openSUSE Leap Adds a New Security Layer Immutable Mode
openSUSE Leap Adds a New Security Layer: Immutable Mode
Starting with version 16.1, openSUSE Leap is adding another layer to its security that should further elevate it as one of the more secure distributions on the market. That layer is immutable mode. According to the official openSUSE blog, “Leap 16.1 is the first Leap release to offer an Immutable Mode, a transactionally updated system with a read-only root filesystem. This is essentially what our users know from Leap Micro, just integrated directly into Leap.”
The blog also mentions that Leap Immutable “is the way forward for container and virtual machine hosts, edge devices, and anyone who prefers atomic updates with easy rollback.” After a bit of digging, it became clear that Leap Immutable will be a fully immutable distribution. Immutable mode is a feature you can toggle during the installation, which means you can choose which version of openSUSE Leap to use: standard or immutable. If you go with immutable, the root filesystem is mounted as read-only. Essentially, when an OS is immutable, those directories (such as /usr and /etc) are mounted as read-only and cannot be altered. If you were to accidentally run a malicious script on an immutable system, it would be unable to alter anything in those immutable directories. That’s a serious security improvement and is also the future of Linux. 🚀
openSUSE Leap doesn’t just benefit from the added security of immutability, as it already includes plenty of security-focused features. openSUSE was already a highly secure Linux distribution, thanks to several layers of security. Starting with version 16.0, openSUSE made the switch to SELinux (Security-Enhanced Linux), which was created by the NSA to further secure Linux systems. SELinux labels every file, process, and port on a system, follows the rule of least privilege to block actions that are not allowed by specific rules, and even requires the root user to follow those rules. Additionally, openSUSE makes use of firewalld as its dynamic firewall management system. openSUSE also includes binary hardening, which is the collection of default security flags and compiler options used during software compilation to make executable files and libraries more resilient to exploits such as buffer overflows and memory corruption. Key hardening measures include:
- Position-independent executables (allow binaries to use random memory addresses to make it harder for hackers to predict target locations when using memory-based exploits)
- FORTIFY_SOURCE (keeps track of functions that deal with memory strings to prevent buffer overflows)
- Stack protector (injects canary values into the stack to detect and halt stack overflow attempts)
- Non-executable stack and heap (prevents code execution from specific data regions such as the stack or the heap to prevent arbitrary shellcode injection attacks)
Further bolstering security, Btrfs snapshots are “moment-in-time” save points of a file system subvolume, and Snapper is the SUSE tool used to automatically manage those snapshots. With snapshots, it is possible to easily roll back a system to a working point, so if something were to go wrong with a system, it could be restored from a previously working snapshot. If your system is hacked, you could effectively roll it back to a point in time prior to the hack and then take action to prevent the hack from happening again. Moreover, openSUSE is built directly from the source code from SUSE Enterprise Linux, which ensures enterprise-grade stability and security. When you combine immutability with the standard openSUSE security features, it’s pretty easy to conclude that the distribution will be highly secure. Immutable distributions are already touted as some of the most secure operating systems on the market, and with openSUSE adding an immutable mode to Leap, you can be sure that it will leap ahead of the pack with regard to security.
An ISO of Leap 16.1, which includes immutable mode, is available from the official openSUSE download server.