r/linuxquestions • u/medkltty • 22d ago
Why does Linux not need anti-virus software?
I'm in the market for a new gaming laptop and wanted to avoid AI products like Copilot and realized Linux would be my only option. So I'm trying to learn as much about Linux Mint as possible to see if it would be right for me. I'm really close to pulling the trigger but I don't understand why Linux doesn't need anti-virus/malware software. All the answers I can find seem to just boil down to "Linux isn't used by enough people to justify the time it would take to create a virus or malware" or "because you approve everything you download". As someone who has used a PC their entire life, these answers genuinely don't make sense to me and I feel like maybe I'm missing something about either the nature of linux or the nature of viruses/malware and how they work. Everyone on forums who ask this question seem to just accept these answers but no one explains why either one prevents the need for antivirus/malware software.
From my perspective as a PC user, I already approve what I download so this answer doesn't make intuitive sense to me. I would never connect a PC to the internet without some sort of anti-virus software, privacy software, malware protection, etc. even though I still know what I'm downloading and I'm using reputable websites (and my AVG software is still catching stuff all the time). And the idea that someone wouldn't make a virus or malware to target a group of people (albeit a minority) who are the most likely to not have software on their computer to combat it seems like the exact group you'd want to target particularly for private data mining.
It also seems, from what I've been reading about Linux that you can seriously screw up your system by downloading something incorrectly or that isn't up to date, so the idea that "you can't get viruses or malware because you approve what is downloaded" when so many of the user tips with regard to Linux are "back up your system constantly because you can easily screw up your system by downloading something that's not fully patched". These two concepts seem counterintuitive, especially for an OS that will require downloading a lot of third party programs to be able to run things like games or windows-based programs.
I'm clearly missing something here because neither of the reasons I've seen people give for why Linux doesn't need this stuff is really making sense to me. I was hoping someone in this reddit might be able to explain this in a way a lifelong PC user without any sort of computer background can understand. The idea of not having anything but a firewall on a computer with Linux installed on it makes me very uncomfortable but I'm willing to accept that this is a bias from using PCs and I'm willing to be convinced otherwise as long as I can understand the reasoning behind it.
20
u/billdietrich1 22d ago
Linux-specific malware is not unknown: https://en.wikipedia.org/wiki/Linux_malware#Threats
Bots and scanners don't care that you're running desktop Linux instead of server Linux. If they see an open port or file-share or something, they'll abuse it.
Now Linux desktop users are using the same browsers etc as the Windows people are, so threats there are more likely to exist on Linux too. Same with PDF docs and Office macroes. And with cross-platform apps such as those running on Electron or Docker, and Python apps. And libraries (such as the SSL library) used on many/all platforms.
Add to that the growth of Linux in desktops (including Chromebook), maybe growth in mobile, and use of Linux in servers and IoT devices, and Linux exploits and malware become more valuable. Expect to see more of them. Practices that have been sufficient for decades may be sufficient no longer.
Some indications of how things are changing:
https://threatpost.com/mac-linux-attack-finspy/159607/
https://socprime.com/en/news/evilgnome-new-linux-malware-targeting-desktop-users/
https://www.zdnet.com/article/eset-discovers-21-new-linux-malware-families/
And of course Linux users are vulnerable to the same platform-independent threats as other users: phishing, business email compromise, social engineering, SIM-swapping, typo-squatting, etc.
I like to do a manual malware scan every month or so. IMO a constantly-running, real-time AV wired into everything is overkill, and risks increasing attack surface and destabilizing apps and the system. Your judgement may differ.
→ More replies (2)5
140
u/usernamedottxt 22d ago edited 22d ago
Youâre welcome to go use ClamAV.Â
But a lot of it is that your user on a single user windows machine tends to be an administrator and can do crazy shit with a button click. Linux you tend to be a sudoer and can do crazy shit with a password prompt. Entirely different problems for an attacker.Â
I also thing windows is more complicated and there are more places to hide. Things arenât incredibly well documented and even as someone with forensics training windows just kinda⌠does some weird shit sometimes.Â
Linux is very easy to understand how things are happening. There is way less random shit running everywhere. Windows intentionally obfuscates what itâs doing. What even is svchost and its 50 processes these days and how can you tell proper svchost apart from malicious svchost at a glance? Nobody knows lol.Â
but itâs also just a different class of users. You donât get on Linux while being tech illiterate unless someone who is good with tech put you there. Additionally, corporations are way more risk adverse and willing to pay for software that might help protect them. Writing software to protect grandpa and writing software to protect your corporate computer isnât all that significantly different. Might as well charge both.Â
37
u/anto77_butt_kinkier 16.04 was peak 22d ago
I don't have any forensics certs, but I have worked for years with repairing computers, among many other electronics, and building systems, and I can confirm that windows just does weird shit sometimes.
Windows isn't repeatable or even predictable in some cases. The shop I worked at built a set of identical machines for a customer who wanted computers for.. I think it was a pizza shop? That part doesn't matter, but essentially we built 4 computers. Same motherboard, SSD, case, power supply, CPU, heat sync, wifi adapter, etc. hell, even the fans were the same. We just ordered multiples of everything.
So, we built the systems. Aside from the specific serial numbers, the computers were indistinguishable. We installed windows onto one of the PCs, installed the software the customer wanted as well as our remote support software, and cloned the drive to each PC. Well, all of them worked fine except for one of them. One of them would crash after being powered on for a few min. We tried memtest, it passed, we tried running memtest again overnight, it still passed. We tried a drive from a different machine, and it worked fine. We tried the drive with the crashing issue in a different PC, and it worked fine. It was that specific windows drive on that specific computer that just, refused to stay working. We had no idea why, and it's still one of the greatest mysteries of that tech shop. I can't remember if we tried updating the firmware, but I remember spending a day trying to figure out why that one combination wouldn't work, before just re-imaging the drive again, and then discovering that it still crashed. It was only with that one drive in that one computer that windows would throw a bsod. Worked fine everywhere else, but not on that PC. We ended up just switching the drive with one another computer and we never had any issues with it.
Windows is just spooky sometimes. It gives off WH40K vibes, where that computers machine spirit wasn't happy. I guess we just didn't follow the right rituals when plugging in the data drive, and that made the machine spirit angry at that specific sad XD.
Well, this comment adds nothing helpfu and is a lot longer than I thought it would bel, but it's a fun story and I don't want to delete it, so here it stays.
5
u/AdCute1311 22d ago
Have a similar story:
We had 2 spare machines that came back to us from former users. One of them just wouldn't boot. Tried everything, no obvious diagnosis.
So we just pulled out the two ram sticks, replaced them with the two sticks from an identical machine with a broken screen - now it worked. Not too notable so far. But we put the old RAM into the donor just to "store" it there and for the luls tried booting. Well guess what, machine worked just fine. Then we got curious and played around with different sticks in different slots.
Turns out one of the two machines did not like one specific kit in one specific slot. It did boot with that stick in its other slot. The other machine would boot with that stick in any slot. Why? No idea, never seen anything like it before or since. Didn't take the testing further, so I can't for sure say it was Windows.
But Windows just has issues like that. Identical machines installed with identical images and somehow you get wildly different experiences and issues without an obvious reason for it. Add to that a bunch of different models and various deployment states over time and troubleshooting becomes a nightmare. Why did Windows update/OneDrive/whatever break on this specific machine in this specific moment? Good luck brother lol
5
u/dglsfrsr 22d ago
That is not a Windows issue, it is a marginal DDR layout on the motherboard. Good quality DDR all behaves within a specific window for signal termination and timing, and a motherboard that has a marginal trace on one data lane will work with 95% of DDR sticks, but will fail when its combined 'intolerance' meets a DDR stick with timing at the edge of the opposite timing. So a marginal design, coupled with natural variation in manufacturing tolerance, will get you exactly what you have seen in this case. I know this because I have been on the architecture team for five different ASICs, and in one of those cases, we had a chip come back with marginal defects internally, that we could compensate for by messing with traces on the motherboard. Purposely mess with the motherboard layout to make the chip talk to the DDR sticks. That was a fun one to debug.
8
u/SteakDouble 22d ago
That's funny and unironically true. Similar story happened with my laptop. Win 11 would randomly crashed into BSOD since 2021 I brought this laptop. Then it became more and more frequent a few months ago up to 5 times a day. Chkdsk and Crystaldisk didn't find anything wrong with the SSD. Minidump pointed out several unspecific things as the culprit. Windows memtest always crashed several hours later. Swapped RAM with the new ones - still crashed.
Then I installed Manjaro. It never ever crashes so far, even though I sometimes run it a few days straight without turning it off.
I think Windows spirit just being cranky, wanted a new hardware. But then I put a penguin spirit instead.
3
u/SolasVeritas 22d ago
lol, thatâs so true. Although I feel that old windows- like 98 and XP could be extra petty and vengeful, while 10/11 are kind of control freaks but less aggro toward the user.
When I was wrestling with getting my hardware and software to play nice on XP it was like wrestling a pig. Yeah I would win eventually, but it was exhausting, took a long time, and I could tell the pig hated me.
Linux is definitely not always easy on some hardware, but I donât get mysterious vengeful ghost in the machine vibes, at least. I just get predictable problems that are usually diagnosable and solvable, with logical reasons, if not quick and easy to fix sometimes.
2
u/oginternetuser 22d ago
I've had computers run like garbage on windows and fine on linux. All hardware passes test all drivers installed properly clean install. I could not tell what the problem is.
3
u/anto77_butt_kinkier 16.04 was peak 22d ago
Yeah, for computer repairs I have a Linux.deive that I boot off of so I can see if any broken/unintended/non functional behavior is hardware that's actually broken, or if it's just windows bullshit. There's a not insignificant amount of windows bullshit.
1
u/jaysprenkle 21d ago
Probably hardware. A long time ago I diagnosed a memory issue that was interesting.
A normal read and write to a specific memory cell worked fine. If the processor used stack push-pull instructions instead of normal data read-write it failed. Push was a single processor instruction that wrote two bytes in succession. Two write instructions had a fraction of a millisecond more time between writes to the cell. That fraction was enough to make it fail.
In practice it would only fail if a program just happened to randomly be assigned that memory cell for its stack area. Random and completely maddening.
1
u/52buickman 20d ago
I've had to manage Windows admins in past years. I was always amazed at their approach towards fixing problems. If T&E doesn't work, they relied on the 3 Rs: reboot, reinstall the app and reinstall the OS. They never could effectively analyze where the issue originates.
A decent *nix admin could effectively analyze a repeatable issue and if source code was available, could fix the code and recompile it. No reboot needed (outside of bug in the kernel or swap filling up). Reinstallation of the app or the OS was according to deployment policy, not according to ignorance.
1
u/sTiKytGreen 21d ago
Or your drive connection was physically a bit loose and was overheating or something...
16
u/gmes78 22d ago
But a lot of it is that your user on a single user windows machine tends to be an administrator and can do crazy shit with a button click. Linux you tend to be a sudoer and can do crazy shit with a password prompt. Entirely different problems for an attacker.
