UNIX Security: Don’t Believe the Truth

One of the biggest reasons for many people to switch to a UNIX desktop, away from Windows, is security. It is fairly common knowledge that UNIX-like systems are more secure than Windows. Whether this is true or not will not be up for debate in this short editorial; I will simply assume UNIX-like systems are more secure, for the sake of argument. However, how much is that increased security really worth for an average home user, when you break it down? According to me, fairly little. Here’s why.

UNIX is geared towards server use, and so is its security system. As we all know, ‘normal’ users do not have permanent root access (well, shouldn’t have, in any case). As such, all important system files are protected from whatever stupid things the user might do. The user does not have full access rights to all files. The user only has full access rights to his or her own personal files.

And that is where the problem lies.

I believe that desktop Linux/OSX/etc. users all over the world have a false sense of security, and are activily promoting that false sense of security on the internet, in magazines, and conferences all over the world. No, they are not doing this on purpose. However, that does not negate the fact that it does happen.

What I am blabbering about?

A hypothetical virus or other malware on a UNIX-like system can only, when it is activated by a normal user, wreak havoc inside that user’s /home directory (or whatever other files the user might have access rights to). Say it deletes all those files. That sucks, but: UNIX rocks, the system keeps on running, the server-oriented security has done its work, no system files were affected, uptime is not affected. Great, halleluja, triumph for UNIX.

But what is more important to a home user? His or her own personal files, or a bunch of system files? I can answer that question for you: the pictures of little Johnny’s first day of school mean a whole lot more to a user than the system files that keep the system running. Of course, they should make backups– but wasn’t Linux supposed to be secure? So why should they backup? Isn’t Linux immune to viruses and what not? Isn’t that what the Linux world has been telling them?

This is the false sense of security I am talking about. UNIX might be more secure than Windows, but that only goes for the system itself. The actual content that matters to normal people is not a single bit safer on any UNIX-like system than it is on any Windows system. In the end, the result of a devastating virus or other malware program can be just as devastating on a UNIX-like system as it can be on a Windows system– without the creator having to circumvent any extra (UNIX-specific) security measures.

To blatantly copy Oasis: don’t believe the truth. Yes, UNIX-like systems might be more secure than Windows systems, but not in the places where it matters to average home users.

–Thom Holwerda


If you would like to see your thoughts or experiences with technology published, please consider writing an article for OSNews.

