7 ms·
Well, the biggest advantages of Linux are that the OS vendor is not itself malicious (in particular, does not collect telemetry, push advertisements or attempt
by devit 3y ago
Well, the biggest advantages of Linux are that the OS vendor is not itself malicious (in particular, does not collect telemetry, push advertisements or attempt to restrict your use of the system like Microsoft and Apple do), the OS is relatively unpopular and thus not a profitable target for malware directed to end-users, and it is flexible and customizable.
You need to use VM-based isolation to have good security with Linux beyond that (i.e. use Qubes or a similar alternative).
- tw04 3y ago>Well, the biggest advantages of Linux are that the OS vendor is not itself malicious (in particular, does not collect telemetry, push advertisements or attempt to restrict your use of the system like Microsoft and Apple do) Except they do: https://www.omgubuntu.co.uk/2022/10/ubuntu-pro-terminal-ad https://www.omgubuntu.co.uk/2022/10/ubuntu-pro-terminal-ad https://www.eff.org/deeplinks/2012/10/privacy-ubuntu-1210-amazon-ads-and-data-leaks https://www.eff.org/deeplinks/2012/10/privacy-ubuntu-1210-am...
- devit 3y agoThat is easily solved by using Debian instead of Ubuntu.
- askonomm 3y agoSo then what you meant to say was that _some_ Linux distros are not malicious.
- galleywest200 3y agoThe distributions maybe, but the producers of the Linux kernel are not.
- tw04 3y agoI doubt the kernel maintainers of Windows or MacOS are involved in the advertisements inserted into the GUI of either OS.
- calamari4065 3y agoThe vast, overwhelming majority of them, yes.
- hereme888 3y agoThat's seriously ridiculous. "Ubuntu let users know about automatic updates in the terminal". It's incomparable to what MSFT does.
- tw04 3y agoLet them know about automatic updates? So you didn’t read either link. One was advertising Amazon, the other was advertising their paid support service. NEITHER was telling users about automatic updates.
- hereme888 3y agoYes, a tiny, inobtrusive "hey, we offer paid support/automatic updates" after doing a terminal update.
- greentea23 3y agoYeah, I don't see how windows or mac could ever be considered secure when you can't turn off telemetry and when the systems are closed source and cannot be publicly audited. Linux lets you be as secure as you need to be. The military for example in extreme cases will compile their own hardened version of linux and run it on a custom hardened FPGA soft core. Having that option makes it an actual engineering tool for security vs. a toy imo.
- dataflow 3y ago> I don't see how windows or mac could ever be considered secure when you can't turn off telemetry and when the systems are closed source and cannot be publicly audited. Security != Privacy Imagine home security monitoring your home 24/7. You lose privacy but gain security.
- wizzwizz4 3y agoAnd imagine me monitoring your home. You lose privacy, and I know when you're on holiday and I can rob the place. It matters who's doing the monitoring. With a home security system, it's you – or whoever you've delegated to –, and you chose to set it up; with these operating systems, it's somebody else, and you have little choice in the matter.
- FirmwareBurner 3y agoSo far Microsoft and Apple haven't robbed anyone, unless you count Apple's RAM and SSD pricing as robbery, which is why many people and companies trust them despite the privacy concerns. Companies and people who also strongly value their privacy, built and host their own on-prem infrastructure.
- timthelion 3y agoAmazon deleted books from people's kindles though.
- ndsipa_pomu 3y agoI think the reason that Linuxes are considered secure is the behaviour that is encouraged amongst its users. With Windows, users are encouraged to install software from random internet sites and there's no central method of updating software (without installing some third party updater from a random internet site). Also, there's some design decisions made in Windows that lead to poor security. e.g. treating a file's extension differently, assigning it special meaning and then hiding it by default from the user.
- calamari4065 3y agoReminds me of the driver update utilities for Windows which notionally did update all your drivers, but also updates all of your viruses.
- lostmsu 3y agoAs opposed to running bash scripts from the Internet.
- calamari4065 3y agoYou can read those scripts, you know. If you have a passing understanding of bash, it's pretty easy to understand what a script is doing and ensure it's not malicious. Can you do that with a compiled executable?
- lostmsu 3y agoYou are comparing behavior of people who can read scripts with the behavior of people who consider random 3rd party driver updaters a good idea. What user can do doesn't matter. It matters what they actually do.
- ndsipa_pomu 3y ago> It matters what they actually do Yes, and Windows users often install stuff from 3rd party websites whilst it's comparatively rare for Linux users.
- helij 3y agoThinking about this. Would firing up various VMs via Boxes be similar to Qubes?
- pabs3 3y agoLinux vendors and lots of FOSS apps do collect telemetry, for eg: https://popcon.debian.org/ https://popcon.debian.org/ https://wiki.debian.org/PrivacyIssues https://wiki.debian.org/PrivacyIssues Advertising is indeed much less common but is being explored. There have been some HN posts about the backlash that occurs when it gets introduced.
- yencabulator 3y agoDebian popularity-contest is as far as I know opt-in and very innocent compared to most of the telemetry stuff out there. Telemetry by default is evil, but trying to paint Debian as evil is a stretch.
- pabs3 3y agoI'm a Debian user and contributor for many years and wrote large parts of the privacy issues page above, based on facts I discovered while using Debian. Certainly Debian isn't evil, and popcon is indeed opt-in. Popcon does make it possible for all Debian members (who can access the submission data) to probably identify other contributors and possibly others too. Also we do inherit lots of privacy issues from upstream projects. For eg GNOME calculator app in Debian still connects to the IMF and other websites even when.