Security through obscurity in OSS lol
Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes
DarkCloud@lemmy.world 4 weeks ago
Linux’s “security through obscurity” was never going to last.
lIlIllIlIIIllIlIlII@lemmy.zip 4 weeks ago
mnemonicmonkeys@sh.itjust.works 4 weeks ago
Linux’s “security through obscurity”
I lost braincells reading this. The entire point of open source software is to have it visible and auditable, aka the exact opposite of security through obscurity.
If you want to bash OS’s for relying on STO, go after iOS and Windows. Those OS’s, being closed source, are the ones relying on it
Natanox@discuss.tchncs.de 4 weeks ago I don’t know where you got the notion from that Linux as a whole uses this concept, but it’s nonsense. There’s exactly one place where this definition fits, which is the GRUB bootloader encryption (which merely shifts the target for the Evil Maid attack from the initramfs to GRUB). But this is already adressed with Verified Boot.
Nothing else, let it be LUKS, PAM, SELinux, AppArmor or whatever has any business with STO.
DarkCloud@lemmy.world 4 weeks ago
From the fact it used to have to smallest user base of the big three. Less users = less probability of a nefarious person.
It’s really not that difficult a concept.
Natanox@discuss.tchncs.de 4 weeks ago That doesn’t make any sense as argument no matter how you spin it. Linux is the dominant system for servers for decades now, and a Debian Desktop is quite literally the same as Debian on a server except it also got a GUI of your choice slapped on top. There’s absolutely nothing obscure about it, neither did anyone from the kernel team (Linux), FSF (GNU utils) nor IBM / Red Hat (systemd & honestly way too much other stuff) etc. ever design something around STO. That’s a domain firmly situated in proprietary code since for FOSS it doesn’t make sense to begin with. The false errand of GRUB is the sole exception, well known and solved.
The desktop market share says absolutely nothing about what you’re trying to argue. Now if you were to argue that Linux is lacking in terms of desktop software isolation then you’d have a point, things like Flatpak still are addressing lots of issues. But to say “Linux” approaches security with obscurity is total nonsense.
helix@feddit.org 4 weeks ago
You confused “obscurity” as in a synonym for low popularity with the word “obscurity” as in people not knowing how it works and people deliberately hiding the inner workings of a system.
Everyone using Linux can know how it works, that’s the opposite of obscurity in the sense it is used within “security by obscurity”.
Apart from that, Linux is very popular, just not on the Desktop. It is therefore not obscure in the sense of popularity either, at least the components which are hit by the bug mentioned in the article.
notfromhere@lemmy.ml 3 weeks ago
Thanks for pointing out the actually definition of security by obscurity. Popularity has nothing to do with it.
Ptsf@lemmy.world 4 weeks ago
I don’t think that word means what you think it means.
Clearwater@lemmy.world 4 weeks ago
Security through what now?
Well, I guess it is obscure… Though only because the number of people who have a full grasp on how the code works is highly limited.
atzanteol@sh.itjust.works 4 weeks ago
The self-hosted crowd thinks reverse proxies protect you from the Internet. Don’t expect too much of them.
nibbler@discuss.tchncs.de 4 weeks ago
The selfhosted guys are correct with that. Of course its not a magic pill, but it can help to minimize the attack surface immensely with little effort.
atzanteol@sh.itjust.works 4 weeks ago
See what I mean?
As if a proxy blindly passing traffic directly to a backend server “reduces attack surface” in any meaningful way. 🙄
nibbler@discuss.tchncs.de 4 weeks ago
Did you just add ‘blindly passing traffic’ to your statement? Did you read my comment about can help?
Move on, joker.
lIlIllIlIIIllIlIlII@lemmy.zip 4 weeks ago
You are right about that a reverse proxy does not protect. But I can not relate that with security through obscurity.
notfromhere@lemmy.ml 3 weeks ago
There’s also a big brigading problem with going against the “common knowledge” of Lemmy. Brave can do no good. Reverse proxy on the internet and you’re secure. Etc.
That your comment is downvoted and barely debated speaks volumes to Lemmy as actual discourse.
qaz@lemmy.world 3 weeks ago
It’s being downvoted with little relatively little discourse because it’s an insult with no relevance to the topic, in addition to supporting a comment from someone who is either trolling or has no idea what they’re talking about
There was never an actual notion of “security through obscurity”. LInux runs the complete Internet and most coporate server infrastructure. That’s where the actual money is.
People hallucinating that Linux is something obscure simply have no clue and confused their home desktop for real computing. Windows desktops are constantly targeted not because they are -unlike Linux- so wide-spread but because they are already insanely insecure. They are the low hanging fruit where you can cobble together some cheap shit and will still find million of PCs vulnerable. If you want to find a Linux comparison it’s definitely not server or desktops but cheap IoT devices not having seen an update (or any security to speak of) for many years.
phailhaus@piefed.social 4 weeks ago
Windows desktops are targeted because any place you have a user, you have a vulnerability. The vast majority of Linux installs are servers with extremely limited user activity, which narrows the attack vectors significantly.
frongt@lemmy.zip 4 weeks ago
In any system, the human is usually the weakest link.
atzanteol@sh.itjust.works 4 weeks ago
You could have just said that you don’t know what “security through obscurity” is.
You are right. I don’t know what your personal definition of “security through obscurity” is as it’s very obviously not matching actual reality.
atzanteol@sh.itjust.works 4 weeks ago
Just google the term next time rather than embarrassing yourself.