Cicada.OS — Arch-based private laptop OS

2 min read Original article ↗

Cicada.OS is an open-source laptop OS. The package engine is Arch Linux (official repos). Cicada is the product layer on top: greeter, dock, settings, launcher monopoly, per-app scopes, Helium browser policy, and a pinned update channel.

It is not GrapheneOS, not AOSP, and not a phone OS. Graphene’s permission model is an inspiration for the scopes sheet — not the codebase. Official releases: download. Install: install.

Status — read this before you trust it

PRE-ALPHA

Cicada boots to a Hyprland desktop on an Intel MacBook Air. Most of the hardening on this site is verified structurally — the configuration says the thing — and a growing part of it is now verified against a real Linux kernel. Little of it has been exercised on hardware end to end. Do not rely on this for anything that matters yet.

  • On a real kernelFirewall + VPN kill switch, NTS time, Tor bootstrap, onion namespace, session duress wipe
  • In simulationUSB gate and its restore path, watchdog arming, escape hatches, beacon signing and alarm
  • Needs the hardwarehardened_malloc under Helium, chipset watchdog reset, kernel USB refusal, LoRa beacon

Full list: Status in the README.

Threats vs evidence

HONEST

ThreatWhat we shipWhat we do not claim
Trackers / school HTTPS filter / cold stolen disk Helium managed policy + LUKS2 passphrase (installed systems) “Unbreakable” crypto or Graphene-class attestation
Device seized while on or just locked (AFU) Lock timer reboot, USB authorize gate, optional duress wipe Cellebrite / GrayKey “no access” — that is userspace, not Titan
Evil maid / firmware on Apple EFI Air Nothing that survives that class Verified boot — needs Heads/PureBoot-class hardware
“Is this just Arch with a theme?” Launcher monopoly + scopes + Work UID + channel path Android UID isolation or Qubes VMs