249 Comments

  1. msg43 2006-02-05 5:26 pm EST
    • Celerate 2006-02-05 5:59 pm EST
    • WorknMan 2006-02-05 6:07 pm EST
      • raver31 2006-02-05 9:43 pm EST
    • AdamW 2006-02-05 7:08 pm EST
      • Dark_Knight 2006-02-05 7:42 pm EST
      • jakesdad 2006-02-05 7:59 pm EST
      • youngstructural 2006-02-06 7:54 pm EST
        • tomcat 2006-02-07 1:47 am EST
      • linuxh8r 2006-02-06 9:09 pm EST
        • archiesteel 2006-02-06 9:32 pm EST
    • mrichard91 2006-02-06 6:11 pm EST
  2. pecisk 2006-02-05 5:27 pm EST
    • Thom Holwerda 2006-02-05 5:36 pm EST
      • raver31 2006-02-05 5:56 pm EST
        • raboof 2006-02-06 8:53 am EST
          • jaduncan 2006-02-06 12:53 pm EST
          • Thom Holwerda 2006-02-06 12:59 pm EST
          • hal2k1 2006-02-06 1:13 pm EST
          • netpython 2006-02-06 1:19 pm EST
          • hal2k1 2006-02-06 1:23 pm EST
      • jaapjan 2006-02-06 8:09 am EST
      • steviant 2006-02-06 12:01 pm EST
        • Thom Holwerda 2006-02-06 12:13 pm EST
          • steviant 2006-02-06 1:26 pm EST
          • psiox 2006-02-06 3:23 pm EST
    • makc 2006-02-06 11:53 am EST
  3. Pliep 2006-02-05 5:28 pm EST
    • Thom Holwerda 2006-02-05 5:34 pm EST
      • Pliep 2006-02-05 5:46 pm EST
        • RenatoRam 2006-02-05 6:12 pm EST
          • ciphernaut 2006-02-05 8:40 pm EST
          • evangs 2006-02-05 9:44 pm EST
      • klynch 2006-02-05 11:34 pm EST
      • Tweek 2006-02-06 1:42 am EST
      • Rehdon 2006-02-06 2:18 pm EST
      • archiesteel 2006-02-06 5:15 pm EST
    • CaptainPinko 2006-02-05 10:41 pm EST
      • abraxas 2006-02-06 1:26 am EST
  4. sappyvcv 2006-02-05 5:31 pm EST
    • FooBarWidget 2006-02-05 6:40 pm EST
      • sappyvcv 2006-02-05 6:44 pm EST
        • FooBarWidget 2006-02-05 7:10 pm EST
          • sappyvcv 2006-02-05 7:13 pm EST
          • FooBarWidget 2006-02-05 7:25 pm EST
          • sappyvcv 2006-02-06 5:20 am EST
          • FooBarWidget 2006-02-06 9:19 am EST
        • DeadFishMan 2006-02-06 3:28 am EST
      • Deletomn 2006-02-06 12:42 am EST
    • HenryT 2006-02-06 5:58 pm EST
  5. sappyvcv 2006-02-05 5:33 pm EST
    • somebody 2006-02-05 6:00 pm EST
      • sappyvcv 2006-02-05 6:03 pm EST
        • somebody 2006-02-05 6:15 pm EST
          • sappyvcv 2006-02-05 6:20 pm EST
  6. Buck 2006-02-05 5:33 pm EST
    • AndyJ 2006-02-06 7:08 am EST
  7. binarycrusader 2006-02-05 5:38 pm EST
    • tomcat 2006-02-07 1:39 am EST
  8. Resolution 2006-02-05 5:40 pm EST
    • binarycrusader 2006-02-05 5:46 pm EST
      • Resolution 2006-02-05 5:59 pm EST
        • sappyvcv 2006-02-05 6:05 pm EST
          • Resolution 2006-02-05 6:09 pm EST
          • sappyvcv 2006-02-05 6:14 pm EST
          • Thom Holwerda 2006-02-05 6:16 pm EST
          • Resolution 2006-02-05 6:38 pm EST
          • FooBarWidget 2006-02-05 7:14 pm EST
          • sappyvcv 2006-02-05 7:18 pm EST
          • FooBarWidget 2006-02-05 7:35 pm EST
      • Celerate 2006-02-05 6:20 pm EST
        • steviant 2006-02-06 12:29 pm EST
          • Celerate 2006-02-06 5:55 pm EST
    • Lumbergh 2006-02-05 8:35 pm EST
  9. postmodern 2006-02-05 5:44 pm EST
  10. karl1 2006-02-05 5:45 pm EST
  11. cayfer 2006-02-05 5:45 pm EST
    • postmodern 2006-02-05 5:57 pm EST
  12. somebody 2006-02-05 5:45 pm EST
    • necrosis 2006-02-05 6:27 pm EST
      • somebody 2006-02-05 6:34 pm EST
