I need a distro that is stable with a particular need to set up zero input automatic updates. If an update asks for a password or needs user interaction in basically any way it simply won’t get done. All he needs is a reliable platform for browsing the web. I am replacing an Ubuntu system that has apparently just stopped working (I have not had a chance to examine it yet) after years and years of not getting proper updates after he forgot his password.
Something like Bazzite is intriguing because of it’s locked down environment although he is very much not a gamer. Is there something locked down like Bazzite but with long term LTS release cycle?
you’re on the right track, i think, but not bazzite–that carries a lot of extra stuff that isn’t necessary here. just ordinary fedora silverblue. clean up the app grid or put dash-to-dock on it and put the few launchers they need down on that. gnome is actually a good desktop for basic users that just need to run one or a few applications. updates are somewhat frequent but should be almost entirely automatic.
i have a few users like your parents on endless os, which is similar to silverblue, just based on an in-house immutable debian instead of silverblue’s fedora base. i rarely ever hear from them, it ‘just works’. i also have it at home, it’s currently my only linux desktop there (i do most my ‘work’ at the office, home is just doom-scrolling and media for the most part these days). updates are less frequent but endless is switching to a gnome os base with the next major version. that will probably increase the frequency of updates a bit compared to their older debian base. that upgrade to v7 should be mostly invisible to the user, they’ve done a good job in the past with upgrades.
Define what you mean by “locked down”. If you don’t give your user superuser privileges, every distro is locked down because the user can only ever write to their own /home
I’d strongly recommend Mint:
- with Cinnamon DE: very Windows-esque UI
- Ubuntu / Debian-based, i.e. rock-solid, unlikely to break
- 100% automated updates (including automatic removal of old kernels so your /boot won’t get clogged
- Timeshift system snapshots in case something does break. (Note: I’ve only ever used Timeshift to un-fuck systems that I, personally, had fucked with superuser rights and manual meddling.)
+1, my parents are using Mint and they are only browsing the web. They have not complained anything after almost a year. In my case, I didn’t dare to set up automatic updates so I’m updating the computer when I visit them.
Same here, parents. Feel free to turn on automatic updates. It’s never broken anything, and vulnerabilities do need patching.
Seconded. Absolutely what I’d install in this kind of situation. I have an old machine set up for my wife with Mint. She only uses it to check her bank account, basically. So far zero issues.
I can also recommend Linux Mint. It’s a great general purpose option for both beginners and experienced users.
I’m a mint hater but mint is the choice here. You’ll need to monitor the transition from x11 to wayland but other than that it should be fine.
Debian and install the “unattended-upgrades” package.
You set it up with an email address to complain to when something fucks up and it just works.
E: no matter what you end up going with, some kind of reverse proxy or vpn will be helpful for when you need to remote in and fix something.
If you end up needing Remote Desktop and can do it, stay away from Wayland. The screen sharing situation there is confusing and annoying for seasoned users, let alone in a tech support situation.
What might be a better bet is either a windows (robust screen sharing setup) or mac (simpler interface and reliability) computer. You’re gonna be on the other end of it, so make sure to pick what you know the most deeply when it comes to remote support.
E2: another note in the vein of hated non linux oses: Those might be good because other people in the users life may be familiar with them and it won’t be such a pain when they wanna open a file or something.
I currently have an older relative using Debian/KDE with unattended-updates and few issues over the past year. Laptop was previously Windows 10, has had replacement battery and HDD->SSD swap, wouldn’t be supported by Windows 11, but is totally capable of running most modern apps.
Browsers can just be flatpak/snap/ppa and auto-update whenever, as Debian’s packaged (ESR) versions might get a bit dated.
From my own experiences with Ubuntu variants, I’ve always had some kind of issue when doing a release update, so I’ve personally stopped using it, but maybe thats just me.
Only significant issues I’ve encountered are with some flatpaks needing permission tweaks to (re-)enable printing, webcam, or filesystem access, and potentially over-doing the ad-block extensions/settings leading some sites to break - its worth setting up multiple browsers to pre-empt and work around those problems.
For remote access, it’s not a problem in my case, but you could potentially just setup a VPN with something like tailscale and just ssh over that. Once connected, I’d explore systems like VNC or KDE’s built-in remote access system. In the short/medium term, it would be easier to stick with X11 for that, but at some point, Wayland and those supporting tools are going to reach parity and distributions/desktop environments will drop X11 entirely - best to future-proof as much as you can.
