[HOME] [DOWNLOAD] [DOCS] [NEWS] [SUPPORT] [TIPS] [ISSUES] [CONTRIBUTE] [DONATE]

Host Operating System Selection Wiki Page Discussion

It’s cleaning up apps that have been removed from the Windows Store from the user’s PCs. Microsoft can’t just delete random apps willy nilly. You can still use whatever .exe you want and Microsoft can’t remove that. It’s only for apps that have been removed from the Windows Store and this has only ever been used to remove malware. If you want to install the removed software, you can still fetch the .exe and install it.

Microsoft has backdoored its disk encryption [archive].

This backed up your keys and was always optional so it isn’t an issue.

Windows 10 S was always optional and is good for security since everything is audited and sandboxed.

The German government does not trust that Windows 8 and the Trusted Platform Module (TPM) v2.0 is not a backdoored combination [archive].

The only source for this is some random deleted blog spreading FUD with 0 evidence.

Windows Insecurity
Adversary Collaboration
Enforced Upgrades

Already covered.

Gotta love how Windows is criticized for being “a pile of legacy code full of security holes” yet also criticized for not supporting legacy code full of security holes.

Windows Interference

These aren’t relevant to privacy/security/freedom. They’re just annoyances.

Windows Software Sources

The Windows Store exists.

Freedom Software Superiority

Already covered.

There’s some others things that I think should be removed but I’m not sure I can edit a pending edit.

and there is a secret “NSA key” [archive] in Windows, whose functions are unknown.

This was just a key named “NSAKEY” and was never proven to be malicious. If the NSA wanted a backdoor in Windows do you really think they’d be foolish enough to stick their name in plain sight?

The smartscreen filter [archive] also reports what software is running on the computer.

Dead link.

The “privacy” policy in Windows 10 explicitly authorizes Microsoft to look at user files at any time and to sell almost any information [archive] it collates.

Not what it says.

https://privacy.microsoft.com/en-us/privacystatement

I covered this above but it was repeated in the surveillance section.

Ok. Still worth mentioning that capability. Could even be considered a feature. Debian / Whonix in theory has the same chance. In theory package upgrade could introduce software/scripts which auto removes known malware, but then again, user has to opt-in for that by starting to upgrade.

Quoted from article:

But what is less well-known is that, if you are like most users and login to Windows 10 using your Microsoft account, your computer automatically uploaded a copy of your recovery key — which can be used to unlock your encrypted disk — to Microsoft’s servers, probably without your knowledge and without an option to opt out.

“When a device goes into recovery mode, and the user doesn’t have access to the recovery key, the data on the drive will become permanently inaccessible. Based on the possibility of this outcome and a broad survey of customer feedback we chose to automatically backup the user recovery key,” a Microsoft spokesperson told me. “The recovery key requires physical access to the user device and is not useful without it.”

Ok.

Therefore Later Windows versions [only allow programs from the Windows Store](https://www.theguardian.com/technology/2017/may/03/windows-10-s-microsoft-faster-pc-comparison) [[archive]](https://web.archive.org/web/https://www.theguardian.com/technology/2017/may/03/windows-10-s-microsoft-faster-pc-comparison) to be downloaded and installed. is invalid indeed.

Since this is opt-in it’s actually an advantage. Please keep / reword.

Similar idea in Linux world is walled garden, firewall whitelisting, application whitelisting, sudo lockdown, superuser mode, protected mode

Here is a better report:
https://www.theregister.co.uk/2013/08/23/nsa_germany_windows_8/

The original source:
https://www.bsi.bund.de/DE/Presse/Pressemitteilungen/Presse2013/Windows_TPM_Pl_21082013.html

I see the point. The issue again is the wording. It is important to mention dropping support for Windows versions older than Windows 10. This is because when people learn about “Windows 10 privacy issue” their immediate reaction isn’t “drop Windows, switch to Linux” but instead “stick with Windows 7” or “go back to Windows XP”. This that is not advisable due to dropped security support, this needs to be mentioned. Please keep and reword.

Please keep and reword. These are useful to show the advantages of most Linux distributions which usually do not contain advertisements and nag screens.

Major applications still aren’t available such as firefox, gnupg, libre office, any portable apps.

Can be rewritten but chapter Freedom Software Superiority still mostly applies.

