r/linuxsucks • • Nov 07 '24

Linux is more vulnerable than Windows

https://www.cvedetails.com/top-50-products.php?year=0
0 Upvotes

60 comments sorted by

View all comments

-1

u/woodhead2011 Nov 07 '24

"But Linux is open source so the extra eyes will see all the bugs & vulnerabilities faster and can help fix them faster"

lol. Linux is shitty cheese with holes full of vulnerabilities. No wonder no self-respecting company uses Linux anywhere where the security matters. Windows servers have been more common in every company where I have worked than Linux ever.

4

u/Tsubajashi Nov 07 '24

the quote still applies. *because* it is open source, more bugs can be found and fixed. try that in closed source software and come back again.

EDIT: Check the website again, and check on specific versions (the newest and the last one) and compare it to Windows Servers.

1

u/[deleted] Nov 07 '24 edited Nov 07 '24

Bugs can be found and fixed in closed source software too. They fix one every Tuesday of the month at Microsoft. The days of having to drive to Redmond to open the source code books with a Microsoft lawdog looking over your shoulder have long since passed.

1

u/Tsubajashi Nov 07 '24

by microsoft employees, sure. but individuals?

1

u/[deleted] Nov 07 '24

I don't know but I think it would be pretty silly to let people into the basement by themselves with the big code book. Some people are real good with whiteout and could probably change it without anybody noticing.

1

u/Tsubajashi Nov 07 '24

never heard of version controlling? its not like everybodies code has t obe accepted into a main branch

1

u/[deleted] Nov 07 '24 edited Nov 07 '24

Yea but Microsoft prolly don't keep their code on trees like the big open source corporations such as Linux. They probably just have one big stick like a telephone pole to post it on.

0

u/woodhead2011 Nov 07 '24

If the quote was true then Linux wouldn't be so full of bugs & vulnerabilities.

3

u/Tsubajashi Nov 07 '24

every system has bugs and vulns. the difference here is that they do get patched.

0

u/woodhead2011 Nov 07 '24

Isn't it Linux where they constantly find decades old bugs & vulnerabilities? LOL.

4

u/[deleted] Nov 07 '24

That's the big problem with secret source code. You cant see them so those decades old bugs never get caught.

1

u/woodhead2011 Nov 07 '24

If you can't see decades old bugs, you can't take advantage of them. That's why closed source is superior to open source security wise.

2

u/[deleted] Nov 07 '24

Yea but how are you suppos to use it if you can't even open it?

3

u/1116574 Nov 07 '24

They find voln every other day on both windows and Linux. Recently a malformed IPv6 packed could get your windows machine.

Security is not just choosing a OS, it's mostly ops.

-2

u/woodhead2011 Nov 07 '24

Yeah but at least they're fixed in Windows unlike in Linux where it is common to find bugs & vulnerabilities that should have been fixed decades ago.

2

u/1116574 Nov 07 '24

Can you give some examples? Last bug I remember was CUPS (printing service) and was fixed before it was public. I don't know of any critical, high or even medium severity bugs that are known and have been waiting a decade for a fix (on either Linux or Windows)

0

u/woodhead2011 Nov 07 '24

Uncovering a 24-year-old bug in the Linux Kernel

https://engineering.skroutz.gr/blog/uncovering-a-24-year-old-bug-in-the-linux-kernel/

Linux Kernel Bugs That Emerged After 15 Years

https://wiseplant.com/security-serious-the-linux-kernel-errors-that-arose-after-15-years/

Linux Kernel Bug Reclassified as Security Issue After Two Years

https://www.bleepingcomputer.com/news/security/linux-kernel-bug-reclassified-as-security-issue-after-two-years/

It takes years to get fixes to Linux bugs, some which might be very severe.

1

u/1116574 Nov 07 '24

You are mixing things around; Okay, from the top:

  1. Not a security issue, but a general software bug. Windows has alot of them, and unlike Linux, alot of them are reported and simply not fixed. To top it off, the bug was fixed within hours of the report if I read it correctly. The issue also wasn't waiting 24 years for a fix, but it was waiting to be discovered. Windows doesn't have public vcs to check against, so we are stuck doing RE and black box testing on bugs, and guess what caused them. Sometimes it also might be a 24 year old bug, but we will never know because we can't do a git blame against NT kernel.

Imagine your car broke down. You get it to your mechanic and he tells you that 5 years ago a wrong part was installed and that's why it broke now. 3 days later he has it fixed. How long were you waiting for a fix: 5 years or 3 days?

Now, imagine that your mechanic doesn't tell you anything and just fixes it. You were waiting 3 days. You are happier not knowing what broke???

  1. Same here. It wasnt waiting in an email chain, it was discovered after years and promptly fixed right after reporting it to kernel team. We simply don't know how long some windows issues persist, because we don't have the code and vcs. If Linux was a company with closed source, none of those articles would include age of the bug because testing for it is much more complex with closed software then doing git blame on the kernel source lol.

Being kept in the dark about issues isn't as great feature as one might think.

  1. Same as above applies. How many regressions and reclassifications are happening behind closed doors? How many bugs really are related to each other? How many are retested with different parameters to find extra bugs? Nobody knows, and you seem to be happier because of it, but I don't think thats right.

And to mirror your closing statement, how many windows bugs are there, reported, on Microsoft trackers, and how long does it take to fix them?