AMA: openSUSE dev for 15 years

Dear Bernhard,

thank you for your effort on Slowroll!

My question: do you take any measures to harden an openSUSE standard install?

Like, what I have done or would like or one could do…

  • a different umask (mine is 0077)
  • use of AppArmor (it is preinstalled, but what about extra profiles to be enabled manually?)
  • use of SELinux (it is not preinstalled with openSUSE, but with Fedora I guess)
  • use of FireJail (some people use it and recommend it strongly)
  • use of FlatPak to use their sandbox
  • DisplayManager (DM): rootless or not? (I use LightDM which is NOT rootless.)
  • delete/disable certain packages/apps/services/daemons? if yes: which?
  • further possible measures?

Thank you!