Linux has nearly half of the desktop OS Linux market
theregister.com
theregister.com
- Verified boot backed by TPM.
- System services are heavily sandboxed: https://chromium.googlesource.com/chromiumos/docs/+/HEAD/san...
- New userspace is written in Rust: https://chromium.googlesource.com/chromiumos/docs/+/HEAD/dev...
- Web pages loaded on Chrome have no access to the device's filesystem, nor to user files.
- Android apps run inside a restricted container.
- Linux apps run inside a VM, which leverages KVM and a custom Rust VM monitor.
I think it'd be great if someone made a de-Googled fork of ChromeOS without all the Google telemetry and bloatware, because it'd be the perfect Linux distro for security-conscious individuals.
It's been a while since I've given it a try, but I dislike ChomeOS for the same reason that I dislike MacOS. They make me feel like I'm wearing a straightjacket and get in my way.
And, of course, any OS that requires me to have an account on any other server is not fit for purpose (to me).
There's a distinct problem with it being the only tool around, though.
https://chromeos.dev/en/posts/making-android-more-secure-wit...
The hard problem of security is giving the user the power of a general-purpose machine without exposing them to the risks. "Don't run your favorite software lol" is not a valid approach to security. ChromeOS remains totally unsuitable for even casual usage, let alone anything serious.
Someone will, I'm sure, claim that the use of virtual machines is a solution. It isn't. The layers of virtualization in ChromeOS lead to atrocious performance, reliability, and functionality. I am not willing to tolerate half my programs living in a different universe from the other half, nor am I willing to tolerate uptime measured in hours.
One could argue that anything you can't do on a ChromeOS machine (or an equivalent Firefox one if that project were more complete) without running a VM is proprietary garbage. The other Apps you will run will work on some percentage of machines, the device you use have incomplete drivers, the window environments they developed for were not worth standardizing such that a browser has to provide the standards layer.
https://madaidans-insecurities.github.io/linux.html
https://privsec.dev/posts/linux/linux-insecurities/
https://bjornpagen.com/en_US/desktop%20linux%20is%20insecure
A brief summary: No trusted boot, no clear security boundaries between system and applications, no application sandboxing, lack of mitigations (both on kernel and userspace), large kernel attack surface, insecure-by-design legacy systems (X, PulseAudio). Windows and macOS perform comparatively better on all of those.
No serious cloud, perhaps tech generally, company, is like "We're switching to Windows/MacOS to run the backbone tech of what we do."
That's Linux, and Linux will get the downstream security benefits of that. Given actual, real life history, I trust this far more than those other two, especially Windows, which just shat the bed ALL THE TIME. Your real life track record is far more reliable that a parade of imaginary horribles, even when they may be little things that only are on the Desktop.
True, but it is also true that practically all the other companies, governments and NGOs in the world--the ones that do not have providing services over the internet as one of their core competencies--chose Windows and keep on choosing Windows.
There are strong economic incentives that keeps an OS or other piece of infrastructure dominant for decades once it becomes dominant in some sector of the economy--if that piece of infrastructure requires many specialists for its deployment and maintenance--even when that piece of infrastructure has major problems if a hobbyist or an individual were to install that piece of infrastructure on their personal computer.
>Linux will get the downstream security benefits of that.
Linux would be able to derive security benefits from that if Linus cared, but a reading of his writings on the subject reveals that he does not care much about security.
I'm using Linux to write these words--a distro I chose and installed. I am however aware that because I'm using Linux, it is significantly easier to pwn me than it would be if I were using iOS, Android, ChromeOS, MacOS or Windows, which used to be a joke security-wise in the 1990s, but which has become much better security-wise.
Actually I believe that Qubes is pretty good security-wise, but it is the only Linux distro that is.
Saying that all those other non-techy big things "choose Windows" is a really stretchy definition of "choose." It's been long enough, we know the story, robber baron Bill Gates was able to jump ahead and cement Windows mindshare. It is what it is.
Again, I don't get what you're relying on when you say "desktop linux is the worst?" Sure, windows claims to be better, etc. But, and here's the important part, they've ALWAYS been cagey. You just can't ever REALLY know.
