do windows viruses get ported by such efforts as well?
do windows viruses get ported by such efforts as well?
However, there is a permissions layer that is more nix than Windows, which means the first foothold is still better than XP - you have to choose to execute the file. Self-running things don't tend to infect systems.
Its not a panacea, and there is a risk factor. And there aren't a lot of antivirus systems that can run correctly under ReactOS, because they freak out and think the OS is the malware, because they're scanning hashes for Windows, not another system.
But for a hobby OS, keeping hardware and software accessible after the rest of the world broke access, it still works.
so you can set an app to use a Windows XP compatibility profile, and this will simulate Windows bugs which were fixed in more recent versions of the OS
EDIT: Worth noting, Arch ain't hosted on AUR. That's the community side only.
[0] https://archlinux.org/news/active-aur-malicious-packages-inc...
I can still happily upgrade via pacman without fear. Haven't been able to update on Windows without concern for over a decade - the malware comes builtin.
[0] https://www.cisa.gov/sites/default/files/2024-03/CSRB%20Revi...
I only have 4 packages installed with AUR and I think that’s the intention. You’re only going there when the other solutions aren’t available or don’t make sense.
Only Apple has made that claim in their marketing and that was 20 years ago when security by obscurity was shielding them, and when Windows XP was such a cesspool that anything with a normal amount of malware would look virus-free by comparison.
Btw if you're running an OS that's never had a malware incident, please, tell us!
the ransomware campaigns would have happened on any OS enterprises use, because they were not security flaws in the OS
...is essentially impossible to pull off against commercial operating systems, because their core components are all written in-house by staff with photo ID badges, details with HR, tax returns filed with the government, and a cubicle that makes sure that they're locals and not some faceless anonymous hacker identifiable by nothing other than a throwaway faked email address!
I get that there was a lot of "stigma" about open source, the world largely forgot about it, but... actually, in this sense of allowing anonymous contributions it remains a very real risk.
"Jia Tan" was almost certainly a paid professional hacker working for a nation-state actor. Their "helpful contributions" to XZ utils was nowhere near a full-time effort. They certainly had "other irons on the fire", most probably in the Linux kernel or immediately adjacent to it.
He's probably not the only one doing this kind of "work".
For all you know, Linux has more remote exploits purposefully baked into it than Windows has security bugs inadvertently left in it... and don't forget Linux has bugs leading to security vulnerabilities too!
A rough count of "named" CVE 10.0 score (or close to it) vulns in the last 5 years:
7 for Microsoft: ProxyLogon, ProxyShell, ProxyNotShell, LDAPNightmare, PrintNightmare, noPac, Follina
10 for Linux: XZ Utils, regreSSHion, Leaky Vessels, Copy Fail, PwnKit, Dirty Pipe, Looney Tunables, GameOver(lay), Baron Samedit, Sequoia
As for "Linux", you'd need to specify the distro and environment, because Linux systems can be very different from one another. Your XZ example for instance didn't even affect most enterprise distros (like RHEL). regreSSHion didn't affect any musl libc distros like Alpine, but other systems would've also been unaffected had you set your LoginGraceTime to 0, which any sysadmin worth their salt would've done so. Leaky Vessels fails on SELinux enforcing distros (RHEL, Fedora etc) and sandboxed environments. I could go on, but you get the picture. Comparing the number of "Linux" vulnerabilities to Windows is completely pointless.