“Computer security 80% solved if we deprecate technology shown in this graphic”
twitter.com
twitter.com
The only other alternative is turning your computer into a glorified phone (a.k.a. a locked-down media consumption device) where everything is nicely sandboxed and nothing has any kind of permission to do "bad" things. (Except tracking. Because guess what, the company who makes the OS also sells ads.)
Linux has a wider attack vector since there are tons of packages out there. Yet the core has a lot of attention and many eyes on it, just because it is so open.
Vulnerabilities get patched rather sooner than later. Linux versions and gnu packages are running basically the entire internet, so there is definitely incentive to break into into it.
It's also a lot clearer in linux when a process is doing something it shouldn't, since it's a lot easier to probe into it to check what's going on.
The dataset is quite small, but on average it took Linux 25 days to fix a 0-day while it took Microsoft 83 days.
Edit: I don’t know much about this topic, but thought “time to deployment of a fix” might be more useful. Edit again: also unclear if the comparison is “apples to apples”.
Something that's been widely discussed elsewhere is how often security issues are silently fixed in Linus's repo and therefore not picked up by distributions for their stable/LTS releases.
I buy the immediacy of patches if you compile your own kernel from the latest kernel.org sources, not if you're relying on distributions.
Is this true? It's been a while but I remember being able to set performance monitors on almost anything in Windows. It seemed to have very robust instrumentation support.
Nit but you probably mean attack surface. A vector doesn't have a width.
Unless they're in the file systems, in which case it's in the too hard basket.
There’s a third alternative: keep the platform powerful but increase the default isolation level for third-party software and let the user choose what permissions it has. macOS is headed in this direction. Qubes is a more radical example and I think probably the future of desktop computing: everything will run in its own virtual machine.
That's the direction Windows is going as well with the MS-Store and appx/msix bundles.
There's also Process Memory protection by using virtualization https://support.microsoft.com/en-us/windows/core-isolation-e...
Either with VM isolation or packed away in a container. Host is basically a hypervisor with external monitoring and logging.
Then of course apps simply get sloppy in requesting permissions.. and in return malware pretends to do the same.
The end result is now doing anything takes a half dozen prompts and isn't any more secure. It just sucks for me as a user.
Windows ... well my expectation is low with regards to phoning home and security defaults.
Considering Apple was brazen enough to name the software that phones home "Gatekeeper" it is all too clear why they do it.
https://support.apple.com/guide/security/gatekeeper-and-runt...
The collective brain damage from a 500ms+ start menu has probably already placed us into a fatal death spiral.
Not saying you can't make an OS secure AND fast, but it definitely seems challenging if you also want to keep support for applications written 20 years ago.
Now there's the Windows Sandbox, which tries to provide a strong security boundary through virtualization while still having the kernels cooperate on performance-critical matters (memory, CPU time and graphics).
Over time someone (maybe even Microsoft) could expand that to a Windows-based QubesOS-light. Having the user segment applications into containers (with temporary containers for sketchy stuff) but allowing all applications to show windows in the same Window manager might be a viable tradeoff that fills most security needs without breaking compatibility with any software.
- MS tried to use it to force developers to distribute their apps through the Store
- Eventually they gave up and let people use it outside the Store, but didn't invest enough in bug fixes and backporting the fixes, so it's impractical to use outside the Store
- It requires code signing outside the Store which is a huge pain
For a while, Microsoft tried to insist that Store apps were UWP apps, but UWP was basically a new OS platform and not really backwards compatible at all. By then though most Windows code had been written and wasn't being rewritten due to new development, so this attempt to get people off Win32 failed. Devs just rejected the store instead.
Project Reunion tried to fix this by bringing together the UWP and Win32 worlds. As part of that MSIX did indeed become available outside the app store and for Win32 apps which run as "full trust" i.e. with all permissions, and it was indeed unfortunately quite buggy. However, some bugs are fixed and others can be worked around. Conveyor [1] is a packaging tool (disclosure: made by my company) that can make and sign MSIX files from any platform, and it works around those bugs so you get a reliable install experience and of course, all the nice MSIX features that motivated the technology in the first place like Windows keeping your app up to date in the background, delta upgrades, sharing of files between different apps, clean uninstalls, being installable without admin privs and so on.
You don't have to code sign apps, btw. If you're OK with requiring admin escalation then Conveyor will self-sign your MSIX and install the relevant cert using a small stub EXE that the user invokes. This lets you get the MSIX feature set without paying for certificates. It's not really recommended though for anything except open source apps, as virus scanners will molest your processes in various ways.
That said, getting into the MS Store costs $19 for an individual and then MS code signs it for you, so it's cheap and easy. Conveyor can also release through that, including from Linux/macOS, after you get approved, but the approval process is more of a handwave these days than anything else.
So that's the current state of play. Win32 apps, unsandboxed, distributed either in or out of the store using MSIX, signed or unsigned. Now Microsoft is working on bringing sandboxing and permissions to the Win32 world, not just for UWP apps. However it'll still only work for MSIXs.
Windows suffers from Malware in no small part due to the systems design rather than simply being common. Plenty of alternatives have more users than windows did back in the late 90’s when it was a huge target.
Even the open source offerings that add sandboxing often drop either the customizability or the user friendliness.
This is true, but there is much badly designed sandboxing. Many of the sandbox systems on Linux will have some problems, including too broad permissions, assuming text (including file names) is Unicode, failure to consider permissions that differ by command-line switches and other configuration files, failing to consider other things that the user might want to connect access to devices by files and other programs, and in case it prompts the user (at run time) for the name of another program to run by using popen or something like that and that program should run using its own permissions instead, etc. (Many of my programs that have an interactive mode do run other programs with popen, which prompt the user at run time to specify what command to run, so it can vary.)
I had my own ideas of operating system design, which is different from POSIX (although there is a POSIX compatibility layer available as a C library; the kernel need not know anything about it). One of its major ideas is that it uses capability-based security with proxy capabilities; these can be used for sandboxing and other high-level features implemented in terms of proxy capabilities. All I/O (except the Yield and Quit syscalls) requires capabilities; capabilities (as well as links) can also be passed in messages through other capabilities, including the initial message. There are many other ideas too, including ways for programs to be connected together and with user codes by user specifications. These ideas can allow working without dropping customizability, etc (in fact, the way I thought to do, would actually improve customizability, even for programs that do not normally have this feature).
- Part of what makes the mainstream OS terrible is the mere fact that it is mainstream. If Linux hit 60-70% adoption, a plague of terrible software, adware, malware, and more would start degrading its quality.
- Despite the points above, it would be really nice if some of the lousy things pointed out the in the graphic were deprecated.
But nobody would write some of the absolute schlock they get over in proprietary-land if they didn’t think they could dupe unwitting consumers into paying for it.
1. Widely criticized.
2. Not something the OS does, or even encourages. The OS permits it in the same way that the OS permits you to set your root password to hunter2 and run telnetd. You can't, and shouldn't, stop people from deliberately screwing themselves.
One certainly cannot change how one feels about one's security, but those don't seem to be reasons Linux is inherently more or less secure than Windows...
Found it: https://inoio.de/images/something-happened.jpg could be from https://www.usenix.org/sites/default/files/conference/protec...
For example: credential hashes. They can be used as a bearer-token, and a privileged enough one can log into absolutely any system in the entire domain and do anything.
Just because some people like to ask you to install their software that way doesn't make it "Linux security best practices" and it doesn't mean you need to follow those directions.
You can review whatever you're running, and you should if you want to install that way and feel it's insecure. At a minimum you can download the script to an actual file you keep around for a while and run it, so if something weird does seem to be happening you can at least see what the script was attempting.
Or, just refuse to install software that way. There's almost always a different way, and that's just provided for convenience. If people are opting for the unsafe method because it's convenient, I don't think that says as much about the OS as it does the people using it.
> You can review whatever you're running
How realistic is this for regular users? And even power users, in some cases. Let's say you download the install script. It's either hundreds of lines or it in turn downloads and runs some blob. Are you comfortable asserting your review is enough?
Is this truly so different to clicking on some random Windows installer?
If the same kind of Windows non-power users start running Linux and it becomes a really widespread desktop OS, would the situation be particularly different?
> Is this truly so different to clicking on some random Windows installer?
Yes, because you literally can't look in a random Windows installer (or, at least, it's not made to allow you to do so). It's true that many users won't have the competence to read and understand source code, but … it seems like that may be a genuinely unsolvable problem (if you want powerful software to be available to non-dev users); I don't know much about my car, but I could, and, when it is genuine complexity making understanding difficult rather than intentional black-boxing and obfuscation, I don't blame that on the car manufacturer.
Most windows installers are regular archive formats, with either msi information or an executable tacked on. They open just fine in 7zip. Of course analyzing the binary files inside the installer is another matter.
Experts can, but it's asking too much of regular users who aren't programmers.
And therefore, that's the answer of why Linux is "safer" than Windows.
A technology superseded by Flatpaks, yet pushed incessantly by Canonical, a befuddling move that I still don't quite understand. Rough to use in any other distro.
> AppImages
Speaking from experience, these don't run on every distro. So they fail to fulfill their intended purpose. As far as I'm concerned, that makes distributing software as AppImages a no-go.
> Flatpak
Better than any of the technologies previously quoted, but it is not without it's own issues. The chances of a Flatpak working on any particular distro are acceptably high, but they still suffer from the same problem AppImages do. I've had an instance were a an app refused to run on OpenSUSE, even though it was working completely fine on Fedora (I was using Flathub's repo on both distros, I wasn't using Fedora's, just to clarify). I think it was Firefox, though I'm not 100% on that.
Still, I'm yet to see a commercial software being distributed as a Flatpak. My guess is that it's all more of a hassle than it is worth. Which, I guess you could say that about packaging commercial software for Linux in general. So, we're back to square one with the chicken and the egg problem that Linux suffers from. Though nowadays it's less severe what with the existence of SteamOS and all of that, so at least there is a substantial marketshare, small as it is.
EDIT: fixed vertical spacing.
Most commercial software in general can be downloaded as a free demo version and then activated with a license key or account, and that model works really well with Flatpak and even Flathub.
