Is the Linux Desktop less secure than Windows 10? [pdf]
fosdem.org
fosdem.org
Also, it seems to be file types that would never be automatically parsed on Windows or Mac. I mean...a Nintendo music file? Why on earth would the desktop environment need to do that? (And, I say this as someone that composes chiptunes and enjoys listening to them, but I don't need my desktop environment to grok them).
And, I guess I like that Linux does things out of the box that Windows and Mac need third party apps for (much less so, today, but still a factor I notice when I reboot into Windows). But, maybe this is overkill?
And, yes, I think it's clear that Microsoft made a significant investment in security a decade or so ago, and it has paid off massively. Windows is remarkably more secure, stable, and reliable than it was a decade ago. I still prefer Linux, but the case for Linux over Windows is nowhere near as compelling and clear cut as it once was.
My only interaction with "Tracker" has been to figure out how to disable it and get it off the system, as it was doing god-knows what and pegging processors. I can (and do) happily exist without apport.
I know this doesn't make me safe per se, but I do think that in becoming more windows-like and 'integrated' we end up with these unintended consequences.
No, it generates thumbnails outside the main UI thread; sometimes it's a bit slow in so doing, but I've never seen it hang an Explorer window, regardless of file size or quantity. (Windows 7, but it would astonish me to learn that 10 displays a regression here.)
One is to optimise view for general, not images or video or sound.
Another is to "reset your folders"
http://superuser.com/questions/1097394/windows-10-download-f...
That said, even the slowness under discussion doesn't actually hang the UI thread. That's something you have to be pretty special to get so badly wrong, in this day and age where even web devs are learning better than to do expensive work in the main thread, and have the tools available to avoid doing so.
I generally prefer Details view myself, but know no reason why this shouldn't work for List or any other. Enjoy!
They're also buggy, XFCEs thumbnailer thumblerd (also used in LXDE and probably others) used to have memory leaks when it encountered video files with unknown codecs, newer versions re-scan the entire cache every time you delete/move a directory, making quite a bit of disk IO.
I've found simpler file managers like rox-filer, pcmanfm to be much faster at thumbnailing.
As an example of the contrary, I've seen misbehaving third party thumbnail-providers cause Windows explorer to crash entirely.
Only way to "fix" it was to install the software which added the thumbnail-provider, or go into the folder via cmd.exe and rename the file you "knew" caused issued to a different extension while doing the operation you originally came to do.
That may have been on Windows 7 though. I don't know for sure if this weakness still exists in Windows 10.
I'm just saying that I've seen bad things happen on Windows too. Not blaming Microsoft, just saying that in a typical end-user scenario with lots of randomly installed software, you will have Explorer break too.
Basically the grass is rotten everywhere :)
macOS is also very chatty, but privacy is usually given more consideration. Not at all as bad as MS.
Definitely not my feeling last time I upgraded macOs: I had to give my full name, address, * phone number * and * * bank details * * while the upgrade is free of cost.
I don't like having these details hanging on server somewhere on Internet when it is not needed.
I felt like my profile was given a lost of consideration by Apple, not my privacy.
... But when installing or downloading MacOS, with the current (tested in January this year in Europe) Apple policy, the system will not let you continue with a 'none' payment method.
Try opening /usr/bin and it takes longer than you would expect.
From what I remember nautilus does excessive stat calls, looking for thumbnails - it could definitely be much faster.
KDE in general has been in good shape, better than GNOME 3 in my opinion. I've been using GNOME 2 and GNOME 3 (up to 3.8 when they completely got rid of fallback mode) for about 10 years, always felt that Nautilus as a file manager was basic and useless.
I switched back to KDE 4 (AFAIR it was 4.10 at that time), the desktop search and index implementation - NEPOMUK (what a bad name) had big performance issues when doing the inital indexing and when it does periodic indexing the desktop simply choke. It took a while to search for tips and best practices to settle it down. Later on I decided to completely disable that as I don't need it...
Later on KDE switched to a new search and indexing engine called Baloo, it seems that the design is better and configuration is more straightforward but I still cannot justify, disabled ;-)
In short, have been running Linux as my main desktop / workstation OS for 15 years, I come to a conclusion that OOTB (most distros) setup is not ideally optimized and secure for Linux Ninja, it takes time and effort to tune the system to suite your personal standard / taste (Now I run Arch Linux on most of my devices).
https://www.blackhat.com/docs/us-16/materials/us-16-Weston-W... is a good reference for all the stuff that Desktop Linux in 2017 is for the most part, missing
Or you can do nothing, in which case you're probably less secure.