Writing https://www.whonix.org/w/index.php?title=Whonix_Stable_Release&curid=6553&diff=56767&oldid=56484 seems like major effort. Partially due to convert from markdown markup (discourse forums) to mediawiki markup. Hopefully not done by hand to safe some effort. Are you already aware of pandoc? @torjunkie

In short: it can convert markdown syntax to mediawiki markup (and more). And it’s “90%” valid markup.

1 Like

The section isn’t meant to be about useful Windows features.

Logging into a Windows 10 account is optional and I doubt most users do.

I don’t see why it should be kept. Again, that section is about Windows’ surveillance/freedom restrictions, not its advantages. Advantages are mentioned above in the overview section.

There was no mention of a backdoor in the original source and if you read the source, you’d see it’s actually a freedom issue and not a security issue.

And from my experience, the BSI generally isn’t reliable and claim some blatantly untrue things.

I don’t see the need to keep those. We should instead add something like “Going back to older Windows versions introduces new security issues and lacks support”.

The page isn’t about Linux nagging the user less.

It’s not Microsoft’s fault that people don’t submit their apps to the store.

It doesn’t. The majority of it is just “free software is super secure” which isn’t true.

Great - thanks. That will be useful.

PS That Debian (host OS) Hardening section that talks about preventing module loading - it is not clear what users are meant to do with those configs etc. I thought this could break their systems based on forum chat (?). Should that be moved to /Dev section instead?

1 Like

Edit https://www.whonix.org/w/index.php?title=Template%3AWindows_Hosts&type=revision&diff=56761&oldid=48328 rejected. There was too much debate and no further edits. I don’t think this would have moved forward. Took some of your rewordings. Applied further rewording improvements according to feedback. Processed all feedback as far as I could. Feel free to mention any remaining non-ideal wording.

I guess there’s enough praise of Windows but if that page should be comparison and thrive to be as neutral, factual as possible then it’s good to mention. Might even encourage developers on Linux distributions to implement these features.

I would guess most do setup a microsoft account as this is being nagged and without microsoft account using the appstore is actually more difficult and requires instructions.

Disk encryption key only uploaded if using a Microsoft account or not, still worth mentioning. Added that quote from article.


Removed following conclusion / opinion:

Ignoring for a moment its own built-in malware, Windows is a pile of legacy code full of security holes that is easily compromised.

Either not needed due to other points raised or should be proven with references.

Mistakes happen. They forgot to strip symbol names. Why would anyone add key named NSAKEY anywhere… To refute the accusation, the source code could have been released. We could recompile and either have a deterministic result or the diff should be minimal. There might not be enough evidence to proof NSAKEY key specifically was used or could be used to spy on users but there’s enough evidence to seriously consider this. Due to this uncertainty, it’s worth at least leaving this mentioned in the wiki. People can read and then make up their own opinion on that.

Fixed and rewritten.

Now using specific quotes from that a article.

Duplication was removed.

i’m signing on with this. this isn’t a new debate here. it’s been going for decades for a reason. lol!

that being said, i’ll also cosign wih cleaning the page up a bit. the last things we want to do are either create a false sense of security with the use of one host os or spread fud regarding the use of others. i think this will be even easier once whonix host is ready for release, since it will hopefully be relatively straightforward to explain both the privacy and security benefits offered by whonix host.

1 Like

It’s still full of FUD and just as ridiculous as it was before. Still peddling FSF/GNU FUD, “Windows Insecurity” FUD, “Linux is secure” misinformation, “Windows Backdoors” FUD etc.

That’s not a valid argument at all. It’s a baseless claim with 0 evidence. The burden of proof is on you to prove it’s a backdoor, not on Microsoft to release their source code.

Grepping the Whonix source code for “nsa” gets me some results. Definitely a backdoor. Now hire a team of security experts to audit all of Whonix and disprove me.

https://www.whonix.org/w/index.php?title=Template:Windows_Hosts&oldid=56930

Windows Backdoors

No evidence of backdoors so those points were moved into the user freedoms restrictions.

Adversary Collaboration

This is massive misrepresentation of what’s actually happening and I already debunked this above. Embargoes aren’t malicious.

Duplicate.

That was a bug that was fixed.

Your source doesn’t say that.

Already covered. Second link is also entirely unsubstantiated FUD.

Again, it does not say that.

Opinion by GNU Project
Opinion by Free Software Foundation

GNU/FSF calls everything that isn’t free software “malware”. Their claims are baseless FUD and they are not an authority on security/privacy.

