4 ms·
Security isn't just about lack of buffer overflows. It's in the way users interact with the system, and the way they're encouraged to interact. In most Linux d
by fractalcat 15y ago
Security isn't just about lack of buffer overflows. It's in the way users interact with the system, and the way they're encouraged to interact.
In most Linux distributions, the user is encouraged (by the design of the system) to, in almost all cases, either install cryptographically-signed software packages vetted and maintained by the vendor; or download a source package and compile it themselves. In Windows, the user is encouraged (by the design of the system) to download unsigned binaries from all over the Web and run them.
That's why I'll never consider Windows to be comparably secure to modern Linux distributions. Sure, you can keep a Windows system airtight, but the way the system is designed makes it require effort, so users, in general, don't.
- epochwolf 15y agoApparently you haven't seen the latest trends in the ruby development world. Here's two examples I've seen lately. The first is for OSX only but the second is for *nix. curl get.pow.cx | sh bash < <(curl -s https://rvm.beginrescueend.com/install/rvm)
- drdaeman 15y agoRubyGems version 0.8.11 and later supports adding cryptographic signatures to gems.
- bad_user 15y agoI'm a Linux user and I do agree, but I do have to tell you - the lack of universal binaries that you can just download and install on a Linux workstation is one of the reasons Linux will never be as popular as Windows or even OS X. People want convenience over anything else. A computer has to be secure in spite of people downloading software from all over the web.
- xilun0 15y agoConsidering how i use computers, most of the time i found it far more convenient to apt-get search and 20s latter install (or the equivalent with the package manager you use) than downloading a random piece of software from a random internet site, which from this point might become a risk if it does not auto update, and if it does it's with a stupid yet-another rewritten auto update program that always uses 50 MB of RAM for just one program installed on the system, even when the program does not run. And considering the success of "app stores" and the general dislike of the traditional windows desktop computers by the general public (except if you are fool enough to help them for free doing all the busy work maintenance tasks that can't even exist on serious systems), I guess the centralized packaging and distribution model is also pretty convenient for the general public...