Blog Closed

This blog has moved to Github. This page will not be updated and is not open for comments. Please go to the new site for updated content.
Showing posts with label Linux. Show all posts
Showing posts with label Linux. Show all posts

Saturday, May 30, 2009

Linux Security

I was reading an interesting blog post about the effects of malware on your computer, and found two gems of comments. The second is a direct response to the first:

The suggestion:
Anyone running Windows volutarily is asking to be hacked. Do yourself a favor- install Linux on a spare machine and try it out. It's friendly, and free! Check out http://www.ubuntu.com/ or http://www.ubuntu.com/getubuntu/download
The response:
Changing your operating system isn't the answer. You don't get security through obscurity. For most people, what you propose would add a great deal of complexity (different ecosystem, learning curve of different system, different hardware/software compatibility, etc.) You would be better served learning how to properly secure and operate a Windows based system. Start with the list below:

1. Use a non-admin (limited user) account for daily use
2. Use a firewall (preferably a hardware firewall at the perimeter and a software firewall on each computer)
3. Keep the system fully patched (includes ALL software)
4. Use Antivirus/Antispyware software that is configured to update itself DAILY
5. Practice safe computing (ex. use caution with downloaded files and e-mail attachments, don't click on links in e-mail, browse wisely, etc.)
6. Routinely (at least monthly) backup your data to external media (CD-R, DVD-R, external hard drive, etc.)
7. Install ONLY required software (reduces system attack surface and minimizes patching). AVOID file sharing software! (too risky to system)
8. Optional (but highly recommended):
a.Use a blocking HOSTS file (http://www.mvps.org/winhelp2002/hosts.htm)
b.Enable Windows Automatic Updates (Auto download and install)
c. Use an e-mail client instead of webmail, configure it to “Read all e-mail in plain text”

There are a few points here in the response that are so rediculous and so ignorant that they require public mockery. First off, Linux is not "security by obscurity", that's exactly the security model used by proprietary software like Microsoft. The hope is that if criminals can't see the source code, that they won't be able to find the holes. Apparently, some people think this model works well enough. Here are the rest of the points:

  1. Talk about the troubles of changing environments, try using Windows as a non-adminstrator user sometime! It's like night and day in terms of usability, especially if you're not the kind of power user who knows how to get into administrator mode to do stuff like install new software. Let me put this into perspective: My grandfather has used a computer for a few years but is by no means "computer literate", much less "computer saavy". His old Win95 box was so overrun by viruses and malware that it was absolutely unusable. So I reformatted the computer to use Fedora instead, and now he has no problems whatsoever. I set up his email account in thunderbird, and I set up his list of bookmarks in firefox, and he was up and running immediately, with no learning curve and no hardships whatsoever. Not only was the transition painless and immediate, but his computing experience from that point forward was far superior to what it would have been otherwise: No invasive anti-virus to deal with. I'll talk more about the evils of antivirus later.
  2. A hardware firewall "at the perimeter" and a software firewall "on each machine"? Seems like a little much for Joe-Schmoe PC user. Maybe we should all be digging foxholes too, and building reinforced concrete bunkers for our networks. And he leaves out the point about how these firewalls would need to be properly configured because the "default allow" methodology behind most firewalls is inherently faulty anyway. Plus, when the firewall decides that it's not going to allow the social networking application du jure, your average non-techie computer user will be pretty unhappy with their computing experience. Sorry, but throwing more firewalls at the problem is not the solution for most people.
  3. Do me a favor: Figure out where "ALL software" on your system comes from, and figure out how to independently update all of it. I'm a pretty saavy computer user, and I doubt I could track down the sources for all the software that's on my computer currently, much less find ways to reliably update them all. There are a few programs on my machine that automatically update themselves, but then you run into problems where your automatic updater runs afowl of your firewall (as happens with my Java updater here at work). Also, tell me where you turn when an update to a device driver breaks one of your programs? Or when updating an application "broke the internet"? In most Linux distros, it's as easy as opening the update manger and letting it track and update all your software for you (and you can even set it to run automatically without interference from the system firewall). On Windows, you're up shit creek with this, and there's no two ways about it.
  4. Antivirus software is the bane of modern computers. I refuse to use it myself, because of the horrible performance penalties you have to pay with it. To give some perspective, my work computer, which is an Intel Core 2 Duo with plenty of RAM boots up in just under two minutes without antivirus installed. With Antivirus, it takes nearly 10 minutes just to turn on. Plus, when it does turn on it's less responsive in many situations. All the while it's popping up nagware "reminders" about the state of my subscription. This completely ignores the fact that antivirus software is almost perpetually out of date because threats usually aren't identified and neutralized until after they are released into the internet. This creates the illusion that you're safe, when so often you are not. Sorry, but antivirus is so much worse then the problem it claims to solve.
  5. The definition of "safe" computing differs from platform to platform, but in general this does hold equally for all systems. This so far is really the only good advice this poster has provided, and it is in no way an argument for using Windows over Linux.
  6. Backing up really has nothing to do with security. This is especially true when you think about how often Windows' "autorun" feature has been used as an attack vector by viruses. I might never put another USB flash drive into a Windows computer for as long as I live, I've learned that lesson the hard way.
  7. What counts as "required"? I do image editing every now and again, is my photo editor a "requirement"? Is FireFox a requirement when we already have IE installed? What about a code editor that's any more advanced then notepad, is that required? What about the tools that I use to stay in touch: Instant messaging, IRC, and Skype? what about office/productivity software? And what about people who's primary reason for having a computer is to share media with friends and family? With a single-purpose server machine, that's one thing. With a family media-oriented PC, that's another entirely. We all know that the safest way to use your computer is to not use it at all, but in this case abstinence is not the solution to the problem.
  8. Monkeying with your HOSTS file is far too advanced and too risky for your average non-power-user, which is 99% of everybody. Automatic updates are great until they download WGA without your consent and then falsely identify your computer as being pirated, and then restrict your access. I've seen this happen on more then one occasion to people who owned legitimate copies and were technically inable to resolve the situation themselves. I can't imagine that using an email client is any safer then using a good webmail app, especially when most webmail clients have built-in abilities to open Microsoft Office documents, which themselves can be sources of viruses. Gmail for example lets you preview documents like these on the web without having to download them to your computer and run malicious macros. That sounds like the safer way to me.
So that's my little response to this little ignorant comment. Your average PC user is not so tied to their system that they couldn't play succesfully with Linux, and I think most people, for most needs, would be up and running on Linux very quickly indeed, especially since there are so few security settings that need "tweaking" on Windows. I don't want to say that either Windows or Linux are superior, I use both and am very happy with that. However, I also won't hear that a good Linux distribution poses any sort of meaningful usability hurdle to the average user, or that it is in any appreciable way less secure then Windows is. I suggest that people try Linux, because trying it costs nothing but some old commodity hardware, and you might find that you like it more.

