Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

The Linux desktop is not much more secure than Windows

Loading...

Sign in or sign up now!
5,913
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Apr 8, 2009

Demonstrates various vectors of attack on a modern GNU/Linux desktop environment. The malware, using only user-level privileges, is able to steal the user's identity. In the meantime, it lies in wait, waiting for the user to give a legitimate program elevated access. It intercepts the elevation and installs itself with root privileges, giving it complete control over the system.

For more technical and philosophical details, see http://www.jordanhollinger.com/2009/04/09/the-modern-linux-desktop-is-frighte...

Category:

Science & Technology

Tags:

License:

Standard YouTube License

  • likes, 43 dislikes

Link to this comment:

Share to:

Uploader Comments (jordanhollinger)

  • Lame, you give one small example and then suddenly Linux is as insecure as Windows. Every time you try to launch an executable file you will get a pop-up telling you that it is an executable file.

    Your scenario also relies on a stupid user, and an executable file aimed specifically at Linux emailed by a "friend."

  • I understand your objects, and apologize for over-sensationalizing my title. The video was an accompaniment to a blog post lamenting that "Linux" is sometimes treated as a magic bullet.

    We dumb things down for non-techies, telling them "Linux is more secure." What we mean is, "it can be." The layers of software we put on top of Linux make things easier, but can also add holes. Now that almost anyone can use it, we have to realize they're going to do the same dumb things they did on Windows.

  • Additionally, the file wasn't executable but it still ran. That was part of the point. But happily, this has been fixed in more recent versions of Ubuntu.

Top Comments

  • 1. 90% of all 3rd party Software is manually compiled(Only lazy people use binaries)

    2. Executable Bit blocks it so you have to manually enable to run it

    3. Root

    4. Ubuntu now looks for the mouse, with out it the program cannot be Root

    5. Ubuntu has home encryption capabilities

    6. Patches

see all

All Comments (115)

Sign In or Sign Up now to post a comment!
  • Linux is the kernel not any of the things that run on top of it. But if you wish to discuss UI which desktops an option to disable showing extensions and have it enabled by default? Enough said.

  • if it were that easy to hack linux I'm sure more people would be trying, not that its impossible, its just alot less likely in general.

  • Oh yeah and Linux has a lot of viruses. Unfortunately Linux has a market share of less than 1% and it's usually technically knowledgeable people or servers or poor, non-profit individuals, institutions. It's much harder to trick a trained sysadmin, servers don't open strange files and have a set behaviour, poor/non-profit = don't care about.

    People create viruses with the aim to gain something from it. Windows and Mac users are the most obvious choice.

  • @tranmere789 You seem to be stupid enough not to understand something easy even when it's clearly explained to you and served on a plate. He didn't open or serve the Internet with root access. Also you don't seem to even get why using root is not recommended. I can even explain it to you with mathematical equation analogy but I've probably already lost you on mathe-e-e-e-..... Watch the video until you get what the bloke is saying...should take you another 200-300 watches.

  • What I don't understand is why is firefox storing secure information. Usually pages that require secure info use an ssl connection so surely the Mozilla Firefox team should know this means this is sensitive data which should NOT be stored anywhere. This is equal to writing your bank accounts, passwords in a text file in your home folder. WTF?

  • @grandmaster1fc If your definition of secure is "Every time you try to launch an executable file you will get a pop-up telling you that it is an executable file." then you're probably a very basic user who can easily get fooled by many of the tricks that exist out there.

    Also stupid users are not the same as inexperienced users. In fact a lot of the linux admins are quite stupid as it doesn't take much to be an admin. That aside - you could be tired, in a hurry etc. and this gen get you.

  • @jordanhollinger OK.. Open Source ideology can create more secure, safe, stable and fast free OS! Do you agree with me? Mac OS X is freeBSD based system, witch is already Open Source. But Darwin project is not so open after Mac moved to UNIX.. and Linux desktop is not much more secure than Windows. Therefore what can we say? Windows is safer than Mac?! :D

    1. Linux

    2. freeBSD

    3. UNIX, OpenSolaris

    4. Darwin (Mac OS X)

    5. Windows.

    Malware is cross platform and stupid user always will be a victim!

  • @tranmere789

    when the % of Linux users reaches 5% of all other os

View all Comments »
Loading...
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more