Security and privacy
Firewall, updates, encryption, Secure Boot, verified downloads and no telemetry.
- Firewall on by default: ufw, the simplest way to "deny incoming, allow outgoing" with a switch in Settings. firewalld has zones for complex setups, which desktops rarely need.
- Automatic security updates with unattended-upgrades, like Ubuntu. Fedora and Debian don't do this by default.
- AppArmor (Debian default) confines services and several apps.
- Full-disk encryption (LUKS2) and Secure Boot on installed UEFI systems.
- Least privilege: Settings never runs as root. One audited helper does privileged actions through polkit.
- No telemetry, no crash uploads, no ads, no account required.
- Every network request the desktop makes on its own, all of them optional:
- weather (Open-Meteo, only the time zone's main city, when you open the calendar);
- exchange rates (the ECB's public file, only when you type a currency conversion);
- update checks (Debian's and Aurora's repositories);
- Aurora AI: nothing while it runs on your computer; model and voice downloads (GitHub, Hugging Face, PyPI) only when you set up a feature; your questions go to a cloud provider only if you choose one and add its key. Everything else (sun position, OCR, clipboard history, emoji, unit conversion) runs offline.
- Fingerprint only for sudo and admin prompts, never instead of the login password.
- Phone integration ports stay closed until you turn it on.
- Third-party downloads at build time (portop, adw-gtk3, grub-btrfs) are verified by checksum.