14 ms·
Why GNU/Linux Viruses are fairly uncommon (2005)
- acct776 6y agoBecause there's less soft targets of mainstream wealth on Linux desktop... ...and the 0 days are saved for valuable servers and embedded devices
- globular-toast 6y agoWay to miss the joke.
- not2b 6y agoThis was a good test to catch those HN members who don't bother to read the article but decide to argue with the headline.
- Dylan16807 6y agoYou can do both!
- acct776 6y agoBusted...I usually do! Just thought this was a Stallman writeup. To be fair, the titles are usually similar.
- chrismorgan 6y agoLook, if the title is “why GNU/Linux viruses are fairly uncommon”, that’s fair game as a topic. In fact, you should expect that most of the discussion will be about that, rather than the self-deprecatory joke answer. Certainly it was last time: https://news.ycombinator.com/item?id=20680291 https://news.ycombinator.com/item?id=20680291. (Also, my own observation is that it’s regularly far more amusing to take jokes seriously, ignore sarcasm, and otherwise wrest humour.)
- deleted 6y ago[deleted]
- fao_ 6y agoI'm not really sure how a virus that can infect a server wouldn't also target linux desktop unless it's targeting SSH or Ampache or something. It would still have a chance at hitting poorly configured developer machines, and yet people barely experience them edit: lol at the article
- deleted 6y ago[deleted]
- grawprog 6y agoThat's too bad. I couldn't get past step 3. My system has unmet dependencies that are unable to be resolved.
- dylan604 6y agoIn Step 5, my check resulted in NSF_BOUNCE. I was eventually able to replenish, but then wound up receiving an 'ACH_DELAY = 3-5 biz days' message. I apparently have to wait before evilmalware is available on my system.
- grawprog 6y agoI finally got past step 3 and 4 with a CHROOT where I manually built all dependencies, skipped the tests after reading your comment, went to go straight to the make install but my distro's got a non-standard directory layout and that failed. I'm over this. Too much effort. I'm just going to install windows and click dodgy popup ads and any ok buttons that appear after.
- m463 6y agoYou might have to meet your spouse, then marry, then have a child. alternatively on debian-based systems using the package manager: apt-cache search spouse choose one, then: apt-get install <spouse-package> Note that this may add other required or recommended dependencies.
- grawprog 6y agoI tried that, now my system's totally messed up. The spouse package was fine, but the child one was only available in 32-bits so suddenly my system was full of 32 bit libraries, my x64 libraries were all autoremoved, I lost half the apps on my system. Now i'm just stuck here with this spouse and child on my computer, can't do anything fun any more. Lost all my games and it turns out the child is a daemon that runs in the background that sleeps and wakes at the most inconvenient times and now every time I try to run spouse -s It just prints 'I'm tired not tonight.'
- 6y ago
- dragontamer 6y agoThis specific joke worked better in 00s when GLIBC compatibility issues were far more of a hassle than today. But the joke still rings true today: not necessarily with GLIBC anymore... but maybe systemd vs initsystem, or XLib vs Wayland, and other such "non-backwards compatible changes" that seem to occur in the Linux world more often.
- ed25519FUUU 6y agoIs there any explanation for why backwards compatibility breaking changes are so common in the Linux world despite the fact that linux itself does such a good job avoiding it?
- Macha 6y agoAre they really especially common in the Linux world? UX: Windows 7 -> Windows 8 -> Windows 10 had some pretty drastic changes, even if a big part of Windows 10 was a climbdown. Have you followed the skeumorphic -> flat -> 3d again or Gingerbread to Holo to Material Design guidelines? Dev facing: How have your migrations to WKWebView, notarised builds, M1, the Mac App Store, away from kexts, etc. been? Did you get onboard for WinRT and UWP? You could argue in the Windows case you didn't _have_ to follow these trends, but you also didn't have to on Linux. Pidgin still works much the same as it did a decade ago. Thunderbird is still here and fundamentally the same as when I started using it as a literal child. You can still install MATE and XFCE and have pretty much the same workflow for desktop linux you had 20 years ago on Gnome 1, except with much much better chance of arbitrary hardware/software X working. In the Apple case, you have to follow their guidelines in a much sooner period.
- stelonix 6y agoAs code ages, people lose interest in maintaining. When you begin coding an application, you're usually adding features and that's fun, but as time passes and the software reaches its goal, you're left with finding and fixing bugs. That's no fun. Microsoft manages to do so because there's a money incentive for its employees, while free software has no such equivalent. That's why we see things like completely dropping X and writing Wayland from scratch: it's more fun and quicker for developer. Sucks to be us on the receiving end, though. I believe until this kind of thinking shifts, there's not gonna be mass adoption of GNU/Linux systems. People expect software to work and keep working 10 years down the road. The current state of the FOSS ecosystem is full of bitrot and rewrites, with zero incentive for developers to maintain code. Beats the hell out of me why there isn't a distro that allows you to give money to patrons of the packages you use. It's a real no-brainer.