      • Marcellus 2006-02-06 10:41 am EST
        • hal2k1 2006-02-06 12:06 pm EST
          • Marcellus 2006-02-06 1:38 pm EST
          • hal2k1 2006-02-06 1:47 pm EST
    • AbsintheSyringe 2006-02-08 6:34 am EST
  13. Varg Vikernes 2006-02-05 5:47 pm EST
  14. Leoandru 2006-02-05 5:49 pm EST
  15. helgegrimm 2006-02-05 5:52 pm EST
  16. Hetfield 2006-02-05 5:53 pm EST
  17. sappyvcv 2006-02-05 6:17 pm EST
    • somebody 2006-02-05 6:31 pm EST
      • sappyvcv 2006-02-05 6:42 pm EST
      • somebody 2006-02-05 6:53 pm EST
        • bytecoder 2006-02-05 6:56 pm EST
          • sappyvcv 2006-02-05 7:04 pm EST
          • somebody 2006-02-05 7:19 pm EST
          • bytecoder 2006-02-05 8:16 pm EST
          • RenatoRam 2006-02-05 8:46 pm EST
          • bytecoder 2006-02-05 8:56 pm EST
          • somebody 2006-02-05 8:54 pm EST
          • bytecoder 2006-02-05 9:02 pm EST
          • somebody 2006-02-06 2:52 am EST
          • Finalzone 2006-02-05 10:45 pm EST
  18. Milo_Hoffman 2006-02-05 6:19 pm EST
  19. LB06 2006-02-05 6:22 pm EST
  20. morganth 2006-02-05 6:24 pm EST
    • devnull 2006-02-05 9:43 pm EST
    • captain_knobjockey 2006-02-05 10:00 pm EST
      • bytecoder 2006-02-05 10:32 pm EST
        • abraxas 2006-02-06 1:01 am EST
      • brian_P 2006-02-06 5:14 am EST
      • ma_d 2006-02-06 5:17 am EST
  21. siride 2006-02-05 6:26 pm EST
    • bytecoder 2006-02-05 6:35 pm EST
      • thadman08 2006-02-06 6:41 pm EST
  22. bytecoder 2006-02-05 6:33 pm EST
    • sappyvcv 2006-02-05 6:54 pm EST
      • somebody 2006-02-05 7:03 pm EST
        • sappyvcv 2006-02-05 7:07 pm EST
          • somebody 2006-02-05 7:30 pm EST
          • sappyvcv 2006-02-06 5:22 am EST
          • somebody 2006-02-06 5:46 am EST
          • sappyvcv 2006-02-06 5:50 am EST
          • somebody 2006-02-06 5:55 am EST
          • sappyvcv 2006-02-06 6:02 am EST
          • somebody 2006-02-06 6:27 am EST
  23. FooBarWidget 2006-02-05 6:35 pm EST
  24. Maxilys 2006-02-05 6:39 pm EST
  25. penguin7009 2006-02-05 6:42 pm EST
  26. 3kirt 2006-02-05 6:45 pm EST
    • bytecoder 2006-02-05 6:52 pm EST
    • sappyvcv 2006-02-05 7:03 pm EST
    • anda_skoa 2006-02-06 12:01 am EST
  27. Dark_Knight 2006-02-05 6:50 pm EST
    • bytecoder 2006-02-05 6:54 pm EST
      • Dark_Knight 2006-02-05 7:24 pm EST
        • Aussie_Bear 2006-02-05 10:28 pm EST
  28. Bonus 2006-02-05 7:02 pm EST
  29. Latem 2006-02-05 7:03 pm EST
  30. hraq 2006-02-05 7:04 pm EST
  31. maxx_730 2006-02-05 7:29 pm EST
    • raver31 2006-02-05 10:09 pm EST
  32. sbergman27 2006-02-05 7:29 pm EST
  33. leos 2006-02-05 8:17 pm EST
    • elsewhere 2006-02-05 9:24 pm EST
      • bytecoder 2006-02-05 9:41 pm EST
  34. Lumbergh 2006-02-05 8:41 pm EST
    • RenatoRam 2006-02-05 8:50 pm EST
    • raver31 2006-02-05 10:20 pm EST
  35. n1xt3r 2006-02-05 8:51 pm EST
    • abraxas 2006-02-05 11:05 pm EST
    • n1xt3r 2006-02-06 4:59 am EST
    • ma_d 2006-02-06 5:26 am EST
  36. addoula 2006-02-05 8:59 pm EST
    • Lumbergh 2006-02-05 9:18 pm EST
      • sappyvcv 2006-02-06 5:31 am EST
  37. moleskine 2006-02-05 9:03 pm EST
  38. license_2_blather 2006-02-05 9:13 pm EST
  39. bits45 2006-02-05 9:25 pm EST
  40. bits45 2006-02-05 9:28 pm EST
  41. dswain 2006-02-05 9:36 pm EST
    • bytecoder 2006-02-05 9:47 pm EST
      • dswain 2006-02-06 1:29 am EST
  42. CrazyDude0 2006-02-05 9:39 pm EST
