Alfie Emanuele to tackle Linux credential gaps at FOSDEM 2026

Software engineer Alfie Emanuele will present on the shortcomings of Linux desktop credential management at FOSDEM 2026 in Brussels. His talk highlights how Linux lags behind Windows and macOS in secure authentication, urging a rethink to improve user security. The discussion comes as passkeys and hardware-backed storage gain prominence in computing.

Linux has long powered servers and embedded systems, but its desktop credential management remains fragmented compared to proprietary operating systems. At FOSDEM 2026, scheduled for early February in Brussels, Alfie Emanuele, a software engineer and security researcher, will deliver a talk titled “Credentials for Linux.” Emanuele aims to examine the current patchwork of solutions on Linux, such as GNOME Keyring, KDE Wallet, and the freedesktop.org Secret Service API, which lack the unified integration seen in Windows Credential Manager or macOS Keychain.

These proprietary systems benefit from deep ties to hardware like Trusted Platform Modules (TPMs) and secure enclaves, protecting credentials even against system breaches. Linux supports TPMs via kernel tools, but desktop applications struggle to access them seamlessly, often resorting to insecure methods like plaintext files or scattered databases. This inconsistency hampers security across applications and desktop environments.

The timing is critical amid the shift to FIDO2 passkeys promoted by Google, Apple, and Microsoft. While Windows and macOS offer built-in support with cross-device sync, Linux users face fragmented browser-based options or external keys like YubiKeys, without a platform authenticator. Emanuele's presentation will likely explore bridging this gap, possibly involving systemd features like systemd-cryptenroll for TPM-bound encryption.

For enterprises, the divide poses compliance risks under standards like NIST 800-171 or EU's NIS2, as Linux endpoints cannot match Windows' hardware-backed policies. Tools like Red Hat's SSSD focus on networks, not desktops. Held at Université libre de Bruxelles, FOSDEM could spark collaborative efforts to standardize Linux credential handling, making it viable for mainstream and business use.

Relaterede artikler

Tech leaders announcing Linux Foundation's AI-powered cybersecurity initiative for open source software with major partners.
Billede genereret af AI

Linux Foundation announces AI security initiative with tech partners

Rapporteret af AI Billede genereret af AI

The Linux Foundation has launched a new initiative using Anthropic's Claude Mythos preview for defensive cybersecurity in open source software. Partners include AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan, Microsoft, NVIDIA, and Palo Alto Networks. The effort aims to secure critical software amid the rise of AI for open source maintainers.

The Linux Foundation has announced that the call for proposals is now open for the Linux Security Summit North America. The event is scheduled for May 21-22, focusing on securing the Linux ecosystem. Submissions must be made by March 8.

Rapporteret af AI

A recent article argues that Linux is grappling with an identity crisis that impedes its growth on desktop computers. Described as the OS of a thousand faces, Linux's fragmented nature is highlighted as a key barrier. The piece was published on March 7, 2026.

The Linux and free open-source software community experienced a busy week from February 16 to 22, 2026, with several distribution refreshes and software enhancements. Highlights include updates to desktop environments, audio tools, and productivity applications. Linuxiac's weekly roundup captures these developments.

Rapporteret af AI

Following initial discussions among Ubuntu and Fedora developers, more Linux and BSD distributions are addressing age verification mandates in California, Colorado, Illinois, and beyond. Responses range from minimal compliance plans to outright resistance, amid unclear enforcement for open-source OSes.

Developers from Ubuntu and Fedora have begun discussing how to comply with California's Digital Age Assurance Act, set to take effect in January 2027. The law requires operating systems to collect age information during account setup and provide an age signal to applications. Canonical and Fedora leaders emphasize ongoing reviews without firm plans yet.

Rapporteret af AI

Enforcement of Selinux and AppArmor in enterprise Linux environments climbed to 55.6% in 2025, covering more than half of production installations. This milestone reflects growing reliance on mandatory access control to block unauthorized access. Key distributions like RHEL and Ubuntu drive this adoption, with openSUSE making a notable switch to Selinux as its default.

 

 

 

Dette websted bruger cookies

Vi bruger cookies til analyse for at forbedre vores side. Læs vores privatlivspolitik for mere information.
Afvis