For every Linux distro, sure, but it is feasible to create an apt repo and a Yum repo, and don't those cover the vast majority of distros by usage?
Assuming this is a commercial vendor not available through your package manager, and that you must go to the website, pay and get a download link (with source in this scenario), how is this fundamentally different to a Windows user paying for and downloading something bundled with malware?
Were Linux to go mainstream, it'd be unrealistic to ask users to vet the source code! Who has the time and expertise? You fundamentally rely on others to tell you it's safe. On Linux it's a safe bet, since malware authors are less interested in targeting it.
I'm torn on this. On the one hand, yes, a "regular" user should be using a distro that has a wide array of natively packaged software, and relying on that as much as possible. But not all software is distributed this way.
And many "regular" users will be coming from a Windows background, meaning they're not going to recognize the fact that the site they found when googling for "Install Spotify on Ubuntu" that tells them to open a command prompt and paste this command or download this .deb file is actually malicious.
In practice, they're susceptible to the same kinds of attacks they would be on Windows.
The incremental way to solve this problem is through various rules based around users engaging with details of the OS. One very simple one of these is "only install software through the system package manager". If users violate those rules, short of the above "solution", there is literally nothing that can be done to help them.
"Only download through this walled garden [Steam, GOG Galaxy, etc]"? So walled gardens are the answer?
Gardens allow you to make a small number of trust decisions, and then trust all the software they have vetted by extension.
Note that I'm leaving out "walled" because multiple software sources can coexist. "Walled" only comes about when some company tries to constrain you to their singular source.
I choose the F-droid garden and the OpenSUSE garden. Other people may prefer other gardens, and they should be free to choose the ones they prefer as I am free to choose mine.
When people criticize walled gardens, it's because the wall is like the Berlin Wall; a wall designed to keep people in against their will.
Fair enough. You are right there.
But in essence, it's not that Linux is "safer" than Windows against malware. It's that it's a nerdier culture with different practices that don't translate well to the mainstream. Like user kbenson above who suggested "reviewing the installer"... I hope we all agree that's ridiculous, right?
That everyone jumped on the "review what you run" part because they weren't paying attention to what I actually said and it looked similar to other arguments when this comes up I think has less to do with what I said and more to do with people wanting to argue that discussion yet again.
The bottom line is that Linux is no different than Windows in this respect (look at the Deno install directions if you want to see the powershell equivalent of curl piped to bash), and this is more a matter of the developer communities being okay with this method, and promoting it regardless of OS. In that respect, saying "Linux security best practices of curl | bash" was just inflammatory and wrong, and deserved to be called out as such. It's not only a Linux thing, it's not anything like a best practice (it's a convenience method provided that trades away security), and as such the statement is just plain wring.
So let me rephrase what I think is the key point here:
Linux is only "safer" than Windows because it has fewer users and they tend to be more technically minded.
However, were Linux to somehow become as mainstream a desktop OS as Windows, two things would happen:
- The userbase would become less technically minded and security aware. I don't want to call them "stupid" however, they likely know other stuff instead. I can't drive a car for example, am I stupid?
- It would become a juicier target for malware creators, and therefore malware would be as widespread as in Windows-land.
There's nothing magical in Linux that would protect a large and careless enough userbase.
There might be a slight edge in Linux in that the main way of getting software, the base OS repos and package manager, are about as trustworthy as you can get if you trust the OS to run in the first place, and generally they are packaging and shipping a lot more software that they've vetted, and built themselves and verified with the system than Windows does, which allows the regular user to not lower that trust as much.
Windows is getting closer, in that they have their store now and you can even use winget to install things from it, but those things aren't packages by MS (even if they might be vetted to some degree), so it's note quite the same. In some aspects it's better and in some worse, actually (there's a benefit to the OS maintainers tracking and building stuff themselves).
Beyond the main OS software, it gets into trust relationships and quickly becomes the exact same regardless of OS, as long as you're allowed to install arbitrary software. This is as opposed to a walled garden, which is explicitly trading away convenience (of one type) and choice for security (and uniformity, but that's not a given), in the same way but the opposite direction as curl piping a script to bash which is trading away security for convenience. I wrote elsewhere in this thread (multiple times, to various degrees) how the trust relationship to the source is the real question, and not really different in the desktop OS cases (in case I wasn't clear and you want more words on it to clarify my opinion).
> There's nothing magical in Linux that would protect a large and careless enough userbase.
Nope, there isn't, just as there isn't in Windows or Mac OS (yet, but they're both heading that direction to some degree with their stores).
You want to be cutting edge, but not get cut.
Who here is a Linux user and never downloaded stuff outside the repo, or compiled sources and run them without reviewing every security loophole? Linux users are the most "demand-ey" of users, even starting flamewars over being forced to do things this way or that way!
I'm really skeptical that this wouldn't introduce malware if malware authors deemed Linux a worthy target.
Games are a bit of special case as they don't exactly play nice with Linux and many of them are also run thru emulation like Proton
Most people don't go on random torrent sites to get their games.
And most people that do also don't get infected because usually the top rated torrent is just fine. I pirated a lot as a dumb kid without income and haven't managed to catch anything at least.
As an end-user, I choose to use Linux because it does not stand between me and my computer. I am the master of the machine. I tell it what to do, and it obeys. That is the relationship I want to have with a piece of tangible property that I paid money for.
So if I do something unsafe, even through ignorance or naivety, I still see that as being my fault. Not the software's. In other words, the software was behaving as expected. There were no bugs. It did what the authorized user told it to do.
But I can see the point of view that secure software could also mean software that makes it difficult for the authorized user to do dangerous things. Especially in an organization setting where the user is not actually the owner of the machine, but is using company equipment and software.
And making it a class at school. We have universal education in most places, we can use it for something useful. There's no reason that we have to capitulate to corporations and their moats. We can teach children how the devices that surround them and order them around work, and how to deal with the predators that they'll encounter while interacting with them.
Way too often it's "download some dumbass script running some half-assed autodetection just to add a line of text to config and a GPG key.
As a Linux nerd who started tinkering around 2001, I’m having a hard time with this framing. Being a Linux user around that era involved regularly compiling code that practically I couldn’t review. While the steps involved were different, the behaviors associated with installing software were not inherently more secure than windows at the time.
The main differences were: 1) I was more technically savvy and thus not as likely to install something obviously dangerous and 2) One just wasn’t very likely to run into a repo impacted by supply chain compromise or somesuch. Those same behaviors today are pretty risky in comparison, leading to threads like this one.
I’d argue that it’s less about windows being a source of maladaptive behavior, and more about windows attracting users who don’t know better than to behave the way they do. If those same low-tech users were somehow using Linux at the time, I don’t think they’d have learned anything more adaptive, and/or Linux would have been a much larger target, changing the threat landscape entirely.
But to go a step further, I guess the question that comes up for me is: why does it matter if it’s the fault of Windows? The typical “OS war” rhetoric never made much sense to me.
To me, the point of running Linux or really any desktop OS is to allow me to go beyond walled gardens.
My brother is a non-technical artist/creator type. If he relied only on the system package manager, he might as well use an iPad.
What you’re framing here as “violating rules” is really just “using the computer for its intended purpose”.
Following those rules may fix the security problem, in the same way that never leaving my apartment will probably protect me from most seasonal illnesses.
We need better ways to universally indicate trust in distributed software beyond system package managers.
Yes, and I would add 3) there was no meaningful malware made for Linux back then, because it wasn't a target for malware authors. Otherwise you (and I!) would have been hit. I didn't understand half the stuff I installed on my Linux box back then, and many install instructions were positively arcane.
> To me, the point of running Linux or really any desktop OS is to allow me to go beyond walled gardens. My brother is a non-technical artist/creator type. If he relied only on the system package manager, he might as well use an iPad.
Fully agreed! Furthermore, anyone using Linux back then would have found your opinion entirely uncontroversial. The point of Linux back then was freedom to do whatever. Gardens -- even non-walled gardens -- were not the point.
But the real condemnation of Windows isn't just an "OS war", but rather the fight is about the virtue of understanding the software in front of you. This is critical to security - not in the small (the idea that an individual can audit every line of code they run is a fallacious straw man), but rather on the large scale. Having published source code allows the building of a distributed consensus that something can be trusted, not beholden to the existing power structure, whereas without that you're stuck trusting the word of a single company and/of their auditors.
Like today we see malware continually being bundled with proprietary software, so often that it's considered banal and just how things are (eg web surveillance). Yet in Libre land when something like this happens it's still seen as an exceptional occurrence that needs to be stomped down hard. That directly follows from the underlying attitudes of unilateral "trust us" versus community consensus.
> We need better ways to universally indicate trust in distributed software beyond system package managers.
I'd love to hear you expound on this. The only two solutions I can see are are trusting and sandboxing. Sandboxing and capability security was a radical pie in the sky idea two decades ago, but now we've got two extremely popular implementations - web javascript and Android. So it feels a lot less like a lofty perfect solution, despite the current failings (both of those implementations have shirked being secure against many types of attacks!).
Is there some third way, especially that isn't just a combination of the two basic existing approaches? I'd love to hear one!
That's a general theme in OS wars, Windows users are eager to criticize Windows, while Linux and macOS users are eager to defend their OS.
I don't criticize Windows when a user installed a malware and clicked on "Yes" when prompted to allow the app to make changes to the computer in the same way, I don't criticize linux distroes for allowing users to install something by piping directly a curl into bash without checking. I appreciate not having an os that's a walled garden unlike what happens with phones but that does put some responsibilities on users.
For a real world example, if someone gets an std from having unprotected sex without a condom, the blame lies on them for doing so.
Curl | Bash usually runs in user context (although I've seen curl | sudo bash in the wild) but there's also concerns of vetting who wrote the instructions, if they actually point to the app or a modified version of the app containing malwares, etc...
- Package managers generally sign their packages, and provide ways to prove the integrity of the downloaded packages, so even if someone hijacks your DNS or exploits the box you're downloading your packages from and injects a malicious one, it will be rejected on your side. Yum/dnf do this with GPG, for example.
- Package managers usually track what was done and what files were put where, so there's an easy way to see what was installed and clean it up (which may also be automated). This isn't perfect, as the packages can run scripts as part of install usually, but it is helpful.
