Live data from Hacker News

Is the Linux Desktop less secure than Windows 10? [pdf]

fosdem.org

111–120 of 190 posts

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#111

It's interesting that the problems are all with things that I actively dislike about the modern Linux desktop. I mean, I guess it's OK that it creates thumbnails of images...but, the tendency to grind away for seconds whenever opening a big folder (Windows does it, too, I guess) is just annoying. I end up using command line most of the time for file management tasks because it's too slow and cumbersome to use the UI.…

Well, Windows 10 has become a form of spyware out of the box, it sends information about what one types and does to Microsoft. They use dark patterns so that users don't disable it and stick to the defaults.

macOS is also very chatty, but privacy is usually given more consideration. Not at all as bad as MS.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#112
post #80

Earlier quoted context omitted.

Just because Windows goes down first doesn't mean that Linux is more secure. It only means that it doesn't have a high enough market share to meaningfully exploit for a return on investment. We should take the metric of "given a motivated party, how difficult would it be to exploit this machine" I have no doubt people are already sufficiently motivated to exploit Windows. But maybe only the NSA gives a shit about Lin…

You're ignoring that most Linux distros come with better defaults, i.e. no open ports. Reducing the attack surface is an important part in keeping the OS safe. Windows is remarkably bad in that regard.

I had a look at Windows 10, by default, assuming you clicked Private for the network connection, there are no ports that are open for any program to use. There are 33 rules for the All profile, 18 for the private profile, some duplicates, each of which specifies what local program is allowed to receive data:

9 connect to Modern Windows apps, 1 for ICMPv4, 12 for ICMPv6, 1 for IGMP, 1 for ISATAP, 12 for TCP, Cast to device, IPHTTPS, Network Discovery, WiDi. 15 UDP: 2 for Cast to device, 2 for DHCP, 1 for Teredo, 1 for Delivery Optimization, 1 for mDNS, 7 for network discovery, 1 for miracast.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#113

I mean, the answer is unequivocally, without the slightest doubt, yes. The Linux Desktop is probably a good 5-10yrs behind Windows 10 in terms of defense-in-depth mitigations as well as exploits in common targets like file parsers etc etc. https://www.blackhat.com/docs/us-16/materials/us-16-Weston-W... is a good reference for all the stuff that Desktop Linux in 2017 is for the most part, missing

Now imagine what a Linux distribution could achieve with the same budget...

Write another desktop enviroment from scratch?

/sarcasm

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#114
post #60
post #42

When this metadata indexing was introduced in gnome/kde many users complained, because it pegged their cpu and was really unasked for. But some felt that this was something the MacOSX had and therefore some developers felt it was a good default. I'm not convinced, partly because of the increased attack surface. The desktop environment itself is but a small part of the complete desktop. Some important differences betw…

Showing dialogs is not a solution. Various studies have already shown users click any dialog which pops up without actually reading the dialog. Loads of browsers do download automatically. Making things inconvenient and delegating security decisions to the user isn't good enough. Make it convenient and secure! PS/Edit: Btw, under Windows 10 loads of things are indexed. It makes things very convenient. You use your pc…

'locate' is 35 years old. And has been available on linux desktops since 1991. Just saying.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#115

It's interesting that the problems are all with things that I actively dislike about the modern Linux desktop. I mean, I guess it's OK that it creates thumbnails of images...but, the tendency to grind away for seconds whenever opening a big folder (Windows does it, too, I guess) is just annoying. I end up using command line most of the time for file management tasks because it's too slow and cumbersome to use the UI.…

> Windows does it, too, I guess No, it generates thumbnails outside the main UI thread; sometimes it's a bit slow in so doing, but I've never seen it hang an Explorer window, regardless of file size or quantity. (Windows 7, but it would astonish me to learn that 10 displays a regression here.)

> No, it generates thumbnails outside the main UI thread; sometimes it's a bit slow in so doing, but I've never seen it hang an Explorer window,

As an example of the contrary, I've seen misbehaving third party thumbnail-providers cause Windows explorer to crash entirely.

Only way to "fix" it was to install the software which added the thumbnail-provider, or go into the folder via cmd.exe and rename the file you "knew" caused issued to a different extension while doing the operation you originally came to do.

That may have been on Windows 7 though. I don't know for sure if this weakness still exists in Windows 10.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#116

There's security and there's safety. Linux desktop may well be less secure, meaning that it could be successfully attacked by an experienced attacker. At the same time it's far less likely to be attacked, so it's safer, for the same reason as macOS: less marketshare, few people are motivated to learn/research attack vectors.

Once again: Mac OS in pre-X days had even smaller market share, but many many more viruses in the wild. It's not all about the market share.

But which kind of virus?

An internet-distributed one would be pretty futile, but a diskette-spreading one aimed at a lab with several macs could be pretty successful.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#117

Earlier quoted context omitted.

Now imagine what a Linux distribution could achieve with the same budget...

Write another desktop enviroment from scratch? /sarcasm

> Write another desktop enviroment from scratch?

I think you mean a new distro which is mostly, but not entirely yet another a Ubuntu-derivative, which comes packaged with its own DE and related software.

And no, this new and perfect email-client will still not try to beat Outlook by managing both email and calendar at the same time. Go away!

Seriously... What are Linux Mint and ElementaryOS even thinking?

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#118

Earlier quoted context omitted.

Realistically, about the same. Many of the problems with Windows are rooted in being developed by a huge corporation with as much budget and manpower as it has.

I get your point, but I meant that the open source community works because it can leverage on the work from each other. The achievements would be multiplied by the potential reach.

No, because everyone is busy doing its own little thing.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#119

Earlier quoted context omitted.

You may be aware that since Trump, when you're not a US citizen, you have no rights to privacy. Everything Microsoft collect about the rest of the world is fair game. IIANM this feature was introduced with the patriot act update.

"Since Trump"? The most recent rev to that law was last year. Obama didn't leave office until this one.

yup! Since trump[1]. As I said IIRC this feature has been introduced with the patriot act. At least out of US, privacy oriented online companies put forward that they are outside patriot act jurisdiction.

[1]: https://www.engadget.com/2017/01/26/trump-signs-executive-or...

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#120
post #27
post #20

Earlier quoted context omitted.

Yes, that does not exactly strike me as a rational stance to take. Are you actually more worried about Microsoft blackmailing you about those photos from 4 years ago?

No, but i'd be worried about a government with power to control Microsoft using such information in a negative way. Basically this scenario comes to mind : a) A power change occurs within a government. This power change facilitates the changing of laws. b) A corporation with massive stores of information about individuals is within this government. c) New government doesn't like X people because they aren't Y people.…

Government could as easily control Red Hat, for example.
Post reply on HN