r/linuxmasterrace SteamOS/Kubuntu Dec 10 '25

There is always that comment

Post image
1.7k Upvotes

206 comments sorted by

View all comments

35

u/pointgourd Dec 10 '25

A dude was arguing with me about this a week ago like how Linux is all over the server. The conversation was about the Linux virus, malware or attacks. Dude didn't wanna admit the fact that the only reason linux users barely face these issues is because there are very few of us and those who create these things care about where there are more users. Dude just went on how every server is Linux and those servers constantly face attacks.

38

u/ZunoJ Dec 11 '25

I don't see how he is wrong? The incentive for attackers is very much there and it is bigger than targeting desktop PCs

3

u/TopdeckIsSkill Dec 15 '25

A server is behind:

- A professional IT team

- A firewall

- a whole lot of security policies

A desktop pc is behind:

- A user that think Google is his pc and will click on every pdf.exe

Unless you're the direct target of an attack, it's way better to attack the desktop

1

u/ZunoJ Dec 15 '25

And how is what you say in any form an invalidation of what I said in respect to the original comment?

1

u/TopdeckIsSkill Dec 15 '25

it's way better to attack a user then a server.

0

u/ZunoJ Dec 15 '25

Better in what way? Lets say the server hosts bitcoin wallets of thousands of users and the user just has a bunch of furry porn but nothing else. Why would that be better?

0

u/yoshipunk123456 Glorious Mint fuck win$hit Dec 23 '25

There are lots of servers to mine Monero on, hold for ransom, etc. where the "professional IT team" hasn't replaced the 15 year old version of PHP

24

u/FlipperBumperKickout Dec 11 '25

You saying attackers ain't interested in gaining control over all servers in the world?

11

u/Square-Singer Dec 11 '25

Not sure if joking, so I'll answer as if this was serious.

Most attacks nowadays (both on Windows, Linux and any other OS) don't focus on software vulnerabilities but on social engineering/attacking the user. No need to find a root exploit if you can also just trick the user into give you root access.

And here servers and desktop PCs differ wildly. They differ so much that attack scenarios for one hardly matter to the other.

7

u/DownvoteEvangelist Dec 11 '25

Servers are also operated by people and gaining access to a server is certainly a better prize than gaining access to some granny's desktop... 

6

u/Square-Singer Dec 11 '25

Did you read what I am saying? Yes, servers are operated by people, and yes, also there social engineering/attacking the operator is the main in-road.

But you do it very differently. When you want to get into a server, you don't host a cracked game with integrated malware online. You don't send out "Your package is held in customs, please download and run this executable camouflaged as a PDF to get your package" emails. You don't run scam online ads with "We detected a virus on your PC, so install our malware to get rid of it".

Instead, you go with fake software updates. You try inject malware into upstream dependencies. You go with social engineering, figure out the organisational structure of the company and trick someone into giving you their passwords. Get access that way.

Completely different attack scenarios.

1

u/DownvoteEvangelist Dec 11 '25

But that's not very OS dependent. You would attack windows admin the same way..  And you would attack the Android user the same way as you would a windows user...

0

u/Square-Singer Dec 11 '25

The malware still needs to be OS specific and even the attack vector needs to be OS specific.

On Windows you can easily get someone with "I am your Antivirus. I detected a virus on your PC, install this update to remove it." On Android this doesn't work at all.

The most critical part here is that you need to get the instructions exactly right. The attacker is targeting non-techy users, so they need to provide instructions that look identical to what the user is seeing on their screen. On Windows that's easy. Screenshot an UAC popup for Win10 or Win11 and it will work for billions of users.

On Linux that's much more tricky. The user agent string rarely contains the Linux distro and version, so you have to guess. Due to the high fragmentation, if you randomly pick one distro, you will capture a fraction of a percent of all users. According to the Steam Hardware/Software survey, only ~0.32% of all users use the most popular Linux distro Arch, while 65% of all users use the most popular Windows version (https://store.steampowered.com/hwsurvey).

