Also, there's some design decisions made in Windows that lead to poor security. e.g. treating a file's extension differently, assigning it special meaning and then hiding it by default from the user.
Also, there's some design decisions made in Windows that lead to poor security. e.g. treating a file's extension differently, assigning it special meaning and then hiding it by default from the user.
The file extension bit is sort of silly as well, as, it's what made Windows as user-friendly and wide spread as it is today. Better that than treating everything as a file and allowing anything to be piped anywhere.
I think the bigger point is the ethos behind the Operating System(s) and the opaque nature of Windows that causes these downstream effects.
I don't think that showing a file extension is massively confusing to people if they were always shown them. The problem is that there were real problems with a file extension looking like e.g. a picture, but instead had an executable extension e.g. image.jpg.exe
Are you sure? To me it looks like Windows got popular in spite of glaring security decisions, not because of them.
Do many third parties use it?
It's also worth noting that all of Winget's code was initially taken from AppGet, without much recognition.[1] Apparently Microsoft cared just enough about that detail to mention the project they forked in passing, as part of a list of third-party package manager projects for Windows.[2] This is why, IMO, you should always first consider a copyleft license for an open source project.
[1] https://www.theverge.com/2020/5/28/21272964/microsoft-winget...
[2] https://devblogs.microsoft.com/commandline/windows-package-m...
EDIT: fixed vertical spacing.
Can you do that with a compiled executable?
What user can do doesn't matter. It matters what they actually do.
Yes, and Windows users often install stuff from 3rd party websites whilst it's comparatively rare for Linux users.
This would need some substantiation. I personally had not seen many setups that did not require 3rd party websites.
Almost all windows applications are distributed as compiled binaries. Even very advanced users would find it difficult to audit most apps.
Bash scripts are in plain text, and idiomatic enough that it can be read by anyone with a passing familiarity with bash. Which is the very large majority of Linux users. The script very clearly states what it does, and if it doesn't, you shouldn't run it.
Driver updaters are nearly universally malware, and the common advice has always been to avoid them as such. Similarly, running random bash scripts from the internet without even looking is discouraged in the same way. Mystery binaries are much more dangerous than a script because you can't audit them, but the same advice is given for both: don't.
If what the user can do matters less than what they actually do, then Windows is the most insecure operating system by a very large margin. Windows users install malware at rates order of magnitude higher than any other system. Linux may as well have zero vulnerabilities compared to the shit that Windows users will blindly install.
You're right, it's stupid to compare these situations. So why are you doing it?
What does Windows have to do with users ignoring best practice again?
> You're right, it's stupid to compare these situations. So why are you doing it?
I was not, you are excusing yourself from your own mistake. I was comparing people who install driver updaters with people who run random bash scripts from the Internet. Then you tried to convince me the right thing would be comparing with (imho mythical) people who read every bash script they download.