    • bytecoder 2006-02-05 9:42 pm EST
    • Soulbender 2006-02-06 5:18 am EST
      • sappyvcv 2006-02-06 5:39 am EST
        • somebody 2006-02-06 5:50 am EST
          • sappyvcv 2006-02-06 5:59 am EST
          • somebody 2006-02-06 6:29 am EST
          • ma_d 2006-02-06 6:43 am EST
        • Soulbender 2006-02-06 6:00 am EST
          • sappyvcv 2006-02-06 6:04 am EST
  43. MamiyaOtaru 2006-02-05 9:45 pm EST
    • sappyvcv 2006-02-06 5:42 am EST
    • raboof 2006-02-06 9:11 am EST
  44. John Nilsson 2006-02-05 10:07 pm EST
  45. Gryzor 2006-02-05 10:10 pm EST
  46. rklrkl 2006-02-05 10:19 pm EST
  47. abraxas 2006-02-05 10:29 pm EST
  48. iSteve 2006-02-05 11:01 pm EST
    • Finalzone 2006-02-05 11:14 pm EST
  49. mr_manny 2006-02-05 11:16 pm EST
  50. Tyr. 2006-02-05 11:25 pm EST
  51. jdve 2006-02-05 11:27 pm EST
  52. chekr 2006-02-05 11:47 pm EST
  53. Tyr. 2006-02-05 11:48 pm EST
  54. 2006-02-05 11:59 pm EST
    • Soulbender 2006-02-06 4:58 am EST
  55. JustAnotherMacUser 2006-02-06 1:08 am EST
  56. hobgoblin 2006-02-06 2:08 am EST
  57. ma_d 2006-02-06 3:36 am EST
  58. TusharG 2006-02-06 4:05 am EST
    • Soulbender 2006-02-06 4:39 am EST
      • ma_d 2006-02-06 5:15 am EST
      • hal2k1 2006-02-06 8:25 am EST
        • Soulbender 2006-02-06 8:43 am EST
          • hal2k1 2006-02-06 9:58 am EST
          • Soulbender 2006-02-06 10:51 am EST
          • hal2k1 2006-02-06 12:02 pm EST
          • Soulbender 2006-02-06 12:26 pm EST
          • hal2k1 2006-02-06 12:46 pm EST
          • hal2k1 2006-02-06 12:15 pm EST
          • stew 2006-02-06 12:25 pm EST
          • Soulbender 2006-02-06 12:32 pm EST
          • hal2k1 2006-02-06 12:59 pm EST
          • Soulbender 2006-02-07 2:42 am EST
          • archiesteel 2006-02-07 5:46 am EST
          • Soulbender 2006-02-07 6:43 am EST
      • archiesteel 2006-02-06 5:29 pm EST
  59. gplCop318 2006-02-06 6:29 am EST
  60. Nycran 2006-02-06 7:26 am EST
  61. kernelpanicked 2006-02-06 7:39 am EST
    • Soulbender 2006-02-06 9:07 am EST
    • raboof 2006-02-06 9:07 am EST
      • unapersson 2006-02-06 1:50 pm EST
    • FooBarWidget 2006-02-06 9:23 am EST
  62. DevL 2006-02-06 8:21 am EST
  63. Darkelve 2006-02-06 9:06 am EST
  64. hal2k1 2006-02-06 10:12 am EST
  65. stew 2006-02-06 10:51 am EST
  66. diegocg 2006-02-06 12:06 pm EST
  67. dylansmrjones 2006-02-06 1:20 pm EST
  68. Thom Holwerda 2006-02-06 1:48 pm EST
    • hal2k1 2006-02-06 1:58 pm EST
    • dylansmrjones 2006-02-06 2:10 pm EST
    • archiesteel 2006-02-06 5:35 pm EST
  69. dukeinlondon 2006-02-06 2:11 pm EST
  70. Barnabyh 2006-02-06 2:33 pm EST
  71. Barnabyh 2006-02-06 2:44 pm EST
  72. rugbuzpafnuti 2006-02-06 2:55 pm EST
    • Soulbender 2006-02-07 2:59 am EST
  73. Windlord 2006-02-06 3:46 pm EST
  74. davecb 2006-02-06 5:03 pm EST
  75. thinsoldier 2006-02-06 5:25 pm EST
  76. Eronysis 2006-02-06 5:33 pm EST
  77. MattK 2006-02-06 5:54 pm EST
  78. markgreene 2006-02-06 6:19 pm EST
  79. youngstructural 2006-02-06 7:48 pm EST
  80. swisswuff 2006-02-06 8:13 pm EST
  81. kotter71 2006-02-06 8:53 pm EST
    • Thom Holwerda 2006-02-06 9:11 pm EST
      • kotter71 2006-02-06 9:37 pm EST
  82. Barnabyh 2006-02-06 9:15 pm EST
  83. l3v1 2006-02-06 10:23 pm EST
  84. ido50 2006-02-06 11:10 pm EST
  85. TheMonoTone 2006-02-07 4:26 am EST
  86. jmtd 2006-02-07 2:56 pm EST