SHIT HITS THE FAN: Linux security woes confirmed - Windows mitigated long time ago

First of all, I would just like to point out that, as the most cursory search on the RBT archives will reveal, the superiority of Windows' security features in relation to Linux's has been pointed out on this board numerous times. Linux apologists disregarded such claims with puerile accusations of "lel pajeet XDDD".

Now that the shit has hit the fan and Linux's out in the open security problems have been exposed by independent auditors, one can only hope Linux apologists would enjoy a nice piece of humble pie.

These are SERIOUS vulnerabilities, that could affect a Linux user by merely visiting a simple web page, by the way. This is EXTREMELY GRAVE: these are problems similar to the ones that plagued very early versions of Windows. Microsoft learned from its early security calamities and implemented sophisticated mitigations - which the posts you'll find on your cursory search of the archives mentioned repeatedly.

But Linux users simply didn't care. They considered themselves unbreakable. They believed in the common but misled notion of "security as a product", which has been extensively repudiated by the entire security community - including such experts as the notorious Bruce Schneier.

They simply replied with stuck up snark and claimed that Linux already had mitigations too, in the form of grsec - ignoring the fact that grsec is a paid patch that does not come by default in any of the major GNU/Linux distributions or Android phones (except for the BlackBerry Priv). This resulted in all of them being vulnerable to the infamous "dirty COW" bug - which is still being exploited by Android malware to brick smart TVs. We stressed the importance of mitigations, only to be met with snobbish derision: "lmao we're bug proof, we don't need that!"

We also pointed out several times that all GNU/Linux distributions run X as root, with no proper privilege separation, which could have greatly mitigated the current problems.

To sum it up: you've been TOLD.

Other urls found in this thread:

mobile.twitter.com/aionescu/status/827663010659315712
technet.microsoft.com/en-us/library/security/ms16-087.aspx
twitter.com/NSFWRedditVideo

>Linux security woes confirmed
sounds about right
>Windows mitigated long time ago
be a little less obvious next time, good luck!

>Linux's out in the open security problems have been exposed by independent auditors
Yes, while Windows rampant security problems won't even be let known to its users, much less "auditors" of any sort due to its closed-source nature.

firejail.
also smartTV's are notoriously buggy.

Youre killing strawmen here

This is what I was talking about in the OP.

What part of humble pie didn't you understand?

Auditors don't look at the source code to find openings. I worked 5 years for Cigital doing that shit.

How are lincucks ever gonna be able to recover?

>Linux security woes confirmed
[by whom?]
- Windows mitigated long time ago
[citation needed]

>linux has problem
gets fixed
>windows has problem
it's a roll the dice

stop attempting to spread fud, modern web browsers are (mostly) secure, even a linux user that doesn't know what they're doing shouldn't have any issues as long as their system is up to date. A more sophisticated user would be properly isolating things like web browsers from the rest of their computing environment.

>A more sophisticated user
Now that's just moving the goalposts. A sophisticated user is able to lock down any operating system, including Windows.

Security is a process. Not a product.

Fuck off OP. Every single year fucking shills brag about exploits discovered in Linux and every single time it turns out the exploit can only be triggered by doing some shaman bullcrap in a command nobody uses, not to mention they usually get fixed very quickly once their threat potential is discovered.

I sometimes use Win7 and some bugs I've seen since 2011 are still not fixed.

What part of "can be exploited by a web page" didn't you understand?

That isn't entirely true, MS has contractors do source code review. Alex Ionescu has been contracted multiple times

DELTE TIHS THERAD

Who has Linux contracted?

>linuxes newest anti exploitation feature: ASLR 10 years after everyone else
>Windows: Bleeding edge features mobile.twitter.com/aionescu/status/827663010659315712

And windohs can be infected by viewing an image.

>mobile
Dumb phoneposter.

Meanwhile grsecurity had this problem fixed for atleast 10years.

Nobody lmao, the NSA contracts VR for it though but they don't get fixed

>the superiority of Windows' security features
>troll harder, Pajeet.

This is what I was talking about in the OP.

PROTIP: you're in no position to mock us with memes when you have egg on face due to your system being so fragile a fucking multimedia framework vulnerability compromises the entire thing.

It's been fixed.

>ctrl f
>poo in loo
>no results
let me fix that
POO
O
O

IN
N

LOO
O
O
XDDDDDDDD

Deluding yourself that shitdows is anywhere near as secure as any other operating system.
Give your fricking head a shake.

You guys figure out control flow guard yet? LMAO owned idiot enjoy your ROP

What Linux bugs can be exploited by any webpage? dirtyc0w requires CLI access.

POO IN LOO PAJEET LINUX IS THE MOST SECURE OS EVER MADE! 1!1!!!1

Can someone give me a quick rundown on these guys?

/thread

>Windows security in a nutshell
>connect to one of those open wifi networks from a printer
>literally gain control of anything connected to that printer
technet.microsoft.com/en-us/library/security/ms16-087.aspx

>But Linux users simply didn't care. They considered themselves unbreakable.
Weak bait and weak strawman. A tip: if you want to actually bait properly provide an argument based on facts and not on putting words on other people's mouth. Otherwise your argument gets quickly countered by any proof of vulnerabilities on other operative systems.

A simple question: If there exists a method to create perfect code what would be the point of opening the source to allow "study, change and improve the software"?

>Now that's just moving the goalposts.
>Security is a process. Not a product.

That's cute, but at least you are right.

Still wait for that webpage.

>mock us

This how you shill? :^)

And some faggot thought windows is better kiosk because easier to hide the cli. saved

...