---
[1] https://wiki.ubuntu.com/AppArmor
[2] sudo apt install apparmor-profiles-extra
I don't know anyone in my immediate circle of peers - not even people who use SELinux on servers or in products that they develop - who doesn't disable SELinux on their desktop. They're not idiots, either, nor re-booted Windows programmers that the IoT and DevOps craze has thrown into the Linux world, many of us have been using Linux since back when there was no E in RHEL.
I feel like there should be a way to write a new set of simplified tooling on top of the kernel API.
I've been running fedora at home an on my laptop for about a year now, and don't need to turn SElinux off. I only needed to add one custom role myself too, when trying to mount certain host directories as volumes in docker. Which is fair enough.
Not only do you get security updates for your distro with the vast majority of Linux distros, but you also get it for all your 3rd party software, using the same system mechanism.
They may not push the updates automatically, (you can of course set it that way), but some of us still want to be in control of what gets installed on our machines
That's not to say it can't be improved, but the situation isn't quite as bad as you are painting it, ie there are mainstream distros that come hardened by default and security patches are regularly backported.
I'd argue that macOS is also technologically less secure than modern Windows, yet its users are in no more danger than Windows users are, (despite its theoretically security), because security depends on a lot of factors including the user culture, market share etc. i.e. Linux doesn't have a culture of downloading executables from random websites for one.
I'd guess most distributions feel like they're providing an adequate level of protection for their users as of now, without introducing too much friction. Once that is no longer the case, it's easy to turn on a few more knobs, the software is already there.
Why is getting the latest security updates giving a false sense of security exactly?
> The File Manager UI, for example, lacks too many features and user must investigate alternatives and either assume that everything is all right or deeply examine security vulnerabilities for each available option. Same goes for basic things like text editor or calculator and so on.
This is where you're being unfair, the notion that the default file manager is not good enough is subjective, it is plenty good for most people.
(Finder for macOS also lacks many features, yet many people never bother with alternatives).
Moreover, if you do need to find a replacement, if it is in the official repos, it probably means it is popular enough to be solid.
As for things like an editor,, are you telling me that Notepad is more featured than gedit?
Because in quite a few distributions you don't get security updates reliably. For example Debian Stable excludes most WebKit-based libraries from their update policy.
https://www.debian.org/releases/stable/amd64/release-notes/c...
So users of browsers like Midori and Epiphany or E-Mail-Clients like Evolution on Debian Stable, currently end up using a WebKit library that hasn't been updated in more than a year.
The same issue applies to Ubuntu and most of its derivatives as well. E.g. Ubuntu 14.04 users get a WebKitGTK+ library which hasn't been updated in almost a year.
http://changelogs.ubuntu.com/changelogs/pool/main/w/webkitgt...
Of course, the user doesn't get a warning dialog when he installs applications which rely on those outdated and insecure libraries.
Ubuntu users also shouldn't rely on packages from the Universe repository (which are by far the most packages), if they care about security. Those packages are community maintained and often don't get a single update in years. In the past they didn't even update Chromium reliably.
BTW, it is possible to check in Ubuntu which packages are supported or not: http://manpages.ubuntu.com/manpages/xenial/man1/check-suppor...
How many times will this have to be repeated? Stable is for servers. If you're running webkit based libraries on your server you have other issues. For desktops, both Testing and Unstable are the valid options.
If you check the Debian web site you'll see stable is the only one which is offically supported and recommended by the project and there is no distinction for "server" or "desktop" use cases. Had stable was non-suitable as a desktop OS you can be sure Debian developers wouldn't bother releasing and supporting thousands of desktop/graphical packages with the stable release.
In the end stable, testing and unstable have all their pros and cons, strong and weak areas and some are more suitable for some use cases. That Debian stable is only for servers and it is not a good desktop OS is a myth that needs to die. Stable is a damn fine desktop OS. Everyone is free to use whatever they deemed best for their use but when you post blanket statements like "You. Are. Not. Supposed. To. Install. Debian. Stable. On. A. Desktop. Machine." and "Stable is for servers" on a public forum you are spreading misinformation and you should just stop.
