5 ms·
How is Linux immune to wannacry like attacks?
by inian 9y ago
How is Linux immune to wannacry like attacks?
- deleted 9y ago[deleted]
- ryanlol 9y agoNot sure why this got downvoted. The claim the author makes sounds ridiculous at best. >My computer running the GNU and Linux software isn’t entirely virus-proof, but it’s immune to “Wannacry” and a lot of the garbage that most of you tolerate. Essentially any Linux desktop install is going to be an absolute security nightmare when compared to a fully patched windows install. While Microsoft has been pushing trustworthy computing for 15 years, on Linux desktops we only recently started to get ASLR/PIE. Wannacry wasn't even exploiting any 0days and therefore "Windows" was also immune to it from the beginning.
- vetinari 9y ago"Trustworthy" computing is not about security, but about platform control. You can still exploit a computer, whether it has TPM & accessories or not. If the Windows was immune to Wannacry, we would not hear about it in the first place. You might argue, that it was the operators who failed to update, but there was already a discussion, that due to Microsoft abusing the Windows Update in the past, many people had many good reasons to disable it.
- ryanlol 9y ago>"Trustworthy" computing is not about security, but about platform control. You can still exploit a computer, whether it has TPM & accessories or not. I'm sorry, but this is just tinfoil nonsense. Trustworthy computing has nothing to do with TPM & accessories. Stuff like this is what Trustworthy computing is about: https://www.blackhat.com/docs/us-16/materials/us-16-Weston-Windows-10-Mitigation-Improvements.pdf https://www.blackhat.com/docs/us-16/materials/us-16-Weston-W... The above PDF is also a good reference guide to mitigations that are not present on desktop linuxes. >If the Windows was immune to Wannacry, we would not hear about it in the first place. You might argue, that it was the operators who failed to update, but there was already a discussion, that due to Microsoft abusing the Windows Update in the past, many people had many good reasons to disable it. Choosing not to install security updates also leaves you vulnerable to such attacks on Linux, and they do happen. Are you seriously trying to imply that you've never had an issue with a package manager on Linux?
- vetinari 9y ago> I'm sorry, but this is just tinfoil nonsense. Please refrain from insults and ridiculing. That does not belong into a honest discussion. > Trustworthy computing has nothing to do with TPM & accessories. Trustworthy computing and Trusted computing are so similar term, that most people will confuse these two. Especially if they are not native English speakers. It was not a good choice to pick a term so similar. > The above PDF is also a good reference guide to mitigations that are not present on desktop linuxes. Of course not, these desktop linuxes do not have the most used attack vectors in the first place. > Choosing not to install security updates also leaves you vulnerable to such attacks on Linux, and they do happen. Sure, but the point was lack of trust in Microsoft and the abuse of the update mechanism in the past. You wouldn't pick any candy from a box, if you knew that just some of them are poisoned... > Are you seriously trying to imply that you've never had an issue with a package manager on Linux? Yes, I seriously do. Since Redhat Linux 5.0 (that's Redhat Linux, not Redhat Enterprise Linux), the only issue I had was an invalid package that failed to install (it was later fixed and the package then installed fine). No Linux distribution ever abused the update mechanism in such a way as Microsoft did. The only questionable thing that happened was Canonical and their forwarding of search data to Amazon. They were rightfully criticized, the fix was easy, the updates didn't flip the setting back and in the end, it was corrected by Canonical. I have yet to see any correction from Microsoft - they didn't even admit wrongdoing yet.
- deleted 9y ago[deleted]
- kelnos 9y agoIt's not, but Linux is immune to Wannacry and a lot of the other _actual_ garbage that's out there because they don't target Linux desktop users. It would probably be pretty trivial to come up with a Wannacry-like bit of malware that was equally (or more?) effective on a Linux desktop, but the market for doing so isn't very lucrative.
- inian 9y agoSo the argument is Linux is more secure now because hackers aren't paying enough attention to it. That is no reason to gloat about how Microsoft is bad in terms of security.