You need to use VM-based isolation to have good security with Linux beyond that (i.e. use Qubes or a similar alternative).
You need to use VM-based isolation to have good security with Linux beyond that (i.e. use Qubes or a similar alternative).
Security != Privacy
Imagine home security monitoring your home 24/7. You lose privacy but gain security.
It matters who's doing the monitoring. With a home security system, it's you – or whoever you've delegated to –, and you chose to set it up; with these operating systems, it's somebody else, and you have little choice in the matter.
Companies and people who also strongly value their privacy, built and host their own on-prem infrastructure.
That's not the point. The question is, why should they be able to? And it's not about robbing but having total control over your own hardware.
Because when the moment comes, you can be sure they will do it. Adobe proved it when they disabled the software their customers in Venezuela used, just like that - because they could.
Technically nothing is stopping them from robbing you similar how noting is technically stopping your landlord from robbing you and yet most won't do it because they don't like the idea of going to jail.
We enter into an agreement that they won't rob you, and we trust that to the protection you have from the code of law, courts and the state enforcement where you live to protect you from the other party robbing you.
Currently in the EU, I see our governments have enough fangs to ensure tech companies won't rob us but those who seek the utmost independence should roll out their own on-prem.
>Because when the moment comes, you can be sure they will do it.
Then they'll get a class action lawsuit.
>Adobe proved it when they disabled the software their customers in Venezuela used, just like that - because they could.
Yeah, if you live in a country where the state is weak, companies can easily rob you, but if you live in a place without a functioning government like Venezuela, then Adobe is probably at the bottom of the list of entities who are out to rob you, way behind the government itself and various gangs.
This is hardly a counter-argument, on the contrary. Imagine being a Venezuelan and already suffering from high inflation rates, social unrest and so on. Now on top of that, you lose access to software you depend on.
Again, the point is not "being robbed". The point is that corporations are in control of important pants of your lives when they shouldn't.
Also, there's some design decisions made in Windows that lead to poor security. e.g. treating a file's extension differently, assigning it special meaning and then hiding it by default from the user.
The file extension bit is sort of silly as well, as, it's what made Windows as user-friendly and wide spread as it is today. Better that than treating everything as a file and allowing anything to be piped anywhere.
I think the bigger point is the ethos behind the Operating System(s) and the opaque nature of Windows that causes these downstream effects.
I don't think that showing a file extension is massively confusing to people if they were always shown them. The problem is that there were real problems with a file extension looking like e.g. a picture, but instead had an executable extension e.g. image.jpg.exe
Are you sure? To me it looks like Windows got popular in spite of glaring security decisions, not because of them.
It's also worth noting that all of Winget's code was initially taken from AppGet, without much recognition.[1] Apparently Microsoft cared just enough about that detail to mention the project they forked in passing, as part of a list of third-party package manager projects for Windows.[2] This is why, IMO, you should always first consider a copyleft license for an open source project.
[1] https://www.theverge.com/2020/5/28/21272964/microsoft-winget...
[2] https://devblogs.microsoft.com/commandline/windows-package-m...
EDIT: fixed vertical spacing.
Do many third parties use it?
Can you do that with a compiled executable?
What user can do doesn't matter. It matters what they actually do.
Yes, and Windows users often install stuff from 3rd party websites whilst it's comparatively rare for Linux users.
This would need some substantiation. I personally had not seen many setups that did not require 3rd party websites.
Almost all windows applications are distributed as compiled binaries. Even very advanced users would find it difficult to audit most apps.
Bash scripts are in plain text, and idiomatic enough that it can be read by anyone with a passing familiarity with bash. Which is the very large majority of Linux users. The script very clearly states what it does, and if it doesn't, you shouldn't run it.
Driver updaters are nearly universally malware, and the common advice has always been to avoid them as such. Similarly, running random bash scripts from the internet without even looking is discouraged in the same way. Mystery binaries are much more dangerous than a script because you can't audit them, but the same advice is given for both: don't.
If what the user can do matters less than what they actually do, then Windows is the most insecure operating system by a very large margin. Windows users install malware at rates order of magnitude higher than any other system. Linux may as well have zero vulnerabilities compared to the shit that Windows users will blindly install.
You're right, it's stupid to compare these situations. So why are you doing it?
What does Windows have to do with users ignoring best practice again?
> You're right, it's stupid to compare these situations. So why are you doing it?
I was not, you are excusing yourself from your own mistake. I was comparing people who install driver updaters with people who run random bash scripts from the Internet. Then you tried to convince me the right thing would be comparing with (imho mythical) people who read every bash script they download.
https://popcon.debian.org/ https://wiki.debian.org/PrivacyIssues
Advertising is indeed much less common but is being explored. There have been some HN posts about the backlash that occurs when it gets introduced.
Certainly Debian isn't evil, and popcon is indeed opt-in. Popcon does make it possible for all Debian members (who can access the submission data) to probably identify other contributors and possibly others too. Also we do inherit lots of privacy issues from upstream projects. For eg GNOME calculator app in Debian still connects to the IMF and other websites even when.
Except they do: https://www.omgubuntu.co.uk/2022/10/ubuntu-pro-terminal-ad
https://www.eff.org/deeplinks/2012/10/privacy-ubuntu-1210-am...
It's incomparable to what MSFT does.
One was advertising Amazon, the other was advertising their paid support service. NEITHER was telling users about automatic updates.