Now on the Linux side, sure -- there are lots of visible issues. That's good, because they are visible.
No one knows "all the code," and more importantly, no one can easily predict what Windows (and perhaps Apple) will do tomorrow to screw up the desktop, but we know they have the capacity to.
No thanks, I'll trust the thing that doesn't come with such possible arbitrary baggage.
I agree and that is one of the thing I meant by my "strong economic incentives that keeps an OS or other piece of infrastructure dominant for decades". But Linux retains its niche in internet services the same way!
Linux became dominant in internet services in the 1990s when the only alternative was Windows (and unlike today, in the 1990s Windows was no more secure than Linux). Apple wasn't even trying to compete in this market (or in the "enterprise" market that Microsoft has dominated since the 1990s): there a nice transcript about an internal meeting at Apple where Jobs tells some engineer that Apple sells its products to consumers and if he want to learn how to sell to IT departments, he should go work for HP or something. The internet-services industry ended up using Linux on its server farms basically because in the 1990s, Microsoft didn't sufficiently appreciate the advantages of open-source licensing, so they ended up disqualifying themselves in the eyes of the Dot Coms.
Also, this conversation is about desktop Linux. What part of a typical Linux desktop (such as my Fedora Workstation install that I'm using to write these words) do you think runs on Google's servers? My guess is that it is just the kernel and a few libraries like libc. How dominant Linux is on servers at Google and Facebook has no bearing on the security qualities or lack thereof of all the other code (Wayland, Gnome, GTK, graphics drivers, media players, codecs, font and typography libraries) running on a typical Linux desktop.
Also there's something to be said for security through obscurity. My bet is I could go through my entire junk mail folder opening all attachments on Linux without a problem, but it'd take me less than 10 on windows to be fully owned. If you're careful on Linux aren't you far, far safer than if you're careful on Windows?
Almost all popular applications on flathub come with filesystem=host, filesystem=home or device=all permissions, that is, write permissions to the user home directory (and more), this effectively means that all it takes to "escape the sandbox" is echo download_and_execute_evil >> ~/.bashrc. That's it.
This includes Gimp, VSCode, PyCharm, Octave, Inkscape, Steam, Audacity, VLC, ...
To make matters worse, the users are misled to believe the apps run sandboxed. For all these apps flatpak shows a reassuring "sandbox" icon when installing the app (things do not get much better even when installing in the command line - you need to know flatpak internals to understand the warnings).
And given that the version of Fedora I use is immutable and even I have a hard time messing with it to the point of pain/exploit with full access to the system (and I've tried for fun in VMs) I feel like a trusted flatpak app I download from a trusted source is going to have a damn near impossible time doing much of anything. While I feel like a simple website hack that serves me a bad .exe could/would cripple every single file it can find on my network on a Windows machine.
You can come up with theoretical threats all day that Linux is susceptible to, sure.
But at the end of the day, there is not a single serious cloud company (or just about any tech company that isn't MS) genuinely looking at "we should switch to Windows or MacOS for the backbone of our company," And it's Linux that gets the downstream security that comes with that.
Whole lotta cope in this thread.
As for immutable distros, AFAIK Silverblue and others are immutable in the sense of package management, but there is actually no process to ensure the integrity of the full boot chain because initrd can be trivially modified by the host and is unsigned. There is a UKI (Unified Kernel Image) proposal that will likely be the path going forward (at least on the Red Hat world), but I think it's still years away.
In my opinion, if you want to use Linux desktop securely, just use Qubes.
If we are talking about a device in which you do banking, shopping, manage sensitive or work data, etc. then I think security should be a priority. For more casual use, I agree Qubes would be overkill.
> Which one are you choosing?
I'd rather execute Setup.exe inside Windows Sandbox or denying UAC prompts, or a random macOS binary (provided SIP is not disabled) than a Flatpak. To be clear, I think Flatpak is an improvement, I'm glad it exists and I hope it continues evolving. But in my opinion, the Linux desktop still has a long way to catch up to Windows and macOS on security.
The only people I know who've had any sort of malware infection at all in the last 15 years are the ones who download and install random .exe files from spam emails and pirated TV streaming sites.
