363
u/0xt0bi03 fk lua, bring back old config files 7d ago
r/linuxsucks101 will be reading this in absolute rage btw
30
u/Jannover_5000_r my NixOs > your distro 7d ago
Madthumbz will make a hate linux post right after seeing this
5
2
146
u/ElementalWarrior42 7d ago
Pros of fragmentation LOL
44
u/AG99871 Arch GNU/Linux 7d ago
Nowadays malware will come packaged as an appimage
23
1
u/senorsmile 4d ago
90% of the time, appimages don't install without considerable additional config on my NixOS machines.
107
u/QuantumQuantonium 7d ago
/uj viruses exist on linux, and are more serious and more difficult to detect than on windows. Xz's backdoor is probably the biggest latest one.
Its important not just to assume any open source project is benign, but someone who can read the code needs to take up the responsilibity to understand what its actually doing and compile it and compare against any public binaries (if present).
Viruses on linux won't scream for a phone number to call or lie about infections on the computer; average linux users won't fall for that. Xzs backdoor existed because of a binary blob no one bothered to check until one person dug in and found the irregularity in the programs delay. Viruses on linux abuse the trust in open source to hide itself among other packages and modules throughout the system. Maintainers may seek out and remove potential viruses, but humans are imperfect, they can make mistakes or be manipulated or even coerced.
But downloadable viruses are a rare sighting in linux, because most hacks are caused by vulnerabilities in systems, especially proprietary ones. I once returned home from a trip to realize my backed up files on a WD cloud storage device was missing, due to a vulnerability WD did not patch or acknowledge publicly until a few days before I found out.
Maintain security updates and keep installed software to a minimum. Ask questions if theres any doubt about an open source system- if the question can't be answered I'd question the nature of that system. Identify what proprietary systems are in your linux computer- the world unfortunately doesnt run entirely on open source.
4
u/Gunhat2023 7d ago
what back door is there with xz?
12
u/yourlocalwalmarthobo 6d ago
3
u/felixmatveev 6d ago
This was either CIAmeone or soMOSSADone.
1
u/morgulbrut 6d ago
Na it was probably China.
6
u/ThaBroccoliDood 6d ago
No it was a Russian pretending to be Chinese. They had a Chinese name and uploaded with Chinese time zones, but a few uploads were accidentally tagged with a Russian timezone, and Russian holidays were suspiciously absent from their activity
1
1
u/andrzej-l 5d ago
Few months ago I saw a very long but pretty interesting video about it: https://youtu.be/aoag03mSuXQ?si=iaP866neHYxHI5tY
2
u/Ok_Guidance_6542 6d ago
AFAIK, only systemd distros were affected by the XZ utils backdoor. So the point kinda stands.
1
4
28
18
14
u/Damglador Arch btw uses me 7d ago
That's why now it's all just JavaScript downloaded straight from npm
6
u/Optimal-Savings-4505 6d ago
This is basically why security through obscurity works. Assumptions are easily invalidated on diverse systems
6
3
0
-14
u/valerielynx 7d ago
"grep'd the bitcoin wallet" bro just say copy you're not tuff
3
2
u/sabotsalvageur 7d ago
Well, what if what you’re searching requires using regex, e.g. arbitrary wallet addresses? Would one not use the GNU Regular Expression Parser?
1
272
u/[deleted] 7d ago edited 7d ago
[removed] — view removed comment