Bonum Certa Men Certa

How Debian-type Centralisation Made GNU/Linux Very Secure

Data storage with USB



Summary: Contrary to some malicious allegations, Microsoft remains the one copying security features from Linux, not the other way around

THE technology news sites have begun pushing the "USB" story, suggesting that inheriting Windows-like behaviour makes Linux less secure. There are rebuttals written about it and we may address them at a later stage. For the time being, let us recall the advantage GNU/Linux has not only when it comes to software centralisation in trusted repositories (which verifies safety and protects from malicious downloads from arbitrary sites). One of the big advantages of this approach is that using the same mechanism GNU/Linux keeps all the underlying software -- not just the core of the operating system -- up to date with security patches. Windows does not have that (Apple emulates this and Microsoft only expresses hopes to emulate that, just like it emulates sudo) and in fact one writer is now saying that "Microsoft has to open Windows Update to third-party developers":



There's a lot of confusion out there about when attacks against computers occur as a result of vulnerabilities in software as opposed to some other weakness, usually social engineering. Considerable progress has been made in protection against vulnerabilities on Windows, and we can make exploitation even harder if Microsoft can be talked into my scheme: open up Windows Update to third-party applications.

My own opinion is that social engineering is far more important than vulnerabilities and has been increasing in importance. One reason for this is that vulnerabilities are a harder target than they used to be, and that's in large part because of the work Microsoft has done over the last 6 or 7 years.


Glyn Moody wrote about the William Hague confession which we mentioned the other day, arguing quite rightly that operating systems play a role here:

The key thing to notice is that the dangerous link that the UK government idiots clicked on downloaded to their PCs the Zeus trojan horse - a keylogger that only affects Windows (not that you'd ever guess that from the pathetic mainstream coverage of any Zeus infection). So if the UK government swapped out lots of those expensive and vulnerable Windows systems with low-cost and rather more secure GNU/Linux ones, we'd be spared most of the losses from those cyber-wallies, for almost no outlay.

But that would be too easy, efficient and intelligent - especially when there's a baying pack of security companies who have the scent of those 650 million smackeroonies in their dilated nostrils. To avoid that threat of minimising the threat with such simple means, they'll doubtless create a crescendo of FUD about the imminent “cyber-Armageddon” we all face if the UK government doesn't throw buckets of dosh in their direction to “defend, delay, attack and manoeuvre in cyberspace”, as General Sir David Richards, chief of the defence staff, put it in the article quoted above (how on earth do you “manoeuvre in cyberspace”?)

The trouble is, no matter how much security firms claim their costly solutions are idiot-proof, they underestimate the cleverness of idiots - or the deep and intrinsic lack of security offered by a Microsoft monoculture, which is even more durable than that pesky “cyber” prefix....


On the very same day, Moody also shared a link to this curious PDF, suggesting that "Nearly 1/3 of internet users in the EU27 caught a computer virus" (Moody added: "no mention of Windows, just for a change").

It was almost 3 years ago that we wrote about statistics suggesting 40% of Windows PCs had become zombies, whether the users know this or not.

Recent Techrights' Posts

Daniel Pocock elected on ANZAC Day and anniversary of Easter Rising (FSFE Fellowship)
Reprinted with permission from Daniel Pocock
Ulrike Uhlig & Debian, the $200,000 woman who quit
Reprinted with permission from disguised.work
Girlfriends, Sex, Prostitution & Debian at DebConf22, Prizren, Kosovo
Reprinted with permission from disguised.work
Martina Ferrari & Debian, DebConf room list: who sleeps with who?
Reprinted with permission from Daniel Pocock
 
