Remix.run Logo
traceroute66 6 hours ago

Might need to silently archive those Microsoft Patch Tuesday jokes...

AdmiralAsshat 6 hours ago | parent | next [-]

Don't worry, Microsoft is still leading:

https://www.bleepingcomputer.com/news/microsoft/microsoft-ju...

1970-01-01 6 hours ago | parent | prev | next [-]

Those that actually understood security, and weren't on some kind of open-source enforcement mission in life, always knew the "Linux doesn't get viruses" statements would not age well.

https://blog.desdelinux.net/en/virus-in-gnulinux-reality-or-...

kvuj 5 hours ago | parent | next [-]

You should be careful not to conflate viruses and CVEs.

Considering no Linux distro come with an antivirus by default, Linux as a desktop was always extremely vulnerable to bad actors.

As a server, I would argue otherwise.

thewebguyd 5 hours ago | parent | next [-]

> Linux as a desktop was always extremely vulnerable to bad actors.

Most distros people use as a desktop are alarmingly insecure by default,the security model lags well behind macOS and even Windows (again, by default. You can of course do work to harden it).

You lose out on hardware verified boot with signed system volumes, virtualization backed security, granular runtime permissions (apps having full R/W on ~Home, screen recording, microphone access).

Immutable distros like Silverblue, flatpak are moving linux desktop security in the right direction but its far from the default, and there are still gaps that need to be closed.

We (Linux community) loves to criticize security through obscurity, but that's exactly what most desktop linux users are relying on to not get pwned, relying on marketshare being so low that there just hasn't been that many incidents.

1970-01-01 5 hours ago | parent | prev [-]

Conflated terms because they've been that way for a very long time. If you're being strict, all computer viruses stopped being a problem a decade ago.

traceroute66 5 hours ago | parent | prev [-]

> Those that actually understood security....

Indeed, and those who actually understood software development always knew vulnerabilities can occur just as easily as bugs.

And in some cases more easily than bugs, because many of modern vulnerabilities are so subtle, especially where crypto is involved.

gosub100 5 hours ago | parent | prev [-]

If they were there this whole time but only discovered now, were they really a threat? The reflexive response to this is "those could be exploited for years and we'd never know", but if it was discovered, it obviously wasn't impacting you personally. If they were under lock and key at the NSA and only judiciously used for secret spy BS, that's effectively the same as not existing. Clearly they weren't discovered by all the white hats for this whole time.

Also, if Microsoft hypothetically open sourced their code, do you think there would be more, less, or the same number of CVEs? I would guess more.

I don't want to go too far to defend Linux. I want to make the case that it has been the more secure OS this whole time.

traceroute66 4 hours ago | parent [-]

> I want to make the case that it has been the more secure OS this whole time.

Your phone is ringing, caller ID says its Theo de Raadt from OpenBSD. :)