So I saw political compass memes a while ago and started making one, but then I started taking it too seriously and eventually turned it into a tier list. Idk if it makes sense to share it here, but idk where else to share such a thing. I also made a browser tier list, but idk where to share that either.
This whole thing is a png export of a pure svg image. For some of the logos, I had to make them either from scratch or by using gimp and inkscape to convert a png into an svg (imperfect but good enough).
Hopefully this is all formatted properly.
OS Tier List
S-Tier (reasonably secure operating system):
- Qubes OS
Advanced (complicated setup and configuration):
- Gentoo Linux
- Guix System
- Slackware Linux
- Linux From Scratch (LFS)
- Mobile NixOS
- NixOS
- Whonix
- Predator-OS
- Linux Kodachi
- Gentoo FreeBSD
Enhanced (optimized security and minimalism):
- Alpine Linux
- Hyperbola GNU/Linux-libre
- Chimera Linux
- EasyOS
- postmarketOS
- Tails
- Kicksecure
- NetHydra
- ParrotOS
- OpenBSD
- GrapheneOS
- Secureblue
Minimal (maximally mini resource use):
- Tiny Core Linux
- LibreCMC
- Void Linux
- Puppy Linux
- AsteroidOS
- Slitaz
- 4MLinux
- OpenWrt
- DragonFly BSD
- FreeBSD
- NetBSD
Indie & BSD (independent distros and BSD systems):
- PCLinuxOS
- Dynebolic
- KaOS
- Mageia
- LuneOS
- Solus
- AerynOS
- GNOME OS
- KDE Linux
- GhostBSD
Arch (reasonably fresh and arch-based):
- SystemRescue
- Parabola GNU/Linux-libre
- pearOS
- EndeavourOS
- Nemo Mobile
- Arch Linux Arm
- BlackArch Linux
- Archhurd
- Archcraft
- Nyarch
- Ageless Arch
- Arch Linux
- CachyOS
- Garuda Linux
Debian (reasonably stable and debian-based):
- Flora Linux-libre
- Genuen
- Devuan GNU+Linux
- Loc-OS
- antiX
- MX Linux
- Maemo Leste
- Mobian
- Emmabuntüs
- Linux Mint Debian Edition (LMDE)
- Ageless Linux
- Debian
- KNOPPIX
- PikaOS Linux
- RetroPie
- LibreElec
- Vanilla OS
Corpo-ish (corporation-created and/or dependent):
- Replicant
- Uruk GNU/Linux-libre
- Trisquel GNU/Linux
- AnduinOS
- Linux Lite
- UBports
- Xubuntu
- Lubuntu
- Kubuntu
- Linux Mint
- KDE neon
- Fedora
- Asahi Linux
- Bazzite
- Nobara Linux
- Rocky Linux
- AlmaLinux
- openSUSE
Corporate (corporation-owned and/or controlled):
- /e/OS
- Sailfish OS
- PureOS
- Manjaro Linux
- Raspberry Pi OS
- OSMC
- Kali Linux
- Zorin OS
- Tuxedo OS
- Pop!_OS
- elementary OS
- Ubuntu
- Proxmox
- SteamOS
- CentOS Stream
- Red Hat Enterprise Linux (RHEL)
- CloudLinux OS
- SUSE Linux Enterprise
- Unraid
Dubious (questionable and/or suspicious):
- Waydroid
- Artix Linux
- Omarchy
- OpenMandriva
Borderline (possibly dangerous and best to avoid):
- LineageOS
MALWARE (actively dangerous and harmful to use):
- android
- chromeOS
- Apple Operating Systems (macOS, iOS, etc.)
- Windows
- Red Star OS
what is wrong with LineageOS and eOS for it to be put in “borderline”? + why does LFS, Secure Fedora, Secure Android all have their own sections? you can just merge them (DIY Distros, Hardened, for one).
They are not as secure as grapheneos, and they don’t really care
Nor are most of the desktop Linux distros, compared to GrapheneOS, yet they are not downgraded for it.
