this post was submitted on 19 Jul 2024
1129 points (96.8% liked)
linuxmemes
20880 readers
6 users here now
I use Arch btw
Sister communities:
- LemmyMemes: Memes
- LemmyShitpost: Anything and everything goes.
- RISA: Star Trek memes and shitposts
Community rules
- Follow the site-wide rules and code of conduct
- Be civil
- Post Linux-related content
- No recent reposts
Please report posts and comments that break these rules!
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Question, how is Linux more insecure out of the box?
It isn't. Most distro's leave the firewall disabled on install but what services are exposed? None. Most are set to localhost only and ssh is normally not installed or enabled. Antivirus on windows especially defender just seems to keep me from doing my job. For instance every decent utility from nirsoft is detected by defender as being infected. I suspect microsoft hates those utilities that allow you to back up credentials and most critically license keys.
I do agree that the main thing that keeps linux from being as easily exploited is the more about the average linux user and less about inherent security. I've only had one Linux machine exploited in thirty years and it was a older version of Debian that a vendor disabled the automatic updates on when it was installed. I woke one morning to 10gb of upstream traffic on my traffic graphs. The attacker had gained access through a outdated version of apache. The fools who had compromised the system couldn't understand why he had to work through a rdp session to reinstall his product when I reloaded it with the latest version. The fool was pissed that I had updated debian. My boss pressed them until they agreed it was time to let debian 7 go since the latest at the time was debian 9.
But in the end the breach happened because of a foolish vendor with outdated ideas regarding updating a OS.
Does it come preinstalled with an antivirus and a firewall?
Does windows come preinstalled and preconfigured with more potentially vulnerable software on open ports?
I personally don't value an antivirus that much, since it can only protect you from known threats, and even then, it only matters when you're already getting compromised - but fair point for Windows, I suspect most distros come without antivirus preinstalled and preconfigured.
A firewall, on the other hand, only has value if you already have insecure services listening on your system - and I'm pretty sure on Windows those services aren't gonna be blocked by the default settings. All that said though... Most Linux distros come with a firewall, something like iptables or firewalld, though not sure which ones would have it preconfigured for blocking connections by default.
So while I would dispute both of those points as not being that notable, I feel like other arguments in favor of Linux still stand, like reduced surface area, simpler kernel code, open and auditable source.
One big issue with Linux security for consumers (which I have to assume is what you're talking about, since on the server side a sysadmin will want to configure any antivirus and firewall anyways) could be that different distributions will have different configurations - both for security and for preference-based things like desktop environments. This does unfortunately mean that users could find themselves installing less secure distros without realizing it, choosing them for their looks/usage patterns.
Answering a question with a question is an instant block you rude af windowlicker
Man, and here I put too much effort writing a reply to a troll 😔
Same...