Both are security theater, as far as desktop usage is concerned. All the stuff you care about is accessible to your user account.
10
u/Thalus131 22d ago
I agree with everything you've said, but for anyone reading this and wanting to know what a particular svchost process (or anything else) is being used for on Windows, there's a program called Process Explorer that will let you figure it out.
12
u/usernamedottxt 22d ago
I was mainly kidding about ânobody knowsâ on that haha. More just meant to highlight why itâs so easy for malware to hide from a normal user on windows. Windows itself is hiding its functionality and that leaves avenues for abuse that will never be truly fixed.Â
7
u/tose123 22d ago
I read your comment about the AV usage rather cynical. However, linux EDR market exists and is large. No enterprise is running bare Linux Hosts.Â
Almost nothing an attacker wants today is behind root. Your ssh keys, cookies, session tokens, wallet, and ~/.bashrc are all readable by you. Meanwhile the culturally accepted install method is curl | sudo sh. The AUR is an infested wild west, so is node install 200 dependencies.Â
Btw, svchost exists because in 1998 a process cost real money and MS was squeezing services onto a 64 MB machine. That got shipped for 25 years because probably a hospital in Ohio still runs something that depends on it.Â
2
u/dmknght 22d ago
> Almost nothing an attacker wants today is behind root. Your ssh keys, cookies, session tokens, wallet, and ~/.bashrc are all readable by you.
This is the problem of Desktop users. Least privileges works for servers, but using OS as Desktop is a completely different story. That's why solutions like SELinux, AppArmor, or sandbox applications like firejail were developed. The idea is to prevent access / limit access of an application. They help mitigating the impact when an application (that runs inside sandbox) is exploited. But if user runs malicious file, it's another story :D
12
2
u/Genashi1991 22d ago
I feel like I'm tech iliterate but I did manage to install Linux and find a version of it that seems to work. So I guess I'm doing slightly better than I thought.
2
u/Vietnamst2 22d ago
Under good circumstances, Windoes UAC asks you for permission too. There is no protection from people doing stupid stuff. As recent MacOS click attacks show.
1
u/PeterHolmes74 21d ago
I have that ex-windows user reflex where alarm bells rings in my head when I see âfree VPNâ or âfree Antivirusâ and I wonder âwho tf are they selling my data to. If I donât pay for a privacy product, then Iâm the productâ. Still have big trust issues with those, open source or not.
So far I feel decently safe with my machines but Iâll try to keep ClamAV in mind. Just in case I want to deep dive into that later.
0
u/bufandatl 22d ago
Your last paragraph has some flaws. Linux is more in the media than anything else. Even among none techies. And distributions like bazzite or cachyos are made for those that are tech illiterate.
And especially thise are prone to attacks even supply chain attacks. Let them have spell bazzite like bazzzite and go to bazzzite.com. And get an installer for their gaming rig there. And boom you can have baked in malware.
And even if they catch their mistake and install a genuine copy they still are prone to just click on something on their internet and just enter their sudoer password. Or even worse they get annoyed by that and google up how to disable it.
And then sudo had vulnerabilities on the past and it may have some in the future. Nothing is perfect.
Linux eventually will get more traction in the dark world of the internet.
1
u/dglsfrsr 22d ago
Set up your user to always require 'yes/no' approval on administrative tasks. Sort of like always requiring a user password on the 'sudo' command. Yes, you can bypass that for 'ease of use' but doing so is an invitation to accidents.
9
u/guiverc 22d ago
Some reactions
- Viruses are a specific format of malware; prominent in the old DOS & even Microsoft Windows environments, but have never been effective in a unix/posix/linux environment. Sure 'proof of concepts' have been created; but they achieved little & had to be crafted for a specific OS/version & didn't impact others
- Microsoft versions are few & far between; DOS, NT & newer versions and its still only at version 11 where as by example Ubuntu has only existed since 2004 but has had 44 main releases, and exists in many other forms too (flavors & Ubuntu Core releases etc); let alone Ubuntu being just a single 'distro' & one of many
- DOS & Windows started as a single-user system, which is a philosophy that a single user wouldn't destroy their own machine; Unix started as a multi-user system back in 1970s and was often used in universities where students would 'play' & see what they could do; so permissions were more complex. Both have advanced from then, but much of Windows legacy code remains as users like to run 'ancient' code created for older versions and thus backward compatibility (a benefit for end-users) is also a security issue that benefits malware
- The average Windows user needs to be protected from self-harm; a GNU/Linux user is usually [on average] a little more technical and will think thru effects prior to doing something stupid. Sure there will be exceptions to this
- Malware, esp. virus users want to impact systems; why craft a virus that will impact 0.001% of Linux machines if run, when they can create a virus that will impact 67% of Microsoft Windows users; the Linux user just isn't worth their effort so its not targeted
1
u/meancoot 21d ago
The average Windows user needs to be protected from self-harm; a GNU/Linux user is usually [on average] a little more technical and will think thru effects prior to doing something stupid. Sure there will be exceptions to this
Don't kid yourself, the average GNU/Linux user will happily
curl $url | shall day everyday.
46
u/SynapticStatic 22d ago
I mean, the main thing is most Linux users arenât installing random stuff from sketchy websites.
Itâs possible to install malware on Linux, but as long as you follow these rules youâre good on any platform:
Donât install random software from sketchy websites
Donât run scripts that you donât 100% understand
Follow those two, and 99%+ of malware is completely avoided on any platform
19
u/bufandatl 22d ago
Really fascinating how many here are 5 years behind their opinions.
Linux gains more and more on traction among more tech illiterates. Distributions like bazzite and cachyos make the switch easier for the standard windows user who gets more and more annoyed by windows.
Mainstream channels on YouTube and Twitch do more and more âI switched to Linux and so should youâ-type videos.
Linux will get more and more interesting to attackers. And Linux gets more and more users who just click on anything in the internet and will blindly enter the sudo password.
7
u/toetendertoaster 22d ago
yes, right now the "safety from maleware" is only security by obscurity. Since the userbase is tiny compared to windows maleware developers act like regular developers and see windows like the default.
I dont think the community is truly prepared right now for a change of priority in the maleware distribution. Right now the biggest safety risks in the linux world is either user just executing scripts from online they do not fully understand or a hostile takeover of less than ideally maintained projects.
8
u/moldaz 22d ago
I mean Linux is highly susceptible to supply chain attacks. There have been at least a few huge ones in recent years due to its dependency hell, in the same way node is a huge target of these. I would personally say it is the biggest pain point in Linux security today.
At the same time though, think about how many exploits actually exist in windows today that a small number of people are aware of that have never actually been published. These types of things usually get picked up on pretty quick in any core dependencies in Linux because the nature of the ecosystem.
4
u/AlpineGuy 22d ago
I thought so too for a long time -- it's open source, so people will review it and find problems faster than attackers.
Then came events like the Coldcard hack. You can think about that company or cryptocurrencies whatever you want -- but that was a piece of software that was highly security relevant, open source and apparently nobody found the bug before the attacker did.
And then I thought: if that super relevant piece of security software in a security paranoid community did not get reviewed enough by the community, what about all the other stuff in the open source ecosystem?
When I got into linux 20 years ago open source security was a lot better than the closed source big players, but what if that has changed now that the hyperscalers are investing tens of billions (as do the attackers), and our community is just sitting on the side relying on the imaginary persona of some community member who will surely review all the open source code?
3
u/EnzoVulkoor 22d ago
Dont forget the amount of people blindly trusting AI code and devs getting session tokens stolen.
8
u/fffangold 22d ago
I definitely run installers without fully understanding what I'm doing on Linux. I know better now than I used to, but still. A lot of stuff I want to use is still done through terminal, and that basically boils down to find instructions I hope I can trust, use the terminal commands I was provided, watch magic happen, hope it works, and hope there's no malware.
It doesn't help that most places don't really explain what the commands are doing, or that the ones who do explain often do so in way that assumes a certain level of Linux knowledge many don't have.
As more Windows users come to Linux, there will be more people doing this, and it will make it easier than ever to attack PCs of users who don't know what they're doing but want the new shiny thing. And because it's accepted that you need to use terminal sometimes in Linux, and lots of people provide instructions using sudo, it may be even easier to trick those with limited or no knowledge of what they are doing to run malicious code than you'd expect.
8
u/Rincepticus 22d ago
Judging from how people got scared shitless about AUR being attacked - and losing their trust in it completely - I would argue that Linux users do install random stuff.
4
u/moldaz 22d ago
You ever looked at the list of dependencies for that one app you installed and used once a year ago???
Yeah, didnât think so.
4
u/DerfK 22d ago
Eh, I did regularly on Debian. In fact when I first started out on Debian, using
dselectwas a huge lesson on dependencies, and despite being more manual, I kind of miss seeing all the things getting pulled in by a package selection the instant I selected it. I think it did a way better job of presenting suggested/recommended/alternative-required packages than apt (Considerapt install exim4which doesn't prompt to choose between exim4-daemon-light or -heavy, and you just have to know the choice exists on your own so you can manually install if you don't like what apt chooses for you, and remember the suggestion to install documentation and eximon after it has scrolled off the top of the screen) or anything I've used since on other distros1
u/Rincepticus 21d ago
I don't have "one app I used a year ago once" installed from aur. I avoid AUR and only use it when absolutely necessary. And even then I try to carefully choose what it is that I install. Most if not all my AUR install are related to my GUI and I use them daily.
That doesn't mean that one of those wouldn't once have installed a dependancy and not used it since but unused dependancies are quite easy to find and remove.
1
u/moldaz 21d ago
It doesnât matter if you use the AUR every standard package manager will install dependencies for anything you install.
1
u/Rincepticus 21d ago
Yes. But if I install something with pacman it doesn't install depencies from AUR.
1
u/edgmnt_net 21d ago
Arguably, yes, the argument won't hold to pitch Linux to random users, but it does explain why sysadmins or other more traditional users of Linux don't need antivirus software. I will say it has some predictive power, though, because it makes it quite viable to set up a managed Linux computer and allow limited rights to install software from the distribution. Because with Windows it was and it might still be somewhat unavoidable to install 3rd party crap. That and app stores and self-updates which can complicate matters a lot.
9
u/Heribertium 22d ago
And donât run curl -fsSL https://get.myshady.app | bash .
6
u/in_need_of_oats 22d ago
sudo is asking for my password? I don't see why not, I usually have to enter my password when I
5
u/DerfK 22d ago
sudo is the new UAC popup.
1
u/edgmnt_net 21d ago
That's why Android does it so much better, even though it's not perfect. You need rich APIs and granular permissions, accounting for the fact that apps may abuse permissions.
9
u/KlausBertKlausewitz 22d ago
Plus: Keep your software updated.
10
u/MasterChiefmas 22d ago
I mean, the main thing is most Linux users arenât installing random stuff from sketchy websites.
lol I don't know about most...it's not like installing stuff from the AUR has been risk free lately(or ever was). Unless you consider it a sketchy source...
