Bonum Certa Men Certa

Nearly 40 Years Without Security Incidents

posted by Roy Schestowitz on Nov 03, 2024

Wires

LATER THIS week (on Thursday) this site turns 18 and we've already bought some party kits for the sister site's 21st anniversary. Next year the combined age - the age of both sites - will be 40. Over the years the sites ran Gentoo, Debian, CentOS, and Alpine.

In all this time we've never suffered a breach (security incidents) and since upgrading to Debian 12 we've hardly had to endure DDOS attacks. Aside from increased capacity owing to static pages replacing WordPress, Drupal, and MediaWiki, there are also some firewalling mechanisms that obstruct abusive bots and botnets.

Speaking for myself, I never ever had security incidents on my desktops/laptops. In my childhood, way back in the DOS days, there would be the occasional "rogue" floppy disk with a virus on it, but that predates the Web and viruses could not pass from one computer to another wirelessly or over a network cable (which most homes did not have at the time). As this predated hard-drives (for most people), a virus would be hard to transmit from one program to another (except RAM) and many boiled down to pranks, not ransom, extensive data loss, or permanently damaged hardware.

People who use Windows have come to sort of "accept" that security incidents are part of life or "normal". Disaster is always "imminent" and "unavoidable" (inevitable). At my last employer we saw clients' systems suffering security incidents (reasons varied), as did the last university I worked for. GNU/Linux isn't invulnerable to 'Windowsheads' assigned to manage it. Yes, a common pattern was neglect and mismanagement; misconfiguration was one symptom. One client put JBoss on Windows. Yes, Windows!! All the other machines (back end) ran GNU/Linux. This boiled down to an old technician (in his 60s) who used Microsoft for everything, even for his E-mail!

People who know how to run GNU/Linux (and not just reboot any time something goes wrong) can use it safely for many years. In my case, my two primary laptops have already had a combined uptime of 700+ days. And yes, those are safe. The world-facing (e.g. over SSH) machine is fully patched and was last rebooted (for a new kernel) about a week ago. It runs Debian 12.

The Microsoft-funded (e.g. by "ads") media likes to claim that "Linux" is not secure, but it often boils down to GPL violations or appliances/servers running Linux (or other key packages) that's years out of date while connected to the Net, sometimes needlessly. Not every machine needs to be accessible by anyone on the Net; or facilitate printing by every/any random IP address, even from North Korea.

3 years ago Dr. Andy Farnell said that "We Can't Teach Cybersecurity" in today's universities. He explained that real security practices are verboten or ridiculed, whereas snake-oil and charlatans take their place. Revisit what he wrote this past summer about "Clown Computing". This issue isn't limited to Microsoft, even if Microsoft remains the "worst of breed".

Other Recent Techrights' Posts

Topics We Lacked Time to Cover
Due to a Microsoft event (an annual malware fest for lobbying and marketing purposes) there was also a lot of Microsoft propaganda
EPO Education: Workers Resort to Legal Actions (Many Cases) Against the Administration
At the moment the casualties of EPO corruption include the EPO's own staff
 
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, November 22, 2024
IRC logs for Friday, November 22, 2024
Gemini Links 23/11/2024: 150 Day Streak in Duolingo and ICBMs
Links for the day
Links 22/11/2024: Dynamic Pricing Practice and Monopoly Abuses
Links for the day
Microsofters Try to Defund the Free Software Foundation (by Attacking Its Founder This Week) and They Tell People to Instead Give Money to Microsoft Front Groups
Microsoft people try to outspend their critics and harass them
[Meme] EPO for the Kids' Future (or Lack of It)
Patents can last two decades and grow with (or catch up with) the kids
Gemini Links 22/11/2024: ChromeOS, Search Engines, Regular Expressions
Links for the day
This Month is the 11th Month of This Year With Mass Layoffs at Microsoft (So Far It's Happening Every Month This Year, More Announced Hours Ago)
Now they even admit it
Links 22/11/2024: Software Patents Squashed, Russia Starts Using ICBMs
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, November 21, 2024
IRC logs for Thursday, November 21, 2024
Gemini Links 21/11/2024: Alphabetising 400 Books and Giving the Internet up
Links for the day
Links 21/11/2024: TikTok Fighting Bans, Bluesky Failing Users
Links for the day
Links 21/11/2024: SpaceX Repeatedly Failing (Taxpayers Fund Failure), Russian Disinformation Spreading
Links for the day
Richard Stallman Earned Two More Honorary Doctorates Last Month
Two more doctorate degrees
KillerStartups.com is an LLM Spam Site That Sometimes Covers 'Linux' (Spams the Term)
It only serves to distract from real articles
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, November 20, 2024
IRC logs for Wednesday, November 20, 2024