5 ms·
>Say what you want about Debian's volunteers, but they're a hell of a lot more trustworthy than the average windows software download website. Really? Software
by whyoh 3y ago
>Say what you want about Debian's volunteers, but they're a hell of a lot more trustworthy than the average windows software download website.
Really? Software developers, who distribute through their websites, have an economic incentive to not give users malware. I'm not sure the same applies to Debian's volunteers. I don't even know who these volunteers are.
- mcpackieh 3y agoAverage windows user does a websearch for software and very often finds not the first-party website operated by the developer, but instead finds websites like sourceforge, cnet, softpedia, etc. Downloading sketchy freeware from third parties is Windows culture. This culture is encouraged by Microsoft not vetting and packaging free software themselves like Linux distros do.
- _gabe_ 3y agoI don't know where you've gotten the idea that Windows will just run whatever software you provide it without saying anything. Executables must be signed with a trusted CA. You can get this trust by buying a CA and waiting for reputation to build (which means any malware you produce can be tracked back to your business), submitting the software to Microsoft for malware analysis, or waiting a very long time for reputation to build[0]. If your executable doesn't have trust, a scary warning pops up (or Windows blocks the app from running) and tells the user Windows Defender SmartScreen prevented an unrecognized app from starting. Running this app might put your PC at risk. This seems about as effective as having a bunch of random people vetting packages for a Linux distro. [0]: https://stackoverflow.com/questions/48946680/how-to-avoid-the-windows-defender-smartscreen-prevented-an-unrecognized-app-fro/66582477#66582477 https://stackoverflow.com/questions/48946680/how-to-avoid-th...
- deleted 3y ago[deleted]
- mindslight 3y agoSure, if by "scary warning" you mean the click through nags that Windows pops up early and often (sometimes multiple times for a single action) and that have trained generations to ignore software warnings and dialogs in general. I honestly just installed my first non-throwaway Windows VM in a long while, and I was appalled how the state of the art in Windows "security" is still stuck where it was a decade ago.
- shortrounddev2 3y ago> Downloading sketchy freeware from third parties is Windows culture No, it's "computer illiterate" culture. Windows has a few package managers available these days (including a first party one). Developers on windows install things the same way that linux users do, though not usually building the software along the way (though I often have to use cmake with visual studio)
- ryandrake 3y agoNot only that, but for a while, a lot of Windows developers had links to sketchy mirrors right on their own web pages! They've normalized sending users to sites with names like DonkeyMirror.ru to download their official ZIP files.
- raverbashing 3y ago> Really? Software developers, who distribute through their websites Yeah, then some company installer-hijacks your software and SEOs your site. Case in point, VLC (for Windows of course)
- 6c696e7578 3y ago> I don't even know who these volunteers are. They're probably on here, reading your comments, or reading LWN. You have more chance of reaching a DD and reading their work than you do of reaching a commercial software author.
- mindslight 3y ago> Software developers, who distribute through their websites, have an economic incentive to not give users malware You're putting way too much faith in the efficient market fallacy. In reality, proprietary software companies are incentivized to distribute malware to increase their own control and their bottom line. Prominent examples being BonziBuddy, Sony Rootkit, Denuvo, all the crapware that comes bundled with Android/Windows, web ads, web surveillance, etc. Like every other day there is a new HN topic about how some company violated the trust they had built and screwed over users.
- ilyt 3y agoAnd how user is supposed to know that the company is a trustworthy company just selling their software and not a scam ? Single Debian volunteer would have to do quite a bit of work to get into position of being able to just push malware into the repo; and if they did it lands in debian unstable/testing so there is also a pretty good chance it would be noticed.