4 ms·
Respectable linux distros(not just android!) use SE, sandboxing etc. Windows lags far behind OS's like Android, iOS and even ChromeOS when it comes to security
by CyberRage 5y ago
Respectable linux distros(not just android!) use SE, sandboxing etc.
Windows lags far behind OS's like Android, iOS and even ChromeOS when it comes to security.
- pjmlp 5y agoPity that CVE database proves otherwise. Where are the driver validation tools with a Z3 theorem prover for Linux drivers? Where is the SAL static analysis for C and C++ kernel code like Windows has since XP SP2? Where is the majority of userspace code implemented in managed languages like .NET?
- CyberRage 5y agoYou can clearly see that from data. looking at 0-day disclose, black market exploit prices and attacks in the wild. 0-day exploits for both iOS and Android are 3 times as costly as windows. You're looking at linux as it is but linux as it is not what you should compare it to. Android\iOS or even something like Red Hat should be the comparison point.
- pjmlp 5y agoI see it from CVE database. Naturally I look at GNU/Linux, that is what average Joe gets on their computers. iOS is not Linux thus not even part of this conversation.
- CyberRage 5y agoAlso Android\iOS in general as a platform is more secure, Android\iOS are far more restrictive when it comes to users. narrowing the attack surface for casual users. For instance, rooting in order to install custom drivers\software is very difficult. A single place to download content(App store) which provide tremendous control over content. detection of rogue apps, removal once they turn rogue, check assurance. Seamless updates through a single pane of glass.(App Store again)
- pjmlp 5y agoPity that almost no one uses them as desktop platforms. Windows store and Windows Sandbox is way more advanced than any GNU/Linux offering, including kernel and hardware sandoxing with help of hardware protections. Still waiting for snap and flatpak to finally fix their security holes.
- amluto 5y agoThe Windows sandbox infrastructure may well be more advanced than seccomp in the sense of being more complicated, but I would argue that makes it worse, not better. There are many sandbox escapes based on the insane complexity of Windows integrity levels. In contrast, there have been maybe 5 known Linux kernel bugs allowing a breakout from a strict seccomp policy in the last few years.
- pjmlp 5y agoWhat hardware vendor does sell GNU/Linux systems already pre-configured with such policies?
- Craighead 5y agoPity that you don't know
- amluto 5y agoWhat hardware vendor sells the Windows sandbox preconfigured with policies? Chromium and Firefox configure the Windows sandbox and seccomp on Windows and Linux respectively. I would argue that seccomp is better. On the other hand, Windows has its app sandbox and Linux has snap and flatpak. I don’t think any of them are amazing.
- RyanPringnitz 5y agoI work on a use case that leverages Samsung DeX and secondary displays with keyboard/mouse. Applications are refactored to run on native Android, or accessed on HTML5 sites. What Win32 is left is accessed on VDI. The solution supports MFA step-up auth to login to device, local print, proxy's traffic, per app vpn. Endpoint threat detection products for Android have more capabilities than ever. You can specify approved IP addresses, countries that traffic can communicate with. You can provide a list of approved WiFi BSSID. With these mobile security SDK's embedded in native Android apps, functionality with the apps can be limited based on threat infractions. E.g. - if the device magically became rooted while authenticated in android native app, or connects to rogue BSSID; the app performs whatever actions (terminates vpn to intranet, logs threat event on public facing endpoint, force re-authenticate with MFA.)