Live data from Hacker News

Is the Linux Desktop less secure than Windows 10? [pdf]

fosdem.org

61–70 of 190 posts

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#61
post #42

When this metadata indexing was introduced in gnome/kde many users complained, because it pegged their cpu and was really unasked for. But some felt that this was something the MacOSX had and therefore some developers felt it was a good default. I'm not convinced, partly because of the increased attack surface. The desktop environment itself is but a small part of the complete desktop. Some important differences betw…

> I hope the Linux desktop never emulates them.

Sadly the big ones are. Because they consider this behavior "user friendly".

At the same time they think they can contain the threat by wrapping everything in sandboxes. Effectively infantilizing the owner/user of the personal computer.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#62
post #60
post #42

When this metadata indexing was introduced in gnome/kde many users complained, because it pegged their cpu and was really unasked for. But some felt that this was something the MacOSX had and therefore some developers felt it was a good default. I'm not convinced, partly because of the increased attack surface. The desktop environment itself is but a small part of the complete desktop. Some important differences betw…

Showing dialogs is not a solution. Various studies have already shown users click any dialog which pops up without actually reading the dialog. Loads of browsers do download automatically. Making things inconvenient and delegating security decisions to the user isn't good enough. Make it convenient and secure! PS/Edit: Btw, under Windows 10 loads of things are indexed. It makes things very convenient. You use your pc…

Hello Gnome...

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#63
post #48
post #35

Hmm. If i look at the slides, the article should be renamed "gstreamer, and some stuff browsers on all platforms do, are insecure"? Is it easier to change your media player on Linux, or to trust Microsoft? Say, does a default Windows install still enable 20 networked services that don't belong on a home computer and can be exploited without the user downloading anything?

To answer the second question, no. A fresh install of Windows connected to the Internet will not be infected automatically (of course, assuming no new 0-day)

Assuming no new 0-day... so there are still services open to the internet by default on a fresh install eh?

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#64

If anything, Linux may benefit from relatively varied installation states in security scheme (SELinux, Apparmor, etc.), libraries included, and desktop environment. It is perhaps bit harder to pull off one-size fit-all attacks. Things like data at rest protection seems to work better on Linux; as far as I know, there aren't out of box solution for Pre-boot authentication for Windows, for instance. Edit: To the latter…

Windows RT was the playground for Windows security ideas. Every Windows RT device connected to a Microsoft account has device encryption backed by the TPM enabled for example...

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#65
post #35

Hmm. If i look at the slides, the article should be renamed "gstreamer, and some stuff browsers on all platforms do, are insecure"? Is it easier to change your media player on Linux, or to trust Microsoft? Say, does a default Windows install still enable 20 networked services that don't belong on a home computer and can be exploited without the user downloading anything?

Gstreamer is more a codec library than a media player. There is a multitude of (GTK based) media players on Linux that tie into Gstreamer. Heck, even Firefox call upon Gstreamer on Linux to play embedded media...

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#66
post #25

I am a big fan of grsec, RBAC and sandboxing stuff. But let's be real here people! Those are good features on servers where there isn't a giant security black-hole called X, where any local exploit of the app can turn it into a compromise of the entire GUI system. Look at the hoops that adversary resistance focused distros like SubgraphOS have to jump through just to mitigate the giant attack surface that X opens. Un…

Security should be multi layered. So if one thing fails there's still yet another layer of defence. This because everything will have bugs anyway, so it should be assumed none of the layers will ever be fully secure.

systemd offers various methods to restrict daemons in their abilities. That's hardly used. Only recently tracker started sandboxing their indexers. Why block adding other security laters on Wayland? There's no need to wait, nor do these layers depend on another.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#67
post #31

Given that piping curl in bash with sudo is considered acceptable, this is not surprising

Outside of architecture astronautical web development (usually done on a Mac while sipping some kind of coffee and milk blend) no it is not acceptable one bit.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#69
post #66
post #25

I am a big fan of grsec, RBAC and sandboxing stuff. But let's be real here people! Those are good features on servers where there isn't a giant security black-hole called X, where any local exploit of the app can turn it into a compromise of the entire GUI system. Look at the hoops that adversary resistance focused distros like SubgraphOS have to jump through just to mitigate the giant attack surface that X opens. Un…

Security should be multi layered. So if one thing fails there's still yet another layer of defence. This because everything will have bugs anyway, so it should be assumed none of the layers will ever be fully secure. systemd offers various methods to restrict daemons in their abilities. That's hardly used. Only recently tracker started sandboxing their indexers. Why block adding other security laters on Wayland? Ther…

The best defense in this regard is not do jack all unless the user asks for it.

Re: Is the Linux Desktop less secure than Windows 10? [pdf]

#70
post #56
post #44

Earlier quoted context omitted.

Yeah, screw that guy for offering free quality content in video form, AND the nicely written text piece you just asked for.

Where is it? The PDF has some slides, not actual text, and the LWN article is also just a summary.

(there should be a video soon)
Post reply on HN