Windows Insecurity

Mostly already covered. First part is a duplicate. Windows not being classed as a “security-focused OS” on some Wikipedia list tells us nothing. There are security-hardened Windows versions although I would never trust/recommend them https://ameliorated.info/

Windows Historic Insecurity

Already covered.

No Security From Diversity

Makes no sense. Every Linux distro runs the same Linux kernel so 1 kernel exploit can affect them all. Distros simply rebranding themselves doesn’t make them immune to exploits that work on another.

It is effectively impossible to directly talk to developers for most people.

Not true at all. No clue where you got that from. Most developers even have Twitter accounts for example.

Freedom Software Superiority

Already covered.

As for the main https://www.whonix.org/wiki/Host_Operating_System_Selection article.

The overview section I wrote before should’ve been kept. You made no points against that.

macOS Hosts

Just FSF/GNU FUD and I’ve already covered why they aren’t an authority.

Recommendation
GNU/Linux Hosts
Recommended GNU/Linux Distribution

Edits I made before to these should’ve also been kept.

This is a backdoor in my book:

Encryption Microsoft has backdoored its disk encryption [archive]. Quote:

But what is less well-known is that, if you are like most users and login to Windows 10 using your Microsoft account, your computer automatically uploaded a copy of your recovery key — which can be used to unlock your encrypted disk — to Microsoft’s servers, probably without your knowledge and without an option to opt out.

“When a device goes into recovery mode, and the user doesn’t have access to the recovery key, the data on the drive will become permanently inaccessible. Based on the possibility of this outcome and a broad survey of customer feedback we chose to automatically backup the user recovery key,” a Microsoft spokesperson told me. “The recovery key requires physical access to the user device and is not useful without it.”

This too:

Software Choice and Deletion Windows has a feature to remotely deleting applications installed through Windows Store [archive] from the computer. At time of writing there are no known cases of abuse of this feature. It was only used for malware removal.

I didn’t see it when I re-read all of this last time. Please copy/paste.

Nobody said that here afaik.

Moved accordingly.

Source?

This is a backdoor in my book:

Encryption Microsoft has backdoored its disk encryption [archive]. Quote:

But what is less well-known is that, if you are like most users and login to Windows 10 using your Microsoft account, your computer automatically uploaded a copy of your recovery key — which can be used to unlock your encrypted disk — to Microsoft’s servers, probably without your knowledge and without an option to opt out.

“When a device goes into recovery mode, and the user doesn’t have access to the recovery key, the data on the drive will become permanently inaccessible. Based on the possibility of this outcome and a broad survey of customer feedback we chose to automatically backup the user recovery key,” a Microsoft spokesperson told me. “The recovery key requires physical access to the user device and is not useful without it.”

This too:

Software Choice and Deletion Windows has a feature to remotely deleting applications installed through Windows Store [archive] from the computer. At time of writing there are no known cases of abuse of this feature. It was only used for malware removal.

I didn’t see it when I re-read all of this last time. Please copy/paste.

Nobody said that here afaik.

Moved accordingly.

Source?

Rewrote that just now:

Tiered Stability (Updates Testing)

Windows forces lower-paying customers to install new updates and gives higher-paying customers the option of whether or not to adopt them. Quote [archive]:

Windows 10 Enterprise does allow users to postpone any update indefinitely but it is only available in bulk licensing.

Entirely unsubstantiated is something else. There’s no claim of proof. Only reasonable suspicion. If that isn’t suspicious, nothing is. Worth mentioning.

Difference: can read the source code. Reverse engineering the binary is way harder.

Not true.

Gross generalization. I haven’t seen any serious rebuttal.

Wondering…
Who is an authority on privacy?

Indeed. The link to https://en.wikipedia.org/wiki/Security-focused_operating_system is there to explain the term security-focused operating system, not to show that Windows isn’t listed there.

The quote is, bold added:

Due to Microsoft’s restrictive, proprietary licensing policy for Windows, there are no legal software projects that are providing a security-enhanced Windows fork.

ameliorated.info might not be a legal software project. I write “might” because nobody can know until a court solves this question. Also I can’t give legal advice. ameliorated looks anonymous. For good reason. Nobody can survive Microsoft lawyers when software forking Windows without permission.

Since someone might challenge legal vs not legal…
My challenge (going to be expensive if lost): 1) reside inside USA, fork Windows, redistribute, publish real names, get popularity. Then see if Microsoft is going to sue and who wins in court.

Theory vs reality. In theory it could be that way. Many things conceiveable in theory don’t happen in reality. In this case in practice it’s not happening.