Linux Desktop is not secure by default for the same reason Secure Linux does not offer the best desktop experience: more secure means less convenient. Desktop Linux aims at being convenient.
Also keep in mind, we are comparing a single Microsoft OS to a variety of Linux distros each with its own default. it would make more sense to compare all of those individually to see how they fit to a couple standard threat models. Then put them through a week of everyday use by a not knowing better user and see how much damage the different OS sustain.
Basically this scenario comes to mind :
a) A power change occurs within a government. This power change facilitates the changing of laws.
b) A corporation with massive stores of information about individuals is within this government.
c) New government doesn't like X people because they aren't Y people. New government coerces corporation within legal boundaries to fess up data on X people.
d) New government does horrible things using list provided by and facilitated by corporation, through no direct fault of that corporation other than the happenstance of existing within a country with ever-changing laws and regulation.
It depends how deep your desire for annonimity is...
It all depends on your threat model and how wanted you are as a target.
[1]: https://www.engadget.com/2017/01/26/trump-signs-executive-or...
1 - (https://jezebel.com/5887363/creepy-cops-use-dmv-database-to-...
Russian hackers, past, present and future, routinely steal information and use it against the victim, whether we're talking about individuals or corporations. And I'm just talking about login credentials or credit card information, nevermind more personal data like phones or even intellectual property.
Microsoft hasn't done any of that, as far as I am aware.
Let say we had two such machines and gave them each a reachable ip address and let the first test just be them running unattended until unwanted software got in.
In the second experiment we had the same machines go to random websites (top 1k), clicking randomly, using the default web browser.
In the third, we let them click and run attachment from email spam.
In the fourth and final experiment, we hire pen testers to target the machines explicitly.
With the same conviction that xpaulbettsx wrote, I have no doubt that the first 3 tests would show Windows 10 going down first. The amount of threats that targets window user is just order of magnitude more than those targeting linux users. The fourth test might give different results, but users who want to defend against targeted attack are generally advised to use extra security tools to defend themselves.
We should take the metric of "given a motivated party, how difficult would it be to exploit this machine" I have no doubt people are already sufficiently motivated to exploit Windows. But maybe only the NSA gives a shit about Linux- do we leave them unchecked?
9 connect to Modern Windows apps, 1 for ICMPv4, 12 for ICMPv6, 1 for IGMP, 1 for ISATAP, 12 for TCP, Cast to device, IPHTTPS, Network Discovery, WiDi. 15 UDP: 2 for Cast to device, 2 for DHCP, 1 for Teredo, 1 for Delivery Optimization, 1 for mDNS, 7 for network discovery, 1 for miracast.
Example: Being in an armored car in a war zone is still more risky than riding a bike in a peaceful country side, even if the bike has significant less security than an armored car. The Advice then is not to tell people in war zones to get bikes, nor is it to tell people to get rid of bikes in favor of armored cars. Security needs to match the need, which depends on the threat level.
In my above post I included "targeted attack" as the fourth test, named by security theory as an attack by a motivated party towards a specific resource. If a motivated party wants to attack a specific resource, then the defender needs to raise security above that of general security. Many government agencies have policies based on such threats, and neither a default Windows 10 or default Linux distribution would qualify for such environment. SELinux however was designed for that threat level and is thus common in military organizations, banks, and similar high risk environments.
When your threat model includes Microsoft or US surveillance then no Microsoft OS can provide you the security you're aiming for.
Then again Desktop Linux is no OpenBSD or GRsecurity[1], A hardened linux experience usually doesn't come out of the box with Desktop Linux, but still there are options to explore[2] if you're so inclined.
[1]: https://grsecurity.net/ [2]: https://wiki.archlinux.org/index.php/Security
/sarcasm
I think you mean a new distro which is mostly, but not entirely yet another a Ubuntu-derivative, which comes packaged with its own DE and related software.
And no, this new and perfect email-client will still not try to beat Outlook by managing both email and calendar at the same time. Go away!
Seriously... What are Linux Mint and ElementaryOS even thinking?