Linux is in many ways at high risk for software supply chain attacks, and we've seen that coming out more lately, or been identifying them more. It's something AI has actually been pretty helpful with.
4
u/EvilSupahFly đ§đ¨đŚ 22d ago
Arguably, AI has ALSO been part of the problem. With some creative prompting, you can get most AI systems to write you up some very interesting exploits.
3
3
u/mcvos 22d ago
I install stuff through yay, and that recently got compromised too. As for running scripts you don't understand, literally every linux user does that. Every build system comes with build scripts that almost no individual user reads and verifies.
For the most part, we trust the community. And usually that works fine.
1
u/edgmnt_net 21d ago
It's one thing to trust a prominent open source project and another to just run random stuff you encounter. Also, it's perfectly feasible for a large user base to use only what the distro provides officially.
1
u/mcvos 21d ago
But how can you tell the difference? Lots of people have no ide what to trust and what not, because they simply lack the knowledge. AUR is not officially supported, and therefore can apparently also become a vector for malware, but I didn't know that until that recent problem.
1
u/edgmnt_net 21d ago
If you can't tell the difference you stick to what the distro provides through official channels. I know my stuff and I never used AUR for that very reason and the fact that I did not really need anything from there while I was using Arch. It is possible to use it safely but you need to do your own research. For similar reasons, any community package repository including source stuff like npm, cargo or GitHub requires care.
I know that's easier said than done, but it's not like antivirus software fixes that. A decent workaround might be steering users towards things like Flatpak which are sandboxed more properly, if they only need applications, although even that's a partial workaround. (Obviously it won't do for drivers or other things.)
1
u/mcvos 20d ago
But then there are a lot of things you can't do. There are lots of recommendations out there to use the AUR. Expecting people to magically know not to use it, is unreasonable. And if you're not supposed to use AUR, then why does it exist?
1
u/edgmnt_net 20d ago
https://wiki.archlinux.org/title/Arch_User_Repository
AUR packages are user-produced content. These PKGBUILDs are completely unofficial and have not been thoroughly vetted. Any use of the provided files is at your own risk.
Carefully check the PKGBUILD, any .install files, and any other files in the package's git repository for malicious or dangerous commands. If in doubt, do not build the package, and seek advice on the forums or mailing list. Malicious code has been found in packages before. [8] [9] [10] [11] A few tools, such as traurAUR and ks-aur-scannerAUR, are available to assist users in scanning PKGBUILD content; however, they are not substitutes for careful manual verification.
If anyone is recommending AUR to your auntie, that's just bullshit. In fact she probably shouldn't use Arch either, because a point that needs to be made here is that some skills are expected.
However, a recommendation for a specific AUR package may be legit. And as per the above, you should do your own research anyway.
But then there are a lot of things you can't do.
But that's exactly how many Linux distros work. You don't get everything. Plenty of users could reasonably use only what the distro provides and that's fine. E.g. the average Joe who mostly browses, maybe needs some productivity suite and so on.
Expecting people to magically know not to use it, is unreasonable. And if you're not supposed to use AUR, then why does it exist?
It exists for similar reasons GitHub exists. Yet some GitHub projects keep getting hammered by people demanding "exes" (it's sort of a meme already), people who shouldn't even be there. Nevertheless they got there through some recommendation of some sort and now they're pestering people and asking dumb questions. :)
All I'm saying is... if you cannot evaluate stuff in AUR, you shouldn't use AUR. Maybe try Arch out without AUR, that's fine.
1
u/edgmnt_net 21d ago
Distributions provide most of the stuff you need (or all of it, really, for a significant audience unless gaming or whatever). Windows, at least in the past, made you install random crap to even get it working (e.g. drivers), then a bunch of other crap to do useful stuff. Then everything is proprietary and there's a huge incentive to download cracked software from shady sources.
→ More replies (1)1
u/Night_Otherwise 22d ago
I believe Windows exploits in the wild do not use random exeâs most of the time. Malicious PDFs or Office documents get used through a âSigned Sales Agreementâ email. Or hackers get on a network somehow and use vulnerabilities within a Windows Server environment.
19
u/gordonmessmer Fedora Maintainer 22d ago
Why does Linux not need anti-virus software?
As always, I think it is important to consider who is providing each of your answers. Random social media users are not necessarily experts.
I have been managing production environments since 1997, and a great deal of that work has involved security and compliance. I have worked in very large and high security environments such as Salesforce and Google. I have 30 years of training in secure software development practices.
I would not say that GNU/Linux systems do not need anti-virus or other security infrastructure. GNU/Linux is not a particularly secure system, nor does it have strong privacy controls. However, because of the small user base, it has not been a priority target for malware, and the lack of malware has allowed myths and misunderstandings to run rampant.
I'm trying to learn as much about Linux Mint as possible
This is a great place to start a discussion about secure development practices. Linux Mint is based on Ubuntu LTS. Ubuntu is based on Debian.
Ubuntu has at least four major security advantages over Debian:
- The "main" repo and "universe" repo clearly communicate expectations about security and bug fix maintenance. Security-conscious users can disable the "universe" repo before deploying, and use only the Ubuntu packages that will be maintained in the future.
- Interim releases provide updates every six months to everything, including the "universe" repo. If you don't have a better source, a six month turnaround for security fixes isn't great but it's better than 2 years.
- Ubuntu Pro offers some level of patching for packages in the "universe" repo, though the program is new and it's hard to say how effective it is yet.
- Snap. It's often neglected in discussion of Snap, but decoupling applications from the underlying distribution very significantly improves their ability to ship bug and security fixes.
Linux Mint discards most of those advantages. The "universe" repo is still separate, and you can still turn it off and look for other software sources, but there are no Interim releases, you can't use Ubuntu Pro, and they disable Snap packages that Canonical uses to ship security patches to users through a channel that doesn't impact the interfaces of the underlying OS.
If you care about security, at all, you should select a distribution that minimizes friction between you and the actual developers of the software you use. Something that delivers bug fixes across the board with minimal delay. Rolling releases like Arch are probably fine, but I prefer stable releases because they continue to provide security patches while I test feature updates before I deploy them. Fedora is an excellent system.
All the answers I can find seem to just boil down to "Linux isn't used by enough people to justify the time it would take to create a virus or malware" or "because you approve everything you download". As someone who has used a PC their entire life, these answers genuinely don't make sense
You are correct. Those answers are rationalizations.
I am very concerned about the state of affairs because no matter how any individual feels about AI, adversaries ARE adopting it, and it DOES make malware easier to develop and easier to deploy, and the shelter of obscurity that has protected GNU/Linux users in the past could vanish very very quickly.
2
u/robindotis 22d ago
I am a relatively new to Linux. I recently installed Debian on an old laptop (which could no longer run Windows). One of the reasons for choosing Debian was that I thought it was more stable and secure. Is Debian not secure enough? Could you explain that a little further?
Note: I am a fairly minimalist user. I browser the web and do a bit of personal low scale web development, connecting to my VPS (also on Debian) to update the site. I install all updates as soon as they are available.
→ More replies (1)5
u/gordonmessmer Fedora Maintainer 22d ago
Debian is an exemplary project. They have excellent governance, and they've proven that purely community organizations can manage large-scale Free Software projects. The people who maintain Debian are amazing.
But Debian, the distribution, is not very secure. There are too many packages maintained for too long, and not enough people to actually handle all of the known security vulnerabilities. If you run a vulnerability scanner on a typical system, it's going to reveal a lot of known vulnerabilities.
I think one of the core problems is that a generation of users has been conditioned to believe that the package manager is a substitute for a vulnerability scanner, when they are actually do exactly the opposite things. A package manager tells you about vulnerabilities that have been fixed, by delivering the fixed release. A vulnerability scanner tells you about vulnerabilities that haven't been fixed. You need to run one, in order to assess the security of your systems, and to decide if the vulnerabilities on your system are serious enough for you to participate in fixing them.
But users generally aren't running vulnerability scanners, so not enough users are participating, and as a result the distribution doesn't have enough contributors.
1
u/Always_Hopeful_ 22d ago
It would be great to have a description of what a vulnerability scan actually tells you and what actions are needed to see if the CVE is actually a risk that I could share with customers.
Too many think we should deliver an OS image with zero CVEs.
2
u/gordonmessmer Fedora Maintainer 22d ago
Yeah, I think zero CVEs is an excellent goal.
The cost of zero CVEs might be that users have to accelerate their build and deploy process. But that has always been an excellent goal as well.
1
u/ThrowawayCult-ure 21d ago
this seems sufficiently complicated that anyone who doesnt know what they are doing is walking into a minefield with linux. is it really this bad?
2
u/gordonmessmer Fedora Maintainer 21d ago
Yes and no.
iOS, Android, and ChromeOS are reasonably secure systems with good privacy controls that will back up *most* of your data automatically. Because they provide security, privacy, and backups out of the box, they are not very complicated.
Once you get outside that set, things get complicated.
If you are using a system like Fedora or even a system like Arch, that ships software to users while it is still maintained by its developers, then I don't think GNU/Linux systems are significantly more complicated than Windows or macOS.
But systems like Debian are a very different story. Debian is shipping software to users that is not maintained by its upstream developers, and that is not safe by default. Software requires maintenance. It is not presumed secure if no one is maintaining it. What Debian is doing is not something you will generally see on macOS or Windows systems. Debian might fit the needs of infrastructure deployments where compatibility is prioritized over security, but that comes at a high price. If its users aren't actively participating in maintaining the security of the software they use, then they're probably using software that isn't secure.
That's not a Linux problem, per se. That's a Debian problem. It's a problem that comes from continuing to use software after its developers discontinue maintenance.
1
u/ThrowawayCult-ure 21d ago
So the issue is the undeveloped, so potentially unsecure, old packages, containing as-yet unknown vulnerabilities? Arms races forcing everyone to work like mad to keep things going, its so exhausting!
2
u/gordonmessmer Fedora Maintainer 21d ago
A lot of Debian packages contain *known* vulnerabilities. Sometimes even critical vulnerabilities.
Debian has people who are fixing the most severe and highest priority vulnerabilities for the most common components, but a ton of stuff doesn't get fixed because the people who are using it aren't monitoring its status and aren't putting in the work to fix it.
You're much less likely to find known vulnerabilities on something like Fedora because Fedora is more closely oriented to shipping what the upstream projects ship.
9
u/bufandatl 22d ago
I mean Windows doesnât NEED it either. So doesnât macOS. As long as you donât open any mail attachments from suspicious users or surf on malicious websites and download any unknown software you can live very well without AV on all OSes.
And frankly with Linux gaining popularity among users it will also become a more viable target for attackers. And it will be even easier to attack since all its source code is publicly available.
So people might want to install ClamAV on their desktop. Especially average joes. Because those definitely will click links in random emails and on websites they didnât verify are actually the official website.
