3 ms·
> Even if you know what you're doing, do you know what your computer is doing? In detail? It's just like a car. You don't have to know how your car's engine wo
by wfunction 12y ago
> Even if you know what you're doing, do you know what your computer is doing? In detail?
It's just like a car. You don't have to know how your car's engine works to be able to tell tell when your car isn't running like it's supposed to. As for my computer, I know it in as much detail as I think is necessary for telling whether or not the computer is "healthy", so yes. (See my response to the other comment for more.)
- weavejester 12y agoYour computer can be compromised without demonstrating any visible signs of it. For example, a keylogging process takes minimal CPU and bandwidth (especially if zipped and batched), and could be inserted by an unknown zero-day vulnerability. It might be caught by a IDS, but the long and short of it is that there's simply no way of telling for sure whether or not a machine has been compromised or not. Security isn't an absolute; it's just a matter of how much risk you're willing to allow for convenience. Ideally you make it hard enough to compromise your machine that an attacker won't bother.
- wfunction 12y ago> Your computer can be compromised without demonstrating any visible signs of it. Yours can too. How do you know yours isn't?
- weavejester 12y agoI don't. Absolute security is impossible, all I can do is take precautions that minimise the risk. That's why sandboxing of apps seems a rather good idea: it reduces the risk without adding much inconvenience to the user.
- wfunction 12y ago> I don't. Absolute security is impossible Yeah then why do you suddenly jump when I tell you the same thing? To the best of my knowledge I don't have any malware, and to the best of your knowledge you don't either. Seems pretty equal to me, yet somehow you freak out when I say the same thing as you do. I'm pretty sure I'm at least as certain as you are that my system doesn't have any malware, so if that's not enough of an assurance for you then it shouldn't be enough for you either.
- weavejester 12y agoBecause regarding the sandboxing of applications, you said: > Absolutely horrible idea. Linux users aren't exactly in desperate need of protection from their computers. If you agree that your system can be compromised, why would you say that an extra layer of protection was a bad idea?
- wfunction 12y agoBecause I'm almost certain that it will cause some kind of inconvenience down the road. It's unlikely to be "free" -- no OS-level security feature I've seen has been "free" in terms of convenience.
- weavejester 12y agoJust off the top of my head, hard drive encryption is an OS-level security feature that's reasonably "free" in terms of convenience. But even if all previous efforts have failed, which I really don't think is the case, trying to improve security is surely a laudable goal. And even if you would consider sandboxing to be inconvenient, there are plenty of people who'd love to have something like that. Right now, if I open up an application, I have no idea what directories it's accessing or servers its communicating with. Forcing an app to tell me whenever it wants to access something new would be fantastic, and as a side effect, it would put pressure on application programmers to reduce the number of privileges they ask for.