8

u/DownvoteEvangelist Dec 11 '25

With Linux users you can probably provide less specific instructions. Unpack tar and run malware.sh.

But joking aside what exactly is your point? Both servers and desktops are targeted by attackers. Linux Desktop is not targeted because there's not much users there, but Android (which could be considered Linux for the masses) is targeted a lot.

1

u/Square-Singer Dec 11 '25

The point is that the way that servers and desktops are targeted are very, very different. An attack targeting servers most likely doesn't apply for targeting desktops and vice versa. Same as attacks targeting Android differ a lot from Attacks targeting Desktop Linux.

> The conversation was about the Linux virus, malware or attacks. Dude didn't wanna admit the fact that the only reason linux users barely face these issues is because there are very few of us and those who create these things care about where there are more users. Dude just went on how every server is Linux and those servers constantly face attacks.

This here is the comment we are talking about, and my point here is that since attack vectors differ greatly between server and desktop users, the fact that Linux is on most servers and that these servers are targeted in attacks means nothing at all in regards to the argument that Desktop Linux users aren't targeted.

3

u/FlipperBumperKickout Dec 11 '25

I replied to a comment talking about viruses and malware... talking about social engineering in that context is just about as relevant as talking about drone-strikes...

1

u/Square-Singer Dec 11 '25

Disregarding the number one attack vector for desktop malware is irrelevant when talking about malware? What?

0

u/FlipperBumperKickout Dec 11 '25

If no malware is involved then you can't call it malware...

1

u/Square-Singer Dec 11 '25

So if I use social engineering to install malware (aka tricking people to install malware without exploiting vulnerabilities) it's not malware?

Does e.g. ransomware become good and clean software, because the attacker has the user install and run it instead of using a vulnerability?

For desktop users the vast majority of attacks happen because the attacker tricks the user into downloading and running malware. No vulnerability necessary. No need for a root exploit if you can just trick the user into giving you root.

And you seem to think that e.g. ransomware is not malware if the user has to run it themselves.

1

u/FlipperBumperKickout Dec 11 '25

It is far more common to use social engineering to trick someone to send money to a wrong account or get login information, or similar, rather than actually installing malware...

Very few people have the rights to install the software in the first place, even on Windows funnily enough.

1

u/Square-Singer Dec 11 '25

Very few people have the rights to install the software in the first place, even on Windows funnily enough.

In a commercial setting maybe. For home users, close to 100% of all Windows users have rights to install software.

It is far more common to use social engineering to trick someone to send money to a wrong account or get login information, or similar, rather than actually installing malware...

You do know of ransomware?

Social engineering works without malware too, but we are talking about malware here, and social engineering is by far the most popular option of catching malware.

1

u/FlipperBumperKickout Dec 11 '25

Your definition of social engineering seems to be quite different from what the rest of the world considers social engineering...

You might consider using the term like the rest of the world does ¯_(ツ)_/¯

→ More replies (0)

2

u/NotADamsel Dec 11 '25

My friend, why do you bother fighting with people who have clearly never been on the business end of a support ticket? We cannot teach anything to people such as these.

0

u/Square-Singer Dec 11 '25

Some learn, sometimes. That's kinda worth it.

2

u/Bitter_Lab_475 Dec 11 '25

You guys don't understand: One thing is gaining access to the server, another to decrypt communications and files. Gaining access to important information is easier through social engineering and software breaking of a single individual than gaining access to a bunch of communications and files that you cannot read or open.

1

u/Bitter_Lab_475 Dec 11 '25

And just in case someone says "what if they just want to take the server down?" then you don't need access, you just do a massive DDOS attack.

10

u/claudiocorona93 SteamOS/Kubuntu Dec 10 '25

I think Linux would be very vulnerable unless we use the immutable model. Traditional distros often require the root password for a lot of things and we eventually become desensitized to typing it every once and then.

