this post was submitted on 26 Sep 2024
347 points (97.5% liked)

linuxmemes

20919 readers
2166 users here now

I use Arch btw


Sister communities:

Community rules

  1. Follow the site-wide rules and code of conduct
  2. Be civil
  3. Post Linux-related content
  4. No recent reposts

Please report posts and comments that break these rules!

founded 1 year ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 9 points 1 week ago (2 children)

Parts of it seem to be inherently more secure, but there are some pretty glaring holes. At least software distribution is much more secure than the Windows approach.

[–] [email protected] 22 points 1 week ago* (last edited 1 week ago) (3 children)

I'd say the biggest, most glaring hole is that, much like in Windows, most users don't really understand the file system and user and group permissions.

Linux, as an OS, requires a lot more on the users part in understanding basic security right out of the gate.

A lot of folks out here dropping chmod 777 all over the place just because they haven't had any education on how any of it works.

Source: Years ago, being a newb without knowledge or education, dropping chmod 777 all over the place

[–] [email protected] 2 points 6 days ago

Hopefully you only chmod'd your own systems. Early in my career, I worked on a project wherein we gave a contracting company root access to a computer they could use to test the software they were writing for us. One morning, they sent us a message saying they couldn't log in. We looked at the computer and discovered it wouldn't boot. Turned out someone on the remote team had chmod 777'd the entire filesystem. Of course we locked down their access after that.

[–] [email protected] 14 points 1 week ago

They used to login as root

[–] DarkroomDoc 7 points 1 week ago (1 children)

Fedora silver blue ftw. Immutable systems are the future.

[–] [email protected] 1 points 6 days ago
[–] [email protected] 4 points 1 week ago

It has the ability to lock things down a lot more. Also, it doesn't necessarily have a big attack surface