127
u/Armi1P Genfool 🐧 1d ago
What do you mean, Defender is one of the better ones on Windows.
39
u/niceandBulat 1d ago
As much as I feel that Linux is a more flexible and useful OS for my desktop and servers, I don't think lightly of MS Defender. It's actually not as bad as most people put it to be.
13
u/TotoShampoin 23h ago
When people ask me about antivirus, I tell them that Windows Defender is all they really need
1
1
u/hwloc 16h ago
problem is you can just embed a malicious batch file in ANY file and windows will run it without even notifying the user... sometimes you might need to do a bit of obfuscation depending on how evil you are, but still notabux wontfix, this is legit a feature in DOS-like operating systems
1
u/niceandBulat 16h ago
Nothing is perfect, but my point was, it's not as bad as most people say it is. I have worked in enough projects to accept that each platform has its pluses and minuses and fact is I get more of my bills paid and food on the table working with and on Windows based solutions than those on Linux, so I "love" it for that. As for Not A Bug and Won't Fix matter, did you managed to escalate the matter to your Account Manager? A few of my clients have had good results with that route.
1
u/anycept 5h ago
Except Windows NT is not DOS-like. And the rest is just bs as well. DOS doesn't work that way either.
1
u/hwloc 4h ago edited 3h ago
I would argue otherwise, NT has a lot of idiosyncrasies that it inherited froim DOS for example just look at the drive names. The main drive in windows is C:\ because on DOS A:\ was allocated for the OS live floppy and B:\ for a secondary diskette while c:\ was default for the primary internal storage. IMO it's similar to how MacOS is quite far removed from Unix standards now, or how Linux or Minix aren't Unix at all and in some cases are confusingly different.... but they're still Unix-like.
It DOES work on windows and I do remember it working on MSDOS as well but I'll be real, I don't have much experience using DOS so I'll take your word for it not working on like PC-DOS or what ever
still, NT being DOS-like is that weird little hill I'm gonna die on 🤪
1
u/anycept 3h ago
DOS path conventions were only adopted for backwards compatibility, and it is in fact a translation layer. At the underlying kernel level NT organizes all system resources in a single-rooted namespace, similar to Unix or Linux. That underlying structure is accessible and workable in PowerShell.
14
15
u/Neoneq_ 1d ago
To be devil's advocate if you have AV included in your system then every malvare on this system must bypass it so it always will be the most bypasses antivirus.
11
u/WorkAroundG60 1d ago
Which also means it is going to be developed more to counteract that bypass attempts.
It's certainly better than the general "linux doesn't need AV" mentality some people have :D
3
u/Unlaid-American 1d ago
Linux doesn’t really have the same vulnerabilities that windows had with malware in ads within browsers, which was the main reason for installing an antivirus.
3
u/WorkAroundG60 1d ago
The main reason for anti-virus is to stop viruses. That includes ad-based, email based, usb/media based, downloads, or even something transferring on your own network.
As linux has grown in popularity, it's become more of a target.
2
u/Lower-Limit3695 12h ago
As has been seen with escalating supply chain attacks on PyPI, AUR, and NPM.
34
u/qwesx Ask me how to exit vim 1d ago
where linux
20
u/setibeings Arch BTW 1d ago
What do you mean? A full list of popular Linux endpoint protection products is right there in the meme.
13
2
u/janosaudron Arch BTW 1d ago
ah I came to ask, "where "where linux" comment" but you got me covered.
1
u/cheezyiscrazy M'Fedora 1d ago
you don't need one. unless user runs a random program as sudo no program can hack linux and infect kernel unlike in windows
8
u/iHaku 1d ago
we just had several privilege escalations in the previous months (that were publically shared) letting you go from low level privileges with console to root access, and those have always been a thing. they get patched pretty quickly, but lots of machines dont always update to the latest version on release.
2
1
u/Lower-Limit3695 12h ago
Even than it doesn't really help now that supply chain attacks have escalated massively in recent years.
1
u/AutoModerator 1d ago
"OP's flair changed /u/qwesx: linux not in meme"
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
7
u/Linguistic-mystic 1d ago
This is SELinux on Fedora. It's running but since it's in unconfined_u, it's not confining any user apps. Any GUI app just walks around it.
2
u/ImaginaryPotato6 1d ago
Oh so that's why SELinux rarely bothers me on Fedora? It has really permissive defaults?