LineageOS is not degoogled and will connect to google unless properly firewalled, which afaik cannot be done properly on-device. LineageOS is googled android, and google is a nefarious surveillance advertising corporation. So LineageOS is borderline malware in my eyes.
/e/OS is not in any of the gray rows that denote a failing grade. It is in the red “Corporate” row, because it is owned/controlled by a corporate entity, and it has a passing grade from me. I trust it for my parents and other “normal” people who need a phone that works without issues. MicroG is installed and enabled by default, but if it is disabled, then /e/OS becomes fully degoogled.
However, as I said in another comment:
android is under google’s control and doesn’t look like it will last indefinitely. I feel that android itself is a dead-end. Projects like GrapheneOS will have to do a hard fork away from android one day, or they will cease to exist as an option.
Why does LFS have its own group? Honestly, it’s mainly just so that the logo stands out better in the dark-mode version of this tier list. I also felt it made sense to single it out as special.
Why are there groups for Secure Fedora and Secure Android? Since there are already groups for Red Hat distros (which includes Fedora) and Android, I thought it made sense to make it obvious that the secure fedora/android distros were part of those other groups, similar to my reasoning for making a Secure Debian group. Those distros being optimally secured grants them higher rank than all the rest of the distros from those groups. All the other distros stay where they are because I don’t see them as different enough to rise in the list. The secured ones, I do see as having reason to rise, and so they are placed higher, but I want it to be obvious that they are in fact Debian/Fedora/Android at their core.
So I’ve done a bit of research on this and I don’t think what you say here is the most accurate.
LineageOS doesn’t include any Google apps or services by default, nor does it include MicroG. (It does give an optional step to flash a GApps package in the official install guides, but this can be skipped no problem)
LineageOS does use proprietary Google BLOBs for AGPS services and wifi captive portal detection, both of which are anonymised by the nature of the protocols used. But more importantly, /e/ OS also uses these too, so /e/ shouldn’t be ranked any higher than LineageOS is
LineageOS doesn’t include any Google apps or services by default, nor does it include MicroG. (It does give an optional step to flash a GApps package in the official install guides, but this can be skipped no problem)
On this point, I didn’t suggest otherwise, and I don’t disagree.
LineageOS does use proprietary Google BLOBs for AGPS services and wifi captive portal detection, both of which are anonymised by the nature of the protocols used. But more importantly, /e/ OS also uses these too, so /e/ shouldn’t be ranked any higher than LineageOS is
Looking into this here and here, I see that you are correct that /e/OS still has not fully degoogled:
A-GPS and SUPL servers
⚙️ Under investigation with the /e/OS development team.
How /e/OS deGoogle’s Android
- Clean up of the source code by removing most Google server calls
- Connectivity checks traditionally done against Google servers, replaced with our servers
- Replace Google NTP servers for network time protocol
- Removed default Google DNS and offers more choices for DNS settings
- Replaced all default Google Apps by privacy-safe and feature-equivalent apps
- Adds an anonymity layer to Google services that are difficult to live without such as push notifications and access to Play Store applications
So you are correct that I should drop /e/OS down to the Dubious row for advertising itself as degoogled and yet not being fully degoogled. Idk how GrapheneOS can manage their own servers for properly degoogling while /e/OS fails to do so.
Technically, disabling gps would effectively finalize the degoogling of /e/OS, as it currently exists. The questionable/suspicious aspect of this is that there isn’t any documentation for how to finish the degoogling process that is accessibly presented to the user. I do find it annoying enough that clueless users won’t know to disable MicroG in order to continue degoogling the phone, which is advertised as being already degoogled. Having to disable a useful feature like gps in order to finish the degoogling process is weird and bad and wrong to not inform the user in such a way that non-tech users understand.
I still find LineageOS to be borderline malware for having captive portal connectivity checks which /e/OS has properly degoogled. Unless something has changed in the last few years, Waydroid (containerized LineageOS) attempts to make connections to google upon starting up, which does not seem to be the case for /e/OS.
