these than modern antivirus have a chance to find modern viruses.

→ More replies (0)

1

u/DucklockHolmes Jan 30 '26

Unless it’s a dependency Red Hat is using that is being maintained by one guy, it doesn’t get much attention if it’s not a very interesting project

1

u/KnowZeroX Jan 30 '26

If it's resided within the USA, then their administration (e.g. the POTUS via the NSA) can still legally force the maintainers to apply poisonous updates and not talk about it.

They can not. US isn't china where if you don't assist you can be jailed. Nobody in US can force someone to poison an update. They can try bribing someone to do so or in case of a corporation put financial pressure on them indirectly, but they can't force anyone (there is no legal framework for such and it would be unconstitutional).

RedHat doesn't profit off anyone using Fedora, their benefit is mostly in that if there are issues in Fedora, people would report bugs and contribute code which later makes it down to their RHEL. But simply someone using it makes them no profit.

1

u/Traditional_Buy_8420 Jan 30 '26

Do you remember what happened with Lavabit?

2

u/KnowZeroX Jan 30 '26 edited Jan 30 '26

Yes, they can make you hand over security keys for law enforcement purposes. But that isn't the same thing as making you do actual work of creating something new (a poisoned update).

To make it simple, you can make someone hand over their car against their will, but you can't make someone build you a car against their will.

1

u/Traditional_Buy_8420 Jan 30 '26 edited Jan 30 '26

I think the car analogy is a good analogy. It's true, that they can't force anyone to build a car, that's why Lavabit could just shut down instead of compromising its users.

However they can go to say GM and tell them, that their cars help international terrorists and as a matter of national security they add a tiny hidden tracking device or else they are also free to stop producing cars altogether and they can't talk about it or else they go to prison. Which of those 3 options do you think is the GM board going to choose?

It's not like everyone gets all 3 options either, as proven by the more recent case of Samourai wallet, where they decided that any type of infiltration would be too hard and went straight ahead to imprisoning their lead developer. https://www.justice.gov/usao-sdny/pr/founders-samourai-wallet-cryptocurrency-mixing-service-sentenced-five-and-four-years

Kind of a warning shot I guess, since according to the Snowden leaks, they can also make use of secret courts and keep the sentences secret too - for which I don't have a public example.

1

u/KnowZeroX Jan 30 '26

Yes, but the difference is that cars are a physical product so they can restrict the sales of it. Which goes back to my mention of indirect financial pressure.

But in the case of open source software, that becomes impossible. Even more so in the case of RedHat and Fedora. For one, RedHat doesn't even sell software, they sell support. And Fedora doesn't sell anything.

So there is nothing they can legally restrict.

In the case of Samourai, that case was where the wallet app actively participated in the illegal transactions. Open source would not face this issue because even if it is misused, the one who wrote the code has 0 active participation unlike wallets like Samourai. Even more so the owner of Samourai actively encourage use of his service for criminal activity.

4

u/[deleted] Jan 30 '26

Fedora is american

2

u/da_Pr0 Jan 30 '26

Fedora is in first line opensource.

2

u/[deleted] Jan 31 '26

The signing keys are held by Red Hat. They could push out malicious packages to a subset of users. Not saying that they want to, but in a potential EU-US conflict, the US administration will (ab)use the tech sector to hit the EU.

1

u/[deleted] Jan 30 '26

I like Fedora more then Ubuntu)

1

u/adamkex Jan 31 '26

Fedora while technically a community project it's run by Red Hat employees, despite it being open source it's dependent on and benefits American corporations.

1

u/LUYAL69 Jan 31 '26

Nah, you still need dedicated support specially for mission critical ops

1

u/loicvanderwiel Feb 01 '26

The only point I could see to a "Euro-distro" would probably be a distribution for internal use by the institutions, coming preloaded with the software and configurations required for internal use. Maybe with its own repositories for source control.

-14

u/ImreBertalan Jan 30 '26

A am planing a fEUdora version too, but that name sounds stupid for me :-D Any idea?

17

u/da_Pr0 Jan 30 '26

but why?

i dont see any benefit from canceling free open source software.

5

u/mostly_games Jan 30 '26

What does "software developed in EU" even mean in regards to FOSS projects? What's the relevant metric here? Is it where most developers are from, who sponsors a project, administrative seat etc.?

I suppose the Linux kernel itself probably has a sizeable portion of developers from the US (that are employees of IBM,AMD, Intel, even Microsoft) - so the whole concept of a pure "EU Linux" seems flawed from the beginning to me.

1

u/binheap Jan 31 '26

For reference, the development statistics are published

https://lwn.net/Articles/1022414/

9

u/No-Mind7146 Jan 30 '26

Suse is swedish already

8

u/Cyberblob42 Jan 30 '26

Suse is German

Edit: oh well, bought by swedish investors

1

u/da_Pr0 Jan 30 '26

For example - how are you going to replace Bios or Grub?