- Packages from package managers are vetted by the team that puts them out, and depending on the system built by that same team. For stores, often it's just vetted in some way and the submitter builds it, but package systems are almost always vouching for the packages you get. In the case of the OS package manager, you obviously trust them if you're running the OS, otherwise this discussion has no meaning.
- Whether things are installed as root or as a user (commonly. You can curl|bash as root too, and many instructions prefix it with sudo...), but I think it's usually more important how trusted the sources are. The OS packagers, a well trusted group or company with something to lose, etc is more likely to have put systems into place to ensure safety (and protect themselves from problems if they are hacked). See above. Regardless of whether they're run as root or not, I think they're somewhat safer and more trustworthy, but this is a personal choice, since it's largely based on your own trust of the sources and the systems used in the chain of getting the software to you.
Ultimately, it's less an OS issue and more an issue of what the individual is comfortable with, which spans operating systems. People do stuff just as unsafe as curl|bash on windows all the time too.
At least on ubuntu and centos I had no problem installing unsigned packages, no warnings, nothing, it's allowed by design. Try it yourself.
>Packages from package managers are vetted by the team that puts them out
It's called distro repo, package managers don't contain packages.
>In the case of the OS package manager, you obviously trust them if you're running the OS, otherwise this discussion has no meaning.
This has nothing to do with security, you can trust your system to run malware correctly too, just like any system does it.
Manually, through yum localinstall or by referencing a local RPM or a manual rpm command, or an unsigned package in the remote repos? I've seen repos configured with signing keys have problems and the install command fails, so I assume you're referring to manually.
I think what you're seeing is that the package manager utilities (yum/dnf/apt/whatever) are all capable of verification, but are also happy to install things without verification in many cases. But if the RPM you downloaded is signed and RPM has had signatures loaded into it and there's a mismatch between what the rpm utility knows about and what the RPM you're installing is signed with, rpm will complain very loudly and fail (I have had to add --nosignature to rpm commands in some cases and import keys into rpm in others).
In addition to at the RPM level, the repos themselves often indicate a gpg key that packages are signed with, which the system package maintainers, which is what I was somewhat ambiguously referring to in my prior comment as package managers (in which I meant the managers of the system packages), will sign all packages they publish with so the integrity of updates and additional software they provide can be confirmed.
Given that, I'm not sure how you can maintain that the package management utils on systems do the same thing as piping arbitrary internet content to a bash prompt. I think you were just possibly a bit mistaken about what the package management utilities are really doing and enforcing with their signatures.
> It's called distro repo, package managers don't contain packages.
It's called the packages the OS provides. It's called many things. My terminology was somewhat ambiguous.
> This has nothing to do with security, you can trust your system to run malware correctly too, just like any system does it.
Sure it does. If you trust your system to run malware from the OS providers, then you don't have to care what other software you're downloading and running, you've already set your trust level of the system to "none".
If you do trust the OS provider (whether that by a Linux distro, MS for Windows or Apple for Mac OS) to not be malicious (and please, let's forestall any digression into privacy, we're talking about malicious intent not allowed by EULAs), then you should trust the other software they provide that's verifiably from them.
This is so far from true, I wish this misconception didn't exist.
First, a package in a distro repo is maintained by known people, the package maintainers. Some do an exceptional job, some put in less effort, but at the very least there is some oversight on what gets into an official distro package. And there is an audit trail of who approved what and when.
Distro packages are signed and verified by the tooling, so inserting a malicious package is much more difficult.
Distro packages are also versioned and prior versions remain available, so if there is an issue we can trace who/when/why it was introduced and when it was fixed.
None of these protections exist when you just curl some random executable off from some third-party website and hope for the best.
Realize that the website might return a different executable every time. Even if you & I curl it within seconds, we might be served different content. It might return malware in a tiny percentage of cases to avoid detection. It may return code without any versioning, or code that claims a constant version even though the content changes. It is impossible to have reproducible installs when you just retrieve something via curl without any validation or versioning.
(You could, of course, curl it to a file and then compute a hash on the file, assign it a version number, store and look up known hash/versions and so on... but now you're down the path of building an adhoc package manager to resolve the problems with curl|bash. So... might as well use the mature package manager your distro already has because it already solved these problems.)
> while curl|bash can run in user context
No, it runs as whatever user you run it as. You can find plenty of websites saying their installer needs to be run as root.
That is to say, if desktop linux use became significant enough to challenge windows and macos, then either the distros will lag out of date packages, not cover widely requested packages, or not have security through curation. Any of these will likely inherently lead to users downloading packages to install manually.
I say this as someone that has been running desktop linux on and off since 1992; and I wholeheartedly believe that there's no inherent reason linux desktop use cannot be popular.
Really? Software developers, who distribute through their websites, have an economic incentive to not give users malware. I'm not sure the same applies to Debian's volunteers. I don't even know who these volunteers are.
If your executable doesn't have trust, a scary warning pops up (or Windows blocks the app from running) and tells the user Windows Defender SmartScreen prevented an unrecognized app from starting. Running this app might put your PC at risk. This seems about as effective as having a bunch of random people vetting packages for a Linux distro.
[0]: https://stackoverflow.com/questions/48946680/how-to-avoid-th...
I honestly just installed my first non-throwaway Windows VM in a long while, and I was appalled how the state of the art in Windows "security" is still stuck where it was a decade ago.
No, it's "computer illiterate" culture. Windows has a few package managers available these days (including a first party one). Developers on windows install things the same way that linux users do, though not usually building the software along the way (though I often have to use cmake with visual studio)
Yeah, then some company installer-hijacks your software and SEOs your site. Case in point, VLC (for Windows of course)
They're probably on here, reading your comments, or reading LWN.
You have more chance of reaching a DD and reading their work than you do of reaching a commercial software author.
You're putting way too much faith in the efficient market fallacy. In reality, proprietary software companies are incentivized to distribute malware to increase their own control and their bottom line. Prominent examples being BonziBuddy, Sony Rootkit, Denuvo, all the crapware that comes bundled with Android/Windows, web ads, web surveillance, etc. Like every other day there is a new HN topic about how some company violated the trust they had built and screwed over users.
Single Debian volunteer would have to do quite a bit of work to get into position of being able to just push malware into the repo; and if they did it lands in debian unstable/testing so there is also a pretty good chance it would be noticed.
Package manager has little to do with security, unless you count hash checking as one. Its about automation.
Besides, windows has multiple good package managers sine long time ago.
BTW, to demonstrate the invalidness of the argument, you don't have to look further then nvm package manager...
If it's actually from the vendor that's already an improvement over the typical Windows experience.
In Linux, .sh installers are common. GOG games get distributed this way. If your wife still metaphorically slaps you when you mention .sh installers, it's only because she doesn't play games on Linux. She wouldn't know how to use apt either.
I think in the end the truth is that Windows is more targeted by malware because it's more widespread than Linux.
I strongly disagree. "Only download from here; if it doesn't have what you want, though luck".
Also, this seems like an argument in favor of a walled garden. If so, I suppose that would fix Windows.
It's not that doing otherwise is prohibited. It's that doing otherwise should get your hackles up.
Which is why it isn't this:
> this seems like an argument in favor of a walled garden.
There are no walls. It's just a garden. But you have to understand that if you leave the garden, you're on your own.
For software developers and IT professionals, that's fine. They have a professional knowledge of the reputation of the source or know how to read the code, or how to set up a virtual machine if they want to try it but don't trust it. And if an ordinary user who is rightly wary of doing that still wants to get the latest AI thing from github, they call up their friend the software developer or their company's IT department or pay a computer repair shop they trust to set it up for them.
But that should be rare, because anything which is both popular and safe should promptly get added to the package manager.
So essentially if Windows had this, problem fixed?
Or put another way, if most users came to Linux and started downloading crap from everywhere, there would be incentive for malware authors to write it for Linux, bringing it to the current situation with Windows?
The problem is that the nature of Windows isn't to have this. Linux package managers are run by the community. They basically include anything popular that meets the licensing requirements to allow them to redistribute it. Windows instead has a "store" that wants to extract a vig, but because most of the software people use on Windows is commercial, the vendors then avoid to store to avoid the vig and the default is to install things from random websites.
And even if they fixed that, people are used to doing it the other way, vendors have already spent the time to set up alternate distribution infrastructure and they don't trust Microsoft not to reverse course once a critical mass of things are using their system and they can increase the friction to installing things from outside of it and then turn the screws on anything inside it.
To make it work there you would need the distribution system to be run by multiple independent third parties so they'd have to compete with each other to keep distribution margins low. There probably is a market for a third party "store" for Windows that pays the 3% to the credit cards and then distributes the apps via P2P so they can charge no more than 5% to app developers, which the app developers might then actually use because they don't have to build their own system for payments and updates. But the stores want to charge 30% and then the developers don't want to use the stores.
Interestingly, they're getting a version of it. The wingget command line package manager that windows ships with now has two sources, the MS store, and the winget community repo. The community repo is something anyone can submit to and it goes through some vetting process[1].
PS C:\> winget search perl
Name Id Version Match Source
--------------------------------------------------------------------------------------------
Perl Formatter 9MSQVFZPRG3Z Unknown msstore
Strawberry Perl StrawberryPerl.StrawberryPerl 5.32.1001 Tag: perl winget
MAMP & MAMP PRO MAMP.MAMP 4.2.0 Tag: perl winget
EditPlus ES-Computing.EditPlus 5.6 Tag: perl winget
XAMPP 8.1 ApacheFriends.Xampp.8.1 8.1.12-0 Tag: perl winget
XAMPP 8.2 ApacheFriends.Xampp.8.2 8.2.4 Tag: perl winget
Sharperlight 5.4 PhilightPtyLtd.Sharperlight 5.4.60 winget
Wtils Perlt.Wtils v1.0 winget
Paperlib FutureScholars.Paperlib 2.2.3 winget
Teambition Alibaba.Teambition 2.0.3 Tag: paperless winget
DingTalk Alibaba.DingTalk 7.0.30-Release.6019103 Tag: paperless winget
It's not quite the same though, as there are different considerations when using a repository of things a unified group has decided should be included and built (or slightly modified existing) packages for and a repo where anyone can submit a package that will go through some level of vetting. In the end I still believe most this discussion is really about individuals and how much trust they apply towards different groups and sources and is not really about Linux or Windows in particular as much.The Linux community "solves" this problem by directing commercial software vendors to the door and implementing anything they want as open source. But having something that works for this would help even there, for the cases where that hasn't worked, like AAA games.
