2 ms·
(Note: I work for Microsoft, although not on the OS. I mostly use Debian and Ubuntu at home for things other than gaming, and know a bit about security--but I
by electronvolt 11y ago
(Note: I work for Microsoft, although not on the OS. I mostly use Debian and Ubuntu at home for things other than gaming, and know a bit about security--but I'm a bit rusty since I wasn't following it from 2010-2014 and haven't really thought about how to attack things since 2008-2009. These are my opinions/thoughts and don't represent the company I work for at all.)
Windows has been harder to attack than OS X since Vista. I don't think that's changed--Apple is generally slow to correctly implement security features that require kernel changes compared to either the Linux devs or Microsoft.
If I remember correctly, OSX didn't have a good ASLR implementation until 10.9 or 10.10, and has generally lagged behind on OS-level security updates and exploit mitigation (NX pages, ASLR, etc.). It was routinely the first thing hit in the early Pwn2Own competitions (partly because exploits on it were a breeze, partly because the laptop was usually a little nicer and you only got the laptop back then, too--but also because moving from crash to reliable exploit was easier).
I haven't followed security updates in Linux in the past few years as closely, so I can't comment on it as knowledgeably. From what I remember, it was about on par with Windows for difficulty to attack in Vista/7, but there's been a lot of security features that Windows has added since then. From what I remember, a fully hardened Linux box was just as bad to attack as a hardened Windows box, but Windows has generally required less configuration to get that right. (I think SELinux still isn't enabled by default in some distros?)
- cesnja 11y agoSELinux isn't enabled by default on many distros because it's not the only kernel security module out there. There's also AppArmor and some others.