Keyword is effectively.
That sentence is not an absolute. Of course, someone somewhere might talk to Windows developers but it’s not the norm.

This point and above I don’t think any progress can be made as for agreement.

That would need a detailed discussion point by point and not just deletion of the whole thing.

Not reviewed yet.

That was debated earlier in this forum thread. I disagree with that and I don’t think it’s productive to debate this ad-infinitum.

Exactly.

Windows officially admits their data mining activity and gives users so-called options to “choose” what they share. Third parties have uncovered time and time again, these user choices are ignored and there is no way to disable data gathering completely.

Let’s take a look at net effect on privacy:

  • A securely coded windows that resists third party spyware + includes data snooping in its core = net loss of end user freedom/privacy and security risk as NSA has been know to use windows error reporting for aiding exploitation.

  • A less defended libre kernel is more vulnerable to active attacks + no privacy invasive code include by default = net gain of privacy by default as nothing is being reported anywhere unless someone decides to target you.

Windows is malware because of what it does. I don’t care if you trust that particular party for some reason with all the data it collects. Their compiler was even caught slipping in telemetry features in apps compiled with it. Classic backdooring.

macOS has added telemetry to their local folder search.


Proprietary software doesn’t need more defenders. I am sure their massive budgets and monopolistic agreements with OEMs and user ignorance has done more than enough to secure their tyranny. Let’s look at how we can improve what we have here so users have a reasonable shot at having any privacy in this age.

It’s not. It’s a backup.

You even acknowledged yourself that it could be a useful feature, not a backdoor and even considered “backdooring” Whonix too.

You’re completely misrepresenting what they’re actually doing. As said in the articles linked, Microsoft gives some companies early access to vulnerability info/releases so they can patch their systems before it’s public.

This is done everywhere and isn’t an issue. Linux does this too.

https://www.kernel.org/doc/html/latest/admin-guide/security-bugs.html#coordination

Fixes for sensitive bugs, such as those that might lead to privilege escalations, may need to be coordinated with the private <linux-distros@vs.openwall.org> mailing list so that distribution vendors are well prepared to issue a fixed kernel upon public disclosure of the upstream fix.

It’s what you’re saying.

It’s still hardly “sabotage”. Should be put in the user freedoms restrictions: “Only paying customers can postpone updates”.

Not a big difference since we’ve already covered that hiding backdoors in open source code is just as easy.

It is.

https://www.gnu.org/proprietary/proprietary.html

Proprietary Software Is Often Malware

“Often” is far too often for GNU/FSF.

Already debunked one of their points above as an example and am not going to spend an entire week debunking the entire website.

Actual respected experts e.g. Bruce Schneier.

Which doesn’t mean anything. Windows is still far ahead than standard Linux distros and even has advantages over Qubes. Where’s CFI in Qubes again?

It doesn’t really matter. It’s still a security-enhanced version.

No, it’s not a theory. It’s a reality and it is happening in practice. There’s plenty examples of widespread Linux malware e.g. https://arstechnica.com/information-technology/2019/05/advanced-linux-backdoor-found-in-the-wild-escaped-av-detection/

It makes no sense to claim malware on e.g. Debian won’t work on Ubuntu when they use nearly all of the same software. They just come from different repositories.

Still not true. It’s easy to talk to Microsoft devs. Again, many even have Twitter accounts where any random person can talk to them. I can even give examples if you want me to.

  • Files on devices can be deleted if they were downloaded from sources competing with Apple companies.

I don’t see that in the GNU page.

  • Intentional backdoors allow remote root privileges, wipes and deletion of applications.

No, the “remote root backdoor” was a bug that was fixed. Perfect example of GNU’s FUD. They immediately call every bug in proprietary software a “backdoor” with no evidence of such.

The deleting apps thing is behind a paywall so I can’t see it.

  • An insecure design allows execution of malicious code by applications and the extraction of messaging history.

Big deal. It had a few bugs in the past. Everything has.

  • Devices are bricked if fixed by an “unauthorized” repair shop.

That’s true and is shitty but it’s not a privacy/security issue.

  • Devices are bricked that were unlocked without permission.

This just seems like they fixed a verified boot bypass.

  • Biometric markers like fingerprints are used for device authorization.

That’s not an issue. You can get fingerprint readers on Linux too.

  • Extensive personal information is sent to Apple servers, such as:

All telemetry can be disabled.

And there were no real rebuttals to my points.

