zlacker

[parent] [thread] 5 comments
1. joseph+(OP)[view] [source] 2024-06-01 10:37:19
> No modern OS would fare better in those circumstances.

Of course they would. Modern Linux, FreeBSD and macOS are totally fine connected to the internet directly with ssh enabled and no firewall. Sure; if you expose samba with write access and no password, you’re in for a world of hurt. But so long as your machine is kept up to date with security patches and has some form of authentication on all remote services, it should (generally) survive just fine on the open internet.

Of course defence in depth is still a good idea. But script kiddies aren’t using 0day attacks to portscan the open internet. But security vulnerabilities in network services get fixed.

replies(2): >>j16sdi+K6 >>jeroen+Uj1
2. j16sdi+K6[view] [source] 2024-06-01 11:44:09
>>joseph+(OP)
In my experience, an weekly-patched, default installation debian Linux cira 2015 get a malware in a week or two on the open internet.
replies(2): >>arnaud+4q1 >>hosteu+2v1
3. jeroen+Uj1[view] [source] 2024-06-01 22:19:13
>>joseph+(OP)
Modern Windows is fine, too. You may even be able to use Windows 7 that way these days. A lot has changed since XP SP2.
replies(1): >>krater+3b2
◧◩
4. arnaud+4q1[view] [source] [discussion] 2024-06-01 23:17:07
>>j16sdi+K6
Which tool do you use to detect malwares on Debian?
◧◩
5. hosteu+2v1[view] [source] [discussion] 2024-06-02 00:10:02
>>j16sdi+K6
I am not sure exactly what you're saying: Are you saying that you had experience in 2015 that your "default installation" Debian Linux server got malware on the open internet despite it being fully updated weekly?

If I read that right, I would like two things clarified:

1: what "default installation" means. Do you have any open network ports?

2: What does "get a malware" mean? Do you mean it was possible to get malware because a user downloaded som random binary off of the internet? Or do you mean that entirely passively, some malware remotely exploited some network service?

I would like to contribute my experience: I have been responsive for running many Debian servers on the internet for that last 25 years. During those years I have not once encountered one of my systems being compromised. Of course, you might say that I have just been unknowingly compromised. While this is indeed possible, it is possible for all systems to be compromised without owners knowing it.

◧◩
6. krater+3b2[view] [source] [discussion] 2024-06-02 09:59:59
>>jeroen+Uj1
I use windows 7 since >10 years, without firewall, virus scan and only with handpicked updates. As long you live behind a NAT and use a modern browser and mail client, nothing will happen. No viruses, no botnets, no malware.

I didn't test this with a virus check, but I have a bitcoin wallet with 0.1 BTC and without password on my HDD. Still there.

[go to top]