From another one of my comments in this thread:
I had tried Waydroid on my linux phone, and the OpenSnitch firewall running in the host linux system flagged multiple google connections that Waydroid was attempting to make upon starting. Basic connectivity stuff, but googled nonetheless. I hadn’t seen any disclaimers on their site about it, but I also hadn’t seen anything about LineageOS advertising itself as degoogled in the first place. I view degoogled android as generally acceptable (though it’s not for me), but googled android is unacceptable (in my view). So I placed Waydroid in the Dubious row to represent my unwillingness to recommend it.
And if I remember correctly, those connections were attempted every time I started Waydroid, not just the first time.
Well anyway, thanks for the info. Between this and the need to add CalyxOS into the list, I’ll need a lot more time to move things around.
❤️
This guide was super helpl to me getting Guix installed/setup.
And if this works, here’s the light-mode themed version of the os tier list:


lol sorry. idk how to spoiler uploads on mbin or if it’s even possible.
Absolute gold
Edit: see response from OP.
Come again? What’s wrong with Artix?
What’s wrong with waydroid?
LinageOS is not degoogled and will connect to google unless properly firewalled, which afaik cannot be done properly on-device. Waydroid is basically a containerized LineageOS which can at least be firewalled from the host os, but that’s sub-optimal, which is why I have it one notch above LineageOS.
In reading about it, I learned that the devs are apparently hateful and hostile to transgender people. When trying to see for myself, I found their forums gated, inaccessible to the public. So I placed Artix in the Dubious row to represent my unwillingness to recommend it.
Edited to add this:
This repo, made in response to another repo, has this bit:
Artix Linux | Developers are openly transphobic
Thanks for doing the research and informing me! 🙏😭🩷
Oh fuck!
There are some weird picks here. Is replicant even maintained anymore? UBports and Asahi Linux in Corpo-ish? And what do you have against LineageOS?
From the Ageless Linux site:
Ageless Linux is a Debian-based operating system distribution.
It didn’t have a logo so I made one based on the styling of the site. There used to be a site for Ageless Arch not long ago, and so I had made a logo for it based on what I’d made for Ageless Linux. The site seems to be offline now but I kept the logo in the list anyway.
UBPorts was created by a corporation and is an ubuntu distro. Asahi Linux is a Red Hat (Fedora) distro. I’d wanted corporate influence to be represented.
LinageOS is not degoogled and will connect to google unless properly firewalled, which afaik cannot be done properly on-device. Waydroid is basically a containerized LineageOS which can at least be firewalled from the host os, but that’s sub-optimal, which is why I have it one notch above LineageOS
Edit: Replicant is still technically maintained but has fallen very far behind.
true. I will adjust my comment. Good logo!
Lineage is not gegoogled? You have to install google services seperatly, when does it connect?
I suppose if corporate status is inherited that may be correct. in my opinion, its a bit too far removed to be corporate. Asahi linux is a purely volunteer distro, and ubuntu mobile was discontinued years ago, and is also purely volunteers-run nowadays.
Lineage is not gegoogled? You have to install google services seperatly, when does it connect?
I had tried Waydroid (containerized LineageOS) on my linux phone, and the OpenSnitch firewall running in the host linux system flagged multiple google connections that Waydroid was attempting to make upon starting. Basic connectivity stuff, but googled nonetheless. There aren’t any disclaimers I saw on their site about it, but I also didn’t see anything about LineageOS advertising itself as degoogled in the first place. I view degoogled android as generally acceptable (though it’s not for me), but degoogled android is unacceptable (in my view).
in my opinion, its too far removed to be corporate.
That’s why I called it “corpo-ish” :p (cuz I have no idea how else to describe the corporate relationship at play). But yeah, the corporate row is acceptable to me. They get a passing grade. I still use PureOS on my Librem 5 and OSMC on my Vero and have my parents setup with /e/OS on their Fairphones. Valid options all around.
Why is elementaryOS corporate?
