Bonum Certa Men Certa

How Debian-type Centralisation Made GNU/Linux Very Secure

Data storage with USB



Summary: Contrary to some malicious allegations, Microsoft remains the one copying security features from Linux, not the other way around

THE technology news sites have begun pushing the "USB" story, suggesting that inheriting Windows-like behaviour makes Linux less secure. There are rebuttals written about it and we may address them at a later stage. For the time being, let us recall the advantage GNU/Linux has not only when it comes to software centralisation in trusted repositories (which verifies safety and protects from malicious downloads from arbitrary sites). One of the big advantages of this approach is that using the same mechanism GNU/Linux keeps all the underlying software -- not just the core of the operating system -- up to date with security patches. Windows does not have that (Apple emulates this and Microsoft only expresses hopes to emulate that, just like it emulates sudo) and in fact one writer is now saying that "Microsoft has to open Windows Update to third-party developers":



There's a lot of confusion out there about when attacks against computers occur as a result of vulnerabilities in software as opposed to some other weakness, usually social engineering. Considerable progress has been made in protection against vulnerabilities on Windows, and we can make exploitation even harder if Microsoft can be talked into my scheme: open up Windows Update to third-party applications.

My own opinion is that social engineering is far more important than vulnerabilities and has been increasing in importance. One reason for this is that vulnerabilities are a harder target than they used to be, and that's in large part because of the work Microsoft has done over the last 6 or 7 years.


Glyn Moody wrote about the William Hague confession which we mentioned the other day, arguing quite rightly that operating systems play a role here:

The key thing to notice is that the dangerous link that the UK government idiots clicked on downloaded to their PCs the Zeus trojan horse - a keylogger that only affects Windows (not that you'd ever guess that from the pathetic mainstream coverage of any Zeus infection). So if the UK government swapped out lots of those expensive and vulnerable Windows systems with low-cost and rather more secure GNU/Linux ones, we'd be spared most of the losses from those cyber-wallies, for almost no outlay.

But that would be too easy, efficient and intelligent - especially when there's a baying pack of security companies who have the scent of those 650 million smackeroonies in their dilated nostrils. To avoid that threat of minimising the threat with such simple means, they'll doubtless create a crescendo of FUD about the imminent “cyber-Armageddon” we all face if the UK government doesn't throw buckets of dosh in their direction to “defend, delay, attack and manoeuvre in cyberspace”, as General Sir David Richards, chief of the defence staff, put it in the article quoted above (how on earth do you “manoeuvre in cyberspace”?)

The trouble is, no matter how much security firms claim their costly solutions are idiot-proof, they underestimate the cleverness of idiots - or the deep and intrinsic lack of security offered by a Microsoft monoculture, which is even more durable than that pesky “cyber” prefix....


On the very same day, Moody also shared a link to this curious PDF, suggesting that "Nearly 1/3 of internet users in the EU27 caught a computer virus" (Moody added: "no mention of Windows, just for a change").

It was almost 3 years ago that we wrote about statistics suggesting 40% of Windows PCs had become zombies, whether the users know this or not.

Recent Techrights' Posts

[Meme] Mentality of a Loser
"There is someone who created a project used by billions; I failed to create project used by billions, so I'll take down someone who did"
[Meme] Plundering the Commons
Free software is licensed to restrict privatisation and hoarding
 
Hate Crimes and Cybercrimes
Not agreeing with us on software issues is one thing; that does not justify committing crimes against us
A Classic Example of Concern Trolling
Embrace reason
[Meme] Chipzilla's Arrogance (False Assumption That the Customer Will Accept Every Customer-Hostile Addition)
"Maybe you can remove the M.E.? Please?"
More Love, Less Greed
The Free software movement is inherently about sharing
Links 20/10/2024: Melodic Design, Qubes OS, and Bloated Web
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, October 19, 2024
IRC logs for Saturday, October 19, 2024
[Meme] How 'Editorial Control' and/or 'Fact-Checking' Work in Social Control Media
"I saw a link with many 'likes' on it, so it must be accurate"
IBM: RMS Asked a Girl on a Date. We at IBM Are Bribing and Receiving Bribes. Cancel RMS.
The FSF is half female now
"The Definition of Insanity"
We've seen this and been through all this before
The 'New' Laptop as a Reminder of Why I Love GNU/Linux
days ago we acquired a 'new' (used) laptop
[Meme] The Way Things Used to Be...
UNIX is 55 already
Fun Weekend, But Very Slow News
we welcome topic suggestions/recommendations
2021 Deja Vu: The 'Counter-Petition' Defending Richard Stallman (RMS) Gets a Lot More Support Than the Hateful Screed
Don't listen to the RMS haters
x86 Drowning in Competition, Bug Doors, Complexity, and Bloat
Making defective chips for a number of decades was sheer Hubris; they just assumed people would continue buying Intel machines forever
Links 19/10/2024: Nokia Lays Off 2,000 Employees, IMF Loans, Lammy to China
Links for the day
Links 19/10/2024: OpenAI, Microsoft Going Deeper Into Debt; FTC Rules Make It Easier To Cancel Services
Links for the day
Gemini Links 19/10/2024: Against Books as Only Possible Legitimation, Megacorporate Copyright Pirates
Links for the day
Links 19/10/2024: European Perspective, Windows TCO, and Google Woes
Links for the day
[Meme] When Hatred (or Envy) Comes First
A lot of attacks on Torvalds and Stallman (Linux and GNU founders, respectively) fall under this category
What "Ethical Source" Looks Like in Practice
People ban people or deny them service (or prevent them running a program) for merely not agreeing with them
The State of GAFAM and the I's (IBM and Intel)
Technology and "tech giants" will continue to exist, but they won't be what they once were
The Drew DeVault Report: Taking Out His Frustration on Other People While Doing Drugs
Be more like Fabrice Bellard
Links 19/10/2024: Riot and Intel Layoffs, Attacks on Journalists
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, October 18, 2024
IRC logs for Friday, October 18, 2024
Gemini Links 19/10/2024: Defending RMS and why "ethical source" "is closed source with different labelling"; Elpher Queue/Pop Key-Bindings
Links for the day
Links 18/10/2024: TSMC Surges, Hamas Leader Killed
Links for the day
Gemini Links 18/10/2024: "In Support of Richard Stallman" and Adapting Ploum's sites to gwit
Links for the day
[Meme] Your Negative Energy Only Makes Him Stronger
Superman bulletproof meme
Half a Dozen More Public Talks by Dr. Richard M. Stallman (RMS) This Month
Even seven, based on his front page today
Links 18/10/2024: Russia Against 'Childfree Propaganda' and Germany’s Green Transition Is Faltering
Links for the day
"Free Software Is Under Attack! (Will You Help Defend It?)"
Rebuttals are appearing online, including analysis of the underlying methods and why they backfire on the perpetrators (as they did back in 2021)
Links 18/10/2024: Kangaroo Courts Spread to Lisbon, Riot Games Layoffs
Links for the day
"FASTCash" is Not a "Linux" Thing, It Was Merely Extended to Also Have a Variant for Already-Compromised Ubuntu 22.04
Is that the fault of Linux? No. But notice these daunting headlines.
Gemini Links 18/10/2024: Florida Water and Messaged Mediums
Links for the day
IRC Proceedings: Thursday, October 17, 2024
IRC logs for Thursday, October 17, 2024
Over at Tux Machines...
GNU/Linux news for the past day