this post was submitted on 05 Aug 2023
1974 points (97.3% liked)

linuxmemes

21605 readers
729 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack members of the community for any reason.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry will not be tolerated.
  • These rules are somewhat loosened when the subject is a public figure. Still, do not attack their person or incite harrassment.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn. Even if you watch it on a Linux machine.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, and wants to interject for a moment. You can stop now.
  •  

    Please report posts and comments that break these rules!


    Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't fork-bomb your computer.

    founded 2 years ago
    MODERATORS
     

    For those who are wondering, yes, Wine is malware compatible so be careful about the EXEs you run!

    https://wiki.winehq.org/FAQ#Is_Wine_malware-compatible.3F

    you are viewing a single comment's thread
    view the rest of the comments
    [–] PutangInaMo 23 points 1 year ago (4 children)

    I think you have a false sense of security with regards to Linux vulnerabilities and exploitations. There are dozen of known exploits throughout the Linux ecosystem that are publicly disclosed frequently.

    What makes you think Linux is more secure than windows? I'm not trying to start an argument here I'm just curious.

    [–] fidodo 13 points 1 year ago (2 children)

    I find the Linux ecosystem has far better updating mechanisms than Windows and it doesn't have as much backwards compatibility cruft as Windows. That and the open source nature I think is better at having exploits uncovered. I'm not saying Linux is perfectly secure, but that it's more secure than Windows. But I think the biggest reason it's less likely to get viruses is just that it's a smaller target and that hackers aren't spending as much time trying to attack it, plus the users are more tech savvy meaning any attacks will be less lucrative.

    [–] Freesoftwareenjoyer 2 points 1 year ago (1 children)

    it’s a smaller target and that hackers aren’t spending as much time trying to attack it

    It's the most popular server system, so I'm not so sure about that.

    [–] fidodo 4 points 1 year ago (1 children)

    The target user base is much smaller. Most viruses are spread through user error and server administrators are far more competent than a typical OS user. Also, typical server exploits lead to exposing credentials rather than spreading viruses.

    [–] Freesoftwareenjoyer 2 points 1 year ago

    Software is usually installed from repositories and not random websites, so there is less room for user error in general. Even if you download an executable file, you will most likely have to give it permissions to run first. So I think it's more immune to viruses not because of its users, but because of the way it's designed.

    [–] PutangInaMo -2 points 1 year ago

    Open source can be a double edged sword for that but I dig it.

    I think dependencies in Linux packages does cause a lot of issues but that's mostly on air gaped networks, and even still manageable.

    Sizing the target depends on what threat actors are involved though so those broad stroke statements don't hold up well in reality, from my Experience.

    [–] [email protected] 9 points 1 year ago (3 children)

    Not sure what their answer is but not delaying security fixes until some fixed monthly date would be my answer.

    [–] [email protected] 4 points 1 year ago

    And a single place to download and install all those security fixes with one command.

    [–] [email protected] 4 points 1 year ago

    To be fair, critical security patches for Windows are often delivered out of band (not on patch Tuesday). And malware definitions for Defender are daily.

    Not trying to defend Microsoft entirely, but not everything is delayed until their monthly update schedule.

    [–] PutangInaMo 2 points 1 year ago

    To be fair if it's scored high enough there are usually workarounds posted and supported to hold you over for patch Tuesday.

    I've done patch management on both platforms and find the predictability easier to manage. But that's not home use so grain of salt stuff.

    [–] [email protected] 3 points 1 year ago (1 children)

    There's a difference between exploits and malicious software (even though malicious software often makes use of exploits, it is different). I am willing to bet there is way way more malicious software written for Windows than Linux, simply because there's way more Windows users than Linux users and there's way more Windows software than Linux software.

    [–] PutangInaMo 1 points 1 year ago

    Yeah that's true. But I say false sense of security because that's what happened to Apple back in the day and they got caught with their pants down lol

    [–] Freesoftwareenjoyer 3 points 1 year ago

    GNU/Linux is Libre Software, so that already makes it more secure, because anyone can actually verify what it does and modify it if needed. This means that users are really in control of what the operating system does. It's difficult to verify what Windows does, but we know that it contains spyware, which isn't easy to remove.

    Installing software from a repository is also safer than downloading it from random websites.

    When some library like OpenSSL has a vulnerability, you will get a new version with system updates and all programs will start using that patched version. On Windows usually each program has to have its own update mechanism or it will be stuck with old libraries.