• Big Baby Thor@sopuli.xyz
    link
    fedilink
    arrow-up
    78
    arrow-down
    1
    ·
    7 hours ago

    Here’s a careful reminder that Linux viruses can come in Windows executables.

    When it comes to hacking in the modern day it’s all about escaping the box - whether that box is a container, a VM, a sandbox or indeed even an emulated environment. So we should still fear the binary blob.

    Remember: update early, update often - no matter how painful that sounds.

    • Maestro@fedia.io
      link
      fedilink
      arrow-up
      41
      ·
      5 hours ago

      Remember: update early, update often - no matter how painful that sounds.

      Not anymore! Supply chain attacks have become so common that it’s prudent to wait at least 7 days before updating to prevent installing malware from compromised update infrastructure.

        • dgdft@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 hours ago

          Debian + unattended upgrades + modern package managers for non-system-installed software covers your bases very well.

          Debian packages are downstream enough from their sources that the packaging delay keeps you safe (and means the updates have had human eyes on them before they hit you). Unattended upgrades means you don’t have to worry about running the upgrades yourself.

          Pip, npm, and the other big package managers now also support dependency cooldowns on their recent releases, but uv and pnpm pioneered that and cover you for older release environments.

          • XiJinpingStanAccount@lemmy.ml
            link
            fedilink
            arrow-up
            1
            ·
            1 hour ago

            Also I would heavily advocate for Debian Testing if you need a rolling release distro. It is less vetted than stable but is still more vetted than many other rolling release options and you can just stay on testing as versions change while getting features pretty fast compared to stable.

      • nroth@lemmy.world
        link
        fedilink
        arrow-up
        4
        ·
        3 hours ago

        I really like Arch because I have a very custom setup and like to try the newest things, but this really worries me as Arch-based user-friendly distros that use the same packages make the repos a bigger target.

        • DevDave@piefed.social
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 hours ago

          I switched from Debian to an arch based distro. holy shit is it weird reading about some new things latest release only to have it pushed to the repo the same month or even the same day! I use btrfs so when things break its a 5 minute rollback and reboot.

        • dgdft@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 hours ago

          You’d still be fine if you’re not exposing public services or visiting actively-malicious websites.

          • Speiser0@feddit.org
            link
            fedilink
            arrow-up
            1
            ·
            57 minutes ago

            You are underestimating things. Unmalicious websites can still host malicious content by users, for example.

            • dgdft@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              52 minutes ago

              Okay, wanna give me a link to a PoC example you set up?

              I’ll reimage my laptop to an old Ubuntu ISO of your choice, and visit your link. Happy to be proven wrong.

                • dgdft@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  28 minutes ago

                  Fair enough!

                  But I can tell you as a cybersecurity expert that you’d have a hard time finding a way to get any sort of remote execution from user-generated content on any major site, much less an exploitable browser sandbox escape.

      • dgdft@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 hours ago

        There’s never been an instance of widespread malware built with a dedicated ability to persist on a Linux host through Wine.

        It wouldn’t be hard at all for a hacker to manually wire up linux-specific malware on a computer once they had a RAT running in Wine, but there’s no credible risk of windows malware automatically installing “linux viruses” at present.

  • Taasz/Woof@piefed.social
    link
    fedilink
    English
    arrow-up
    13
    ·
    6 hours ago

    Isn’t your user data available in Wine on Z:\ though? I laughed at the meme but I’d still be worried info stealer malware or similar would have no problem grabbing the data it’s looking for as Wine does no sandboxing at all.

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 hour ago

      you can remove the Z drive letter, but that’s not enough. Nothing prevents a windows program from attempting to call linux syscalls

      • Taasz/Woof@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        54 minutes ago

        Yeah, I’m sure some malware would fail on wine but some could still be just as bad compared to running windows natively.

  • MrSoup@lemmy.zip
    link
    fedilink
    arrow-up
    4
    ·
    5 hours ago

    Proton for some reason insists in mounting root on Z. Plain wine doesn’t care. So I had to use firejail.

        • zurohki@aussie.zone
          link
          fedilink
          English
          arrow-up
          9
          ·
          7 hours ago

          It’s not just the drive letter mapping, Wine doesn’t make any attempt to secure software.

          You can run Wine inside an actual security solution.

          • Aceticon@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            4
            ·
            4 hours ago

            All my Windows games that I launch from Lutris (which are most, since I tend to avoid Steam and prefer GOG) are launched by default inside a Firejail container configured amongst other things to have no networking enabled.

            All you need to do for it is to setup a “command prefix” with firejail and its launch parameters at the Lutris level and it becomes the default one for all games.

            So yeah, this runs Wine inside an actual security solution and since it’s setup at the level or the launcher I use, it does it for all the games I launch from it.

        • mysterious_cake@feddit.nl
          link
          fedilink
          arrow-up
          10
          ·
          9 hours ago

          I guess not allowing flatpak wine to access anything that is not necessary is the easiest way to achieve it. No idea if it is also the most secure solution.

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 hour ago

      more correctly every wineprefix. Depending on how you install games, they might not be running in separate wineprefixes, but I believe steam does it that way

    • Ghoelian@piefed.social
      link
      fedilink
      English
      arrow-up
      61
      ·
      13 hours ago

      Yea im pretty sure thats the point. The virus will get a drive that has nothing but the infected game on it.