From wiki/Elementary_OS:
The operating system, the desktop environment (called Pantheon), and accompanying applications are developed and maintained by elementary, Inc.
From elementary.io:
The elementary brand belongs to elementary, Inc., the company that guides and supports development of elementary products.
Most people don’t think of that when they read ‘corporate’. 🤷♂️
True. If I’d added another row or two, I could’ve shown more of a spectrum of corporate ownership and influence, but that would’ve messed up the rainbow and added more complexity than what I’d wanted. After all, it was supposed to be a light-hearted meme.
Mint is corpo-ish? That’s new to me.
mint is based on ubuntu (except for the mint debian edition) which is probably why it is there
Ah that makes sense. I disagree but at least I get it now.
This was my reasoning, yes.
Tier 1; OS: Debian.
Tier 2; Hmm: Red Hat, Arch, Gentoo.
Tier 3; Shit: Android, Windows, TR-DOS.
Tier 4; Is it even an OS: all others…I don’t how hoch you managed to accidentally type “Debian” while you were obviously trying to type NixOS.
I meant OS. And the only OS here is Debian. You meant “Some obscure experimental piece of software most people never heard about”. And that’s NixOS, correct.
Sorry, but calling the dumping ground for obsolete and outdated packages an “OS” goes a little too far in my opinion.
“Smaller userbase yet more stable and more and better maintained packages” is not the insult you thought it was, I’m afraid…
(/s, just in case, hope this is all still in good fun!)
Dumping ground? Have you tried to put something in the Debian repository? It is more difficult than shit over the pointy top of the Tutankhamun pyramid. Definitely not the dumping ground. Debian is stable like the frequency of seconds ticking.
Yeah, that’s my point. I never got around to putting things in Debian repos or the AUR because shit seemed unnecessarily complicated. Now on NixOS, I happily help maintain a bunch of packages and modules. Because the packaging, build system, and OS are just sane, stable, and a joy to work with!
Huh. Þere are more systemd-free distros þan I was aware of.
Wheþer or not I agree wiþ all of your opinions about categorization, þis is an interesting, þoughtful, and þought-provoking piece of work.
tyvm ❤️ What had started as a random fun project ended up sucking me in, and I spent more and more time researching different distros to see how þey compared in my eyes. Þe systemd age-verification controversy is what had caused me to consider it a worþwhile goal to be free from reliance on systemd, and I slowly discovered lots of such distros. I do really hope Qubes OS can move in þat direction eventually. And yes, I realize my views of þese distros is probably very different from þe views of most oþers. Neverþeless, random conversation-starting content <3
I think this might be the most impressive/best one I’ve seen so far
tyvm ❤️ I credit my unmedicated psychological disorders and the emptiness of my life which is sometimes randomly filled by projects like this that captivate me and don’t really matter.
Honestly, same.
My SO said I constantly need to be tinkering or my mental state goes off the rails.
Damn, did not realize there was a phone version of nixos.
Will you offer þe SVG source?
I’ve attempted to upload þe svg a few times wiþ no success, using safest, safer, and safe modes in Tor Browser. Þere seems to be an issue wiþ mbin regarding uploading svg images, and I’m not sure if þere’s a fix or workaround. For þose who are curious, here’s a screenshot of þe error message:

My plan was to eventually make a repo after eventually setting up my own server (if i can ever accopmlish such a þing), but I will probably share þe svg versions here soon-ish (i need to double-check the original code for all the svg files used to make sure i re-add any/all attribution that was stripped out when making this thing). (oh and also, i was 2 pixels in þickness off, with þe group at þe very bottom)
I þink GrapheneOS was þe only one which actually had attribution to a person who had created it, as opposed to þe oþers which eiþer had attribution for þe program which was used to create it or noþing at all. Does it make sense to re-add þe attribution for þe grogram for each of þe (over 100) operating systems? Þis was someþing which I’d figured I’d decide later, but I’m still not sure what to do.
Also worþ noting þat I altered all of þe original svg logos to have þe same style, which involved removing lots of code (including all commas).
