3 ms·
Yes, but on the other hand, all the Linux source code is publicly available, and it's still considered secure.
by brianberns 6y ago
Yes, but on the other hand, all the Linux source code is publicly available, and it's still considered secure.
- glouwbug 6y agoCausation vs. correlation, Linux is secure because it _is_ open source. Closed systems can cut corners, assuming the source stays secret
- acct776 6y agoNo, it is not, by any stretch of the imagination, by security researchers. This has been on the front page all day: https://madaidans-insecurities.github.io/guides/linux-hardening.html https://madaidans-insecurities.github.io/guides/linux-harden... It is safe to assume it is more PRIVATE than a Microsoft OS, but not more secure. Please don't react emotionally to this... It was a bit jarring of a shift in thought to me as well, at first.
- acct776 6y agoDownvoters, consider reading first: https://madaidans-insecurities.github.io/linux.html https://madaidans-insecurities.github.io/linux.html
- tester756 6y agoI'm curious whether somebody will challenge it
- richardwhiuk 6y agoThat article is comes from an extremely naive security posture.
- 0134340 6y agoRegardless of what mitigations Windows has in place, when you run closed source programs, without competent security auditing you never know what it's doing. Once you click run your precious user files are always in jeopardy. Even with GUI isolation, a point of contention in the article, it's trivial with a few bytes of code to implement some other form of keylogging which the user will run without much thought because hey, it's Windows, it's "secure" while having no real idea what the program is doing in the background. To reiterate, any execution of closed programs will result in execution of closed processes. With the Windows model, you don't check your guests at the door. You can't search all guests so you assume all guests are hostile and with it you're always taxed with playing security theater which can not only be expensive in terms of hardware resources but mental resources as well as losing more control over your own environment. Because you let unaudited people in your home, before long you have to lock down most parts of it, even from yourself. In gaining control you've lost control because you don't control for openness in the first place. For the few binaries I run on Linux I sandbox them in a VM anyway. But different models, different hosts, each has their weaknesses.
- m4rtink 6y agoMost importantly, how do you check the binary you are running is actually built from the source code the vendor says it is if the source is not open ? They might sincerely thing so, not knowing they were targeted and now all the binaries they ship are also containing a payload added by the attacker. With open source software and especially the Linux distro model where one set of people writes the software and another buikds it from source and integrates it is much harder if not impossible to pull off such an attack affecting all users of a piece of software.
- merb 6y agowindows sandboxing btw. is barely at use. every program can basically read everything in user profiles, that is imo the same on linux. only windows applications that do not run in full trust mode, like store apps won't do that. and even without store apps you can use something like msix or app-v to package your apps in a "small" sandbox, but you can breakout from the sandbox via runFullTrust
- MeinBlutIstBlau 6y agoLinux isn't any more secure or safer than a lock on my door will prevent someone from just breaking the window. Hackers do in fact target linux machines, just not average desktop users. They typically go after servers since they run basically everything. And chances are, standard linux users know what they're doing so a ransomware attack isn't really much to frighten a linux user as much as it is to just piss them off but still recover in like 24 hours or less.