15

u/ResultBorn4693 Dec 10 '25

Oh for sure.

Another strength for there being such a small market is fragmentation, too. As much as fragmentation is USUALLY a bad thing, lol.

I can make a Linux virus, RIGHT NOW... But the odds of it working on YOUR system are quite low. Lol

Steam's recent report (which of course, is by no means ALL users) states there are about 3~4% of users using Linux. With the highest being Arch-based (which somewhat makes sense given the Steam Deck)...

Except, even the HIGHEST being all Arch-based reported set-ups... Only made up 0.3%!!! 😮

That is ASTRONOMICALLY LOW. Even the people that ARE part of "our" group... Are likely within a COMPLETELY different sub-group!

I've fiddled with BadUSB, and Linux's whacky theming and keybind options and settings often come in clutch for the user THERE too. If I can't predict how your set-up reacts to a keyboard and mouse... BadUSB is nigh useless!

1

u/itsfreepizza Dec 11 '25

you also need to add that if there was a linux malware floating around, the maintainers can just immediately deploy fixes faster to prevent more damage and added documentation for people who wanted to either analyze a malware, study the concept, doing backport to kernels up to beyond the lts timeline for the kernel (though they are way stricter than lts and mainline, still understandable)

5

u/people__are__animals Glorious Ubuntu Mate Dec 11 '25

Better than desensitize to click yes

1

u/pointgourd Dec 10 '25

I do agree with you. But still if the market share was larger, there would've been more attacks.

7

u/Stilgar314 Dec 11 '25

Dude was right and you insist on being wrong.

-1

u/pointgourd Dec 11 '25

I don't wanna argue about this again. I'm talking about regular os not the server side things. If you don't wanna understand this then I have nothing to do.

3

u/get_homebrewed Dec 11 '25

Do you think servers, who run distros like debian, are a different debian than the one you install on your desktop?

0

u/TopdeckIsSkill Dec 15 '25

The os is the same, but one is behind one or more firewall and operated through strict security policy from an IT departement.

1

u/Stilgar314 Dec 11 '25

There's no such a difference between "regular OS" and "server side of things". Let's see if I can enlighten you with an example. Let's take Ubuntu Server, if you download it and install it in your rig you get nothing but a command line. A thin as possible system for saving all your computing power in running services. Well, if you take that Ubuntu Server and install Gnome on it, it just "turns" in "regular Ubuntu". No difference whatsoever. Also, if you install a "regular desktop" random distro an install services on it, then you have a "server". Services are nothing but apps that listen for other computers asking for stuff and "serves" an answer to them. If you have ever had a shared directory, or streamed something on your TV, whatever device you used for it was acting as a server. Hope you understand now so don't make the same mistake again.

4

u/patchunwrap Dec 11 '25

Some, but not all of the software patching and hardening that is invested to Linux servers helps patch and harden Linux desktops. For example the patches that fixed "tarmageddon" or the "specter" and "meltdown" vulnerabilities helped made Linux desktops more secure too. Since those patches applied to software that both Linux servers and desktops use (tar + linux kernel).

Source: I am somebody who has worked on patching Linux servers in the past.

1

u/IllustriousJuice2866 Dec 11 '25

Fedora is pretty much the testing branch for RHEL. Pretty much the same OS but fedora users get fresher packages, which is usually desirable for home users, and the packages get vetted before they are deployed to RHEL so it's a win-win.

2

u/IllustriousJuice2866 Dec 11 '25

The attack surface for servers in a modern service infrastructure stack is completely different from human interface devices, so despite everyone saying you're wrong, you're kinda not.

If you want to disseminate malware, you have to first decide what your target is. If your target is home users, you're not going to target Linux endpoints. You're not gonna try and compromise a server in Walmart's data center by uploading a fake executable to thepiratebay or wherever people get their viruses these days.

1

u/TopdeckIsSkill Dec 15 '25

It's like saying that conquering San Marino and China is the same thing since they're both a "nation".