ChromeOS is dead simple. So much so that my otherwise computer-illiterate wife can (and does) use it regularly. There's no way that I'd get her to use debian, though, unless I set everything up for her in advance. Choosing the desktop, setting up PPAs / flatpack / whatever (if you don't want the stock firefox browser), tweaking power settings, there's all sorts of faffing about in comparison.
I'd have to set up syncing in Firefox for her (or whatever browser) but to be fair, I helped her set up her account in the chromebook too.
Hence, as my original post was meant to convey, a ChromeOS clone is a better option to set up a laptop for her than just grabbing debian.
An A/B partition scheme is very simple and the system as a whole is integration tested in CI. An OSTree based atomic system is pretty close, although there is some added complexity.
Not to mention Debian out-of-the-box is a pretty miserable experience for everyday users. Their Nvidia drivers won't work, they can't figure out how to install Chrome, videos won't play due to missing codecs, etc.
The author mentions this as well but there's no details there. We've been shipping chromeos-style images with universal blue for over 4 years and the ostree parts are invisible to end users. What do you feel takes away from the user experience?
I think my main concern is something like a known OSTree design issue around UID/GID drift, there was a bug that was partly fixed in 2023 but the issue comes from OSTree assigning known UIDs from the deployment once created, but this may not map to the proper UID on the system the deployment is being blasted to. You can get improper ownership out of this.
Not something I've ever encountered myself, but if I were developing an embedded device it seems like one less thing to worry about.
I'll bring it up during the next bootc meeting[1], which are public btw! Thanks for using bazzite!
1: https://github.com/bootc-dev/bootc?tab=readme-ov-file#commun...
The Chrome OS is running trusted boot and immutable partition, and completely closed host system, with no user-installable apt [0]. This means it's impossible to completely break the system - nothing that user does will escape browser sandbox. And, for defense-in-depth, even if browser sandbox got compromised, there is no sudo nor ~/.bashrc nor any other executable per-user configs, so malicious software will disappear after reboot. And if you compromise kernel and modify disk directly, there is verified boot...
And this is not just theoretical benefits, it's stops practical attacks. Are you sure that "bash | curl" command you typed was safe? Are you sure that "pip install" or "npm install" you did didn't actually install malware on your PC?
It is possible to build systems like this based on open-source Linux, but this will be quite a lot of work, and may even require separated trusted builder machine. Definitely out of reach of non-technical user.
[0] https://www.chromium.org/chromium-os/chromiumos-design-docs/...
This is why it was such a revolution when Ubuntu came out and quickly dominated the Linux desktop space. When it was new.
It took Debian and made it something approachable. But even then it was a 1/3rd of what is described as needed in the article.
edit: i'll add, link your image to a github repo with a readme describing how to get it on disk. there's the project.