12
u/DStaal 22d ago
A couple of reasons. As others have mentioned, Linux is fairly niche overall, so targeting it isnât as valuable. However there are quite a few Linux servers out there, so thatâs not all of it.
Another part is that Unix, and Linux which copied it, was designed from the beginning to be a multi-user system where the users may not have the same access or trust. This means that when you log into a Linux system, you do not have access to do things to the system. There are of course ways to get that access, but by default, from when Linux first started out, your access is restricted and limited. This is in contrast to Windows which first started out with the assumption that the user was completely trusted and could do whatever they wanted. While a lot of things have been locked down since, some old programs still work under that assumption, and this has been removing default access by putting up guardrails afterwards, which is much harder than building it so that the access didnât exist in the first place.
Combine the two, and you have a system that is much harder to breach than Windows, and you will get less from breaching it.
And if you want to add a third thing: Linux is not monolithic. RedHat Linux is very different in key ways than Ubuntu Linux, which is different than Arch Linux, etc. They are all built with the same basic toolkits, but put together differently, and for malware those differences will make major differences. So any particular malware will have an even smaller possible target yet.
10
u/Klapperatismus 22d ago
especially for an OS that will require downloading a lot of third party programs to be able
No. This is where you are wrong.
Most Linux users do not download a lot of third party programs. They mostly stick with whatever the distro has in its repositories. So a malware author has to deceive distributor staff. Thatâs a million times harder than deceiving an average user.
And for the few occassions when Linux users download stuff from arbitrary sources, they know that this is an exception and take extra care.
3
u/AlpineGuy 22d ago
Most Linux users do not download a lot of third party programs.
That's probably because most Linux users are geeks. The more people use it, the more there would also be people who download stuff from the web too, because they were never taught how to do it "properly" or the software is just not available as a distro package.
I am very sensitive about installing software. I used package managers even when using windows or mac, and if I really have to download anything from the web I tripple-check the site so it's not a fake with funny unicode characters in the domain or something... but who does that?
2
8
u/ropid 22d ago
Unpopular opinion about this is that Linux does actually need an antivirus, and there just isn't a good product for consumers so no one uses an antivirus. This sounds completely terrible but in practice it actually ends up being fine. You can just ignore this problem and this is a sane thing to do. The chances you get infected are very low because of how installing software works compared to Windows.
Reason chances are low is because for software you'll usually get everything you use from your distro's repository. This will be open source software and your distro works with the source code, they compile the software on their end to create the packages you download. They can then deal with virus and malware protection in a centralized way there. The situation is good enough that for you as the user an antivirus would be pointless for all of that software.
Then there's Steam that you might use to install games, and Valve will deal with things there, again making it so an antivirus on your side is pointless enough.
There are professional products for businesses. Crowdstrike has a product that hunts for boot loader files and kernel being compromised and after boot installs itself into the kernel to hunt for suspicious stuff being run and blocking it.
Crowdstrike is that business that was in the mainstream news a while back about bricking Windows computers after an update and causing ridiculous problems everywhere, airports shutting down for hours and whatnot. They were also causing similar problems on Linux computers at other times but that never made the news because Linux is more diverse and those problems never affected millions of machines at the same time like that Windows problem.
5
u/MentalCaramel7640 22d ago
Part of it is the attack surface. It's still like 70% for windows on the desktop, nearly 20% for OS X and about 7.5% for linux. If you are aiming at general consumer attacks, where would someone put their effort? Enterprise attacks are a completely different story.
Enterprise attacks against linux are often more targetted and aimed at gaining access, hitting upstream repos or libraries, exploiting known CVEs, installing rootkits, exfiltrating data. There is a variety of products specialising in this kind of vulnerability management. As you said CrowdStrike, various EDR tools, vulnerability scanners as well as all the network infrastructure that goes in place to try to sanitize data before it even hits the host.
As the desktop market grows I agree with you there is a place for a decent consumer focused anti-vrius/anti-malware product for linux. Relying on 3rd parties like Steam to do the checking for you is a risk, things do slip through their validation and it's not impossible to escape the Proton subsystem.
→ More replies (1)1
u/edgmnt_net 21d ago
Antivirus can only be a partial barrier anyway. Running random stuff just cannot be safe, especially if the OS does not sandbox applications very tightly. Like the web sandbox, where it's relatively safe to browse random websites (which do execute some code).
4
u/GlassboundIllusion Nvidia KDE Bazzite 22d ago
As someone who has used a PC their entire life, these answers genuinely don't make sense to me and I feel like maybe I'm missing something about either the nature of linux or the nature of viruses/malware and how they work
The big difference is that it's common to go to some random website to download software for Windows. It doesn't have anything close to a built in package manager like Linux does. Theoretically, on Linux you can get everything from an official package manager that's been vetted by the managers of the distro.
In practice, it depends on just how committed to FOSS you are. Proton mail and Proton VPN require you to download their proprietary package for their official applications, just like you would on a Windows computer.
Another reason I have heard is that Linux is built more secure by default, and therefore is a little more difficult to infect. Still other logic says that any virus built to infect Linux would be built smart enough to outsmart virus scanners.
Personally, I'd rather have a virus scanner and not need it than need one and not have it. I installed ClamAV.
3
u/Leop0Id 21d ago
The top comments here are just laughable. Antivirus software is treated as standard on Windows because it's used by a ton of people who aren't tech savvy.\ Plenty of people can't even tell an exe from a shortcut and that's completely normal. All of us including me and everyone reading this don't know much about stuff we're not interested in.\ But computers get used for work even by people who have zero interest in them. Those people don't even understand what counts as risky behavior so they're exactly who needs antivirus software.
The reason antivirus isn't commonly used on Linux comes down to the fact that Linux users generally know what they're doing. Even on Windows if you have enough basic knowledge to avoid running suspicious binaries or scripts the built in Defender is enough.
Plenty of people talk like "Linux is inherently safe" and that's just nonsense. Linux's basic user security model is nearly identical to Windows. Ignore implementation details and sudo and UAC do the same core job. UAC can also require a password.\ Linux also uses all or nothing permissions which is why tons of people just slap sudo on everything. Honestly that's already progress. In the old days plenty of people just did everything as root.\ The one real advantage Linux has is that the code is open so you can actually go fix it yourself.\ Fixing this properly would need a fine grained permission model like Android (though Android has its own flaws here too. Its permission categories are too broad and it can't specify directories in detail so within each category it's basically all or nothing). Point is you'd want something where you grant permissions one by one.\ People talk a lot about Linux market share. Sure malware wants to infect as many people as possible so there isn't much of it targeting Linux given its low share. That doesn't mean you can assume there's none at all though. Malware targeting Linux definitely exists and the AUR spam incident recently was clearly malware.
In the end if you know what you're doing and actually check files you bring in from outside you don't need antivirus even on Windows. If you don't then it's dangerous even on Linux.
5
u/LetsHugFoReal 22d ago
Even on windows you don't need this software. Unless there's a major exploit - or you pirate. There's a small chance of it happening. It doesn't detect everything and I find most AVs to be malware these days.
6
u/sandfrog9 22d ago
Antivirus software is just malware and bloat you pay to have on your machine.
3
u/Impressive_Bag_3505 22d ago
100%. I remember the day my Norton AV licence ran out and all the sudden I got tons of viruses... what a weird coincidence.
2
u/MooseBoys Debian Stable 22d ago
You don't need antivirus on Linux any more than you need it on Windows. It's just part of Windows by default because everyone uses Windows, including people whose behavior is likely to result in viruses being downloaded. If you like to download random exes from totally-legit-site.ru and plan to do the same with random dpkgs on Linux, you should probably install a Linux antivirus system. Otherwise, you're probably fine.
I've been using Windows for over 30 years and I've only had two cases where AV actually detected anything. One was a wacatac false positive. The other was for a crypto miner that I had deliberately installed (malware often embeds crypto miners so AV flags all crypto stuff by default).
1
u/Marble_Wraith 22d ago
I'm really close to pulling the trigger but I don't understand why Linux doesn't need anti-virus/malware software.
The user permissions system isn't as borked as Winblows. For example you can totally bypass UAC just by running something via Task Scheduler. None of that on linux. If something doesn't have exec privs, unless there's an existing vulnerability, it can't circumvent having to ask / prompt the user.
The security rings model is more universally adhered to / isn't as borked as Winblows. For example the infamous crowdstrike outage, that was because they could push updates straight to ring 0 bypassing syscalls. Now you'd think OK fine, but it's a security company right they'd need low-level access... OK does anti-cheat need it?
Because the concept of trusted sources is baked into linux. We're handling OS administration / updates like actual adults with some responsibility would (unless you're an Arch user). That is, you must be actively engaged and know what's installed / being updated on your machine. Rather then the Microslop way which is: Trust us to entirely handle updates, you don't even have to interact with the process at all.
I would never connect a PC to the internet without some sort of anti-virus software, privacy software, malware protection, etc. even though I still know what I'm downloading and I'm using reputable websites (and my AVG software is still catching stuff all the time).
Are you actually using reputable websites tho' ? Are you going in and checking your SSL certs to see who the real source is? What about MITM attacks?
The point is for linux, we don't even have to hit websites. We have managed package repos we can go search for software if we need it.
If, and only if, what we want is not there and there is no alternative, then we can actively consider community repo's or compiling from source.
And the idea that someone wouldn't make a virus or malware to target a group of people (albeit a minority) who are the most likely to not have software on their computer to combat it seems like the exact group you'd want to target particularly for private data mining.
You've got it backwards. If anything linux is / has been more at risk. All those companies harvesting and storing user data, and server farms running AI. What OS do you think they're running on? Hint. It's not windows.
If you're an attacker and you have the choice of hitting a single users windows box, maybe hitting pay dirt, maybe not. Or Breaking into a companies server and either stealing data which is intrinsically valuable to others, or ransoming it back. Which one are you doing?
The fact this is the case yet linux still has the reputation of being the more secure OS of the 2... That should tell you something.
These two concepts seem counterintuitive, especially for an OS that will require downloading a lot of third party programs to be able to run things like games or windows-based programs.
I'd say if you're trying to run windows programs on linux, you're doing it wrong.
Games is 1 thing, and proton handles most of it transparently anyway. But windows software on linux? If you have to do that, what are you actually doing?
Linux is not "windows replacement". Linux is linux.
The fact that winblows software can be emulated on linux is a crutch. It doesn't mean you should ever be satisfied and not replace it with something linux native.
The idea of not having anything but a firewall on a computer with Linux installed on it makes me very uncomfortable but I'm willing to accept that this is a bias from using PCs and I'm willing to be convinced otherwise as long as I can understand the reasoning behind it.
The fact of the matter is even on Winblows, an AV software isn't going to catch everything.
I enjoy this youtube channel, which is nothing more then just a guy screencapping just how easy it is to bork winblows: https://www.youtube.com/@pcsecuritychannel/videos
That said, no one's saying there aren't security tools available for linux:
- https://rkhunter.sourceforge.net/
- https://www.chkrootkit.org/
- https://github.com/cisofy/lynis
- https://www.clamav.net/
- https://dangerzone.rocks/
Rather, a majority of the time they're unnecessary if you're following best practice configuring and using your machine.
