3 ms·
I wonder if those supposedly secure Linux distros are actually secure. Anything from MS, Google, and Apple cannot be trusted.
by deregulateMed 5y ago
I wonder if those supposedly secure Linux distros are actually secure.
Anything from MS, Google, and Apple cannot be trusted.
- deleted 5y ago[deleted]
- ipaddr 5y agokde linux is popular.
- Anunayj 5y agoWell unless you are building everything from source (after auditing software), you end up trusting someone for the executable (packaged by distro maintainers). Distros like Gentoo solve this pretty well by giving a good suite of build tools, Nevertheless it's too bothersome for most users. Arch distributes it's package signing abilities to multiple maintainers who can revoke each other's keys. which imo is better than trusting a downloaded exe signed by Microsoft. Open source has one really good benefit, Having more eyes on the code, which means less likely a bug goes undetected. It also means reduced effort for finding bugs. Though imo Linux is arguably more safer because if it's smaller surface area. I think Linux (with additions like AppArmor/SELinux) is definitely more than enough for most high profile people. That coupled with Good Security practices (not running untrusted binaries, using end-to-end encrypted mediums for communication) imo should deter 99.9% of those surveillance attacks.
- squarefoot 5y ago> Open source has one really good benefit, Having more eyes on the code, which means less likely a bug goes undetected. This a million times. The concept is so simple it doesn't even need proof or examples as solid arguments, but just in case, here's one: the famous Interbase backdoor. Interbase was a database engine by Borland. In 1994 some developer added a hardcoded credential backdoor to ease development, but forgot to remove it in production. The backdoor wasn't malicious, yet still dangerous as it gave administrator privileges to anyone; it went unnoticed for about seven years and multiple versions of the product. In mid 2000, Borland released Interbase as Open Source, and within six months the vulnerability was discovered and fixed. https://www.schneier.com/essays/archives/2001/03/back_door_security_t.html https://www.schneier.com/essays/archives/2001/03/back_door_s...
- rannor 5y ago“more eyes on the code” Unless the code is coming from the University of Minnesota. :)
- pabs3 5y agoEven if your software is secure, that does not mean it is private. For example there are all sorts of privacy violations in Debian: https://wiki.debian.org/PrivacyIssues https://wiki.debian.org/PrivacyIssues