Ironically the best way to solve this for proprietary software would be an open system. Have someone create a software distribution framework that uses open source code and federated P2P for distribution with pluggable payment processors. Make it an interoperable standard.
The idea is that it's a distribution system with no central distributor, a payments system which is independent of a payment processor. The vendor chooses which payment processors they want to accept (which might just be all of them), then the user chooses which ones they want to pay with, and if the vendor gets into a dispute with a payment processor their users automatically get diverted to a different one. If they get tired of their hosting provider they move to another one without the users ever noticing.
But then you need someone to develop it when its very purpose is to make sure nobody can extract high rents.
A coalition of mid-sized developers might be wise to pool their resources. Or, for that matter, get in with a bigger pool, because this is a problem that exists for subscription services and small businesses in general.
It doesn't address a very important aspect of this which is trust, and that's most of the point of this discussion. People use repos usually because there's some level of trust in the repo maintainers. If anyone can push anything, then it's a liability to have that repo configured. If it requires careful vetting, then that costs money, and requires a central authority, which means it doesn't really matter whether it's P2P or not (except to lower cost), as it's centrally managed anyway.
Theoretically I could see a system like that in place where the "network" is all open and P2P and you just subscribe to sets of packages that have been "signed" by an authority you trust, but I'm not sure that the P2P portion is really all that useful then.
The whole reason the default repos in a linux Distro are things people feel safe running whatever they find in is because they know a group of people they trust has vetted it. If you're running Debian/Ubuntu/RHEL/Rocky/Windows/MacOS you've already trusted the maintainers of their default repos/etc by the nature of running their OS in the first place. People also often choose to trust large companies (Adobe, VMware, Google for Chrome in some cases) and/or well known groups/projects (Apache, ffmpeg, etc) when they distribute software separately, even it downloaded manually. Finally, people make ad-hoc choices about random less well known sites and people, and that's where random windows executable or Linux binaries, or installer scripts that are downloaded and run or piped to bash form curl happen.
All those levels of trust and those parties exist for every OS. Even Linux has it's fair share of third party downloaded applications people use, depending on what they use their system for. Some communities of people (e.g. developers) are much more comfortable with ad-hoc installation methods like curl|bash than others, and that's across OS boundaries. That's really what I meant way upthread when I said this isn't a Linux problem, it's a people problem.
(Genuine questions, I don't know the data, or even if the data exists outside of MS)
1) Download random shit from the internet at your own risk. If you're given a vast supply of safe software, and you choose not to use it, remember that you're a grown up and you should do what you like.
2) Nobody is objecting to walled gardens with no walls. Almost nobody, I should say; I've seen people tell Apple users that the fact that they are happy with the app store makes them bad in some way, but those people are shitheads. The reason to attack Apple is on behalf of their users, not some perverse brand nationalism.
If an Apple user can install whatever they want, and end their relationship with the Apple corporation at any time, that's winning. If the vast majority of Apple users decide that they value whatever contract (implicit or explicit) that Apple has made with them, and enjoy the relationship and the stewardship of the app store, that's a choice they're making as free people. And under the pressure of free people, the app store would have to improve anyway. I certainly have affection for what Debian does (and for everybody who wrote the software packaged in Debian.) Why shouldn't they feel that for Apple?
Linux users often rail against Apple's gardens, so it'd be dishonest to pretend otherwise. I should know! I've been a Linux user for 20 years now.
> If you're given a vast supply of safe software, and you choose not to use it, remember that you're a grown up and you should do what you like.
But lots of software in Linux isn't available in any repos. For example, games and stuff a typical mainstream user would expect. So Linux couldn't be turned into a "safe" mainstream OS unless it adopted a more diverse "app store", like macOS.
But this could very well be done by Windows, so it's not that one OS is "safe" or "safer" than the other. It's essentially a popularity thing.
> Download random shit from the internet at your own risk
And here we have it! Linux users "download random shit at their own risk" because they are not mainstream users; their needs are served by their distro's repo because their needs are different. If Linux was a mainstream OS, with the kinds of users that come with it, it would either have to turn into macOS or Windows. Either draconian measures (a single store where you can buy everything), or no measures at all (== malware).
Expecting people to "review the installer" is ridiculous.
They should be adding a repository trusted with keys but so far UI/UX for it is horrible for regular users. Still better than... whatever the fuck windows is doing tho.
It is always entertaining to see HN's commentariat both rail against walled gardens by (for example) Apple or Android that are aimed at making life easier for regular people, while advocating them for Linux.
have you ever met a regular user?
Sure, downloading executables and running them in UAC-protected environment is a Windowsism. Linux way is to copy commands from a random web page and run them as root. Of course all the commands on how-to sites in search results are trustworthy!
Excuse me, what?
Downloading via web browser was the original means (besides ftp) of getting anything. Hell tarball distribution was how everyone used to move bits around.
Package maintainers are not Linux. Never will be, never have been. Linux may start with a distro or live CD, but from there it's you arranging things in a way that best works for you.
Or are you going to try to sell me on the fact that Linux From Scratch is basically pushing you to wget source tarballs, is peak windowsism?
If anything, distribution package managers are more of a windowsism than anything else. About the most I tend to allow myself is to use the apt-ified form of software install after I've torn apart an sbopkg build from source. Even on windows I've gotten to the point I've started dumping symbol tables from binaries, for all the cold comfort and reminder that the world is a capitalist hellhole that offers nothing but clients of servers looking to charge you rent anymore.
How do you ever expect to learn how your computer works and how to drive it if you don't read?
I'm surprised by some of the answers I'm getting -- and I'm both a Linux fan and an almost exclusive user for the past 20 years. Yet I don't delude myself about the ton of crap I download in order to get things to be the way I want. Sometimes it's Steam, sometimes it's GOG, sometimes it's the official repo, sometimes it's a PPA, sometimes it's just random stuff on the web.
And yes -- downloading stuff from the web is how it's supposed to be used. Have people really changed so much that this is now frowned upon?
In any case, I still think we're "safe" because malware authors don't think it's worth their time to target Linux.
Unfortunately not at all feasible for a small dev releasing software on Linux. The choice is either to support 15 different package managers yourself (including QA!) or just hope that the community gets it right.
I eventually refused to support any user who didn't download the AppImage directly from my GitHub page because the distro-specific versions would frequently break.
They don't (unless following instructions). But that's my point: downloading stuff and "reviewing" it is not feasible except for power users -- which are not the scenario we're describing -- and not even then! Can you tell me you trust yourself to review a non-trivial install script?
> stuff users need is generally in the repos
Even games? If we're talking about regular users, they'll want to play games and other things not packaged with their repo.
Which is probably the same thing they do on Windows: use a browser to download and run whatever program claims to do what they want.
I know regular users don't use Linux. What I'm refuting is the notion that Linux is safer than Windows because "you can review the install script".
What I'm arguing is that you really can't review anything. Suppose Linux were to magically go mainstream on the desktop: you cannot ask users to review installers. That's crazy.
Finally, what I'm supporting is the assertion that Linux is safer from malware precisely because it's less widespread than Windows, making it a less interesting attack target for malware creators.
They're not qualified to only make safe decisions during their computing because they're not educated enough to understand what makes any given action safe or unsafe.
Using a computer is fundamentally not like using a car. Using a car, by and large, does not change. The only major exceptions are when the user fails to properly maintain it, altering weather conditions, and altering traffic conditions.
Once a driver has driven in any given permutation of traffic condition and weather condition, as long as they've maintained their vehicle, the driver's experience will be almost identical when they find themselves in that same permutation of conditions again.
This consistency allows drivers to build experience in adjusting their driving to operate in those conditions, which makes them better at it in those same conditions in the future.
We let laypeople drive, even those who haven't the slightest idea of how their braking system works mechanically, because there is an extremely limited range of outcomes from pressing the brake pedal at a given pressure in a given set of conditions provided it's maintained.
The scope of inputs we give drivers is ultimately tiny.
Computers are not like this. The safety habits you learned in 1995 are not going to cover every threat you encounter in 2005, the safety habits you learn in 2005 won't cover every threat in 2015, and likewise from 2015 to 2025.
As long as we give users a broad range of possible inputs, they will find ways to screw themselves with their own incompetence.
The reason iPhones and Mac OS computers are perceived by the layperson to be more secure isn't that they're inherently less hackable, it's because they treat the average user like the moron that the average user actually is by substantially restricting the input freedoms of that user. How many millions of iPhone users didn't get hacked because the developer denied them the freedom to sideload aribtrary unsigned IPA's
With great freedom comes an increased responsibility to understand the consequences of one's own actions. Users are lazy. Many are stupid. They do not read very much of anything. They do not understand the systems they are using and they don't want to.
As a technologist, I love having the freedom of an unbridled OS that lets me do whatever I want, including deleting the whole file system. That kind of freedom just isn't optimal for a typical user's security.
This may sound misanthropic to you, but look no further than the scores of people who microwaved or soaked their iphones because 4chan made spoofed ads that looked like real apple ads promising software updates that made it possible to charge one's iphone by microwaving it or a software update enabling waterproofing.
Users really are that stupid, and will ultimately find ways to harm themselves and their devices any way you allow them to, so long as there's a competent adversary trying to get them to do it.
Unpopular? I'd go so far as to say it's a given, and go so far as to so even an "expert user" isn't going to be able to reach 100% certainty while still using the system for it's purpose in almost all cases, unless it's air gapped or they've had their permissions reduced to the point they can't do certain things (which might help the regular user as well).
> Using a computer is fundamentally not like using a car. Using a car, by and large, does not change.
Except in the way that it's exactly like using a car. That is, in that it's someone operating a complex piece of machinery within narrow bounds that make it generally safe, but sometimes things happen either from the operator stepping outside of those bounds for convenience or inattentiveness or because of outside actions that make it unsafe.