Straw man. Not once have I claimed that Windows doesn’t have privacy issues. I’ve acknowledged Windows’ privacy issues numerous times now. Read the discussion, stop making wild assumptions and stop putting words in my mouth.

I know Windows is spyware. I’m not claiming otherwise.

All macOS telemetry can easily be disabled and you can verify that it is with simple network monitoring.

Good to see we agree on something. I equate privacy with security because they are very much related in the real world especially for whistleblowers.

That’s besides the point. Most people don’t know about it and will never disable it. Defaults matter. Windows in theory also allows you disable its spyware.

macOS asks about telemetry during install and makes it extremely easy to disable.

It doesn’t respect those options fully unlike macOS.

honestly, i don’t think this is truly fair. it was a horrible choice of variable wording on microsoft’s part, which also became public knowledge around the same time of the controversy involving the secret nsa router closet with at&t as i recall. microsoft did ackowledge the controversy. but, if i also recall correctly, the discussions on this broke down.

this also wouldn’t be the first time that something shady or unethical was exposed with microsoft. as an example, despite microsoft’s “anti-piracy” aggressive litigation stance, metadata in wav files for their media player with xp demonstrated that a version of soundforge was used to process the wav files was supplied by a well known cracking group. despite the horrible public relations that could have caused, microsoft missed that, even though it should have been obvious. microsoft has a rediculously huge development team, both in house and out sourced. is it that unrealistic to believe that employees involved may be nefarious in the context raised in this paragraph regarding “nsakey”? it’s a valid concern, despite being paranoid.

yes, i agree with you that “open source” doesn’t absolutely provide greater security. but, the option to audit is there, which is absent with microsoft. and that is a fair critique at the end of the day. does “open source” make something more secure? obviously not. the ancient bash vulns discovered way too late obviously prove that. but, they were discovered eventually due to it being open source, which may never have been discovered or addressed by the likes of microsoft absent a very open and problematic exploit in the wild that stood to harm their stock prices. if the exploit was discovered by microsoft privately, and it didn’t stand to affect their market share if not disclosed, it’s not an unfair critique to believe that microsoft may have avoided addressing it if the thought was there that it could harm their bottom line if publicly addressed. after all, that’s the oracle way, no?

furthermore, since you brought up the debate regarding privacy vs. security, it would appear that we agree that debian respects privacy more than microsoft, apple, google, etc. whonix host is looking to plug the security holes that exist in vanilla debian. thus, when whonix host is reaady, while i agree with you that the “linux is more secure than windows” argument is largely bogus from various technical standpoints at this point as far as exploits are concerned, i think the whonix team will be able to make a case for being better for both privacy and security once whonix host is released. in my honest opinion, that should be the focus. once whonix host is ready for delivery, the “other os” wikis can be focused on that, which i think will be more beneficial.

if anyone thinks i’m off base here, please let me know. but, let’s keep this away from a “microsoft/apple vs. linux” debate. there are way too many subjective uses which makes that debate unfinishable. but, for what whonix adrdesses, which is a fairly specific use case, i think we can do it without engaging that debate.

point blank, whonix will never be a panacea. but, for people who want a best case scenario for anonymity with an operating system, whonix fulfills a need there, which will be even better with whonix host. if we keep the focus on that without engaging in fud, hyperbole, or pie in the sky promises, i will continue to believe, and promote, that whonix is the best os for this use scenario. it will never be perfect. but, what compares?

absent qubes that implemented whonix templates, i can’t offer much as an example in that regard referenced above. but, as someone who was once involved with very problematic activism as far as some govs were concerned, compatriots of mine who didn’t use whonix, but used tor, got busted due to very trivial mistakes. i’m still free. that is a huge selling point for me. whonix was the main difference, and i’m not implying that i engaged in anything criminal. whonix kept me free of harassment that could have affected my immediate freedom, right to travel, or employment opportunities. whonix alone wasn’t the answer there. but it was an incredibly significant part, which freed me of relying on a number of custom scripts and steps to anonymize a debian host, which i’d developed for my own use over years of experience, and could still screw up. and, for that, i will forever be thankful. if the majority of clients i have now knew of my involvement with “anonymous,” i would not have a job, despite being no threat to them. that is part of the reason that i started publicly sharing an originally private document through anonymous on how to set up a basic system using debian as a host with whonix as virtual machines. and it’s why i publicly updated it for years.

in the end, i think we all need to keep focused on the notion that whonix is both a secure and private os for people who want anonymity. that is the end goal, correct? the debates on the flaws of other operating systems are less relevant there, since the enhancements that whonix team actively works on is better for people who want anonymity in comparison to the others. let’s keep the focus there. we don’t need to bother with the “linux vs” arguments, since this is “whonix vs” for those who want an anonymity geared operating system.

