4 ms·
Well. The principle of Linux was and still is to give tools and have users use them. It gets out of the users way to use them. One can always use firejail or ot
by alcoholic_byte 6y ago
Well. The principle of Linux was and still is to give tools and have users use them.
It gets out of the users way to use them.
One can always use firejail or other sandboxing solutions to do that.
Chrome itself is a security nightmare, always with the mic on and listening.
Microsoft and Apple also have CVEs unattended.
Binary checks before starting a program? Why I have a package-manager that does the checks.
Untrusted binaries are ususally installed with local user rights in a seperate path or best, not run at all(never needed to turn to some website offering tools since moving to linux aeons ago).
Not all distros use Flatpack or Snap, and I hope it remains that way regardless of how fiercely Canonical is pushing for it.
Granted, the out of the box security provided by Linux as a Desktop OS is behind the Windows/MacOS one;Only think of the non-existing firewall rules on a fresh Ubuntu installation.
But I think that is ok, because installing Linux is a conscious decision, unlike using a preinstalled Windows or MacOS.
So, if you do that move from one OS over to another, the user should read up and not expect the community to hold their hands without asking questions.
Not everything is perfect, yes moving the toolchain would be nice, but then again, most a community run projects, so the user needs to know about locking their basement as well. Hence the audience is/should be more technical minded anyways.
IMHO another post about comparing apples and oranges leaving out second-level effects.
Just an example:
Looking for CVE-entries https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=MacOS https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=MacOS , https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=Linux https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=Linux , https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=Windows https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=Windows .
We see that MacOS has the fewest and Windows the most CVEs.
(So it doesn't matter that Microsoft closes the CVEs quickly and Debian might take some time (haven't really run metrics on that one), there is a huge attack-surface on Windows, compared to Linux and new once have to pop up all the time :D)
That isn't looking into severity, because a chaining of medium CVEs might also lead to a compromise as well ,and not everything requires system or root. User might be fine as well.
I see a reflection of favoured OS. Only few people use MacOS (some artists, companies streamlining their assets for maintenance and rent,etc.). Windows, on the other hand, was always the big dog on the desktop market. Naturally, maleware authors focus on the biggest market.
- cwyers 6y ago> The principle of Linux was and still is to give tools and have users use them. A circular saw is a tool, one without a handguard is a bad tool even if it cuts wood well.
- twothamendment 6y agoI found that a 14" circular saw with the guard removed was a great tool. It demanded a lot of respect - much like some tools in Linux. ./run-saw --yes-without-the-guard
- blaser-waffle 6y agoIt sounds like a good idea until you lose a least (or most) significant digit
- j88439h84 6y agoExtremely well said.
- nonick 6y ago> Chrome itself is a security nightmare, always with the mic on and listening I can understand the mic being always on as a privacy nightmare, but how is this a security nightmare?
- atq2119 6y agoLack of privacy is lack of security. This is true even if you're only interested in "hard" security concerns. For example, consider that keystrokes can be reconstructed from audio, which means that being able to record from your mic means being able to gather your passwords.
- alcoholic_byte 6y agoAs the other guys said. And it is not just that. Chrome is, considering it's architecture and purpose, a minion in a botnet, working for google to harvest data. They even got a lawsuit pending because they were even tracking users in privacy mode. This stuff cannot happen with IE, or FF. Brave, Vivaldi, I dunno, don't use them, but I am weary that they are using the same rendering-engine (and soon Redmond as well) (well depends where the G-men(what a pun) put their mischiveous code in). Because it is a pipedream to expect a privacy-compatible product from a company that build it's empire on mining the users data to the bit.