> We let laypeople drive, even those who haven't the slightest idea of how their braking system works mechanically, because there is an extremely limited range of outcomes from pressing the brake pedal at a given pressure in a given set of conditions provided it's maintained.
I would say it's more because "normal" operation of a car only requires being trained to a specific level on specific capabilities. A professional driver that races may use the controls of the car very differently and achieve a much different outcome (the e-brake is just for when parked? Says you...).
We do tend to only legally allow specific types of car use in specific contexts though, so that's food for thought.
> Users really are that stupid, and will ultimately find ways to harm themselves and their devices any way you allow them to, so long as there's a competent adversary trying to get them to do it.
I totally agree. I just don't think that Linux is particularly worse than windows these days with regard to the trouble you can get into (you can run powershell scripts to do installs to, and I've seen the powershell equivalent to curl | bash.
There's a whole host of behaviors that people view as different when the context changes that aren't really different in practice. Running random executables on Windows is generally unsafe, and most people develop that sense after a while (either from being told or the hard way). Doing the same on Linux is unsafe in many ways too (except that often there's some additional trust we layer on some of the places we're getting the executables from), and running random shell commands isn't really any different, but people feel like it is because it's no longer in the context of Windows. That doesn't really make it better, it just makes people feel better about it.
If you want to be safe, you either stick with a vetted source you trust such as the package repo for the OS or software originating at a company you trust (which might just mean they're someone possible to track down and sue, so they're less likely to go rogue), or that has a reputation they don't want to screw up and a mechanism is in place that you're fairly sure you're using code from them (e.g. github and a trusted author or project). Other than things fundamentally like that, you're just rolling the dice. Which happens, and we've all done it, usually without problem. Which makes up complacent.
This Linux superiority complex isn't rooted in reality, not that I'll ever pick Windows as my daily driver.
I like and been using Linux as my personal and work computer for decades. But I don't delude myself about what safety is inherent to the system and what just about popularity.
Contextually, it feels different, but it's not. Not really. If you want safe, there's needs to be a chain of trust or something analogous, whether that's vetted repos, trusted companies (i.e. "able to be tracked down and sued") you're installing from, or an individual or group with a vested interest in keeping things safe (a project that has a track record).
Should regular users be using a script from some site to install stuff? Probably not. It's not safe. But that's not a Linux problem as much as it's a developer ecosystem problem and people not recognizing it as unsafe when they'd be leery of doing the same thing on Windows.
As an example, I give you Deno's installation instructions page[1]. Notice that equivalent to curl and bash as the first available Windows installation method? You can do that, or you could winget install it from the Windows Store, which presumably goes through some vetting process. Mac OS is in there as well with a bunch of possibly unsafe options (depends on how much you trust each package system...).
This isn't an OS problem, it's a community problem. Either we have the option of people being able to do less safe things, or we all run the equivalent of iOS and can only install and run software vetted by others. Pick your poison.
1: https://deno.land/manual@v1.35.0/getting_started/installatio...
"Is this truly so different..." Yes.
"...would the situation be particularly different?" Yes.
It only takes a few people to actually check something for everyone else to benefit from the results, and we even benefit from the mere possibility that anyone could at any time.
The fact that this benefit isn't 100% (we still discover 20 year old critical flaws in widely dispersed open source code) doesn't change the fact at all.
Granted, you might sometimes need to run something else, perhaps even closed source software. But insofar as that's considered necessary, the security posture of Linux isn't significantly worse than Windows, where almost everything is installed that way.
It's not a panacea, but it's the best option for most people. I get why some may not like it though... I don't quite get the visceral resistance though.
Of course, the adult version of this nerd will be able to weave much better post-hoc rationalizations. Head on over to ars technica or reddit or macrumors or linustechtips video comments for thousands of examples.
All said, I like and dislike aspects of Windows, Mac and Linux... they all have faults. I'm a bit more forgiving of Windows in terms of security today (after a decade+ of working very diligently at it) than a couple decades ago, when I saw the likes of ILoveYou and I forget the SQL Server one a year or two later. Those were just stupid decisions all around (running Email in "local/full-access" security context instead of internet/untrusted). Similar for the SQL issue.
This take is reductive and should not be taken seriously.
edit: Editing to say, I do agree with the OP in spirit, you should try to avoid running untrusted software. But the devil here is in the details, it's simply not an easily feasible goal.
But that only helps power users. On linux learning these things is simply a necessity because installing things outside your package manager is even less user friendly.
My personal opinion regarding security I would say is easy ability to apply sandboxing at various levels on the user side for software we trust less. (By user side I mean not depending on the developer to package the app a certain way etc. A virtual machine or a chroot jail etc are examples of what I meant by this).
Obviously you don't do that for every binary you run, but you have options if there's something you're a bit suspicious of.
And that's in the cases where they (or trusted third parties) aren't actually packaging it already for more normal installation in the OS you're on.
So, I'm not being idealistic and saying "read the code of everything you run", I'm saying "realize that running random scripts is equivalent to running random executables in a lot of cases, so maybe don't do that no matter the OS, as it's not an OS problem and one OS won't really protect you regardless of whether it's Linux or Windows or Mac OS", and thus it's not really a Linux problem at all. As an example, I'll leave you with this[1], which I find fairly relevant since it has the powershell equivalent if curl piping to bash.
1: https://deno.land/manual@v1.35.0/getting_started/installatio...
The situation is relatively straightforward, though people with biases (&/ desire to just argue &/ trolls) complicate it over and over again:
UNIX, and specifically Linux as a descendant, was evolved with very sensible and fairly solid security models (in multiple ways - including balancing simplicity [making it easier for users to specify and have that specification actually match their intention] against flexibility / rigor). Furthermore, from early days, there were heated substantial arguments about security vs. usability.
When I was younger, I had a more "Theo de Raadt" POV - it should be way more secure. But, I think that the arguments people like Torvalds made about "enough trouble getting adoption AT ALL", in essence, were better arguments.
Linux has been pretty good through the years. Far from perfect, but a good enough mixture in terms of balancing "getting sh1t done" against "keeping people safe".
Windows is a mess. It's always been a mess (though, to be fair, it DID really improve between 2000 and 2010, but only to the point sort of REQUIRED to continue to be commercially viable). The incentives etc. are all different. The M$ model is always "make things as easy as possible to just start using" and "try to keep everyone chained to the platform, in part through the otherwise almost altruistic method of never breaking ancient software".
There is no question that security - in terms of what is best for the user - is not the key principle / drive, there. You can judge that however you like, or not at all - it doesn't implicitly mean Windows is "worse", because that always depends on what is "important" ... what perspective you're looking at it from.
But, I certainly find that model ugly and unfortunate, personally.
Step by step directions on how to install are done because of what you say.
An script you execute from the internet is a convenience method that automates those steps. For that convenience, you are trading away some level of security. It may be a very small amount, if you're getting the script from a well respected and secure source. It may be a quite lot if it's some random blog or 4chan comment.
For decades now there have been methods to deal with the problem of multiple OS targets. A self extracting shell script, so the installation script is packaged with the script, is still used by companies that need to ship in a mostly distro agnostic way. You still get a single package which can be signed or include checksums. Anything that the web script would do would be just as easily accomplished.
Directions to pipe a download of a script to an interpreter to execute it exist because a subset of people don't give a shit. It's nothing to do with Linux, it's everything to do with people not caring. As evidence of this, I give you Deno's install page, where they allow you to user powershell to retrieve and automatically execute a powershell script[1].
Note how the themselves call it out as a convenience. Many things in life are convenient, but aren't really all that secure, like leaving your keys in your ignition because you live somewhat remotely and feel secure. This is just another one. People like to play the odds.
1: https://deno.land/manual@v1.35.0/getting_started/installatio...
The only time this doesn’t hold is when there is a very strong overriding driver or a mandate pushing people to overcome friction.
Linux probably happens to have a higher proportion of those, which might be why it's seen more as a Linux issue, but I don't really see them necessarily as intrinsically related.
It's the de-facto option for installing cross-distro software on Linux, especially if it's not in a package manager repo.
You could also review remotely hosted OOXML and its chain of oddly side-effecting dependencies.
I don't know who tells you about Linux security, but you should replace them.
The best practice for installing software on Linux is to use the package manager and install from the repositories of your Linux distro, or trusted software vendors.
Bingo. In Windows and even MacOS, it is normalized behavior to download and run software with your web browser. Want VLC? Google for VLC then maybe end up on a website like sourcef*rge that adds malware to the installer. On Linux, this sort of workflow is possible and permitted, but not encouraged. Instead users are encouraged to only install software through their package manager.
I can leave my dad with a Xubuntu install and trust him to not download malware because I taught him how to use the package manager, and warned him against trying to download software with his browser as though he were using Windows. 15 years like this and he still hasn't messed it up. With Windows he had new malware every week. Downloading and running strange software off the web is normal windows culture and windows scarcely even provides a better alternative to it.
(The "Windows Store" is an improvement to this situation I guess, but from what I understand most software available through it isn't free. This means windows users are incentivized to fall back on old habits and go scrounging around on the web for free binaries to blindly run.)
1. curl | bash = npm/pip/cargo/whatever install = developer provided package repositories = proprietary software installers
2. App stores from proprietary OS vendors. You still don't really know what's in the software, but at least you already have to trust Apple/Microsoft if you're using those OSes and they can remove detected bad behaviour globally.
3. Package repositories from trusted traditional linux repositories. You can view the purported source code of the build, plus there is now someone who can block bad packages.
4. Package repositories from linux repositories with public build processes. Not just the scripts, but being able to see the execution of the build and have it signed to prove where it came from (as opposed to Joe packager's personal machine then FTPing it up).
5. Making your own copy of every piece of software, auditing the entire source code, building it in an environment you control, and keeping the artifact you then sign somewhere you control. This is so much work that nobody does this.
People like to tut tut at curl | bash, but most of them are happy to do everything else in line 1, and maybe trust line 2. This is not the position of safety and moral superiority it's portrayed as.
Furthermore I'd argue that a big reason (2) > (1) is not that Google/Apple are that great at detecting malicious applications, but that malicious applications also have a harder time getting too many permissions with their system.
