I’m the Never Ending Pie Throwing Robot, aka NEPTR.

Linux enthusiast, programmer, and privacy advocate. I’m nearly done with an IT Security degree.

TL;DR I am a nerd.

  • 0 Posts
  • 54 Comments
Joined 1 year ago
cake
Cake day: November 20th, 2024

help-circle




  • N.E.P.T.R@lemmy.blahaj.zonetoLinux@lemmy.worldLinux Antivirus?
    link
    fedilink
    English
    arrow-up
    24
    arrow-down
    2
    ·
    edit-2
    24 days ago

    To be more clear, antivirus in general are mostly scams because they are advertised to do much more than they are actually capable (especially proprietary ones that act as spyware such as Norton or Avast, which have been caught selling user data). Hash based antivirus solutions (such as ClamAV) aren’t effective either because they rely on “badness enumeration”, in which you try to determine all the bad samples (through a sample list(s)) and alert or delete them when detected. This isn’t a good solution because a threat actor only has to add for example a single whitespace character into the code and it will produce a wildly different hash (which has not been sampled before). Badness enumeration is shit way to deal with real problems, much better is an allowlist approach, such as a permission system where to minimize the access given and soften the security until the app runs.

    TLDR: Antivirus bad at job of stopping malware, and sandboxed apps good for security of your device.


  • N.E.P.T.R@lemmy.blahaj.zonetoLinux@lemmy.worldLinux Antivirus?
    link
    fedilink
    English
    arrow-up
    38
    arrow-down
    1
    ·
    edit-2
    24 days ago

    An antivirus is mostly unnecessary when care is taken to not install or use untrusted software. If you install everything as a Flatpak (and modify some of the default permissions), you can avoid allowing software to gain much access to her computer.

    While I think people suggesting Linux is immune to malware is stupid, for reasons such as it is “too secure” or “too niche” to be effected by malware, anti malware is like a bandaid to a gaping wound. If you have malware, it is already too late and you should first unplug the device from the network and any connected devices, backup any important data, and fresh reinstall by overwriting the infected install.

    If you still think you need some way to defend against malware, use the VirusTotal website, or a native Flatpak called Lenspect, to upload and scan files (such as an executable binary). Lenspect requires no permissions other than network access, so it is safe and the only risk is if you input a file containing personal data it will be uploaded to VirusTotal.

    Though to stress again, antivirus is a bandaid! The real solution is to be smart about what you install and only take stuff from trusted sources. Try to make sure everything is a Flatpak and avoid apps with excessive permissions, which weaken the security of the sandbox.



  • I personally don’t like LTS Linux distros because Linux is always changing, and unlike Windows, overwhelming for better. Plus security patches are not always backported because the threat severity of fixed bugs isn’t always properly categorized. I don’t like the following LTS distros: Ubuntu/Mint, Debian, Leap. I also don’t like distros which don’t have good defaults in respect to security hardening. Fedora and openSUSE are my ideal distros.

    For example, I recently installed Mint for an older family member and it has been alright. X.Org kinda sucks and she has encountered buggy behavior with apps crashing or desktop freezing. I personally used the desktop I gave them with openSUSE Tumbleweed and encountered no such issues. I just went with Mint, against my best judgment because it is so widely recommended.

    Since GNOME and KDE Plasma have first-class Wayland support, I basically only recommend those two DEs. I personally like the look of GTK4 apps more than Qt, and GNOME apps over KDE, but the freedom of KDE Plasma is superior.

    The distros I recommend are as follows:

    General Use: Criteria: general purpose, SELinux, modern technologies (Pipewire, Wayland, close to upstream kernel)

    • Fedora Workstation/KDE
    • openSUSE Slowroll/Tumbleweed

    Gaming: Criteria: gaming focus, baby easy install process, modern version of Mesa and kernel, first class Nvidia support

    1. PikaOS (rolling-Debian)
    2. Bazzite (Fedora atomic)
    3. Nobara (Fedora traditional)
    4. CachyOS (Arch Linux)