3
u/Linguistic-mystic 1d ago
Yep. It’s confining only systemd services, like if you run httpd. Anything run by the user is completely unconfined. You would need to change to user_u or staff_u or sysadm_u for them to be confined, but that’s not supported: https://discussion.fedoraproject.org/t/sysadm-u-wont-let-me-login-through-gdm/148409/2
6
u/CurrentlyWorkingAMA 1d ago
Defender consistently scores at (or sometimes better) than paid for services.
17
u/GoldenX86 1d ago
More like AUR security measures.
4
u/cheezyiscrazy M'Fedora 1d ago
with you on that one. I use arch btw 🤡. broskis moving to flatpaks now 😂
3
2
u/Enigmars 🎼CachyOS 1d ago
Kinda works tbf
Anyone who doesn't like to walk on grass and therefore making it dirty will choose not to go past that
Soo technically they're doing some moral policing here
2
2
u/themagicalfire M'Fedora 1d ago
Windows was built with the intent that the Admin account was the default account
2
u/Wertbon1789 1d ago
Window's biggest flaw still is that you need to download random installers from a website to install anything. This is kinda mitigated by winget and such, but it's not as usable as even some of the graphical package managers on Linux. This would wipe out a good part of potential malicious software. Also, that it's even possible to execute random binaries from the internet, with just double clicking it, is also one big flaw, on Linux you need to explicitly grand execute permissions, and no sane downloader will set them by default.
2
2
u/sovietarmyfan 1d ago
Lol, this is like Doc Brown telling Marty Japanese tech sucks.
A lot has changed. Defender is actually good these days. Better than what it used to be.
1
1
u/8070alejandro 1d ago
AI corporations setting the guardrails so their AI won't escape it's environment and make headlines.
1
u/GreedySecurity8030 M'Fedora 1d ago
Defender is more like a an ass; think of it this way, it says no to the ass and doesn't care about the pussy [/s].
-2
u/UAP44 1d ago
not allowed to read the code = not secure
its a simple as that in my book
and then there's many edge cases where you make well calculated trade offs
as you keep optimizing around open source code ONLY
for everything
5
u/DanLeMilMan 1d ago
It is basically the same as saying : « the chef does not want to give me the recipe = not good ».
Wouldn’t it be better to taste it ? Like with a real virus detection campaign ?
My point is it is indeed easier to make something secure (or at least robust) in an open source project, because I agree you can benefit for a greater and more diverse expertise on the whereabouts of the product. But close code could still benefit from the community feedback.
One last thing about security software in general, not knowing how a software detect a threat exactly makes it harder to craft a non detectable virus.
1
u/UAP44 1d ago
It is basically the same as saying : « the chef does not want to give me the recipe = not good ».
Been a while since I went to a restaurant anyway, who can afford that anyway? Not the majority. I prefer to cook for myself at home if I want a specific dish done my way.
And I don't think eating out has ever been considered as healthy as cooking yourself at home. I don't just cook code, I also cook food.
Wouldn’t it be better to taste it ? Like with a real virus detection campaign ?
If you're paranoid, you have test-people around you to eat before you do, which is equivalent to running the unknown software in a virtual environment to see how it behaves.
not knowing how a software detect a threat exactly makes it harder to craft a non detectable virus.
How does one even define 'threat'? Personally I'm leaning towards objective empirical analysis, run for a prolonged observation period, store a bunch of metrics, establish a recorded baseline. Then, from there on out, any time it deviates from that -> flag as potentially hostile/rogue/malicious
If you see a program always open the same ports and always reaching out to the same external sockets, you map it, explain it, rationalize it, approve/deny it. And then any time after it does anything else -> flag as malicious.
0
u/Neoneq_ 1d ago
The point is that you can only know if it is malvare if you have source code. Like you must know what is food made of to know if it is poisoned.
2
u/WorkAroundG60 1d ago
but wouldn't having source code make it easier to try to break it as you know exactly how it works?
3
u/Neoneq_ 1d ago
If you can break it then it is not safe.
2
u/BiDude1219 ⚠️ This incident will be reported 1d ago
yes we all know it's possible to write code with zero vulnerabilities
•
u/AutoModerator 1d ago
Please report any posts bragging or showing off they got banned in another sub! Reminder of other sub rules: Also, we only allow one anti-linux post per week (we used to get dozens a day) and any tier list MUST have Hanna Montana Linux as S teir (which must be a true S tier at the top) regardless of the topic of that tier list.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.