Since such a thing is currently unavailable, I'm inclined to try running ChromeOS, then having a headless Linux box next to it in the hopes that my customizing the headless Linux box will satisfy my need to customize my software environment.
For example, I'm inclined to try to keep most of my personal files on the headless Linux box.
Ironic that this article would ignore Mac OS, a somewhat notable commercial Unix.
https://gs.statcounter.com/os-market-share/desktop/united-st...
A PC costing as much as the Mac would fare better, but all Macs are high-quality hardware, and only a fraction of PCs. The average PC is discarded before the average Mac.
*Caveat, I can't agree or disagree with the claim that most PCs are discarded faster. We still have a software problem with Macs. I don't know.
These figures are consistent if we assume that the average Mac makes 2.2 as many requests to web servers as the average desktop computer does--which I am ready to believe: some people use the web much more intensively than others do, and I can easily believe that such people are more inclined (specifically, more than twice as inclined) to chose a Mac than the average computer buyer is.
If a person does not care about computers or the internet and uses them only occasionally, then simply based on the differences in purchase price, they are probably much more differentially likely to buy a Windows machine than a Mac.
I don't understand this headline, was it written by a bot?
It might be that the title may be clickbait-y, but that is I guess to be expected in this day. Someone reading has the choice to just not interact if that title is too much bait.
Here it's a loose game of word association. For example, title says "GNU" in any context so we get 300 comments with unrelated anecdotes about Stallman. The comments section becomes stories about whatever random nonsense is in the top 2-3 comments. When it was being published, n-gate[0] was great at highlighting this.
The Linux VM has limited availability. I believe it depends on your processor (I have an i5, some Chromebooks have ARM.) It needs to be enabled as a "developer option" and yes, it is labeled as a developer tool, which means it could break. It will not work if you're logged in with multiple users. (Neither will the Android subsystem.)
ChromeOS will not run graphical Linux applications out of the box. I haven't experimented enough with the VM, but it does not have X11, Gnome, KDE, or Wayland dependencies installed; it is a minimal package list.
The Linux CLI runs in a VM (and a container too, I believe.) So you're running Linux in the sense that WSL runs Linux. ChromeOS Linux has limited access to the rest of the system. You need to configure each shared folder, for example.
That's userland. There aren't any Linux drivers to install, uninstall, or corrupt. You can't look through /proc or do meaningful system monitoring that you would find on Linux. There's no crontab or any scheduled tasks, for that matter.
I'd say it's one notch up from your Android phone in the hierarchy of "what is Linux?"
The point of most publication titles is more to grab attention than merely a dry summary.
The point of this one was to grab attention by being funny and curious through being seemingly illogical.
The readers are expected to be humans not robots. Humans understand and enjoy this. They even have a term just for it. You may google the term "wordplay" for more information.
I agree with you. It's just that this case is unusual.
> The point of the title is to summarize the article.
This title does just that.
Sorry but this is rewarding bad behavior by giving the article a click instead of pointing out how this is a bad headline.
We should not be excusing headlines like this by simple saying that the article has the answer.
While yes I have an issue with the article headline, the person I am responding to just saying "read the article" is just feeding into clickbait.
I really don't think we should be saying "it's their style" as a defense for bad clickbait headlines when we are actively spreading those headlines. Clickbait is a serious problem on the internet and here we are defending it? No... it deserves to be called out. I don't care how funny it is, they are not the onion.
You're right, they can do whatever they want to do. That doesn't mean they are free from bring criticized for doing it.
I do not understand how we are defending a clickbait headline right now.
The headline was intentionally written in a way that it does not make sense to get someone to click it. By saying "read the article" we are rewarding that behavior.
Are you also going to defend the clickbait of Kotaku?
I understand why these companies do it, but I refuse to give them a free pass encouraging clicking a clickbait headline when talking about the fact that the headline does not make sense.
This title, at least not with the cover image included, did not artificially and pointlessly withhold information. The title doesn't mention chromeos or any other linux-based systems, but the picture includes a chromebook, and from that I knew the article was going to be about chromeos, and the title was a joke about chromeos being arguably both a linux system and not a linux system.
