CESG, the UK government's arm that assesses operating systems and software security, has published its findings for ‘End User Device’ operating systems. The most secure of the lot? Ubuntu 12.04. For the full article see here

Dani AI

Generated

Short summary and context: as highlighted, the UK government’s CESG compared a small set of end‑user platforms in late 2013 and the public summary noted Ubuntu 12.04 LTS scored best of the platforms they examined. The vendor write‑up and the original CESG platform guidance make that clear. Canonical summary and the official Ubuntu guidance page show the assessment approach and findings. (See CESG’s Ubuntu platform page.)
(https://www.gov.uk/government/publications/end-user-devices-security-guidance-ubuntu-1204/end-user-devices-security-guidance-ubuntu-1204)

Important nuance (why ’s caveat matters): CESG’s work was a snapshot against a 12‑point security framework aimed at the UK “OFFICIAL” classification, not an exhaustive survey of every Linux distribution. The guidance deliberately targeted specific platform releases and does not mean every Linux distro—or every later Ubuntu release—would score the same. CESG explicitly warned it would not update guidance for every new vendor release. CESG introduction and principles pages explain that scope and lifecycle.

What the report actually showed and practical takeaways: CESG assessed platforms on items like VPN, disk‑encryption, authentication and secure boot. The Ubuntu 12.04 page lists the areas CESG flagged as “Significant Risks” (for example, LUKS/dm‑crypt not independently assured, Secure Boot not fully chained, and keys not protected in dedicated hardware) and also recommends mitigations (StrongSwan, LUKS, AppArmor, central configuration via Landscape). That page is the primary source for those specifics. (https://www.gov.uk/government/publications/end-user-devices-security-guidance-ubuntu-1204/end-user-devices-security-guidance-ubuntu-1204)

Bottom line: use the CESG documents as a useful historic, requirements‑driven checklist, but don’t treat the 2013/2014 snapshot as definitive today. For current deployments pick actively supported releases, require hardware‑backed key protection (TPM), an assured VPN, centralized patch/MDM/remote‑wipe controls and up‑to‑date vendor security guidance—then validate against a current threat model rather than relying solely on the older CESG snapshot.

Thank you for the information it was interesting reading. It is nice to have someone validate what has been said by those of us who have been promoting the security of Linux based systems for years (and I include you in that number Jim).

You might note that although they evaulated at two versions of The Andriod OS, two blackberry, two Apple OS and three Windows based the only version of Linux they reviewed was Ubuntu. It is possible that this is the only linux distro besides Fedora, that specifically has a version to run on mobile devices. And that Fedora 20 was just recently released probably too late to be considered.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.