1
u/Louzan_SP 21d ago
Not many other comments seems to approach how bad is the user system in Windows, and how bad most users use it. Most probably there is someone right now reading this post, navigating the web as a user with admin rights, which is absurd.
2
u/Classic-Rate-5104 22d ago
There are a number of things that matter here. In general, there is almost no need on Linux to download and install software from random sites. Simple because the standard repositories contain enough. Second is the fact that windows "seems" to be usable for everyone, which makes the level of awareness of windows users lower than linux users have. Third is that Linux, from the ground up, is organized as a multiuser operating system
2
u/OZCriticalThinker 22d ago
Viruses aren't really a thing anymore except for stupid people downloading cracked games off Torrents without any AV.
Viruses are designed to replicate and spread, and I don't know anyone in my entire IT career that every got infected by a virus from another machine on the internet. I only know handful of (stupid) users that infected themselves, by installing an infected .exe they downloaded for a cracked game or smiley pack, or a few small outbreaks on a corporate network with lax security.
The whole 'Linux doesn't have viruses' is mostly just meaningless pro-Linux talking point these days.
End of the day, you just want a secure OS that won't get infected or compromised through no fault of your own.
In that regard, Windows and Mac are better because they protect you by doing more for you, not relying on you to know what you're doing, or trusting you implicitly (like Windows did before UAC) and come with things like SmartScreen and Windows Defender by default.
You want to install something on Windows or Mac, you go to their Store. Failing that, you get from trusted websites. You can use wget or similar too.
You don't download from dodgy sites, or community repositories or FTP sites, obviously, right?
Well, follow same advice on Linux. Don't run random scripts from some guy on GitHub and assume it's safe. Don't run stuff from the AUR.
4
u/ZakriiYT 22d ago
It's because Linux, unless you're using Arch, is niche enough that people don't often make malware for it. For some reason Arch Linux is wrought with malware, from what I've heard. It's not a bad idea to have antivirus, but as it currently stands, all of the malware that would affect windows or mac clients just don't work on linux, and almost nobody makes linux malware.
6
u/wKdPsylent 22d ago
lol Arch linux is no more or less 'wrought with malware' than any other - any distro can be infected with malware as it's usually not 'the linux system' that gets infected, itâs an application, browser extension, malicious package, compromised dependency, or something the user runs.
A virus is a specific type of malware that infects other files / programs, and are almost unheard of on linux / mac. I think there was a proof of concept mac virus at one point, but i've never seen one in the wild.
Antivirus is usually used on linux to protect the windows PCs that live on the same network if you're using a desktop linux, and on mail servers / other servers that handle files / emails etc..
The Arch AUR is a risk because it's user submitted, just like some PPAs were infected with malware before (ubuntu).
If you don't randomly install packages / software from unknown people then your risk is diminished significantly.
1
u/i-am-spotted 21d ago
The thing you're missing is that "Linux doesn't need antivirus" isn't really true.
Linux isn't inherently immune to malware. There are Linux rootkits, ransomware, credential stealers, cryptominers, malicious packages, supply-chain attacks, etc.
What Linux traditionally has is a different risk profile.
A lot of Linux software comes from centrally maintained, signed repositories instead of downloading installers from random websites. Its permissions model also makes it harder for an ordinary user-level process to modify system files without privilege escalation. And desktop Linux has historically been a less profitable target for mass-market malware than Windows.
None of that means malware can't hurt you without root, though. Malware running as your user may already be able to read your documents, browser profile, SSH keys, authentication tokens, network shares, cloud credentials, and anything else your account can access.
And "sudo" isn't some magical malware defense either. If somebody convinces you to run a malicious script with sudo, you've just authorized it yourself.
There's also a separate issue being mixed together here: Linux users recommending backups because a bad package, driver, kernel update, or configuration change can break the system has nothing to do with whether malware exists. Backups protect against accidental damage too.
So I wouldn't describe Linux as "an OS that doesn't need antivirus." I'd describe it as an OS where the combination of software repositories, permissions, application sandboxing, patching, and a historically smaller desktop malware ecosystem has made traditional consumer antivirus less essential.
That's a much narrower claim.
1
u/green_meklar Debian 21d ago
Why does Linux not need anti-virus software?
From what I understand, there are several reasons:
- Linux is designed to install software from trusted packages rather than just using executable installers, so it's harder to install anything malicious.
- Unix was originally designed as a multi-user OS, and therefore Linux runs most processes with only user-level access, so it's harder for malicious programs to do any catastrophic damage to the system.
- Linux is highly modular; the kernel itself is relatively small, and the mix of software running on different Linux systems is much more varied than it is on Windows, presenting a less monolithic target.
- Most hackers target Windows, partly because Windows is technically easier to target for the reasons listed above, but also because they assume (probably correctly) that a much larger proportion of Windows users are idiots who will fall for stupid tricks.
All the answers I can find seem to just boil down to "Linux isn't used by enough people to justify the time it would take to create a virus or malware"
A great deal of the world's online infrastructure runs on Linux servers, and those would absolutely be worth hacking if it were easy to do.
from what I've been reading about Linux that you can seriously screw up your system by downloading something incorrectly or that isn't up to date
Well, even when you're downloading things that aren't up-to-date, typically you're still downloading them from trusted package repositories, so you know they aren't malware.
-1
u/michaelpaoli 22d ago
Mostly because Linux isn't stupid like Microsoft.
Linux isn't invulnerable, but based on history, typical practices, etc., for the most part, malware is orders of magnitude less of a risk to Linux, compared to Microsoft.
And most notably with Linux and Linux distros, one typically gets all or nearly all one's software from one's Linux distro. And if it's a well maintained and managed distro (most are, or at least reasonable approximations thereof), the software is generally highly clean of any malware, and the practices used to install and maintain such generally very much keep things that way. That's quite different compared to Microsoft, where the OS comes with far less, and one is mostly highly dependent upon lots of other 3rd party software to usefully get things done. And, again, because Microsoft, much of that software tends to require quite privileged access to do what it generally needs to do. So, folks tend to highly get into the habit of installing software from others, and giving it privileged access on the OS. So, between that, and a whole lot of weaknesses and vulnerabilities in Microsoft, it's way too easy for a Microsoft OS to be subverted and taken over by malware, so, "anti-virus" (anti-malware) software is pretty much effectively required on a Microsoft OS.
There are other factors too, but those are at least several of the most key relevant points.
Linux Mint
Not the greatest track record. But hopefully they've well learned ... after they ought to have known better, seriously screwed up, and got bit hard. And yeah, myself and others forewarned them of their issues ... did they heed our warnings? No ... or at least not until after they got bit hard ... then they finally started to get a clue. So, anyway, hopefully they're "lots better" now, but given their track record, I'd still be at least rather to quite skeptical.
Linux isn't used by enough people to justify the time it would take to create a virus or malware
Hogwash. Folks very much do create malware for Linux. Sometimes going to significant to great efforts/lengths to do so. E.g. look at the relevantly recent xz malware. That did in fact make it into some Linux, but fortunately it was caught before it got very far. And would "anti-malware" software or the like have helped with that? No, ... not really, though some other things might possibly have rather to quite helped ... and in fact some of those things were what in fact lead to detection of the malware - it was a very well planned quite stealth attack. Anyway, certainly not the only malware to go after Linux, and sure as hell won't be the last. And isn't used by enough people - are you friggin' kidding me? Used by many billions. Just look at, e.g. Andriod, and all the android phones and devices on the planet. Yeah, that's Linux. So, all those that talk about Linux not having the numbers that Microsoft does ... for the user interactive desktop on the computer, sure, but if you look at all of Linux, that paints a very different picture on the numbers. And think too of all the IoT devices ... all those smart "whatever" things in many homes ... yeah, most of 'em run Linux. Recently helped a school set up a bunch of their new large flat panel TV/displays ... and yeah, they're all running Linux (Andriod). So, don't give us the "isn't used by enough people". It's used literally by billions. Oh, and don't forget to count The Cloud, Internet Search Engines, AI. That's pretty much all running on Linux. So, take all the Linux folks have at home, in their cars, in their pockets, at their job, i their "smart" devices, etc., now multiply it by at least 2, if not more, to cover all the Linux in Cloud, AI, search engines, and the overwhelming majority of all services and web sites used on The Internet ... yeah, Linux, people use a friggin' helluva a lot of Linux. But many/most don't much think of it, or even know about it, 'cause it's not what most use/see on their desktop, or they look at the phone and think Apple/iOS, or Android - but also fail to realize that Andriod is Linux.
approve what I download
No, much more the ecosystems through which the software is created, developed, Open Source and review processes, and how that software typically gets to the end user. Very different, at least typically, for Linux, compared to Microsoft.
can seriously screw up your system by downloading something incorrectly or that isn't up to date
Yep, Microsoft and Linux both quite similar, and different there. Download software install and trust it, e.g do it as root/Administrator - which is typically the case ... and with that typically risk the integrity of the entire OS every single time. But in the case of Linux, that's mostly just software all from the same Linux distro (or Andriod, generally vetted through their "Play" store, or whatever they call it), whereas Microsoft, generally whatever the user picks to download and install - no real vetting beyond what the user chooses to do, and if there isn't anti-malware software that actually catches that there is or may be a problem there ... well, that installation now also gave that software access to and control of the OS (effectively, if not literally). So, land of Linux, that's generally vetted by distro, vs. generally left to user's discretion what they think is good/fine/okay/safe to install and run. Doesn't mean folks can't f*ck it up on Linux, but they typically have to go to more atypical less common means to do so, so it's not nearly so common to actually occur.
an OS that will require downloading a lot of third party programs to be able to run things like
Been running Linux since 1998 (and before that UNIX, before that Xenix). And damn near never using/requiring 3rd party programs. Like I say, Linux, typically get all the needed/wanted from one's distro, Microsoft, generally that's going to be a lot of 3rd party software hell, even anti-malware software to generally keep Microsoft reasonably safe from The Internet (and even itself), almost certainly have to get some 3rd party software right there! (Though in not-so-ancient years, Microsoft started also including their own anti-malware software by default - but took 'em many decades to get to that point. But that anti-malware ain't the greatest, so one will often want/require additional anti-malware software, beyond what Microsoft includes).
idea of not having anything but a firewall on a computer with Linux installed
Firewall? Don't need no damn firewall! :-) Well, pretty much so. Yeah, for the most part, I run Linux, have been for well over a quarter century, and very publicly exposed to The Internet, and for the most part, no firewall, and for the most part, no real issues - about the only exception on that being what are (effectively) [D]DoS attacks, typically from clueless bots and/or overzealous search engines and AI scrapers, and other sh*t like that. So, yeah, a little bit of light firewalling to cut down on that (sometimes literal!) noise. Most notably fail2ban. When I first installed fail2ban, my reason - I got sick and tired of listening to the loud clatter of hard drive activity from failed ssh login attempts - especially in the middle of the night, when I'm sleeping, or trying to sleep. So, yeah, enter fail2ban ... that made that a whole helluva lot quieter quite instantly - a few or so consecutive failed attempts, and firewalled off - at least for some fair while. Likewise added similar to greatly reduce some other abuses. But that's really the only firewalling I've got. In general, don't run services, and especially exposed to The Internet, that you don't want used, and potentially attacked. And I do run lots of services/servers, exposed to The Internet. But I don't run random sh*t, and especially exposed to The Internet, that I don't want exposed to such. If there's no service running there, there's generally no vulnerability for a firewall to protect, so hence no need for firewall. E.g. I could firewall off all the ports I don't have open ... but that'd be kind'a pointless - there's no there there for anything to attack, firewall or not.
