Edit: typo

  • NightDice@feddit.de
    link
    fedilink
    arrow-up
    1
    ·
    11 months ago

    why does linux not have an AV?

    I can recommend running ClamAV, if anyone is looking for a good one that runs on Linux.

    • dzervas@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      11 months ago

      I’ve never even considered ClamAV. I have the idea that it’s just a malware signature DB (changing the signature of a binary is almost as simple as recompiling it with a bit different variables)

      Am I incorrect? does it have heruistics/active scanning?

      • NightDice@feddit.de
        link
        fedilink
        arrow-up
        1
        ·
        11 months ago

        It is pretty exclusively a file scanner, but that, combined with Linux’s privilege separation, any decent firewall and not willfully executing untrusted files is enough for most cases, I would say.

        • dzervas@lemmy.world
          link
          fedilink
          arrow-up
          1
          arrow-down
          2
          ·
          11 months ago

          what kind of privilege separation? you’re talking about containers/namespaces?

          cause as it is linux desktop has 1 unprivileged user and that’s it. from an attackers perspective privilege escalation is irrelevant - you have access to the screen, keyboard, browser, files. there really is nothing left to gain from gaining root

          and if you have any reason to gain root, it’s super easy by just replacing sudo with an alias in .bashrc you’ve got the user’s password

          We REALLY need sandboxing and soon, that’s why I want to give fedora silverblue a try but my hopes are quite low

          btw windows is in a bit of a better place and M1 mac is in much better place

            • dzervas@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              11 months ago

              I’ve not looked into fire jail in depth but I’ve read lots and lots of bad takes on it

              What we need is docker with a better graphics integration, in terms of both ease of use and security. maybe wayland can help in that (cause with X you just forward the whole management socket and that’s it, anyone can draw anything)

              There’s a chance that snap has done it right (I know that everyone hates it but there’s a CHNACE that they got it right in terms of security and ease of use)

              flatpak “is not enough” since the controls it gives you are not enough. first you need flatseal to disable stuff per application and the defaults aren’t good enough and steam for example REQUIRES access to the whole home folder which defeats the whole purpose