cross-posted from: https://piefed.world/c/uncommon/p/1089778/linux-is-actually-very-vulnerable-to-exploits-and-it-s-showing-with-high-value-vulnerabi
I hate when people keep repeating the myth that Linux is more secure than X OS without any understanding of how much Linux gets exploited.
On the other hand, FreeBSD rarely suffers from wide security issues.
Overall, I don’t think anyone should repeat the myth that Linux is secure.
And at least if they gonna recommend Linux, they better recommend a good distro with SeLinux, hardened kernel and hardened OS.
much smaller target so far fewer people are looking for holes in bsd, subsequently there are fewer reported ‘issues’.
and if you tasked all the persons and organizations looking for holes in linux to do the same to bsd…
this ⬆️
also it is a gud thing we are finding exploits so that we can fix them ; theres currently no OS with zero exploits, the fact that none being found is concerning bcz nobody is checking and there might be some bad exploits in them…
Sometimes I wish people would back up their factual claims with numbers and studies.
Also: FreeBSD phone, when??
Thanks for the link! But I’m afraid it doesn’t tell me much. a) FreeBSD isn’t even on the list, so I don’t know the numbers to compare it to. and b) there’s things like survivorship bias. Looking at numbers like this is literally the textbook example of how to do it the wrong way. You have to do statistics the proper way around. For all we know by those numbers, Linux could be the best battle-tested OS in the world. I mean they fixed 3 times as many vulnerabilities as Microsoft did for any of their products?!
Interesting that this chart separates the SKUs on the Windows NT kernel but lumps all the Linux kernel stuff together. I have to imagine that this isn’t intentional and it’s just an artifact of how they collect data.
This seems like a better resource for tracking a specific product over time than comparing between them. It’s also worth mentioning, as the other person pointed out, that the Linux kernel is the most audited codebase of all time, so that likely also plays into this a bit.
Me when I’m not a professional with no understanding of his things actually works and I accidentally reinvent “computers insecure, avoid them at all costs for max cybersec”
OpenBSD can, objectively, do only a fraction of what Linux can. As a result, it is expected it will have only a fraction of vulnerabilities.
Sure, let’s lump all distros into a pot called “Linux.” A vulnerability in one must mean a vulnerability in all.
FreeBSD buffer overflows go brrrrrr, and I say this as lemmys official™ FreeBSD shitposter
I just had some great hamburger helper. Cooked some onions with the meat, add some extra cheese and a little mustard to enhance that cheese flavor. A few more noodles. Incredible.
Linux isn’t inherently secure, it never was, just unpopular. Now that’s changing, *BSD becomes the safe heaven.