And furthermore, a reason why "curl | bash" is bad, is that you are piping arbitrary code straight into a shell, which gives no chance for the system to know which permissions the code needs. Whereas if you do a "curl ... && flatpak install ...", it can.
For that matter, I build my own Firefox even though Fedora offers a package because I like the concept of doing so, I can submit fixes, and I can do local optimizations. It's a lot of work but it's hardly infeasible.
I'm guessing no. So your overall security posture is line 3, where you're trusting fedora to be the gatekeeper for you.
You do realize that even this is the same as downloading and running an executable from a website, which is still the norm on Windows, right?
When you distribute those scripts around your org, you also want to verify them with a sha256 hash or something like that. This is what I do for installers I use this way and other software downloaded over HTTPS at work.
I also generally avoid installers that download other installers. If you've got a script that downloads platform-specific installers, you may prefer to write out specific instructions for each platform and download the platform-specific binaries directly. A shell installer like this running curl is a red flag imo.
$ rm -rf *
No permissions in this directory - want to try with sudo? (Y/n)
This sounds like a misconfiguration or lack of support for policykit to me.
> Then some programs like VLC just straight-up refuse to run as root.
That IMHO should be the standard behaviour of most non-basic/GUI programs to me, running as root is overall a terrible idea.
Cuz if you download from a random site, you might think twice about what it is, is the source trustworthy, etc? But the App Store, well Apple and Google tell me it's 100% safe, so just download all kinds of trash.
For desktop operating systems, I think you are probably wrong. Downloading and installing binaries from web sites is a huge cause of malware infection. And warez sites were not trustworthy at any time.
I doubt much malware has been installed via Linux package managers or by the Windows app store (if anyone actually uses that).
On the other hand, I do trust F-Droid. The vetting of ideological motivated volunteers beats the vetting of disinterested corporations.
Secondly most software on Linux is not installed this way - it's installed through the distro's package manager, flathub, Steam etc. where it actually is way more vetted than a random download. Of course you can install random downloaded appimages etc. if you want as well because this is Linux and it doesn't treat you like a child in a sandbox, you own your system, you do what you want with it.
Which gets to my last point - the software which is installed through curl | bash is generally targeting developers and frankly, as a developer, you should know what you're doing. You take the risk where the risk is small (on your throwaway dev VM), you vet & review the code first where the risk is real (on a production server or something).
Your comment was counterfactual nonsense
The curl | bash is bad practice and shouldn't be used.
You have way more control and security using a Linux distribution. The objectives of that and Windows are completely different, and that affects user's security.
This comparison would only be valid if almost everything you install on Windows was at least theoretically inspectable before installation, instead of, well, almost nothing. LOL, nice cope.
Anyway, here's a Bash function you can add to your dotfiles to add confirmation to that sort of "workflow":
confirm() {
tmpfile=$(mktemp)
# use tee to split stdin to stderr and the temporary file
tee "$tmpfile" >&2
echo >&2
# Prompt the user.
>&2 read -p "Do you want to pass this code along? [Y/n] " response < /dev/tty
case "$response" in
[nN]*)
echo "Operation cancelled." >&2
rm "$tmpfile"
exit 1
;;
*)
echo "Proceeding..." >&2
cat "$tmpfile"
rm "$tmpfile"
;;
esac
}
Now you can just take those one-shot install lines and stick this "confirm" function in the pipe like so:curl <url> | confirm | bash ...
There's probably a slicker way to do this, if you're super into Bash. And you may want to `set -o pipefail` in general, so that the "exit" code of 1 actually gets seen...
It's common for some developer oriented software to list a lazy way to install software from a trusted source. They also aren't running curl $URL | bash on a $URL from a scam email they just got. It is indeed bad practice but its a relatively contained bad practice and its not reasonable to compare this situation where some developer oriented software recommends a controllable insecure method with the common user experience of hundreds of millions of windows users constantly installing all software by downloading and clicking on executable the functional equivalent of curl|bash
> to run untrusted code,
No again, that depends on who you trust, right? If you trust noone, it is all up to you, certainly.. and at least you have the theoretical possibility to review almost everything (which other people actually do).
Gotta take offense here. That's a MacOS paradigm.
All Linux distros have proper package management, always cryptographically signed and increasingly reproducibly verified, and extremely broad coverage of virtually all the software in the community. The closest you get to this kind of thing as an "official install mechanism" is e.g. bootstrapping a package repo for third party software, which has you hand-verify the keys.
People who pull unverified code to their boxes are virtually all developers cloning stuff to build.
At the time Windows had far worse vulnerabilities than running untrusted code.
You didn’t need to download or run anything, just connecting to the internet without a firewall (which was common in the dial-up era) exposed services that could be exploited by a remote attacker.
the only thing I can recall asking me to do that is rust... (which tracks, as the rust ecosystem seems to have decided that the only kind of safety that matters is memory safety :) ).
The CPU spying is more of a real problem, though.
People objected to seatbelts in cars when they were introduced. Some people still do.
People object to EVs and don't believe that burning hydrocarbons is a problem.
We've mostly banned smoking in public places. A lot of bar and club owners thought that would kill their business, but it didn't.
We banned lead paint, despite the fact that it worked really well and covers just about anything without needing multiple coats.
It's easy to think of more examples.
When MacOS killed 32-bit libraries, it didn't save me from harm. It just made MacOS incapable of playing old steam games, and therefore my macbook air was no longer an acceptable laptop for vacations. I'm not saying it was a crime for Apple to change it -- OSes change. But it wasn't a benefit to me, and I took my business elsewhere.
The users were sold Windows as a solution to doing a wide variety of things. Now those things are getting compromised. They are not wrong that it was oversold.
I don't think the 10S example works here at all - 10S was never locked down for security, it was locked down because it was for cheap devices to drive sales on the mandatory Microsoft Store software distribution - you get cheap Windows, it comes with software distribution strings attached was the deal offered with 10S effectively.
People hated having a crippled copy of Windows on their cheap computer understandably because app availability on the Microsoft Store was poor at that time (and still is today), whether it had security benefits wasn't the issue there - people just wanted to use their computers to run a Windows app and rightly got upset when 10S couldn't sometimes.
10S was arguably much more a product planning/marketing decision to offer cheap Windows PCs at ChromeBook price points, even if there were some security implications.
So yes, the security benefits is the issue. Once you impact people's ability to install Chrome and give it full permissions, they scream. 10S didn't allow this, and Google (just using them due to popularity and because they weren't trying to be malicious here either) didn't give a damn about adhering to the new app format's restrictions on permissions.
God forbid we waste a little processing power on security instead of the ever-expanding slime of bloated frameworks and nonsensical UI.
Seriously, someone competent, please bring an OS to market that can waste my CPU cycles on a robust sandboxing model, a la Android. Take my money. I'm tired of spending it on Apple's constantly degrading UX disaster and security half-assery.
Unfortunately Android's sandboxing sometimes literally wastes CPU cycles – when Google forced people more seriously to use the new scoped storage API, people stumbled across quite a few performance bugs once you stray past the very simple use cases.
And like almost all attempts at file sandboxing (except to a limited extent Apple's implementation for Macs), it's broken interacting with more complex file formats that don't consist of a single atomic file. Using a file explorer to directly open that kind of file (e.g. a local collection of HTML files) in another app has become impossible that way, because the sandboxing system will only grant access to the one single file you've clicked on, and ignore any related file that are implicitly required, too.
Popularity is a factor. Poor design of 90s software is another factor. Neither of these are 100% of the problem.
- take a screenshot
- record the screen
- capture audio output and input (microphone)
- use and record the camera, if present
- read almost every file
- write and delete most files (excluding some OS-owned ones, without elevation at least)
- capture mouse and keystrokes
- use the internet without too much restriction
(Tbf, it’s mostly the same on Linux with X11/Xorg, but at least there’s more/better sandboxing and packaging like flatpak - and Wayland).
MacOS, AFAIK that is, is leading the way in this regard .
Popularity was definitely a huge factor.
macOS does have stronger security, but it's security in the form of stopping apps accessing files until they need permission and things.
One would assume the average personal has more personal data lying around on their phone than their PC.
If popularity was all that mattered, Android would be the top target.
YMMV.
If you pwn just one server you can attack thousands of people, their data, their credentials, etc.
Saying that there's no malware for Linux because there's no reawrd is myopic - the payoff is potentially larger.
I didn’t say that. My comment was really just commenting on the fact that most attacks (mal/ransomware/phishing/exploits) very frequently need some sort of user interaction. Without users or users doing user stuff it makes it harder to get things to execute on the machine/server. Sure if the server is in the DMZ and unpatched then yes it will be hammered by scanners and automated exploiters. With proper security hygiene and a proper patch cadence servers are usually more protected through defense in depth and lack of human.
Mea culpa.
Just this week I did some work for a client (a tech company) on a public facing webapp.
After fixing the issues, I gave the manager and their architects who had been reviewing my PRs a short list of errors that I noticed in the current app.
They politely declined to have them fixed, but want to proceed with another engagement for more features.
You just cannot win sometimes ...
It's been probably 20 years since I've seen passwords stored as plain text at any company I've dealt with, which is some progress at least!
Linux is hugely popular on phones (android), which are every bit as juicy (if not more so at this point) than a desktop target.
There is mobile malware but it's far more rare and harder to come by.
But then there's just the fact that the way software is installed on a linux machine is wildly different from how you'd install it on windows. Just getting that binary blob to run requires some heroic efforts (To the point where we've pretty much decided it's easier to distribute via containers rather than compiled binaries for a given desktop).
And if we expand beyond the desktop, we find linux everywhere in the server world. Easily the most popular OS to run server software. Which makes it a hugely valuable target for hackers. They'd love nothing more than to compromise a bank server.
To say there's nothing about linux that makes it inherently more secure than windows seems just unreal. Because nix was designed around multiple users from the ground up, user permissions have been baked into the common flow for decades. That alone creates a huge layer of security that makes things like root kits or worms running at root super hard to pull off. The old windows (9->XP) pretty much gave everyone running admin permissions. Writing or changing a system32 dll was child's play.