- Darmody 6y agoHi. I'm trying to compile this virus but it says it didn't find any makefile? What am I missing?
- gpvos 6y agoTry ./configure --with-evil-intent
- m463 6y agoThe makefile?
- colejohnson66 6y agoMakefile* (don't forget the capital letter)
- wtfrmyinitials 6y agomake works perfectly fine with an all lowercase makefile
- colejohnson66 6y agoIt does, but the de facto standard (it seems) is to use a capitalized name
- clankyclanker 6y agoOr MAKEFILE. All 3 are perfectly valid.
- 13415 6y agoWell, it may be a joke but the number of times I've downloaded some source code, hit ./configure, make, and then sudo make install on my linux box without checking any of it is also a joke....
- Ericson2314 6y agoSwitch to NixOS! No sudo for your make install, at least.
- worik 6y agoSigh... ./configure --prefix=`pwd` : :
- throwawaygulf 6y agoAs the saying goes, viruses on Linux are hard to get right because you need to make assumptions about API/ABIs, libraries, required dependencies, etc. which is never assured across-the-board. Oh wait... Good desktop software needs all that too...
- Dylan16807 6y agoYou can just have a static binary......
- throwawaygulf 6y agoYou can't statically link a vulnerable process running with elevated privileges.
- simion314 6y agoThat would be a really bad virus that tries to depend on GNOME/GTK or some other library. Maybe you are thinking at those terrible web based viruses where an Windows XP themed popup appears that tells you that you need to download and run something to fix your computer. So it is harder for those guys to detect the correct theme to use for their popup to trick the user.
- danieldk 6y agoAs the saying goes, viruses on Linux are hard to get right because you need to make assumptions about API/ABIs The Linux system call interface is stable. Or if you want to go up one level of abstraction, glibc has great backwards compatibility (using versioned symbols). GNU/Linux viruses are fairly uncommon, because (virtually) no one uses Linux on the desktop. So, it is much harder to spread. (Disclaimer: not a bashing attempt, I use Linux on the desktop.)
- superkuh 6y ago>glibc has great backwards compatibility (using versioned symbols). As long as the virus or other software dev can restrain themselves from using the latest added features to glibc and c++??. Usually they can't so compiling something written with today's libs on a distro from 5 years is infeasible.
- m-i-l 6y agoAs a corollary, there was a very old joke that a Microsoft Windows virus would require that the user "Please insert virus disk 2" to complete the installation.
- jMyles 6y agoIf this were the actual explanation, don't we expect it to have substantially changed with the rise of apt/yum/snap/appimage/flatpak or any other technology which provides the virus with an end-around these steps?
- 2Gkashmiri 6y agoi have a bunch of viruses which i collected last year when i was under a 9 month internet blackout, propagated only in windows machines without internet access. at one point, i set up a "xp vm" on my kde neon, loaded an infected file and spend a good day figuring out where it was. turns out this particular virus saves a copy of itself in user/appdata folder in C, then opens a process with that name, "usually newfolder" and once a removable drive was detected, it would 1, move all contents into a " " folder (yes. a folder named as a single space, then put that folder as system hidden folder so that it gets hidden (and only visible if going into folder settings, show system files) then create new shortcuts to all old files which did 2 things, one, symlink style open that particular file and more importantly, copy the virus executable to the current system if not already present. it was a fun exercise. i had told a colleague, "either this virus survives today or i will". oh, there was one downside to another strain of this virus. if i deleted the autorun file, it would go ahead and delete the entire removable drive data. that was PITA the only reason this virus and similar others propagated so wildly during that time was because there was no internet and windows as far as i know, "expects" 24x7 internet connectivity
- indymike 6y agoMalware with a man page. The see also section is hilarious. The GNU Humor archive is full of gems.
- throw2838 6y agoNice joke, bit bs. Ever seen static binary or python script? And with recent sudo debacle, Linux security is joke..
- torcete 6y agoWhat I like about Nixos is that they make linux viruses reproducible!
- john4532452 6y agoThe only way i am aware of to assure no unwanted program is running(virus or not) is using the top "ps -e" command to monitor cpu activity. What if the virus modifies the ps command to hide the malicious process in the output ? How should this situation be handled ?