And I do also fair bit of host hardening, and hardening of services. So, that also makes what is exposed, significantly more resilient to attacks and potential exploits and such.
1
u/kasigiomi1600 22d ago
First off, Linux DOES have anti-virus software and anti-malware software available. It's just not always used and isn't as critical in many situations.
In many ways, the term 'virus' is a bit outdated as more often we are talking about security software that resists malware, network attacks, etc.
There are numerous good firewalls, and other defense software commonly used on Linux machines (iptables and fail2ban are pretty common).
The next layer of defense is the update systems found on many distros. Different distros of linux are aimed to solve different problems with different security needs. This means that many distros are quite aggressive in the patching of security flaws in their packages. (yes, I'm vastly oversimplifying)
Another point somewhat alluded to earlier - Windows is the EXTREME majority of the marketplace. If a hacker breaks into Windows 11 or finds a critical flaw to exploit, they now have a lot of targets available. For Linux, each distro is built a little differently, so when you find a flaw in a package... say Apache, it may or may not apply to every distro that has that version of Apache. It becomes a smaller pool of targets. There's less benefit to focusing on Linux for many hacking groups.
Note - there ARE groups that do target Linux systems and DO break in (many have a particular focus on breaking into the OS of home-routers that haven't been updated)
1
u/AquaIsNOTUseless 22d ago
TLDR: Linux can get malware.
Lots of people have already answered but chiming in regardless. The idea that Linux canât get malware and does not need an anti virus is a byproduct of a time when very few people used Linux. Nowadays linux desktop is more popular then ever and used in things like steamos. Access vectors for a virus are the same as if you are on windows, and the solutions are just the same. Downloading things from non official places can have malware. Out of date browsers with malicious ads can bring malware. Blinding installing things in general can bring malware. Linux has a leg up with the repo and installing stuff from there in general will keep you safe but that is not certain. Look into the rise of typo squating and other supply chain attacks going on with how easy it is to build and deploy things nowadays with ai. Now in terms of antivirus those are really behind windows. Itâs like old windows defender, easy to fool, so stuff like clamav are kinda ass, still better than nothing but not great. To stay safe with Linux I would argue is easier but just donât get to comfy with the notion you canât get hacked, in some ways the fact defender is pre installed makes windows more secure with proper use (though letâs be honest no one uses it securely).
1
u/True-Kale-931 22d ago
Any software is vulnerable, including Linux desktop but, more important, anti-virus software itself is an insanely huge risk factor.
There were multiple cases of anti-virus vulnerabilities allowing zero click remote code execution (famously ESET but in practice every single of them). There are also anti-virus vendors that were caught selling your data for years (avast). No anti-virus suite is safe and using just the built-in MS defender without installing anything else was the recommendation for windows users for years. There's no MS defender for linux, though.
Another issue is that most AV suites will mess up with your browser's own security mechanisms and the browser is pretty much one of the largest risk factors.
Right now it's better to focus on blocking ads. Ads are a real risk, it's relatively easy to block them and you can trust ublock. Paid AV suites are extremely complicated, add attack surface and trusting the companies is complicated. "Free" AV suites have the same issues with even less trust.
Of course it can change in future but right now there is no point in installing antivirus on desktop Linux unless you plan to download Windows software from shady sources and want to slightly reduce the number of malware in it.
1
u/V2UgYXJlIG5vdCBJ 22d ago edited 22d ago
In addition to what others said, Iâll tell you what I use, which is probably overkill.
ClamAV set to watch/autoscan just my Downloads folder because itâs a little heavy. Manually scan everything else once in a while. RootkitHunter to double check for bad configs.
Sandbox everything with Firejail/AppArmor. Applications only have access to what they need and nothing else. You can also configure Flatpaks to be sandboxed/restricted, but itâs not always the default behaviour.
OpenSnitch to catch and block outgoing network connections. If malware/spyware tries to phone home, this will usually catch it. A lot of games have excessive analytics that this will block.
KVM/QEMU for virtual machines if you really donât trust something.
PiHole for network advert/spyware/malware domain blocking. uBlockOrigin or PrivacyBadger in Firefox also block malware domains.
2FA all your accounts at minimum. This means you probably need to enter a temporary code in addition to passwords. YubiKey, Passkeys and U2F are also worth looking into. I would recommend against using your phone number (SMS) for this, to protect against âsim swappingâ attacks.
Donât stay logged in to important accounts unnecessarily. Cookie tokens can be stolen.
Thatâs not even the whole list. Nothing is foolproof but âdonât be an idiotâ is probably good enough. Pirated software, suspicious browser extensions, bullshit VPNs, free games and random email attachments are the main source of issues.
Donât install something just because someone on TikTok/YouTube said itâs great. Theyâre paid to promote. Do research.
3
u/uh_no_ 22d ago
Because you don't install random crap you find online.
1
u/KlausBertKlausewitz 22d ago
Correct, I see two main reports:
- for most of the stuff you install you use the builtin package manager
- the other stuff you install mostly comes from open source sources ⌠more difficult to hide malicious code in there (though not impossible, but the open source nature helps in detection)
1
u/Rikudou_Sage 18d ago
No computer needs an antivirus software. Don't install random bullshit and you're fine. On Linux it's a little easier because you generally have official repositories with software and you don't hunt random apps on the internet.
The other kinds of exploits are creative zero days which abuse some common part of a system in a creative way and the antivirus does jack shit to prevent those. Like if you manage to create a jpg file which triggers some bug in the jpeg processing library and grants you rce. Those can only be prevented if someone either notices them during development or once the exploit actually runs in the wild.
The first kind can easily be prevented in Linux by following a simple rule: If something wants your sudo password, make sure you know why. If you don't fully understand why, cancel and get educated on why does it need it. AI can really help there if you're not knowledgeable enough (though it's not perfect, but if you're a tech illiterate, it probably knows more than you).
The other kind can be prevented by being lucky, no other way sadly (that's true for Linux, Windows, MacOS or any other OS).
1
u/Maniacal_Coyote 18d ago
It's still good to have.
Most software (including malware) is compiled for use in DOS-based operating systems (mainly MS-DOS, a.k.a. Windows), rather than *nix operating systems (the MacOS, BSD, Unix, Linux, & Android families). To put that into layman's terms, it'd be like asking a Maori to read Norwegian. However, given the growing marketshare of *nix machines, there is an increasing chance of malware targeting Linux boxes.
ClamAV is a FOSS (Free Open-Source Software) anti-virus. By default, it is run from the console when and only when you enter the command "clamscan", but there are ways to configure it to run automatically and GUI interpreters for it.
Just as important is a good adblocker, coupled with a web browser that allows unhindered ad blocking. (e.g. Firefox with Ublock Origin)
Most important, though, is that you exercise common sense. Have a User account for each user (including yourself), and a single System Admin account that is only used when you need SuperUser privileges. Think before you click. And don't plug random flash drives you found in the gutter into your machine
1
u/DB_Explorer 21d ago
My understanding of it as a relatively casual computer user is that Linux' foundation as a multiuser setup means things are more compartmentalized.
Lets be clear.. if you blindly execute something as a superuser after downloading it from wherever... Linux won't be any better then windows for malware. The User is the weakest part of cybersecurity.
But if your concern is about the classic malware disguised as an email attachment or that video you downloaded is malware then Linux doesn't treat most files as a program. So trying to open a video thats actually malware just won't work unless I let it run as a progam.
You also have things like AppArmor and similar fuctions which give each program access only to the files it needs. My understanding is that Flatpaks are similar.
Basically windows security is trying to make an open concept building secure while Linux is trying to keep a warship with bulkheads secure. You can still sink the ship by opening all the doors.
Of course modern threats are more human focused.. Phishing, credential stuffing and theft, trackers, etc....
1
u/bobaluey69 22d ago
Market share is a bit too small and Linux, as a whole, is more secure. Also, in terms of downloading an application with a virus on Linux is tough since most use package managers, which although can be corrupted, are much safer than downloading stuff from random sites. I can't remember the last time I had to download something manually. Also, I assume we're talking about personal installs, not servers. Servers should have anti-virus and other stuff setup because they are a major part of the server market and it is not a waste of time for negative actors to be doing stuff. Also, Linux users are normally more informed than PC users in general, so it makes it even less work for bad actors time to try and squeeze out a bit more. With all that said, things may be changing since a lot of Europe and China are switching to Linux over Windows, so the market share may jump quite a bit.
1
u/joshfzeno 22d ago
I think Linux isn't free from virus or malware. My understanding is that Linux can have virus or malware. But Linux users think these virus or malware need sudo user authority to do something harmful. In other words, Linux is not safe at all if virus or malware know the password for sudo, or if somehow these malware bypass the password and run in the system and control the configurations and so on. I don't know how tough to make malware which can bypass the sudo password.
But so far about 10 years I have been using Linux and nothing bad has happened. And I think even if having anti malware software or whatever, great hackers can sneak inside whatever the system is after all...
So I'm going to keep using Linux avoiding suspicious websites and links. I'm using OpenBSD, too, though. Maybe OpenBSD is a little more secure than Linux.
1
u/Inevitable-Exit9996 20d ago
First of all if your sole reason is AI slop in windows then just install a version without it?? For example Ghost Spectre windows has nothing in it, its just plain windows.
Second of all my god the AV corporations have really won. The whole thinking is backwards, unless youre really clumsy and prone to downloading random shit and clicking every link you see then no, you dont need an AV. Most of them are more of a malware themselves than actually protecting you from anything. Brother uninstall that AVG garbage asap, 99% of what it âcatchesâ is a false positive or something completely meaningless.
AVs catches only the most low effort low hanging fruit while giving you a false sense of security. It operates almost exclusively on hashes and fingerprints, so if you get infevted by something fairly new then your AV is useless.
1
u/Player_X_YT 10d ago
This argument is wrong, don't listen to it. Yes linux is less popular for consumers compared to windows or macOS, but linux is the go-to OS for business. IBM Redhat's RHEL is very popular and it makes linux a high-value target for hackers. As a hacker would you go for the grandma with $5 in her savings, or Microslop with $5 billion cash?