Joerg (Ganneff) Jaspert, Dalbergschule Fulda & Debian Death threats
Reprinted with permission from disguised.work
Amber Heard, Junior Female Developers & Debian Embezzlement
Reprinted with permission from disguised.work
[Video] Time to Acknowledge Debian Has a Real Problem and This Problem Needs to be Solved
it would make sense to try to resolve conflicts and issues, not exacerbate these
[Video] IBM's Poor Results Reinforce the Idea of Mass Layoffs on the Way (Just Like at Microsoft)
it seems likely Red Hat layoffs are in the making
IRC Proceedings: Wednesday, April 24, 2024
IRC logs for Wednesday, April 24, 2024
Over at Tux Machines...
GNU/Linux news for the past day
Links 24/04/2024: Layoffs and Shutdowns at Microsoft, Apple Sales in China Have Collapsed
Links for the day
Sexism processing travel reimbursement
Reprinted with permission from disguised.work
Microsoft is Shutting Down Offices and Studios (Microsoft Layoffs Every Month This Year, Media Barely Mentions These)
Microsoft shutting down more offices (there have been layoffs every month this year)
Balkan women & Debian sexism, WeBoob leaks
Reprinted with permission from disguised.work
Links 24/04/2024: Advances in TikTok Ban, Microsoft Lacks Security Incentives (It Profits From Breaches)
Links for the day
Gemini Links 24/04/2024: People Returning to Gemlogs, Stateless Workstations
Links for the day
Meike Reichle & Debian Dating
Reprinted with permission from disguised.work
Europe Won't be Safe From Russia Until the Last Windows PC is Turned Off (or Switched to BSDs and GNU/Linux)
Lives are at stake
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, April 23, 2024
IRC logs for Tuesday, April 23, 2024
[Meme] EPO: Breaking the Law as a Business Model
Total disregard for the EPO to sell more monopolies in Europe (to companies that are seldom European and in need of monopoly)
The EPO's Central Staff Committee (CSC) on New Ways of Working (NWoW) and “Bringing Teams Together” (BTT)
The latest publication from the Central Staff Committee (CSC)
Volunteers wanted: Unknown Suspects team
Reprinted with permission from Daniel Pocock
Debian trademark: where does the value come from?
Reprinted with permission from Daniel Pocock
Detecting suspicious transactions in the Wikimedia grants process
Reprinted with permission from Daniel Pocock
Links 23/04/2024: US Doubles Down on Patent Obviousness, North Korea Practices Nuclear Conflict
Links for the day
Stardust Nightclub Tragedy, Unlawful killing, Censorship & Debian Scapegoating
Reprinted with permission from Daniel Pocock
Gunnar Wolf & Debian Modern Slavery punishments
Reprinted with permission from Daniel Pocock
On DebConf and Debian 'Bedroom Nepotism' (Connected to Canonical, Red Hat, and Google)
Why the public must know suppressed facts (which women themselves are voicing concerns about; some men muzzle them to save face)
Several Years After Vista 11 Came Out Few People in Africa Use It, Its Relative Share Declines (People Delete It and Move to BSD/GNU/Linux?)
These trends are worth discussing
Canonical, Ubuntu & Debian DebConf19 Diversity Girls email
Reprinted with permission from disguised.work
Links 23/04/2024: Escalations Around Poland, Microsoft Shares Dumped
Links for the day
Gemini Links 23/04/2024: Offline PSP Media Player and OpenBSD on ThinkPad
Links for the day
Amaya Rodrigo Sastre, Holger Levsen & Debian DebConf6 fight
Reprinted with permission from disguised.work
DebConf8: who slept with who? Rooming list leaked
Reprinted with permission from disguised.work
Bruce Perens & Debian: swiping the Open Source trademark
Reprinted with permission from disguised.work
Ean Schuessler & Debian SPI OSI trademark disputes
Reprinted with permission from disguised.work
Windows in Sudan: From 99.15% to 2.12%
With conflict in Sudan, plus the occasional escalation/s, buying a laptop with Vista 11 isn't a high priority
Anatomy of a Cancel Mob Campaign
how they go about
[Meme] The 'Cancel Culture' and Its 'Hit List'
organisers are being contacted by the 'cancel mob'
Richard Stallman's Next Public Talk is on Friday, 17:30 in Córdoba (Spain), FSF Cannot Mention It
Any attempt to marginalise founders isn't unprecedented as a strategy
IRC Proceedings: Monday, April 22, 2024
IRC logs for Monday, April 22, 2024
Over at Tux Machines...
GNU/Linux news for the past day
Don't trust me. Trust the voters.
Reprinted with permission from Daniel Pocock
Chris Lamb & Debian demanded Ubuntu censor my blog
Reprinted with permission from disguised.work
Ean Schuessler, Branden Robinson & Debian SPI accounting crisis
Reprinted with permission from disguised.work
William Lee Irwin III, Michael Schultheiss & Debian, Oracle, Russian kernel scandal
Reprinted with permission from disguised.work