It completely owns that market. There’s macOS and iOS I guess, but they’re not generally available to install on third party equipment.
Linux, sadly, is just not at all a consumer OS and never became one. The security model alone is an unfixable disaster (and many have tried over the years).
Surely you are talking about Windows... :-)
It's executable by default, opens up in something like Eddie and just asks for a password.
Nothing about Linux is really more secure than windows other than the fact it is a small target.
Not sure what the example proves. The simple fact you can compile your kernel, have a strong model with Linux SE, it's just another ballpark.
Besides the fundamental aspect that Microsoft are telemetry kleptomaniacs, one OS assumes the user machine does not belong to the user, and Microsoft knows better. Linux assumes it's your machine and nobody else.
You can have your own hardened and lighter Linux kernel, with less surface exposure, while with Windows you start with whatever version version of Cortana Microsoft would like to push that week on it's users...Plus all the other unnecessary components that create an almost infinite opportunity of attack vectors.
Naturally for Linux, the open source code, makes for a more transparent process, even if I don't subscribe to the idea that more eyes on the code, correlates directly to higher safety.
The fact that deb extension is associated with an application (I don’t know what Eddie is) does not make deb executable. It’s like Winzip opening a zip archive on double click in Windows: yes, the file is opened, but no untrusted code has been run (assuming, Winzip is installed already and is considered trusted).
Linux is more secure because it has a much smaller attach surface. Even from the kernel interaction perspective, the number of syscalls in Linux is much smaller than in Windows, they are in a way more primitive and easier to audit. But the biggest distinguisher is lack of DCE (or MS) RPC - in Windows it’s ubiquitous, available both locally and sometimes over the network with various ways to access it (named pipes over SMB, DCE over TCP/IP, even over NetBEUI, over HTTP in some cases) which makes it hard to secure (Windows firewall is very complex as a result). Finally, Windows Carrie’s enormous amount of legacy and Microsoft is not interested in fixing it (they would rather push you to “cloud”).
Combination of code complexity and large attack surface makes Windows less secure that competition (although Pottering seems to be working on fixing it).
You literally just described an .exe or .msi.
- sandboxing
- root of trust hardware encryption
None of the above can be enforced at a distribution level, and where these features are opt-in they’re significantly underdeveloped relative to Windows/macOS/ChromeOS as no-one is using them in significant numbers.
I’m not even sure you could find any amount of FOSS advocates to even get on board with notarization let alone get it implemented.
You could maybe enforce protected folders at the distribution level but I don’t know if anyone could really trust a feature like that if it wasn’t implemented in the kernel directly.
If you feel adventurous you can eventually transcend dual boot to a VFIO setup that helps to keep your bare metal protected from Windows entirely.