If you didn't, assuming you don't happen to be blind and assuming the images alt tag doesn't happen to be specific enough, the deficiency is in you not the article.
Myself, I would not be so eager to advertize that I don't get simple things like this.
https://www.theguardian.com/media/2021/may/13/guardian-200-m...
My English teacher has this on the wall of his classroom: https://www.ambaile.org.uk/asset/49730/
> We feel that a more accurate reckoning would be that Linux has now reached 7.23 per cent of Statcounter's usage figures, with ChromeOS at just over half: 57.4 per cent of the total.
Linux laptops are as Linux as Linux desktops. I had a Linux desktop in the 90s but all my Linux boxes have been laptops since then.
There's a reasonable argument that Chrome OS is Linux--or at least more so than Android is. But it's not so much that it's "the wrong kind of Linux" according to purists as the article says but that it mostly addresses a different use case than installing Fedora or Ubuntu and therefore, IMO, it generally makes sense to treat them separately unless your point is that some form of Linux (and *nix generally) has a pretty large market share on both desktop and mobile.
I've never seen the security stuff from ChromeOS be ported to live outside of ChromeOS. When I looked at it (trying to build the inside-container agents for acustom container image), the error messages for setting it up incorrectly were.. let's charitably say hard to understand. I doubt anyone outside of ChromeOS developers understands it, really.
It's pretty intricate, e.g. giving Wayland access to virtual machines in a safe way.
Have an Android phone? Technically yes. It runs the Linux kernel but not GNU (probably, unless you've installed a layer with gnu).
Have a Chrome OS device? It runs GNU/Linux and most have a user layer that can run Debian.
Have a Windows device? wsl exists and is quite nice. Lots of developers use it.
Is Windows Linux too now?
I don't think this is principled really beyond the fact that Google chose to use different branding whereas FOSS distro vendors actually called what they distributed "Linux." Sort of how Hyenas are phylogenetically feliform but most people consider them dogs.
Do you have some reference for this? I just did a quick survey of the people in the horse barn I'm typing this from and none of them consider hyenas to be dogs. I imagine some people do consider them to be dogs since in some cases they can have a passing resemblance, but I'm dubious that most people consider them dogs.
Mind you I'm not in a horse barn.
Now, I think most people mean "Is that running something that markets itself as Linux, at it's core?"
Even that disambiguation isn't great, though.
How? Last time I looked at this, I needed to install a dedicated Linux-Environment, which came with its own hiccups. That's not really what I would call out-of-the-box. The Android-Integration made a better impression.
Of course, they could base ChromeOS on Debian directly and be done with it, but then they'd lose the incredible ease of custom tailoring to the hardware that Gentoo offers.
In the same way one should ask, are ChromeOS-Installations also counted for the android-marketshare? Do WSL-Installations on windows count to the desktop-linux-share too? Does wine-usage count for windows-installations? They all are important, but also a bit special on their own. How do statistics handle them?
Since ChromeOS is for casual users who will never need to install tools system-wide, I don't really see that much of a limitation in being able to only use things as non-root.
Yes it is, but AFAIK it's still a walled garden. The user has no control over what's going on under the hood. This is different from what most people understand as desktop Linux. Linux is a synonym for full control from the device owner, which in case of ChromeOS is not given.
This is a shortcoming in the naming, and it might be better to find a better term, but this is still the current situation we have.
> Linux is a synonym for full control from the device owner, which in case of ChromeOS is not given.
It really is not, either in theory or more importantly in practice (cf the billion devices that ship Android or shitware ARM trinkets that ship Yocto builds with forked kernels that can't be updated, userspace blob binaries, etc.) One of my last companies had an opts team that provisioned immutable cloud VMs for developers where persistent updates had to go through CI and be deployed/rebooted. Does this mean we weren't "Using Linux?" or that our VMs were "Walled gardens?" Is it a walled garden if I distribute a .deb for my FOSS project and not an .rpm or PKGBUILD for Arch Linux? If anything, the fact of the matter is that you can just install Chrome or $FAVORITE_BROWSER on your favorite distro and then use 98% of the same apps ChromeOS users do -- they're mostly webpages!