To exploit linux, you have to either trick a user to run something with elevated permissions or find a vulnerability in software running with root permissions. To exploit windows (particularly older windows) you have to trick a user to run your software.
The response to true malware on Android isn't looking for and removing APKs from compromised devices after the fact, it's patching the vulnerabilities in system APIs.
It is always the abuse of legitimate features which are the problem
At the windows malware peak, your system could be infected merely by having an internet connection. How many android worms are there? None that I can think of.
Heck, windows PCs were regularly infected by browsing the wrong website. Or getting served a malicious advertisement. Can you honestly say that people are getting infected on Android regularly by surfing the internet?
The vast majority of android malware relies on social engineering to get the end user to grant a malicious app permissions to be malicious. That's hardly a failing of the OS. It's also nowhere near as bad as "I'm online and now risk being infected".
I have used Windows for nearly 2 decades and I can't tell you the last time my system was infected. I do agree that browsers are the largest vector of attack but that also means browser vendors share some of the largest responsibility for creating secure systems.
There was a span of a few years when a Windows box connected directly to the Internet, using a public address, would reliably get pwned before long, even with nobody using it. But that was quite a while ago, and, again, just being behind a NATing router mostly solved the problem (assuming nothing infected ever connected to your local network).
Android is more secure by not acting like a typical Linux install; it's not really evidence of Linux being a tricky target.
All true, but I guess I'd just say that the main difference is without root, recovery/removal of the virus is fairly simple (as is detection). To recover, reboot, login as a different user, restore the .bashrc/startup configurations to default, remove the virus. Done.
If a virus gets root access, really the only safe way to recover is a full system wipe and reinstall.
But I would say that typical linux is more secure than android. It's fairly uncommon to install software from untrusted sources. On debian, I'd do an `apt install xyz" for most stuff. I'm not typically just installing unvetted software from the internet, certainly not something emailed to me.
Usually there is a lot of pushback along the lines that APIs should simply be made secure.
A very long time ago, Windows normalized the absolute worst security practices ever. This was never meaningfully addressed/punished publicly and we just kind of drifted to today -- where we're stuck with absurdities like the fact that you can't use a USB key literally as intended. No other product is this bad in terms of security; bread will not destroy your toaster the way a USB key can your computer.
You can't JUST put this on market share.
Every organization that does internal phishing testing still fails every time. Any modern discussion about information security that doesn't deal with that is a red herring, and provides zero utility to anyone who isn't the enemy of a nation-state. Focusing on the remaining few buffer-overflows that take a chain of ten other exploits to even reach in the first place while everyone's data and info is leaked daily because the CEO clicks everything in an email is a dereliction of duty. It's like investing in StarWars and magic lasers that can't work while placing nukes on Moscow's door step.
"Security Researches" keep looking for the buffer overflows because that's fun and they don't want to admit that the real problem is a social one because that's hard and boring and doesn't let them play with the newest fuzzer or get them a $100k bounty.
Like Javascript? Sure, it's VERY versatile, but "just download arbitrary code and run it in the browser?" That should have never happened in the way it has.
This is also why there's not as much software in general. So if a (lack of) regular software is a valid reason to not use linux, a lack of malware is also a valid reason to use it.
I don't eat that argument anymore. In the mobile space, Android (Linux) is the biggest player. It is even bigger than windows if both are considered among end-users[1] and I don't see as many people complaining about malware on Android as people complain about it on windows.
Of course, I don't think ms is incompetent with regards to windows security. But there are design decisions that make it historically problematic. The fact that win9x had zero process isolation (although with was possible since i386) and people expect program to continue working on winxp (NT kernel), the fact that centralized software distribution is a relatively novelty on windows (compared to apt which exists since 1998) and many other minor things, like extension hiding, make it an easier target than ChromeOS, iOS, Android, MacOS and GNU/Linux.
I remember people saying "when Linux become as popular as windows, you'll see it being target by malware devs". Well, consider smartvs, infotainment, servers, supercomputers, embedded systems, mobile (specially Android). Linux is bigger than windows for a long time. I don't think its lower desktop market share is the main reason for its lack of malware.
[1] https://gs.statcounter.com/os-market-share#monthly-202206-20...
Can't believe I'm seeing such a statement on HN. Android phones are arguably worse on malware-related threat vectors, especially when most OEMs themselves package in the majority of malware on consumer phones to begin with. Even assuming less dumb users, at its best it is an unholy combination of adware mixed with spyware, ridiculous amounts of tracking in the name of "telemetry" and consumer-hostile design choices often literally designed to make the user choose the wrong option. Combine that with how ridiculously easy it is to get malware installed on Android (the most popular apps and games on the Play Store are all adware, installing compromised "modded" apks that "unlock premium features" is just one tap away) and you get a platform that would make any infosec manager cry. At least Windows PCs are controllable by the organization's administrator, how are you going to control people's phones unless you start issuing company phones as well?
>At least Windows PCs are controllable by the organization's administrator, how are you going to control people's phones unless you start issuing company phones as well?
You mean the same "controllable" Windows PC's that are responsible for nearly 100% of the ransomware, virus and malware infections in corporations? Right.
> As long as some platform is capable and powerful for many things, there will be malware.
Android != GNU/Linux. iOS != MacOS. GNU/Linux, Mac, Windows are far more capable and powerful that mobile platform and therefore far more susceptible to malware. Plenty of Linux-based servers are hacked every day, plenty of scanning bots are targeting Linux-based software vulnerabilities over the internet.
If, by default, users only downloaded software directly from the Microsoft store, would Windows achieve a similar level of security?
As for smart TVs, infotainment, servers, etc. they all share the commonality that the end user doesn't typically download untrusted software. And if they do, it's typically from a vendor's own store.
This is true but there are also degrees of that. Windows in particular is a graveyard of discarded tech waiting to be galvanized by malware, because of the backwards compatibility and because of the Microsoft's habit of abandoning the half-done frameworks and APIs. Apple's stuff is much tidier just because they regularly deprecate and compress their fully owned stack (although they also have their turds of course). In Linux, there's terrible fragmentation and a lot of ancient and barely maintained stuff, but at the same time it can be customized to only include the best practices and omit a lot of dead weight.
Might want to rephrase that, uhm, Linux?
Windows is a platform that is accessible to the most dumb (and disinterested) users in the world. No offense, but phishers, malware authors and spammers all rely on a sucker buying OEM every minute.
[1] https://fedoraproject.org/silverblue/ [2] https://github.com/ublue-os
It's an operating system that automatically executes code found on USB sticks.
How is this even a discussion?
Your understanding of security research is badly out of date.
Turns out that, since the 80's, we've found a lot of ways to make computing platforms much more secure while sacrificing little flexibility.
For instance: capabilities. Apps working under a capability model get denied access to resources by default. If you later determine that yes, you want a program to be able to access the internet, then you can grant it that capability...but, say, only while the program is running, and you can revoke it at any time.
The dichotomy of "either malware or a locked down media-consumption device" is completely false.
If there were an executable bit, exe’s from strange places wouldn’t just run without being granted permission. If extensions were visible by default, the very slightly savvy could SEE the danger. The combo lack-thereof is the danger.
With how many notifications Windows gives you already, it really seems like at the very least just warning you when you double click something the first time “this is an executable, use caution” would go a long way.
Binaries downloaded from browsers get stapled with a “potentially unsafe” extended attribute that pops a warning the first time you try to open it. This helps but is backwards. It should go the other direction and every binary should warn you until stapled with a “user has acknowledged the danger” attribute.
https://learn.microsoft.com/en-us/windows/security/operating...
By default Windows does not run anything which does not have valid signature, unless you give the permission.
Maybe you have disabled this feature? Many do it, because it is annoying, as you need to give permission almost for anything you download from the internet.
And how it is different than asking permission to run it?
Edit: as prompt I thought command-line
"Users will literally run the icon that's called malware" has nothing to do with Windows being written in not-Rust, and won't be solved by an operating system written in Rust.
You cannot simultaneously empower the user to do useful things and prevent the user from using that exact power to fuck themselves.
It's no different from trying to build a gun that can only shoot criminals. It's a completely invalid goal.
Actually, in its default configuration, it's telling you it has blocked a dangerous file from opening (but you can click a tiny link to show a second button to allow executing the file anyway).
When you download a file from the Internet Zone (the old IE concept, but it applies to current browsers), Windows will _block_ the file preventing you from running it (or for certain file types, open it) until you explicitly unblock the file, then re-perform your action.
The macOS prompt is much better. It doesn't have a "ok run this anyways". You have to go into the Security pref pane and explicitly open the application (or launch it via context menu in Finder). The dangerous path is blocked for most users.
If the file is downloaded with IE/Edge and comes from the Internet zone, there is an ADS written (Zone.Identifier) which flags the executable to prevent it from being executed. The user needs to manually unblock the file.
Also, Windows ACLs come with an execute permission per user, group, or any other policy related object. It's enabled by default for executable files you're allowed to read, but there's absolutely nothing stopping you from making executables unexecutable.
Furthermore, just about every executable file gets a massive "you're about to infect your computer, kill your pets and sacrifice your children to Satan" prompt by default. You can disable it, but it's enabled in almost every other case.
That's why attackers leverage the side effects of fringe cases, like RTF OLE embeddings and CHM/MHT wrappers.
Half the steps in this graph would work for macOS or Linux as well if they're set up for corporate environments. Most of it is browsers and office applications just doing their thing. Notice how none of these include code actually executable in an operating context until the very end, when the very last sandbox has been escaped and a script downloads the actual payload from a position where it would be able to set the executable bit anyway.
That's the whole point that GP is raising: whether the execute bit is set by default, or not.
However personally I think the file itself should carry the information that it is meant to be executable (e.g. through a magic like shebang, an ELF/PE header, file extension, etc). Under UNIX-like OS's, it just creates pointless friction for users who are already certain that they do want to run the executable they just downloaded.
Quarantine is (at least conceptually) a better and more general mechanism than the execute permission, as files other than executables could also be considered dangerous (like an image file trying to pwn the decoder, or a local HTML file trying to access the network). The quarantine bit could tell the OS and/or application to highly distrust the content (e.g. run it in a sandbox that denies FS/network access).
