4 ms·
Absolutely horrible idea. Linux users aren't exactly in desperate need of protection from their computers.
by wfunction 12y ago
Absolutely horrible idea. Linux users aren't exactly in desperate need of protection from their computers.
- catern 12y agoSo, you run as root at all times? :)
- wfunction 12y agoYes? In fact I hate getting prompted for privileges/passwords/etc. I don't run antimalware either, neither on Linux nor Windows (permanent admin there too). I know what I'm doing when I'm working on the computer and I haven't gotten malware in years.
- weavejester 12y agoEven if you know what you're doing, do you know what your computer is doing? In detail? I have only the most general of ideas of what my computer is doing at any one time. I know that the software I was using one year ago was riddled with vulnerabilities that were undetected at the time. It seems foolish to assume that the software I'm using now doesn't have similar issues. I personally welcome anything that lowers my security risk. Sandboxing applications seems a fantastic idea, if it can be done without unduly affecting my workflow.
- wfunction 12y ago> Even if you know what you're doing, do you know what your computer is doing? In detail? It's just like a car. You don't have to know how your car's engine works to be able to tell tell when your car isn't running like it's supposed to. As for my computer, I know it in as much detail as I think is necessary for telling whether or not the computer is "healthy", so yes. (See my response to the other comment for more.)
- weavejester 12y agoYour computer can be compromised without demonstrating any visible signs of it. For example, a keylogging process takes minimal CPU and bandwidth (especially if zipped and batched), and could be inserted by an unknown zero-day vulnerability. It might be caught by a IDS, but the long and short of it is that there's simply no way of telling for sure whether or not a machine has been compromised or not. Security isn't an absolute; it's just a matter of how much risk you're willing to allow for convenience. Ideally you make it hard enough to compromise your machine that an attacker won't bother.
- wfunction 12y ago> Your computer can be compromised without demonstrating any visible signs of it. Yours can too. How do you know yours isn't?
- weavejester 12y agoI don't. Absolute security is impossible, all I can do is take precautions that minimise the risk. That's why sandboxing of apps seems a rather good idea: it reduces the risk without adding much inconvenience to the user.
- wfunction 12y ago> I don't. Absolute security is impossible Yeah then why do you suddenly jump when I tell you the same thing? To the best of my knowledge I don't have any malware, and to the best of your knowledge you don't either. Seems pretty equal to me, yet somehow you freak out when I say the same thing as you do. I'm pretty sure I'm at least as certain as you are that my system doesn't have any malware, so if that's not enough of an assurance for you then it shouldn't be enough for you either.
- weavejester 12y agoBecause regarding the sandboxing of applications, you said: > Absolutely horrible idea. Linux users aren't exactly in desperate need of protection from their computers. If you agree that your system can be compromised, why would you say that an extra layer of protection was a bad idea?
- ayrx 12y ago> I know what I'm doing when I'm working on the computer and I haven't gotten malware in years. And how do you know you have not got malware in years? Not all malware are of the flashy "pop up ads in front of you" nature. Running as root 24/7 is a ridiculously stupid idea, especially for a desktop, no matter how careful you are.
- wfunction 12y ago> And how do you know you have not got malware in years? Same way you can tell whether you're feeling healthy or sick. Same way you "know" something is wrong when your car stops running the same way it usually does. i.e., I can't prove it one way or another, but that doesn't matter. In practice, I mentally keep a tab on how my computer is running -- my computer's CPU usage, network activity, I/O activity, internet connection speed, etc. so I can tell when something's not going right. I don't keep crapware on my computer either, so when a process shows up that I don't recognize, then I can easily tell. I have notifications set up for newly-installed system services, so when a new service or driver is installed I get a popup for that too. Obviously, I can't prove it's malware-free, but who cares? I don't need to. I simply have no evidence in support of malware existing on my computer, so as far as I'm concerned, it isn't. Just like you can't mathematically prove to me that your car is OK, I can't mathematically prove to you that my computer is running OK. But that doesn't matter because I'm reasonably sure it is, and I have no evidence to believe otherwise. And that's really all that matters. And for that matter, it's not like I could be sure I didn't have malware if I did follow those practice either. It's just a tradeoff between the likelihood of malware and the amount of convenience you're willing to give up. You can never be sure, and you don't need to.
- ayrx 12y agoYou are missing the point. If malware has root privileges, and they will if you are running everything as root, all the signs you are looking for can be masked.
- scrollaway 12y agoYou may very well be running malware you don't know about. Things that report to the NSA or to some random botnet; stuff that replaces /usr/bin/ps and /usr/bin/top to hide itself, and so on. Yes, it can do that. Because you run as root. And, no offense, but seeing your judgement regarding root and you actually thinking that sandboxing is a terrible idea because "you know better", well... I wouldn't touch your judgement with a 3 meter stick, be it on feeling healthy or on your computer running malware.