Well, it’s more so that I wished the open source community wasn’t as averse to implementing a security model that wasn’t heavily reliant on the systems being obscure. Security through obscurity is a horrid way to do such things, but it seems like that’s the way things were done before I got here.
It would be nice to see the vision of the SecureBlue project come through elsewhere in the desktop Linux world, but any time someone so much as hints at fixing the flagrant security issues of something like the AUR, all they get is dismissal and knuckle dragging in response. I’m not a blind shill for corporate products by any means, I just would like for the community to quit treating security as an afterthought, because it’s truly needed if we want to keep the new converts safe from the looming threats that are coming day after day.
Acknowledging the successes of projects that just so happen to not be community driven isn’t shilling inherently and I’m a little perturbed at that conclusion you immediately jumped to.
My bad then. I’m sorry I thought you were a shill, but those do come through here pretty often to dump their winblow and crApple dung.
As I said in another response, security is difficult to marry with convenience. You can see it on mobile operating systems where a flashlight app asks for network and storage permissions, and users just accept because they can’t be bothered with even reading it.
I too recognise that there is a lot of room to improve, but I’m hopeful that with more attention, linux will become more secure. There will be more brainpower and money flowing into it.
Yeah the real point was that those systems have things in place we could stand to learn from, to do better, and continue to keep people protected. It’s a learning lesson we could stand to be more careful.
I’m cynical of it mostly due to the way people respond when you suggest it in cases like the AUR malware. Speaking of mobile permissions I’m impressed with Voyager (my Lemmy client), it asked for literally nothing!
Astroturfing. Pretending to be grassroots but just being a corporate shill to be for or promote corporate services and products.
Turfblaster is a word for someone who astroturfs.
Well, it’s more so that I wished the open source community wasn’t as averse to implementing a security model that wasn’t heavily reliant on the systems being obscure. Security through obscurity is a horrid way to do such things, but it seems like that’s the way things were done before I got here.
It would be nice to see the vision of the SecureBlue project come through elsewhere in the desktop Linux world, but any time someone so much as hints at fixing the flagrant security issues of something like the AUR, all they get is dismissal and knuckle dragging in response. I’m not a blind shill for corporate products by any means, I just would like for the community to quit treating security as an afterthought, because it’s truly needed if we want to keep the new converts safe from the looming threats that are coming day after day.
Acknowledging the successes of projects that just so happen to not be community driven isn’t shilling inherently and I’m a little perturbed at that conclusion you immediately jumped to.
My bad then. I’m sorry I thought you were a shill, but those do come through here pretty often to dump their winblow and crApple dung.
As I said in another response, security is difficult to marry with convenience. You can see it on mobile operating systems where a flashlight app asks for network and storage permissions, and users just accept because they can’t be bothered with even reading it.
I too recognise that there is a lot of room to improve, but I’m hopeful that with more attention, linux will become more secure. There will be more brainpower and money flowing into it.
Yeah the real point was that those systems have things in place we could stand to learn from, to do better, and continue to keep people protected. It’s a learning lesson we could stand to be more careful.
I’m cynical of it mostly due to the way people respond when you suggest it in cases like the AUR malware. Speaking of mobile permissions I’m impressed with Voyager (my Lemmy client), it asked for literally nothing!