Live data from Hacker News

Is the Linux Desktop less secure than Windows 10? [pdf]

fosdem.org

151–160 of 190 posts

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#151
post #100

Earlier quoted context omitted.

> Windows does it, too, I guess No, it generates thumbnails outside the main UI thread; sometimes it's a bit slow in so doing, but I've never seen it hang an Explorer window, regardless of file size or quantity. (Windows 7, but it would astonish me to learn that 10 displays a regression here.)

It's pretty well known. There are several workarounds. One is to optimise view for general, not images or video or sound. Another is to "reset your folders" http://superuser.com/questions/1097394/windows-10-download-f...

Might another option be to have the default view be "List"? I'm not sure if that's possible, but I've been wanting to do this for years.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#152

Earlier quoted context omitted.

A random exe file you download won't be running through sudo, you'll see elevation requests. The elevation request is ~very spooky~ unless the exe is codesigned by a reputable certificate issuer. W10 turns the whole screen red and sometimes warns you that the exe itself is actively unsafe. Of course, end users will just click OK on the elevation request, but regardless, it's not a fair comparison. Downloading random…

So is your objection just that sudo isn't scary enough?

No, his objection is something like "I'm a poweruser. I can shoot myself in the foot, please neuter me."

To elaborate a bit: most of the times, you don't have to sudo-install. If you're someone savvy enough to use a command line and understand these commands (if you enter them without this knowledge you're just plain stupid and nothing will save you), then there's no problem: you are the firewall, and you apply the level of caution appropriate for how much you thrust your source.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#153
post #111

It's interesting that the problems are all with things that I actively dislike about the modern Linux desktop. I mean, I guess it's OK that it creates thumbnails of images...but, the tendency to grind away for seconds whenever opening a big folder (Windows does it, too, I guess) is just annoying. I end up using command line most of the time for file management tasks because it's too slow and cumbersome to use the UI.…

Well, Windows 10 has become a form of spyware out of the box, it sends information about what one types and does to Microsoft. They use dark patterns so that users don't disable it and stick to the defaults. macOS is also very chatty, but privacy is usually given more consideration. Not at all as bad as MS.

"macOS ... privacy is usually given more consideration"

Definitely not my feeling last time I upgraded macOs: I had to give my full name, address, * phone number * and * * bank details * * while the upgrade is free of cost.

I don't like having these details hanging on server somewhere on Internet when it is not needed.

I felt like my profile was given a lost of consideration by Apple, not my privacy.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#154
> ASLR: Debian: Work in progress (Stretch / 2017).

From the dpkg-buildflags manpage:

> Additionally, since PIE is implemented via a general register, some architectures (most notably i386) can see performance losses of up to 15% in very text-segment-heavy application workloads; most workloads see less than 1%. Architectures with more general registers (e.g. amd64) do not see as high a worst-case penalty.

Is this the reason why the adoption of pie is so slow? Does rust enforce hardening techniques?

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#155
post #60

Earlier quoted context omitted.

Showing dialogs is not a solution. Various studies have already shown users click any dialog which pops up without actually reading the dialog. Loads of browsers do download automatically. Making things inconvenient and delegating security decisions to the user isn't good enough. Make it convenient and secure! PS/Edit: Btw, under Windows 10 loads of things are indexed. It makes things very convenient. You use your pc…

'locate' is 35 years old. And has been available on linux desktops since 1991. Just saying.

Locate doesn't do what Windows 10 does with search (locate just does filenames). Plus it's slower than Windows 10 nor does it give the most relevant results first.

Windows 10 experience: you press start then type in a few letters and you already get good relevant results. This completely different from locate!

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#156
post #60
post #42

When this metadata indexing was introduced in gnome/kde many users complained, because it pegged their cpu and was really unasked for. But some felt that this was something the MacOSX had and therefore some developers felt it was a good default. I'm not convinced, partly because of the increased attack surface. The desktop environment itself is but a small part of the complete desktop. Some important differences betw…

Showing dialogs is not a solution. Various studies have already shown users click any dialog which pops up without actually reading the dialog. Loads of browsers do download automatically. Making things inconvenient and delegating security decisions to the user isn't good enough. Make it convenient and secure! PS/Edit: Btw, under Windows 10 loads of things are indexed. It makes things very convenient. You use your pc…

>Showing dialogs is not a solution. Various studies have already shown users click any dialog which pops up without actually reading the dialog.

I can't count the number of times that I was in the middle of writing a sentence, a dialog showed up, I accidentally pressed space bar and I was left wondering WTF just happened.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#157

Earlier quoted context omitted.

> it gives a false sense of security Why is getting the latest security updates giving a false sense of security exactly? > The File Manager UI, for example, lacks too many features and user must investigate alternatives and either assume that everything is all right or deeply examine security vulnerabilities for each available option. Same goes for basic things like text editor or calculator and so on. This is where…

> Why is getting the latest security updates giving a false sense of security exactly? Because in quite a few distributions you don't get security updates reliably. For example Debian Stable excludes most WebKit-based libraries from their update policy. https://www.debian.org/releases/stable/amd64/release-notes/c... So users of browsers like Midori and Epiphany or E-Mail-Clients like Evolution on Debian Stable, curre…

This is why I think Rolling Release is the only viable model of Linux distribution in desktops. Instead of overloading a team of security experts expecting them to backport every security change to the stable version of a package, they simply follow upstream releases, build it and make sure that isn't horrible broken (however, they can't be sure that the upgrade path is seamless for every possible configuration).

BTW, it is possible to check in Ubuntu which packages are supported or not: http://manpages.ubuntu.com/manpages/xenial/man1/check-suppor...

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#158
post #77

Earlier quoted context omitted.

That's how Flatpak works with its portals, so assume you'll now read what I wrote instead of simple responses?

Should have guessed you would claim that monstrosity as the fix for your (Gnome's) other monstrosity.

I didn't argue that there's one fix, I mentioned that there should be multiple layers. If you'd read what I write you'd have known this. Further, just being negative and calling names vs maybe making an argument isn't helping your case.

You dislike GNOME.. meh.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#159

what Linux desktop?

The Gnome DE...

Apport, gstreamer, Tracker/Baloo, Chrome/Chromium/Epiphany, ASLR isn't just GNOME. It seems investigation started on Ubuntu (Unity 7). It affects multiple desktops and as others notes, also Baloo.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#160
post #30
post #27

Earlier quoted context omitted.

No, but i'd be worried about a government with power to control Microsoft using such information in a negative way. Basically this scenario comes to mind : a) A power change occurs within a government. This power change facilitates the changing of laws. b) A corporation with massive stores of information about individuals is within this government. c) New government doesn't like X people because they aren't Y people.…

But surely almost all of the above, while theoretically a possible future issue in the USA, is day-to-day reality in Russia and China already.

I don't live in Russia or China. I'm not worried about their governments not liking me.
Post reply on HN