Monday, May 18, 2009

Linux On the Desktop

Slashdotted this morning was a very interesting list of reasons for why Linux is "Not Ready" for general use on the desktop. It's quite an interesting list, although I would remove some things from it and add others.

Far from being an attack on Linux, I see this list as being a labor of love. Consider the parallel of chromatic criticizing Perl 5, and there almost isn't anybody I can think of who loves Perl more then chromatic does. He has a lot of good things to say about Perl, but he's also very vocal that things need to change to keep it strong and modern.

It's like punishing your children for misbehavior: You love your children, but sometimes you need to teach them important lessons the hard way.

I started using Linux a long time ago. I made what I now see as a mistake, taking a crash course using the "Core" linux distro. Core is a minimalist distro where users are expected to be power users who build the rest of the distro from source. By starting at the bottom, I was hoping I would learn quick, and I did. I quickly learned to scrap Core and move to a more full-featured distro. From there I moved on to Red Hat (back before it was Fedora, but not long before) and used that for a little while. At the time all this experimentation was happening my family was using Windows XP for their computing experience, and I have to say that the differences were staggering. Their computer was more usable on average (it did get virus'd up pretty regularly and needed cleaning and reformatting on a regular schedule), and it was easier to make configuration changes. Sure I had all the power in the world to monkey around in configuration files, but when you compare the time it would take me to look up a configuration change on the internet, find the appropriate config file, make my changes, reboot to make sure I didn't destroy my computer, etc, to the time it would take to make the same change in Windows it was almost comical that I was using Linux at all. Hell, Windows power users stopped having to edit autoconfig.bat by hand back in Windows 95.

My third foray into Linux was with Ubuntu, and I am much happer with it now as a full-featured replacement for Windows. With RedHat several years ago I still felt like I needed to keep a Windows PC around. Imagine trying to make changes to your internet configuration when you needed to look up all the complex documentation for it on the internet, to get a feeling for why I needed the extra machine. But with Ubuntu, the internet just works every time in any configuration I need.

That said, Ubuntu is still not perfect and I still run into the rare occasion when I see that Windows has implemented some particular thing better. The Asynchronous IO stuff that I wrote about a few days ago is an example of a place where I think Windows has a better approach at the fundamental level then Linux does. Of course that's not something that directly affects the experience of the average desktop user although for particularly sluggish programs it might help boost performance. I've also run into the kinds of problems that the list author mentions about audio and video configuration. I had a few really lousy Skype calls from my laptop before I was able to find the bad settings that were making everything sound bad (and I'll give you a hint, they weren't in the audio mixer that has the icon on the task bar).

I use Linux on my only computer, and I use it for almost all my needs. I do double-boot into Windows Vista sometimes, mostly for testing Parrot on that platform prior to a release. However, I do use my computer in a way that your average PC consumer does not: I do very little with audio or video and I'm willing to do a lot of stuff from the commandline. Is Linux ready for general acceptance by the PC consumer public? Maybe not yet but it is getting there in a hurry. I think the work that's being done by Canonical on Ubuntu is quite encouraging and maybe in a few more releases they will have reached that milestone where, for the average Joe Schmoe computer user, Linux is more usable immediately then Windows is. I hope that time comes soon.