Categorized | Sophos

FLAMING RETORT – Cooling the friction when Linux meets anti-virus

Welcome to the first installment of a brand new Naked Security column, Flaming Retort!

Some of the topics we write about on this site provoke spirited comments from our readers, both here and on our Facebook page. Unsurprisingly – this is the internet, after all! – some of these comments represent what one might politely call an uncompromising position. And not a few of them are outright flames.

Flaming Retort does not exist not to praise our readers’ best flames, nor to repeat them merely in the name of perverse humour, nor to return fire in the wearisome tradition of a flame war.

The goal of Flaming Retort is to comment on one or two recent flames which represent a position which a significant minority seem to believe, but which isn’t quite as true or as certain as they might think.

To kick off, then, we’ll consider malware on Linux. Naked Security writer Carole Theriault mentioned last week that Sophos had just won (yet another!) VB100 award for Ubuntu.

That’s right. Anti-virus on Linux.

As you can imagine, it wasn’t long before we had our first outspoken comment:

I object to running a Windows virus scanner on my *nix systems just to help prevent the spread of viruses to/from Windows machines. They want to run an insecure system, so be it, but leave me out of it. And certainly don't expect me to expend my CPU cycles to try (in vain) to solve Windows' security issues."

Wow! With friends like that, who needs enemies? As a follow-up remarked:

I buy and sell diseased animals intended for use as food. Never mind, I don't eat meat, I don't care.

Nice attitude.

Ouch. Hot dog, anyone?

The first comment doesn’t actually say that Unix is secure by design. It takes an “us-and-them” attitude, and simply says that “they” are insecure. But a later comment wasn’t so equivocal, stating explicitly that:

The architecture of Linux prevents malware from being a self-propagating problem.

That’s not exactly a flame, but it’s certainly a grandstanding position. And it would be lovely if it were true. But it’s not. The architectures of Windows and Linux are surprisingly similar – they’re much more alike than they are different – and although Linux malware is, happily, very rare, there is nothing about the architecture of the operating system which prevents it.

(Be careful of claiming that something is impossible in computer security. A single counter-example will knock you off your pedestal. And 12,238 counter-examples will leave you reeling. That’s the number of unique IP numbers SophosLabs enumerated, between May and July 2008, which were infected with the Linux/Rst-B virus. In 2008, this virus was already more than six years old. And we only counted computers on which the virus was running as root. It doesn’t call home if it’s not running as root, so the total number of active infections was probably significantly higher.)

So here’s my flaming retort to the Linux-heads out there:

* Linux malware exists. It’s not a huge problem. It’s easily avoided. But don’t be in denial. There’s no “magic smoke” inside your operating system which renders you automatically immune to a determined cybercrook.

* Windows systems aren’t invariably less secure than those running Linux. You may know how to secure a Linux system more tightly and more easily than a Windows one. But other Linux admins might not. And accept at least some Windows admins will know how to secure their systems to a standard as high as yours.

* An injury to one is an injury to all. Stopping malware and spam even though it won’t harm you directly is just the sort of altruism which the internet needs. Please don’t be aloof about the problems which affect everyone.

Full story: Naked Security – Sophos

Related Posts
  • FLAMING RETORT – Whither Anonymous, our new generation of cyberfreedom fighters?
    Welcome to another installment of the controversy-soothing and crack-paper-overing Naked Security column, Flaming Retort! As explained in the first Flaming Retort, this column does not exist to prais...
  • Dr.Web anti-virus for Linux updated
    October 20, 2010 Doctor Web has updated its Dr.Web for Linux 6.0. The update incorporates fixes of errors found after the previous update. To apply the update users need to reinstall Dr.Web for Lin...
  • PerlBot: A reason to run anti-virus on Linux?
    This morning I noticed that SANS were talking about a Perl bot that has been reported on various Unix systems. I went looking for this file and noticed that a colleague had already updated the identit...
  • Remove Antivirus Center (Uninstall Guide)
    Antivirus Center is a rogue anti-spyware program from the same family as Internet Protection. This malware is installed onto your computer through the use of fake scanner pages and Trojans that preten...
  • Malicious Spam on the increase again
    Malware distribution via email is far from dead.  While we had a distinctly quiet period from October 2010 to March 2011, our stats show the bot herders are gearing up again with the proportion o...
  • IME Injection Evolution
    Recently,we found many malwares using a smarter way to inject the specified dll into system related to IME management. Comparing to the old IME injection tricks, it is much more difficult to be discov...
  • The Royal Wedding and The Fake Antivirus
    The Royal Wedding of Prince William and Catherine Middleton that will be held tomorrow, on April 29, will attract the attention of many people around the world, and has become a trending topic on vari...
  • Cyber Crooks All Set to Crash the British Royal Wedding
    As we have seen with many major events in the past, news of the British Royal Wedding is currently being used by cyber criminals to bolster their spam campaigns and push rogue antivirus software throu...
  • FedEx used for continued email malware – Zombies up 70%
    It's been almost one month since we reported about the huge increase of email-borne malware attachments.  The outbreaks have continued on an almost daily basis since then and we have noted a corr...
  • 500 free credits from Facebook – malware
    There's no such thing as a free lunch - or free Facebook credits.  As proof consider the attack described below which has several stages:1)      Users get messages with o...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago