Here’s a careful reminder that Linux viruses can come in Windows executables.
When it comes to hacking in the modern day it’s all about escaping the box - whether that box is a container, a VM, a sandbox or indeed even an emulated environment. So we should still fear the binary blob.
Remember: update early, update often - no matter how painful that sounds.
Remember: update early, update often - no matter how painful that sounds.
Not anymore! Supply chain attacks have become so common that it’s prudent to wait at least 7 days before updating to prevent installing malware from compromised update infrastructure.
Debian + unattended upgrades + modern package managers for non-system-installed software covers your bases very well.
Debian packages are downstream enough from their sources that the packaging delay keeps you safe (and means the updates have had human eyes on them before they hit you). Unattended upgrades means you don’t have to worry about running the upgrades yourself.
Pip, npm, and the other big package managers now also support dependency cooldowns on their recent releases, but uv and pnpm pioneered that and cover you for older release environments.
Also I would heavily advocate for Debian Testing if you need a rolling release distro. It is less vetted than stable but is still more vetted than many other rolling release options and you can just stay on testing as versions change while getting features pretty fast compared to stable.
I really like Arch because I have a very custom setup and like to try the newest things, but this really worries me as Arch-based user-friendly distros that use the same packages make the repos a bigger target.
I switched from Debian to an arch based distro. holy shit is it weird reading about some new things latest release only to have it pushed to the repo the same month or even the same day! I use btrfs so when things break its a 5 minute rollback and reboot.
But I can tell you as a cybersecurity expert that you’d have a hard time finding a way to get any sort of remote execution from user-generated content on any major site, much less an exploitable browser sandbox escape.
There’s never been an instance of widespread malware built with a dedicated ability to persist on a Linux host through Wine.
It wouldn’t be hard at all for a hacker to manually wire up linux-specific malware on a computer once they had a RAT running in Wine, but there’s no credible risk of windows malware automatically installing “linux viruses” at present.
Here’s a careful reminder that Linux viruses can come in Windows executables.
When it comes to hacking in the modern day it’s all about escaping the box - whether that box is a container, a VM, a sandbox or indeed even an emulated environment. So we should still fear the binary blob.
Remember: update early, update often - no matter how painful that sounds.
Not anymore! Supply chain attacks have become so common that it’s prudent to wait at least 7 days before updating to prevent installing malware from compromised update infrastructure.
So, what’s the solution? Debian Stable?
Debian + unattended upgrades + modern package managers for non-system-installed software covers your bases very well.
Debian packages are downstream enough from their sources that the packaging delay keeps you safe (and means the updates have had human eyes on them before they hit you). Unattended upgrades means you don’t have to worry about running the upgrades yourself.
Pip, npm, and the other big package managers now also support dependency cooldowns on their recent releases, but uv and pnpm pioneered that and cover you for older release environments.
uv is owned by openai fun fact
Also I would heavily advocate for Debian Testing if you need a rolling release distro. It is less vetted than stable but is still more vetted than many other rolling release options and you can just stay on testing as versions change while getting features pretty fast compared to stable.
N-1
I really like Arch because I have a very custom setup and like to try the newest things, but this really worries me as Arch-based user-friendly distros that use the same packages make the repos a bigger target.
On the other hand, AI has made the patch to exploit code as short as 45 minutes.
What if you use for example ubuntu and wait 3 years?
I switched from Debian to an arch based distro. holy shit is it weird reading about some new things latest release only to have it pushed to the repo the same month or even the same day! I use btrfs so when things break its a 5 minute rollback and reboot.
You’d still be fine if you’re not exposing public services or visiting actively-malicious websites.
You are underestimating things. Unmalicious websites can still host malicious content by users, for example.
Okay, wanna give me a link to a PoC example you set up?
I’ll reimage my laptop to an old Ubuntu ISO of your choice, and visit your link. Happy to be proven wrong.
No, I will not spend hours of my time to win an irrelevant internet argument. :P
Fair enough!
But I can tell you as a cybersecurity expert that you’d have a hard time finding a way to get any sort of remote execution from user-generated content on any major site, much less an exploitable browser sandbox escape.
Compatibility layer. Wine Is Not an Emulator.
Which is what makes the situation much worse
I read a hilarious article, probably 2 decades ago by now, where a guy decided to try running Windows viruses on Linux in Wine.
If this really is a threat today, I would say that Wine has become a pretty damn impressive project. Here’s the link in case anyone else wants to read it: https://entertainment.slashdot.org/story/05/01/26/219201/running-windows-viruses-under-linux
There’s never been an instance of widespread malware built with a dedicated ability to persist on a Linux host through Wine.
It wouldn’t be hard at all for a hacker to manually wire up linux-specific malware on a computer once they had a RAT running in Wine, but there’s no credible risk of windows malware automatically installing “linux viruses” at present.