The desktop environment itself is but a small part of the complete desktop. Some important differences between those specific desktops are are: 1) Clicking a file both runs the code and opens the file, and difference is hidden from the user. 2) Mail clients start pretty much any software automatically to open attachments. 3) Office software runs code embedded in documents with just a user prompt. 4) A lot of plugins are active by default. Flash and ActiveX used to be, but this is better now. 5) Code is run automatically on removable media insertion. 6) Users download software from random web pages instead of vetted archives.
These things are not technical but behavioral in nature and make desktops ownable. I hope the Linux desktop never emulates them. Web browsers have gotten so much better but one simple thing they could is stop downloading things automatically. That save dialog won't scare anyone, and users will stop having lots and lots of unknown files in their download directory.
Loads of browsers do download automatically. Making things inconvenient and delegating security decisions to the user isn't good enough. Make it convenient and secure!
PS/Edit: Btw, under Windows 10 loads of things are indexed. It makes things very convenient. You use your pc like Google. Instead of knowing exactly where things are you just "Google" for it. With that I mean it has a good working search that's also really quick in giving accurate results.
I'll put in somewhere in the middle of my "mildly interesting to maybe know" research list.
Windows 10 experience: you press start then type in a few letters and you already get good relevant results. This completely different from locate!
I can't count the number of times that I was in the middle of writing a sentence, a dialog showed up, I accidentally pressed space bar and I was left wondering WTF just happened.
Sadly the big ones are. Because they consider this behavior "user friendly".
At the same time they think they can contain the threat by wrapping everything in sandboxes. Effectively infantilizing the owner/user of the personal computer.
Microsoft had those problems, too, when they introduced their own indexer with XP. Doing desktop support for slow XP boxes, you rapidly learned to disable the indexer first. But by roughly mid- to late Vista, it had ceased to be a general problem. (Maybe earlier; I had ceased to be closely involved with support by then.)
The other thing about an indexer like this is that you need it well integrated into the UI to get the benefit. macOS has Spotlight, which is excellent. Windows has Start search, which is OK for programs if you don't misspell the name, and tolerable for documents if you use the MS default home directory structure. I haven't used desktop Linux since Ubuntu 8 or so, so I don't know what it has, but if it is indeed a Spotlight-like experience they're shooting for, file indexing is just the start.
Except ofcourse in the 100% theoretical, never ever seen in the wild, case of bugs in file-format parsers. It's not like Linux's "file" or "strings"-utility[1] has had a local exploits in the past or anything.
Uhm... So yeah... About that....
Back in the real world, this is a very real attack vector. Especially when it runs in the background on a large batch of files, automatically and unasked for.
Note: I'm not saying I'm against indexing content for easier access and help locating files. I'm just saying that you can't simply dismiss it as a security-risk because it runs in the background.
[1] http://lcamtuf.blogspot.no/2014/10/psa-dont-run-strings-on-u...
As the slides may not tell the whole story (there should be a video soon), I covered this mostly also for LWN recently:
But I shouldn't, they found bugs in software I use daily (ffmpeg for example), it would be relatively trivial to make me execute something with it, since my brain is trained to 'exes as threats' not mp3s.
I work on several C programs. I wish for the day when we have an easy to use, cross platform method of setting up a small set of open files at the start of a program, then be able to say "No more file access, no more network connections".
I know this hides a whole bunch of complication, which is why it's hard and why there are so many ways to do it -- I view it the same way as the move to distinct virtual memory spaces for each process. Once we have it we'll wonder why we ever allowed every program free access to the whole file system for it's entire life-span by default.
> say "No more file access, no more network connections".
Looks like you're advocating OpenBSD's pledge(2). http://man.openbsd.org/OpenBSD-current/man2/pledge.2Hopefully someone (and it won't be me :) ) will write a library which looks like pledge but wraps all the various things in different OSses (I hear words like seccomp on linux)
Sadly that's a huge change in programming and security model for most and wouldn't be an easy change to make.
Just thought it was an interesting approach I'd share.
You could potentially use setrlimit on RLIMIT_NOFILE to limit your number of open files.
Although... you probably still want to display something to the terminal which means you still want stdout and stderr, so an attacker could just close stdout and stderr before doing whatever they wanted with their 2 remaining fds.
on linux the low-level building blocks that can achieve similar are seccomp and namespaces, but the only abstractions that I am aware of involve separate launcher processes like runc[0] or firejail[1].
A library providing similar functionality to pledge that could be added during application startup or when doing fork+exec would be great.