The real distinction people need to make is who controls the project and what direction it has, and whether that matters to them. The other stuff are just random goalposts that people make up. ChromeOS is Desktop Linux, it's secure, it's highly successful, and it's also lead by Google. The "Google" part is what makes everyone uneasy. But it's unquestionably a productionized Linux Desktop.
Android is not desktop, and as I understand it, neither are yocto-devices?
We are specifically talking here about market share of desktops, not market share of linux-kernel or the gnu-userland. And while there is some overlap, I don't think it makes much sense to mix those statistics as both have different purposes.
ChromeOS is objectively Linux Desktop. RHEL desktop machines where only the IT department (and not the employees) has root access are objectively Linux Desktop.
you can just install Chrome or $FAVORITE_BROWSER on your favorite distro and then use 98% of the same apps ChromeOS users do -- they're mostly webpages
you could do that on windows too. which just shows that chrome OS is not linux or GNU/Linux on the desktop, but it is actually a web OS. like android, linux and even GNU is only there under the hood and not on the actual desktop.
This is why android and chrome os don’t count. Those operating systems are different enough from my fedora workstation installation that proprietary drivers and software won’t be useful to me.
On the other hand someone using another distro like Debian or Arch does help.
Because when you write about about hardware manufacturers, and software vendors, “supporting” Linux - it is seemingly apparent, that “Linux”, consists of only computers of the “Intel” variety - from my experience.
three years+ daily solid operation, no tech support problems except very rare microphone problems.
If you do not change the peripherals, and the client uses a browser mostly, then "long way away" is just false in 2020s.
Like, click Firefox to browse the web. Click the folder to see your files. Click OpenOffice to write a document. Click yes to run updates. He even somehow installed Zoom himself and set it all up to make calls to his doctor.
Getting him to learn how to swipe, click the hamburger menu, and do basic shit on a smartphone was a pain in the dick.
NB: I dislike Linux.
This is a "ship of thessius" problem. At what point does the ship become a new ship? When it is no longer recognizable as the old ship.
It's basically "Linux proper" (whether is the GNU libc/musl + GNU/whatever userland breakdown) vs "Linux that's a backend for Google's ChromeOS GUI and for which Google could replace the Linux part and noone will be any wiser". Rare or not, the exotic combination I mentioned would still qualify.
Besides, I'm pretty sure ChromeOS still has the whole GNU userland installed.
And while being pedantic about this, they still called Linux a Unix (which it's not) while ignoring the commercial unixes because they're dead (which, as much as I'd like it to be true, it's not in the case of MacOS).
The person who wrote this article was dishonest or ignorant in so many levels.
Uhhhhhhh, on what basis ? The only arguments I can see for this would be either of:
- Pedantry, as technically the Linux kernel itself isn't UNIX certified by the Open Group, who owns the trademark - though multiple distributions have been certified to past standards, with no meaningful changes necessary. As an additional note, if you want to only count implementations conforming to the latest standard as being "real UNIX", then AIX is literally the only UNIX in existence.
- Purity, as Linux doesn't directly use any of the original code from AT&T-created UNIX OSes. But by that standard, it seems like modern BSDs wouldn't qualify as "UNIX", given that all of the AT&T code was stripped out a long time ago, and MacOS would qualify even less given it uses a non-AT&T kernel and only a few parts of some BSDs in the userland. Also, if including AT&T-produced code suffices to be "UNIX" then I must ask whether a Linux distribution that comes with ksh qualifies (...or even if Windows with UWIN or Cygwin+ksh qualifies). Generally though, the argument just reeks of ancestor worship to me.
...and neither of them are satisfactory to me.
Linux is just one piece, and also quite old; by your logic we should really just call it a GNU system. In fact, from a user perspective, a GNU/HURD or Debian GNU/kFreeBSD system far more closely resembles what you're calling Linux than, say, Android which literally uses the Linux kernel.
It's nonsense to argue that Ubuntu and Fedora are "Linux" and Android is not. It is not nonsense to want to put Ubuntu and Fedora in the same bucket, which does not contain Android or Alpine. That bucket is GNU.
When we use the words to mean what they are (not using Linux to mean software other than Linux) the point that the author is trying to make becomes obvious.