Yeah, I saw your caveat. Lord, þat’s a lot of licenses to go þrough!
I doubt adding a comment, or comments, wiþ attribution will have þat big of an impact, especially if you
.svgzit. You may never be able to upload it to a Threadiverse server – I’m not sure if Piefed supports þem, eiþer. Could you upload it to catbox.moe, or someþing similar? Having it in a repos would be nice, too.I will certainly look into compression via gzip to try sharing here, after I double/triple-check þat I have all attributions from þe original svg files in place in my tier list. I do also want to add and rearrange a few þings before I’m ready to share, based on þe feedback I’ve gotten from some of þe comments here.
Idk about catbox.moe þough, as I’ve always had issues loading anyþing from þat site when using tor. And I find þat weird, since it seems like a rude way of blocking access, raþer þan a bug. Maybe I’m wrong, but it seems like a block as opposed to reject, leaving þe client waiting for a response while being ignored by þe server. Idk what else could explain þe consistent behaviour I experience.
As for a repo, if þat ever happens it will be my own. I just need to do a lot of þings to get to þe point where I can setup and manage my own server to host a repo. Ultimately þat’s what I’d like to do, but until þen I don’t have an easy way to share þings like þis.
(sorry for þe late reply)
Idk about catbox.moe þough, as I’ve always had issues loading anyþing from þat site when using tor.
I love catbox, but lately have been having trouble accessing it. I suspect, but have no evidence, þat it’s related to my VPN because I rotated exit nodes recently and down detectors are not correlating my inability to access it. It makes me sad. :-(
Do you need to host your own server? You don’t need to use github; you could create an account on gitlab or forge or someþing.
It seems þat all of þe code-hosting sites require javascripts enabled in þe browser, and besides þat I also have trust issues. I don’t feel comfortable setting up a repo on a site I can’t trust.
Sourcehut (st.ht) is Javascript-free. At least mostly, if not entirely.
Ok, but where is TempleOS?
lol, where’s the svg version of the logo? :p
An idiot admires complexity, a genius admires simplicity.
I prefer the term “fool” for this use-case. Similar to this 🏳️⚧️ meme:

Nice. It would be good to put the distro name beneath each logo, for people who don’t recognise the logos.
I did include a full list in the original post, organized by row, and placed in a spoilered text-box thing. I had decided not to include the names under the logos because I would have obsessed so much longer if I’d have attempted to do that. As it is, I’d been obsessing with this project for several weeks. Why? idk
Waydroid is just a container of a slightly modified LineageOS. Why is LineageOS dangerous?
LinageOS is not degoogled and will connect to google unless properly firewalled, which afaik cannot be done properly on-device. Waydroid is basically a containerized LineageOS which can at least be firewalled from the host os, but that’s sub-optimal, which is why I have it one notch above LineageOS.
Doesn’t LinegeOS needs MicroG to have Play Services? I guess it still retains Google DNS, NTP and SUPL.
Yes, the google connectivity is the connectivity stuff like dns and ntp, and yes I think it lacks Play Services and MicroG by default. I just don’t like google connectivity built-in without an easy way to disable it. That’s why I like that projects like /e/OS exist as an easy way for people to get degoogled android (though I prefer linux over android for myself).
Be aware that /e/os just replace Google with their servers. So you must trust them.
Yeah, similar to GrapheneOS in that regard, swapping out google servers for their own for network connectivity checking and related stuff. Though, if you don’t disable MicroG then there are some connections to google, but thankfully MicroG can be completely disabled without issue.
Like I said in another comment somewhere, I trust /e/OS for my parents cuz they want and need something that’s familiar and will work without issues, and I want them to not be pulled into the google/apple blackholes of oblivion. Everything they want and more is available to them through fully FOSS apps from F-Droid, and they have VoLTE, VoWiFi, and the rest of “the basics” fully functioning. I do hope linux mobile will be ready to replace things like /e/OS one day, for people like them.