Yes indeed, but this logical and thought out explanation is no match for a limited-characters hot take (plus an image!) on Twitter. That's "information" now.
This is literally a side channel installation of software. As much as I hate the store concept, I would prefer everything be handled via a store than this mess.
The idea was not about installing without user's permission, but was entirely about allowing normal (non-admin) users to be able to install software, which would obviously be limited to their account only.
This means it needs to install to part of the filesystem where a non-admin user has write permissions. There are only two possible places. The user's profile, or the Programdata folder. Installing to the latter would have problems where one user could maliciously modify a program another installed (or issues if two users installed different versions of the same program), so the user's own profile is where it must go.
This concept is nothing new, users could long compile and install software into their home directories on unix platforms.
File extensions aren't necessarily mandatory in Windows as long as the Magic Number is recognized by Windows (Word documents, for example).
Windows is like a zombie clown at a haunted carnival, shambling from booth to booth just long enough to offend by its very presence before it shuffles off back to big top corporate america, arguably the only place it still exists to an audience of appreciative patrons at all.
Its remarkable how many button combinations lead to a popup telling you to use a different Microsoft product you don't need. I can't believe its gotten this bad.
We need a Windows alternative for the average consumer.
This is a generic tangent. The article is about computer security - nothing to do with Windows' user-hostile experience.
Windows NT and all versions of Windows after NT have more security controls than just about any other operating system as those controls came right out of VMS. They are mostly all disabled or weakened to lower friction and increase adoption. The controls are also weakened by default on Linux but it was late to the party and was not as happy-clicky as Windows thus more friction for less technical people at first. It isn't just security controls. Both Windows and Linux allow memory over-commit by default which can affect stability but improves adoption by developers. All of these things can be hardened at the risk of breaking applications that were coded to the default behavior so to speak.
As others mentioned Windows has the highest adoption and usage so it will be the default target. Should Linux take the lead some day it would gain more attention by malware authors. There are plenty of unexplored attack vectors in udev, binfmt mount, eBPF, systemd and how some of those things are glued together currently for a lack of better terminology. This may happen sooner than later if Linux gaming continues to improve at it's current rate. Gaming platforms often code to default behavior or expect elevated privileges thus rendering OS-hardening not an option and not many people will buy a separate gaming machine to keep this isolated from the machine they do taxes, banking, emails, social media, etc...
Android by itself has 50% more devices than Windows.
If some day there is a truly open Linux distro on fully unlocked-by-default phones that come with root access enabled and said phones are adopted by the masses and people can tweak the OS however they wish without using debugging tools or installing custom images then I think the phones will almost be on equal footing to Linux desktops, gaming and graphics power aside. They key part being adopted by the masses.
Even Android is not a majority market share [2] so people would have to target apps that Android, Apple and others share.
[1] - https://www.scmagazine.com/news/malware/letscall-vishing-mal...
[2] - https://www.bankmycell.com/blog/us-smartphone-market-share
I thought this tweet
>Computer security would be about 80% solved if we just deprecated every technology shown in this graphic.
is going to be about memory unsafe languages like C, C++ and JIT compilers (web browser) since
>Around 70% of our high severity security bugs are memory unsafety problems (that is, mistakes with C/C++ pointers). Half of those are use-after-free bugs.
https://www.chromium.org/Home/chromium-security/memory-safet...
>Figure 1: ~70% of the vulnerabilities Microsoft assigns a CVE each year continue to be memory safety issues
https://msrc.microsoft.com/blog/2019/07/a-proactive-approach...
Also HN title is editorialized.
Most of malware, logically, abuse common features within the operating system
Hmm, no. You'd use other attack vectors and once you've closed most of the attack avenues you'd find yourself on a smartphone OS with no permissions and mass tracking... and there would still be malware galore.
https://www.bleepingcomputer.com/news/security/apps-with-15m...
in an ideal world every time you need to break compatibility you would provide extensive documentation and make migration as painless as possible.
this might work if it wasn't for the tiny little problem of abandonware. the amount of critical tasks for which a piece of software that nobody knows how it works anymore is required is astounding.
should it be illegal for businesses and public-adjacent entities to operate proprietary software that is not actively maintained by anyone and has zero support contracts attached?
People with some specific legacy need can run an old OS on a computer isolated from the rest of the network, but there's no reason to have such security-compromising backwards comparability built into every OS install by default.
Say what you want about their proprietary lock ins and abhorrent business practises, but they have had some great ideas that took competing operating system years or even decades to copy. You still can't embed documents as easily and effective the way you can in Microsoft Office in most competing products. These features aren't abandoned, they're used by millions across the globe.
Microsoft does need to configure its tooling better to detect executable code. The VBScript at the end of the chain shouldn't have been executed. I'd be sad to see most of the other "legacy" tools disappear because of their malware capabilities.
abandonment refers to the lack of support, not lack of usage
Seriously, if another platform would hold 90% of the juice, you realy think it would not be the victim of malware by a long shot?
FwIW, I used to be a front line malware eradicater in the 80's , the prime target back then were Apple Mac's on uni computer classrooms.
Do you really think that a typical scenario of Windows infection is some kind of RCE in the OS? No, that's extremely rare.
Most of malware doesn't exploit any vulnerabilities in the OS. Either a user downloads and runs an infected executable, or they get infected through a bug somewhere in userland (e.g. web browser or image viewer).
The opportunistic attackers like that mainly go for dropping some blockchain mining software (monero is popular payload) and sometimes go for deploying botnet agents for things like DDoS ransoming and similar.
Low success rate, but low effort on attacker's side, who often buys a premade tool on a forum.
But history is a thing.
Also, every time I click on a twitter link, I seem to get "something went wrong" and have to reload. Is that the modern twitter?
So, yes or no. Depending on your idea of modern.
There's absolutely no negative impact disabling the support other than someone still using Windows XP with custom screensavers saying "SEE MICROSOFT IS EVIL!!!"
They also seem to have isolated them onto their own desktop, meaning that if a screensaver crashes then the users desktop won't be shown. That broke the official 'Bubbles' screensaver in Windows 11 - and they clearly don't test that stuff, because they released it anyway, broken.
This included 64 bit Windows (at least for 10), which can't actually run MS-DOS programmes, and has no real reason to actually try and do anything for PIF files anyway.
Computer security would be 100% solved if we just got rid of computers. It's impossible to break into something if it doesn't exist. I wonder why we haven't tried this strategy yet?
Overall, I do feel like new technologies are being scrutinized more than in the past. Especially when those implementations were done in a corporate vacuum and released as a canned solution.
Them having actual backwards compatibility (unlike the fruity side) is the least of our problems.
There is an argument to be made that these researchers work for "developers", i.e., the people who create and perpetuate the stuff in the graphic, more than they work for "users", i.e., the people suffer as a result of its continued usage.
Here the security researcher does not tell users, most of whom do not read Twitter, to stop using software that utilises the stuff in the graphic. Instead he communicates with computer security researchers, developers and other Twitter users apparently hoping that developers will deprecate such usage. (But knowing this will never happen.)
Note this comment does not argue that this state of affairs is good or bad. Only a reader can make that so. The comment only makes some observations.
Human sustenance is solved if we choose to let everyone die.
These statements have equal utility.
I have mostly stopped clicking on twitter links these days.
Until capability based security[1] becomes widely deployed, we'll keep blaming the wrong things, instead of Ambient Authority.
This is not permission management as practiced on smartphones and tablets.
https://www.zdnet.com/article/microsoft-70-percent-of-all-se...
The result of which is what, no new CVEs related to memory security? Rewriting everything in Rust? There need to be more tools to detect and prevent memory issues in current C/C++ codebases - and C++ specifically has a lot of tools like this already.
While windows evolved into a data exfiltration and malware distribution platform, android was designed for the task from the beginning.
"Computer security 80% solved if we deprecate technology shown in this graphic. The other half is software."
" Windows is the malware compatibility layer for everything."
C
Windows can actually be managed by am IT department and has a massive security ecosystem. If a corporation with more than ten people has to deal with my data, I'd much rather see them use Windows than anything else.
lol and we all know why
And so on.
WinNT would be secure if MS ditched Office Macros (or at least hard-sandboxed them) and ran all w9x software on seamless VM's.
If people chose things according to what is better, marketing would not exist.
I suppose you may not be very experienced. Windows is actually pretty powerful. I am a full time Linux user and still miss how convenient installing things like drivers, weird software, etc was on Windows. I just can't stand the new spyware angle they've taken their consumer offering. It's not hard to configure Windows to be safe and Microsoft is often times better than many linux distros about pushing patches.
Yikes. The hands that typed this should not have admin/root access to servers.
I don't. Except this isn't an uncommon opinion. There are literally tomes of knowledge (available via nostarch for example) describing firewall configuration and many other aspects of server administration. My linux desk reference is the size of an encyclopedia.The PfSense book is similarly massive (though that's more of a BSD thing).
In Windows Server's defense most common fixes are available either via console (azure) or through a series of often very simple clicks. Microsoft really nailed the user-friendly GUI-driven experience to setting up a server (mostly) safely and I think that shows in their adoption.
I am not a server admin because they aren't paid enough for all the crap they have to deal with.
Netfilter and PF are capable of doing actual router stuff, you can just skip over that section if you want to.
The "GUI driven" argument is why businesses should just skip over hiring mediocre IT people who don't really "get" servers and just do SaaS. Kinda like how "just use GSuite" replaced all those MS Exchange ""experts"".
I have supported CAD software in business environments that had Windows OS as a dependency. We still virtualized Windows and used PCI pass through. It really wasn't that hard to set up. All the Linux, some Unix (BSD) were managed with Salt States (way simpler than AD).
A decade ago this was true but today this is utter bullshit. There is a 20% of games that are exclusively Windows, sure.
You wanna play vidya sure have a dedicated Windows box for that, no one will judge you for the Windows part specifically.
>> I am a full time Linux user and still miss how convenient installing things like drivers
If you're buying hardware that doesn't already have drivers in the Linux kernel tree, or you don't have the skills to use DKMS, you should go back to using Windows only. Please uninstall all/any Linux you have.
>> It's not hard to configure Windows to be safe
Tell us we can't take anything you post here seriously without telling us we can't take anything you post here seriously.