SECURITY Signal 335
Show HN: Bor – Open-source policy management for Linux desktops
For teams managing Linux desktop fleets, Bor now covers more of the policy surface—email clients, an enterprise browser, and host firewalls—reducing the number of separate configuration tools needed. The security hardening and per-action RBAC make it more viable for production deployments where auditability and least-privilege admin access matter.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Three new policy types extend coverage to Thunderbird, Microsoft Edge for Business, and Firewalld zones, with tamper protection on managed configuration files.
Per-action RBAC replaces the single blanket admin permission, enabling finer-grained delegation of administrative duties.
A security hardening pass binds agent identity strictly to mTLS client certificates, migrates TOTP secrets to HKDF-derived encryption, and stops writing the initial admin password to server logs.
THE CLUSTER
↗