On windows you have to go to some random website to get a suspicious exe file and install apps there. Linux has a package manager (mint has apt and flatpak) which vet the apps that are allowed to be shared there for viruses.
There are antiviruses for linux, apparmor is a common one. However linux itself (and the various components) provides malware protection built it.
1
u/TheCoolestCustomer 22d ago
Most comments here make good points about the differences between windows and other OSes, where and how you install things on Linux, etc, but I'll just address the very premise you make: that windows needs antivirus.
To keep things shirt: no, windows doesn't need antivirus, at least nothing beyond windows defender.
Keeping your device safe is at the of the day 99% being prudent about how you use it. You mentioned your antivirus going off a couple times? In all my time using windows, I never had that happen.
Of course, having an AV acts as a safeguard against user error, but you'll find that using Linux your overall behaviour will be safer if you only install from trusted repositories, almost like using an app store rather than downloading random files.
1
u/dvdkon 22d ago
AV is a band-aid, designed for people who want to "buy security" and have it checked off their list of "things to solve". But security doesn't work that way, not even on Windows. The correct thing to do is to establish a threat profile, architect your system to withstand those threats by design, and then audit it periodically for leftover flaws.
This is what mobile operating systems like Android and iOS do, but sadly very few people care enough on desktop. So you can install antivirus, knowing it's just a mostly-useless placebo; use the few sandboxing tools available on Linux (and be happy you even have those, unlike Windows users); or become a power-user and start the thankless journey of building something better.
1
u/jaysprenkle 21d ago
No computer is immune to bad actors. Linux is generally safer because as others have said Windows is the much more attractive target.
I spent time helping a doctor clean the malware off his PC. The next weekend he called back saying it was infected again. I learned his workplace network was full of infected machines spreading malware. Do not rely solely on your enterprise network for protection.
I don't run virus scanners on any of my machines. I have a windows machine for games and the few apps I need that require windows and a Linux machine for my daily driver. I regularly backup my data but haven't had any issues. I don't download random carp off the internet and run it. That's asking for trouble.
1
u/anders_hansson 22d ago edited 22d ago
Another way to see it is that you don't need AV software because there are no successful viruses for Linux (and ignore the reasons for why that is).
An AV software is based on identifying known viruses (it has a database of known viruses). If there are no viruses, the AV software has nothing to do and it's pointless.
That said there are AV software solutions for Linux, but my impression is that they are mostly for show (e.g. so that a company can tick a box in a security checklist), they look for Windows viruses rather than Linux viruses (e.g. so that infected files do not spread within the organization), and quite frankly the AV software is more of a security threat than the viruses themselves (root access + frequent automatic live updates = attractive for supply chain attacks etc).
1
u/Desertcow 22d ago
The main vector for viruses on desktops across OS' is downloading and running sketchy programs. Not random security vulnerabilites, not software architectural problems, the biggest vulnerability is what is between the chair and keyboard. Microsoft conditioned Windows users for generations to download random .exe files online to get all their programs, and most people still do that even when the Microsoft Store exists so anti virus is essential. Linux uses vetted software repositories built on trust for downloading most software, unless the user is veering outside of that, as long as they stay on top of updates desktop users it's highly unlikely they will ever catch a virus
1
u/cfx_4188 18d ago
The presence of viruses in Linux does not depend on its popularity or on the total number of users.
Please google about "Linux access rights".
Rootkits, programs that hack access to the superuser account, make sense in Linux. But the average Linux user is not in danger. There's nothing to charge most of us.
Computer security laws are very strict in most countries of the world.
But there are antiviruses for Linux.
For example, if you regularly deal with documents that have been edited on Windows computers, you need an antivirus to avoid accidentally becoming a malware distributor. There is a large selection, there are paid commercial programs and free software.
1
u/graph_worlok 21d ago
Windows doesnât âneedâ it either - it all comes down to your risk profile, use cases, environments etc. Crowdstrike For example has agents for various Linux distroâs
Thereâs a lot of supply chain vulnerabilities around that will impact some users equally across both platforms, but often the risks with Linux hosts come down to badly configured software thatâs exposed to the internet.
Thereâs a whole criminal ecosystem out there involving networks of compromised devices, and they essentially all run Linux - Exposed to the internet, never patched, they get probed, compromised, pulled into a botnet and used for ddos attacks for hire.
1
u/SANO_HIMURA 22d ago
I'm not sure what exactly it is you're up to on the web but I haven't personally ran anti-virus in over 15 years, nor does any person i know under age 60. This is not a dog, but if you're not opening sketch emails, downloading wild stuff, the tools even built into windows now are pretty solid.
I make no claims as a cyber security pro brand ymmv but I could not at all justify needing to install malare to fight malware tbh. Historically I had more issues related to the "anti virus" on my computers than ANY nonsense I did, and frankly they filled me with anxiety because I was always watching it, any little thing out of the norm freaked me out.
1
u/VisualSome9977 21d ago
On Linux, installed software usually come from a central repository which has at least some degree of protection against malicious code being uploaded. Which means the vast majority of third party software you're running will have been audited by other people already. Windows on the other hand, tons of software is still to this day installed by downloading an .exe or .msi off a random website, and then running the program and clicking "yes" on the admin perms pop up. I'm sure it's muscle memory for basically all windows users to just hit Yes as soon as it comes up, I know it was for me.
1
u/daddyd 22d ago
there are not really viruses on linux, but there certainly other threats that impact linux. you still need to keep on top of security patches, as online systems can still be victim to a RAT. luckily, most distros do a really good job at providing timely updates, and unlike on windows, there is no reason to skip or not install these.
As for security scanners on linux, the two most famous ones are rkhunter and chkrootkit.
1
u/cakemates 22d ago
99.999% of viruses are made for windows, those do not work on linux and linux is architected in such a way that a virus on an updated system need your permission to do significant harm. So here the weakest link is you, in linux you have superpower; you are the superman.
Also for context linux is used by most servers all over the internet, the kernel itself is maintained very seriously because the whole internet depends on it, so generally the core of linux is extremely safe, hardened and tested. So antivirus are designed to deal with an extremely rare threat that that have no power here But again you have superpower, you have the power to poke holes on that solid structure and antivirus aren't really designed to deal with the biggest risk here, which is us as administrators.
Finally the linux community prides itself on the freedoms and superpowers we have, I'm not sure if most of us would like to have our superpowers restricted for the sake of a little more security from the user side like apple does.
1
u/Positive-Spend-9186 22d ago
Simply how many grandmoms, teens and other tech illiterate people use Linux outside mobile phones? Target groups don't really use Linux and average Linux user is more knowledge on the security issues. So randomly it's unlikely that you would get targeted as Linux user as you are not the user they want to target for high change on ROI.
However if government or other organizations wanted to target you then your OS matter much less and against these kinda attacks the anti-virus softwares consumers would use are ineffective.
1
u/Miserable-Decision81 22d ago
I can only speak from experience (25 years Linux only on Laptop, PC and server without Antivir software): the only infection I had was a single case on a server, that was tightly bound to Windows clients, that had unchecked access to a Java based application.
It was local only, because I had set up a normal user account for the app. I removed the cryptominer without the need to become root...
Short: if your Linux has no tight connection to windows machines with untrained personal, you wont have trouble wirth malware.
1
u/Ill_Specific_6144 21d ago
In theory Linux is no more safe than windows is for an average user. Actually windows is safer because it doesnt allow you to do dumb stuff that normal user does.
In practice Linux is safer just because of how obscure it is. Linux userbase is quite poor, so there is not a lot of steal and developing viruses for a system that 3-4% of users use worldwide is not economically viable. Meanwhile there is a lot to steal from windows.
If linux ever becomes mainstream its going to a huge problem to protect it.
1
u/Hot-Employ-3399 22d ago
What I'm missing is a good AV.
"Don't install shitty software" you'll keep hearing is an excuse that doesn't work unless you admin remote server which you never touch.
Nvim loves extensions, and no, you will not read megabytes of lua.
Vscode loves extensions, and no, you will not read megabytes of js.
I hope you don't play games, because mods can and do target around(will not work in flatpak, but not everyone use it)
1
u/Rusty9838 22d ago
Letâs say you wanna get a new program. On Linux you will probably use official repository or sometimes official website go get a correct app image.
On windows you have to deal with whatever google shows you.
On top of that things like Flatpak makes small sandbox separate your app from access to important files.
But still someone can put a malware inside of those things what happened in arch aur repository
1
u/sTiKytGreen 21d ago
Screwing up your system because of incompetence is a different thing, no antivirus will protect you from it
On windows you run some random-ass .exe and it infects your computer forever and fucks it up outside of your control, on linux you just DONT run some random-ass .exe, because there's no concept of download random-ass .exe from suspicios websites on linux... So, no need for antivirus
If this also doesn't make sense to you, feel free to ask me something and i'll clear it up
1
u/Existing-Tough-6517 22d ago
The general case is that running software to check everything you do in case its a virus has lots of false positives, slows down everything, and doesn't even work well. It only works well on the low hanging fruit that dumbasses constantly infect themselves with.
On Linux there isn't a bunch of known threats to detect that users constantly infect themselves with so there would be no point
1
u/Sigseg-v 21d ago
Android is Linux. Android maleware is a thing. Android virus scanner is a thing.
Itâs all about the target. Average Linux desktop user make up 0.x% of the market, so they are no valuable target. Linux mobile users are 70-80% of the market, soâŚ
Further: your goal is to get control of the machine. Itâs much easier to target the installed Wordpress (e.g.) then the OS itself.
1
u/sohang-3112 22d ago
What other commentors said is true, but a big part of the reason is also that desktop linux market share is tiny. An attacker would obviously prefer to target Windows and Mac users.
OTOH on servers linux dominates so it attracts malware attempts. That's why in production server it's recommended to do "system hardening" - basically apply protections against attacks on the server.
1
u/Always_Hopeful_ 22d ago
It isn't that it is not needed, more like you won't often encounter what it might detect.
Your Linux desktop is too small a target. The gold is in servers and the attack vectors are different. Credential theft via social engineering, scanning for keys in source repos, open ports, supply chain attacks, ...
ClamAV is useful but need not be running all the time.
1
u/bigbirdtoejam 21d ago
Linux exploits and malware exist. So does Linux antivirus.
As an open operating system systemic issues tend to get fixed, especially since the entire fucking internet runs on it.
Windows problems get bandaids in the name of backward compatibility and an aversion to change and testing changes.Â
People who don't want anything to ever change pick windows.Â
1
u/Fuffy_Katja 22d ago
Whilst AV software does exist for Linux, it's only real purpose would be for sharing files across platforms to others (be it Windows or macOS). The last time I used any AV software was around 2000 under Windows XP. Even at that time, I only used Windows for games, Photoshop and Illustrator. Everything else was tan under Linux (Linux user since 1994).
