Comment on [deleted]
DjangoFett@lemmy.zip 1 day ago
Linux is safer than Windows
Yes and no. Security through obscurity doesn’t innately mean its more secure. The recent AUR debacle proved that all it takes is a competent and malicious actor with the time and dedication to make something to target Linux. And why has nobody done it? Because the Linux market share is still absolutely pathetic compared to Windows, and is even abysmal when compared to MacOS. The returns on hacking a single Linux distro simply aren’t worth the investment.
I would also argue it is far easier to unintentionally brick your system with Linux, and if people don’t know what they’re doing (see: most end users) they can and will very easily leave themselves more exposed in the long run than by using the spyware that is Windows/MacOS/iOS/Android.
This pretty effectively explains all your other bullet points with minimal extrapolation; everything else you listed requires significant know-how for the systems to function properly. These are the super-deep superusers. Some of them probably tossed a few bones to Microsoft and their end-users, but as others have pointed out individuals and companies have vastly different motivations.
Between those main ideas… Yeah…
corsicanguppy@lemmy.ca 1 day ago
Linux cannot leverage security through obscurity, since its source code is open, so this point is not pertinent.
Aur isn’t Linux. Aur is a feature of a distro and not Linux code.
But I get your point: Aur is a product of dark-pattern app coding that flies in the face of established best practice, of ISO, and of SLSA. Had we not fired our mentors and documenters 20 years ago we would not have had such a Lost Boy generation of system engineers growing up in that wasteland without mentors to tell them why something is a really dumb idea.
Supply-chain exploits are preventable, but only if coders are led by proper system engineers who follow and enforce standards; but this is boring and costly so neither VC money nor the kids building these really bad tools are gonna magically support such a notion.
DjangoFett@lemmy.zip 1 day ago
Obscurity as in there are how many flavors each with their own repos and dependencies? And which one are you using? So which vulnerabilities work on you? And are you even aware of them?
Hiding among the weeds obscures you from view.
And while AUR isn’t Linux code and I definitely understand that, it is very much what you’re talking about; if anybody bothered to RTFM, they’d have had as many AUR issues as I did when the shit hit the fan - precisely none. And I’m only on Arch because Cachy is basically iOS for Arch if you can read and utilize copy/paste functions, a dazzlingly high bar for entry that somehow even I am capable of.
Then again, I also know enough to have a clue as to how much I really don’t know. Most people just assume magic box makes pretty pictures happen and anybody who knows how to change operating systems are literal wizards.
And so I would argue that being on Linux and the variety of flavors is, again, a form of obscurity in and of itself. Yeah, its all open source. Did you plot an attack for that distro? That file structure? How about a missing dependency? It simply isn’t worth it to plot Linux malware at this market share just like 20 years ago it wasn’t worth it to put malware on Macs; their use is still too obscure. Once critical mass is achieved, watch Ubuntu and Mint malware variants increase by an order of magnitude. Until then, the whales are all on Windows and Mac.