1 Like

Since I won’t have time soon for this the potentially remaining Windows / macOS enhancements suggestions from this post Long Wiki Edits Thread by @madaidan I’ve created ticket https://phabricator.whonix.org/T993 as reminder and mentioned this in on the related wiki pages.

Added to wiki just now.

I disagree and then you are going to say “I don’t have to to refute them”. I.e. no agreement will be reached. But it’s not necessarily you that has to refute them anyhow. GNU/FSF are popular. Meaning:

  • If GNU/FSF make libelous claims, it is likely that they will be on the receiving end of a defamation lawsuit. This didn’t happen yet to my knowledge.
  • The internet is big. Others would have made a rebuttal. If you can find a good one, that might be a a good alternative as rebuttal.

Any write-up is non-perfect and the GNU one was a comprehensive one.

Agreed. Who build the security and for what purpose. Benefit of user or maximizing profit at expense of privacy and security from vendor.

It’s besides the point. Please don’t cling on a single phrase “Level Security” and then view everything through that lens. That chapter has to be viewed in a bigger context.

The headline iPhone and Android Level Security for Linux Desktop Distributions is also bad for other more pragmatic reasons. Through conversations I’ve learned that many people know about how bad many phones/mobile apps are in their default configuration for privacy they equate this with security, and then intuitively discard the idea that iPhone / Android have any worthwhile security features worth porting to Linux desktop. I.e. even if iPhone and Android Level Security for Linux Desktop Distributions was fully possible in theory and even if madaidan would agree, it would still be bad self-representation of the project. Will change chapter title to Kicksecure Development Goals.

https://googleprojectzero.blogspot.com/2020/02/mitigations-are-attack-surface-too.html

Interesting. Added.

https://www.whonix.org/w/index.php?title=Kicksecure&oldid=57338&diff=cur

Please don’t do “burn the house down” / delete all changes. Rejected edit. Took some changes suggested with modification by me. And added more content.

2 Likes

No, I’ve even refuted some of their points above.

Big companies like Google or Apple don’t care about them.

I’m not clinging to that. I don’t really have much of an issue with the title.

Just look at the comparison table. It’s wrong to pretend that the full system MAC policy in Android and Kicksecure are similar. SELinux is ingrained into Android’s architecture and the entire ecosystem was shaped around it. Additionally, SELinux allows for far more restrictive policies (e.g. ioctl filtering or even just stricter permissions for files) than apparmor.

We’re slapping an apparmor policy on top of an OS that it wasn’t intended for. While this is good and we can make some great progress with it, it’ll never be as good as a strict policy on top of an OS that was designed for it.

Another example is the hardened kernel row. Our hardened-kernel is nice but it’s not the same as Android. Android kernels contain a lot of hardening patches including fine-grained forward-edge Clang Control-Flow Integrity and ShadowCallStack to prevent code reuse attacks (CFI/SCS is only on Pixels >=3 though). CFI isn’t in mainline or linux-hardened and won’t be for a long time. ShadowCallStack isn’t even possible on x86 due to the way it handles returns.

Although, I’m looking more into Android/Qualcomm’s hardening patches and might submit some to linux-hardened (I’ve been talking to Daniel Micay about this on Matrix).

The comparison table is also neglecting to mention all the advantages of Android over Kicksecure. One example is that Android has the majority of the system written in memory safe languages (Java). Another example is that Android/iPhone has modern user space exploit mitigations like CFI/PAC.

This subject is too complex to be a simple Yes/No comparison table which is why I removed it and expanded a bit below it. What I meant by “Security is not just a checklist of features” is that the implementation matters. Not the general topic. Sure, you can have a “sandbox” but that doesn’t mean it’ll actually restrict anything meaningful for example.

I don’t think it should mention mitigations specifically since it’s not just mitigations vendors introduce. They add tons of bloatware that contain their own security vulnerabilities. I’ve found Samsung to be particularly egregious in this regard although sane vendors like Google are usually fine.

I’m not. The comparison table just doesn’t make sense.

1 Like
[Imprint] [Privacy Policy] [Cookie Policy] [Terms of Use] [E-Sign Consent] [DMCA] [Contributors] [Investors] [Priority Support] [Professional Support]