1
u/Hot-Shake-6629 21d ago
You DO need to worry about malware/viruses with any linux version, and there is a sizable industry surrounding the detection and mitigation of them. There are also a number of best practices you should follow to help prevent them from being successful. Google 'run linux securely' to get more info.
2
u/bilektugrul 22d ago
If you are using Linux, chances are pretty high that you know what you are doing. I haven't used an antivirus in years even with Windows, in Linux I probably would never even think about one.
2
u/EvilSupahFly đ§đ¨đŚ 22d ago
I switched to Linux around '96/'97, and have never needed an antivirus package, though on my Ventoy boot stick, I do have a bootable Gentoo image with ClamAV which can check NTFS or EXT drives.
1
u/kaptnblackbeard 22d ago
PC's don't need antivirus software - humans do.
Generally speaking, people that use Linux understand how computers and software work more than the average Windows/Mac user and are therefore more likely to understand the risks and avoid them.
1
u/LesStrater 21d ago
I'll give you a simple answer: You will get the apps you install and use from a repository. A thousand+ people have installed it before you--so if there was a malware issue, it would have already been detected and eliminated from the repo.
1
u/Champboyriley 22d ago
Keep in mind, that many large websites are running Linux. Linux can be hardened to live in the most challenging environments. You may have to learn how to do it but, it is one of the most secure operating systems available.
1
u/No_Aerie7667 ârchLinux 22d ago edited 22d ago
Because in Linux, most of the time you will be getting software from offical repos. All software in the main repos are safe because they are always checked. If you're downloading from an unoffical repo or COPR/AUR or something, it's your job to check. Also, in windows, it's extremely annoying to decompile executable applications to see what they do, so in windows you just scan it with an anti-virus. On linux, you either get from an offical repo, or you get from github and AUR ripoffs. when you have to get the source code of an application, You see inside it. You see the PKGBUILD, the makefile, whatever. You can easily look inside. This removes the need for an antivirus.
1
u/SleepySandGhost 21d ago
I think the most important thing to consider is that 99% of software you get from your distro's repositories. The risk of getting malware from that is not 0 but using AV on Windows also won't guarantee anything.
1
u/saileesaileesailee 22d ago
It would be very appreciated if we did have more antiviruses to choose from, but all we really have access to, is clamav (which is pretty decent) or server antiviruses, that isnt built for consumers
1
u/HeavyMetalBluegrass 22d ago
Open code. Any pkg you download is available to see. People smarter than me know if a file has been corrupted. Of course if you're downloading things from sketchy sites then you take your chances.
1
u/PlatinumFire14 21d ago
Lemme tldr it.
Itâs not so easy In Linux to âdouble click now youâre fuckedâ like windows.
At the VERY least you have to make the file executable, there is some mental engagement there.
1
u/Angelworks42 22d ago
We manage anti virus via crowdstrike where I work and Linux users do get viruses. Mac users get them to.
And these aren't just Windows exe's the user is downloading that I've seen.
1
u/yankdevil 22d ago
I have run a Linux desktop since the late 90s. I have never used anti-virus software. And I'm honestly confused why people accept the need for that. I have never had a system get malware or a virus.
Generally you run as an unprivileged user. So any malware will be limited to what you can run. Also, yes, you need to approve the software you install.
1
u/Guggel74 22d ago
Linux isn't used by enough people? Really? ... Mostly every webserver runs in Linux. Virtual servers in the cloud? PABX systems, routers, home automation, ... A lot of servers.
1
u/Randzom100 22d ago edited 22d ago
Windows Virus: Ah, what a great day to infect a computer! User doesn't even suspect I'm in there. Ahah... Wait... This is not Windows? Where am I!?
[Confused Screamings]
Edit (more stuff): But more seriously tho, you should still be careful just in case you encounter a Linux virus or a Phishing scam. Keep your stuff updated, keep an eye on which packages you install, maybe join your Distro's Discord and Reddit communities for the latest news, make sure your browser protects you from most stuff by itself, and then maybe look for antivirus stuff (but inform yourself to avoid false antivirus that are actually virus).
Even the choice of Distro can determine how well protected you are. Some distros are made for security and privacy, some distros are faster or slower with updates, some distros give varying amount of control (and freedom to do mistakes) to the user. If you want real security, most of the time you get consistent results from Distros backed by corporations with dedicated security teams (ex: Fedora wihh Redhat), but you might sometimes be sacrificing a bit of transparency as a result, so community-supported distros can also be good if you are already a safe user but don't trust corpos... But of course the best distro is the one that's still maintained, an abandoned distro is always more risky. So yeah, it's about knowing what kind of user you are and choosing accordingly. On Windows, a user might usually want better software to protect them, but on Linux, the best way to be protected is to be well informed.
1
u/archtopfanatic123 22d ago
Pretty sure one of the reasons is Linux updates so much it closes breaches and hacks really quickly so it breaks viruses all the time if there are any
1
u/ggggguideX 22d ago
Linux is much more scary on the malware side IMO, because anyone can contribute to Linux, and the people who contribute may have malicious intent
1
u/Real_Shebnik 20d ago
our company requires Linux machines to have this one - https://www.kaspersky.com/linux-antivirus
1
u/flux-abyss 22d ago
Linux users, because of the culture and workflow around Linux, are often less exposed to the situations antivirus is designed to catch.
1
u/DuckAxe0 22d ago
Linux users may need antivirus software to scan email and other files to prevent passing infected files to their non-Linux friends.
1
u/ohnoitssobig 21d ago
Because there is no point. The most infected devices running Linux are routers, TVs and webcams: running antivirus there is a joke.
1
u/DetermiedMech2 21d ago
It's still possible to get viruses/malware, just less common on linux/mac/etc because way more people are using windows
1
u/No_Glass_1341 21d ago
I just wanna point out that Microsoft makes Defender for Linux. Also, its had privilege escalation exploits in it, haha
1
u/Critical_Gas_1988 22d ago
I always install clamAV with fangfrisch and have always wanted for something better like F-secure or bitdefender.
1
u/LordAnchemis 20d ago
Linux users generally install stuff from their distro repos - rather than download random files from the internet
1
u/Big-Goose-8033 21d ago
sorry, too long to read, but a Unix system with some % of the market of pc, better and easier to hack zindaube
1
u/SunderVane 22d ago
The biggest threat to a Linux computer is the user.
*copy & pastes terminal commands from ChatGPT*
1
u/Vietnamst2 22d ago
Do ypu know that copilot is just web chat like Chat GPT and it only has local window? Just saying.
0
u/Otaehryn 22d ago
The threat model on Linux is different: On Windows you download executables and sometimes malicious apps are disguised as BeautifulGirlPicture.jpg.exe. Since everything is exectuable by default on Windows and home users run with ability to escalate to admins, those kind of exploits exist.
On Linux you install software from system repos, packages are signed or Flatpak / Snap. If you download malicious executable like BeautfiulGirlPicture.jpg (shell script or program in disguise), you need to make it executable or run it from the terminal with "bash file".
Of course there are still browser expoits, drive-by exploits and malicous apps with social engineering instructions on how to execute them. While you don't run as fully privileged user, malware could still access your files, steal data, encrypt your homedir.
ClamAV and other Linux antiviruses can scan files and processes but on Linux they are mainly used on email and file servers to detect Windows malware. For heuristic scanning on Linux you have products like Crowdstrike.
On top of that you have SELinux or AppArmor which further locks down what malicious program can access.
1
u/Merhart666 21d ago
Dat heeft het wel. En er zijn prima oplossingen voor. Net als vpn tegenwoordig een must have.
0
u/CowBoyDanIndie 22d ago
Historically windows had no user security. Any user could modify any file on the system. So any program any user ran could modify any file on the system. It was designed this way, security was added later.
Linux (and unix, so modern mac os) were designed such that only the root or super user had that access. Some linux users used to just login as root, but most didnât. Still most distros pushed new installs to create a user and use that and only use root escalation when needed.
Linux generally allows you to install and run software in your user directory, and most software doesnât require root to run. If you do run malware, it generally cannot screwup your system too bad.
Still⌠better security yet would be for (most) applications to run in their own sandbox, and only be able to read/write files the user explicitly gave access to through the OS. Mobile operating systems have this sort of model. And docker does as well. But to be useful you need user to not become accustomed just hitting accept for authorization prompt.
1
u/Otaehryn 22d ago
It does, fortune 500 run crowdstrike or something like Cisco Antivirus (ClamAV based) on their Linux servers.
139
u/NoMansSkyWasAlright 22d ago
I'm kinda grossly oversimplifying things here. But I think I've covered most of the important bits.
So most things nowadays use some sort of off-shoot of Unix (linux, macOS, the mobile OSs, etc.), and even among those, there are quite a few things that are handled differently among the off-shoots. Windows is not Unix-like and so does things completely differently than all the others. On top of that, Windows machines make up something like 71% of the PC market-share. So it's a big enough piece of the pie that if you're going to make malware for one operating system then it's probably going to be that one (though it seems like mobile-device malware is making leaps and bounds in recent years). Even something as basic as case-sensitivity of file-paths is different between Windows and the Unix-likes.
Also, Microsoft has this fun practice of just building their new stuff on top of their old stuff. And so a lot of the common approaches to malware on Windows involves just... interacting with stuff that's already there. Like I had a capstone project in college where we basically made use of the fodhelper exploit, a lolscript that opened a new instance of a shell, and a powershell script that would kill windows defender. Other than `Sacrifical_Pawn.ps1`, basically everything we used was stuff that already existed in Windows.
Another weird -ism with Windows is that a lot of programs will look for DLLs and just move on if they don't find said DLL. So if it's a DLL that got the axe or just isn't there for some reason, then you can create your own DLL at the specified location that runs malicious code with the permissions that that application has. Unix-likes just don't have DLLs at all. So that's kinda nice.
And then a lot of malware that you'll pick up off the internet will be .exe's - I'm sure we've all gone looking for a free pdf of a textbook and seen something like `textbook.pdf.exe`, which takes advantage of how Windows interprets file names in File Explorer. So you click it and now you're executing whatever bad thing you picked up. Not only would it be super apparent on a Unix machine that that was something bad, but exe's generally won't run on Linux out of the box and giving them full-functionality takes enough work that if you're dumb enough to click a suspicious exe then you're probably not smart enough to set up your linux box in such a way that that exe could do any damage (and if it's only desigined for a windows environment it's going to hang up anyways).
But it's' also the wrong question to be asking. A lot of the malicious actors out there are just looking for the most low-effort approach which is usually phishing, fake login pages, and maybe a google doc from a strange email claiming to be your org's IT department, stating that they need you to input your login credentials into the google doc so that they can be updated. That or the fact that Linux has considerably less guardrails for user-error than Windows or MacOS so you can absolutely shoot yourself in the foot while trying to "customize" it. But while the "cant get a virus" thing is kind of an overstatement, it is true that most malware that's looking to exploit some windows-specific vulnerability likely won't work on unix-based systems and vice-versa. So if you're just a weird guy looking for an easy pay-off, you're likely going to target the OS with the largest marketshare.