For regular maintenance, it’s worth checking-in regularly to make sure the system and user is happy, and maybe setting a cron-job for house-keeping tasks (removing old kernel files and temp files, checking disk-usage/health), and having that notify you. But that probably depends how physically hands-on you’ll be.
It’s worth to consider that since they already used ubuntu, they might be already familiar with the gui and may feel lost if it changes
Whichever distro you choose, you could set up SSH access for yourself to do things for them (apart from fixing most networking issues if they can’t connect to the internet ofc).
Don’t think in terms of easy to use and unbreakable. You won’t get that because something as simple as losing icons on the desktop is the kinda thing that’ll confuse someone that’s bad with computers. Instead, think in terms of what’s going to be easy for you to fix when you inevitably have to play tech support.
ixnay on anything but the vanillaest of the vanillas and that goes triple for bazzite and friends. you don’t want “intriguing” shit left behind to take care of pops, that’s a thing for you to play and experiment with.
your solution is already staring you in the face: the ubuntu you left behind persevered even under those circumstances. either fix it and update it or install a fresh one, with a tweak here and there. and don’t touch nothing else…
Take a look at the immutable distros like Fedora Silverblue. It would install updates automatically, and has the ability to always rollback to a working version. I haven’t used it long enough to have version upgrades tested. Perhaps it asks for user input. These upgrades happen twice a year.
If I was doing that these days with my current skills, I’d install some minimal version of Arch Linux and probably would remote into it once in a while to update, or invent some simple script to do the updates unattended. The lesser the packages the easier the whole task.
Also, don’t forget there’s Chrome OS which you can install on a regular PC. (It was called Chrome OS Flex last time I did that for a relative.) It’s the easiest I can remember right now. That’s for situations when all they need is actually just a browser. For those cases Chrome OS shines.
Also, don’t forget there’s Chrome OS
No, please forget Chrome OS. Also, I’d hesitate to call it “Linux” at this point
Haven’t used one myself for years (close to a decade). Installed it for a relative about 5 years ago, never maintained it ever since.
What’s wrong with it?
It worked pretty well on an ancient PC which was running some Windows 7 if not XP. Can’t remember really. The relative is about 80 years old, so all he needs is a browser. So, Chrome OS came naturally. The hardest part was, for some really stupid reason Google wants Google account password to be entered upon booting, and not some other password. PIN code didn’t work for us for some reason. The solution I took is we changed the password to his birthday (perhaps with some A letter, if it wants at least one letter to be present). The password included dots, which was trivial to enter with a Numpad. Like A1945.09.05. But personally, I just hate it. There are use cases when you can allow a computer to have no password. Here, Google forced us to use less secure password, out of convenience. I’d prefer to have my Google account having stronger password, and forcing no password of my computer at all. The potential security risk is someone breaking into the house, and surely they’ll be very dumb to steal that computer, to have … what? YouTube history of some old fart? But that’s a bit of a different story anyway.
Me, I’d rather go with some very minimal distro and maybe even kiosk-mode browser, if necessary.
Still, what’s wrong with ChromeOS? Did I miss something important? Beyond Google dropping ‘don’t be evil’ obviously.
Still, what’s wrong with ChromeOS? Did I miss something important? Beyond Google dropping ‘don’t be evil’ obviously.
A quick look through some of the privacy communities will give you an overall vibe on what Google is doing. But overall, they’re getting monopolistic.
They’re requiring all android developers register their identities with them or they’ll be blocked on all Google’d android versions (which almost all Android phones ship with). They’re also datamining everyone more and more each year, just like Facebook.
And they’re using their influence over Chromium to force adblock blockers into every Chromium browser. And the only non-Chromium browsers are Firefox and its derivatives
And by far the worst one, they bought out ReCaptcha and they just rolled out an update that requires verification with a device that has either iOS or stock android. It doesn’t support deGoogle’d android like GrapheneOS or LineageOS, and it doesn’t support desktop. So now any website you visit that uses the new version of ReCaptcha requires you to verify your identity with a phone, even if you’re accessing the website on desktop. This is so they can link all your systems to your identity
If you value your privacy, you should work to get your digital footprint off Google’s software as much as possible









