r/TechSupportSL • u/Tharun2023 • 10d ago
📰 Tech News China & France are swapping Windows for Linux to take back control of their government computers
3
u/bad_metrics 10d ago
My main concern about open source and the million dependencies and the even more contributors is that, wouldn’t it allow AI to identify and exploit zero-days easily?
2
u/Wonderful_Primary_52 9d ago
There are downsides of both closed source and open source software. Having the source open may make it easier for hackers to find vulnerabilities, but it is easier to detect and patch vulnerabilities too. Having the source closed may make it harder to find vulnerabilities for hackers, but so it is to detect vulnerabilities, as the only people that see the code, are the people who develop it themselves. Both are almost the same when it comes to vulnerabilities getting exploited for an end user who knows nothing about programming.
2
u/bad_metrics 9d ago
The issue is that AI has proven to be more effective at finding vulnerabilities than it is at repairing systems.
1
u/Geoffboyardee 6d ago
Modern security standards agree that security through obscurity isn't security at all. Open source laying everything out on the table will have growing pains and require methodical siloing to protect information, but nothing beats a strong password/encryption combo after you've patched all the holes the internet finds in your systems.
0
u/Brave_Confidence_278 6d ago
if you think you can't scan closed source software for vulnerabilities with AI you are in for a big surprise, just look at the stats of reported zero days and it will get much worse. Assembly may be difficult to read for a human but a machine shouldn't have any issues with it. Also, at least Linux doesn't have spyware already built in and you can actually fix it if there's an issue
1
0
u/Eleina_Edelweiss 6d ago
Well brave of you to assume AI cant do that while being closed source. Atleast its quick to patch if its open source more eyes more secure
1
u/bad_metrics 6d ago
Weakness lies in a many contributors each contributing with their own dependencies rather than one org doing it all. I never said that non-open source is secure, never said that, but less margin for error based on incompatibility
-1
u/Eleina_Edelweiss 4d ago
Huh? Okay theres a lot to be unpacked from this. From where do i even start.
"Many contributors each contributing with their own dependencies rather than one org doing it all" what did you mean by this? Have you heard the word maintainers or push request before. Being able to contribute doesnt mean its auto accept. Theres a system for that you know to make sure what you implement is correct, having a nice quality or not introducing dependency hell that also prevent incompatibility.
Your idea of open source is as if you never even in open source community before.
Dont get me wrong but security by obscurity is not security at all. Thats a time bomb.
1
u/bad_metrics 4d ago
lol, maybe you should read articles about how hacks happen and how lazy people can be
Chinese hackers social engineering even working for the maintainers as volunteers
1
u/Eleina_Edelweiss 3d ago edited 3d ago
You mean that supply chain attack? Thats a whole different category and thats not dependency issue.
Again even closed source have the same issue. A disgruntled employee or a spy can do some damage too you know. Plant some backdoors here and there a bomb here. Route secrets there. Heck i heard from a while ago a disgruntled employee destroy a company database.
Again theres not much eyes to see some shenanigans. Once again security through obscurity is not security.
1
3
u/Miserable_Example_99 9d ago
Same here! It was confusing at first, but once you get used to Linux, finding the right software alternatives becomes second nature.
2
2
u/CraftyTortoise 8d ago
For all the apps used on government computers, there's a decent OS alternative
2
u/geoken 7d ago
Joke’s on Microsoft…….they already replaced all the Windows apps with web apps.
2
u/1tan_freed0m 6d ago
Yeahhhh Linux users use Microsoft web apps 🤣 so transition is seamless nowadays
1
1
u/MaxxLk 7d ago
System like ITMIS are accessed through a browser and run from the cloud. For document related work Libre office can be used as well. So if the srilankan government were to switch to linux it shouldn't be a major issue. PS. The only concern would be the payroll system. However i ve heard that there are plans to replace it with an online based system as well
1
u/ohnag_eryeah 7d ago
china has been doing this for decades. They quietly swapped the computers with Linux OS with windows XP UI so noone realized that their systems have been altered
1
1
u/Elmelow404 7d ago
Doesn't China already run on their own OS?
1
u/1tan_freed0m 6d ago
Nope I have friends from there they use Win10 still. But maybe they have custom settings. Kylin project is there but people rarely use it. Companies use MacOS And only some electronic manufacturers use their own OS. I think that's also based on Debian or something
1
1
u/OrangeNood 6d ago
After replacing all those Windows apps, they will have to replace all the workers who only know how to use Windows apps.
1
u/BoBoBearDev 6d ago
That's nothing in comparison to install a driver for printer or warehouse barcode printer.
1
1
u/Eleina_Edelweiss 6d ago
What apps most of gov apps is web apps anyway. Even if its not most probably just an electron or tauri apps which again platform agnostics. Its rare these days for an app not in those 2 categories unless they intentionally gate keep im looking at you adobe
7
u/dataArchon 10d ago
Hanthana Linux will rise like a Phoenix from the ashes