[0] https://github.com/opencontainers/runtime-spec/blob/master/c... [1] https://firejail.wordpress.com/features-3/
Say, does a default Windows install still enable 20 networked services that don't belong on a home computer and can be exploited without the user downloading anything?
My default installation came with VLC, firefox and KDE. No gstreamer nor gnome installed, google products including Chrome are not welcome. Though I'm pretty sure manjaro is part of the Desktop Linux family.
Too bad this misrepresentation is hurting the message OP is trying to carry to the world. Then this message is hardly news, the guys at grsecurity have been at it for 15 years providing hardening security patches to the vanilla kernel.
I dislike this idea that the Linux desktop is all Gnome and systemd, too, but the situation is pretty disastrous. Things that have an X in them, from X11 to (especially...) XDG shouldn't be trusted too much...
Seccomp (bpf version) is only available since 2012 really, but I hope more apps will start picking it up. It's pretty simple it should become a shameful thing not to use it in new apps.
Look at the hoops that adversary resistance focused distros like SubgraphOS have to jump through just to mitigate the giant attack surface that X opens.
Until Wayland becomes the usable default standard, "Linux Desktop Security" is an anachronism.
systemd offers various methods to restrict daemons in their abilities. That's hardly used. Only recently tracker started sandboxing their indexers. Why block adding other security laters on Wayland? There's no need to wait, nor do these layers depend on another.
You dislike GNOME.. meh.
I seriously doubt it's like you say. It's probably a lot more like a "custom made distro" that's based on Ubuntu as Linux Mint is based on Ubuntu: all the core stuff exactly the same, and a few things on top different (namely the DE in the case of Mint).
From the dpkg-buildflags manpage:
> Additionally, since PIE is implemented via a general register, some architectures (most notably i386) can see performance losses of up to 15% in very text-segment-heavy application workloads; most workloads see less than 1%. Architectures with more general registers (e.g. amd64) do not see as high a worst-case penalty.
Is this the reason why the adoption of pie is so slow? Does rust enforce hardening techniques?
>KDE has baloo
Again, not every Linux user uses KDE. That's like saying Windows 10 is less secure because of Total Commander[1].
Then, there is no "one" Linux desktop. You have different X servers, different window managers, different desktop environments...
In Windows there's only one of everything, the configuration is less flexible in terms of what things you can disable, and once something is vulnerable that's it.
e.g: Vulnerability in fonts being rendered on the kernel? What can you do about it exactly? Nothing but to wait for updates... but then the Flame malware installed itself via Windows Update. It's fantastic.
Things like data at rest protection seems to work better on Linux; as far as I know, there aren't out of box solution for Pre-boot authentication for Windows, for instance.
Edit: To the latter point, it looks like BitLocker has the mode to allow that, if you have Professional/Enterprise with TPM...
I have a pretty strict AppArmor profile for Evince (AKA Document Viewer on GNOME-based DEs), so I thought that automatically downloading PDFs and opening them in Evince instead of in the web browser would be safer. I didn't even thought about this kind of attack surface.
Also: if one desktop doesn't check SSL certificates and the other desktop does, then one desktop doesn't even enable the user to be secure. Checking SSL certificates is a pretty recent thing btw. E.g. various mail clients accept any self signed certificates silently.
$ wget http://example.com/foo.tgz && tar xf foo.tgz && cd foo && ./configure && make && sudo make installOf course, end users will just click OK on the elevation request, but regardless, it's not a fair comparison. Downloading random exes off the internet is more like 'curl | bash' ('still bad' level) than 'curl | bash | sudo' ('are you insane?' classification)
To elaborate a bit: most of the times, you don't have to sudo-install. If you're someone savvy enough to use a command line and understand these commands (if you enter them without this knowledge you're just plain stupid and nothing will save you), then there's no problem: you are the firewall, and you apply the level of caution appropriate for how much you thrust your source.
Betteridge's law of headlines: https://en.wikipedia.org/wiki/Betteridge's_law_of_headlines
Probably this list: http://distrowatch.com/search.php?category=Desktop
An internet-distributed one would be pretty futile, but a diskette-spreading one aimed at a lab with several macs could be pretty successful.
Anyone care to define default outside of Ubuntu?
I run OpenSUSE and have it down to just a tiled window manager, terminal and FireFox.