Windows: Insecure by design

Just to add my general thoughts & perspective:

I don’t see any way anyone could trust a Microsoft product or service with their data, especially after after what’s going on with Outlook, which I don’t think was covered enough in the mainstream at all, I guess people are just way too used to this type of data collection at this point. Selling data to over 800 advertising companies is insane. Not to mention every time I hear about this story, the number of ad companies seems to go up - It looks like we’re now at 840.

I think the key in general when it comes to this stuff is finding a balance between privacy & security. Windows does have some neat technical security features… but does it really matter if they’re just going to sell your data to over 800 ad companies? Sure, you can use group policies & regedit to mitigate the damage, but that’s only until the next surveillance feature gets added.

Linux is far from perfect from a security perspective, there’s no denying that (In general the desktop security model is just completely broken & a disaster IMO), but I think it can be a solid and good enough option for most people, especially once hardened. All just depends on one’s threat model and specific situation. It’s also worth noting that there’s a difference between insecure & less secure.

I think sometimes people just get too caught up with technical security features (Ex. seeing people shill Microsoft Edge & ChromeOS), but I’m not sure how you can say something is secure if it’s just sending all of your data to some remote server somewhere anyways. Similarly you of course can’t say something is private if it’s insecure and easy for one to break into. Again, the key is striking the right balance and what works best for you and your needs.


I think security is mostly a config thing now

Windows 11 LTSC with enterprise group policies >>

This is only applicable for free version of the personal Outlook accounts, right? Not Personal Premium or the business versions?

@Bhaelros AFAIK it pertains to ALL Outlook variants. But I may be wrong.

That advertising section which was mentioned on Proton’s blog doesn’t exist on M365 Family

and below is the only thing that is blocked by uBlock

Those advertising and data collection is not happening on business plans, that I am sure. You can even select your datacenter with business plans, along with a lot of DLP and compliance configurations. So, I can say with confidence that the advertising and data collection from Outlook happens only with Free and consumer accounts.


It wouldn’t be the first time corporations lie. You still have to trust Microsoft, regardless of what they say.


Then just recently OpenSSH Vulnerability: CVE-2024-6387 FAQs and Resources | Qualys

In Qualys TRU’s analysis, we identified that this vulnerability is a regression of the previously patched vulnerability CVE-2006-5051, reported in 2006. A regression in this context means that a flaw, once fixed, has reappeared in a subsequent software release, typically due to changes or updates that inadvertently reintroduce the issue. This incident highlights the crucial role of thorough regression testing to prevent the reintroduction of known vulnerabilities into the environment. This regression was introduced in October 2020 (OpenSSH 8.5p1).

Why isn’t everyone looking at the source code!


Might that be simply because Windows and macOS are proprietary, so security analysis that can be done on Ubuntu cannot be done on Windows or macOS? FOSS allows the study of exploits via source code analysis.

I never said Windows doesn’t have security features, that Linux is secure, or that FOSS implies secure. What good are Windows’ security features if Microsoft can remove/disable them or insert backdoors at their own whim, and the operating system in general is spyware? That seems to be lost on people who have been sucked up into the Microsoft corporate vortex. I don’t believe my Linux operating system is really secure, but I would never ever ever trust Windows with my data or activities.

But yes, the article is obviously biased as evident in its exclusive criticism of Windows. Unless the Linux user is willing to go to extreme lengths to harden their operating system and vet the software that is installed, which is unreasonable to expect users to have to do, Linux is nowhere near as secure as it should be.

Yes. For reference, for those starting this journey and looking for some reading on this topic, one can find some information on these sources: Privesec and Madaidan.

Nevertheless, adopt a certain level of criticism when reading because of two reasons: it was created some time ago, and certain deficiencies could have already been fixed or improvements made since Linux is evolving quickly nowadays; second, certain things are exaggerated.

In the Fedora community there are plans or discussions trying to captivate improvements in the security front.

I feel that Linux, in general, is kind of like democracy or capitalism - it has problems, but it’s probably the best system that mankind has available today if you’re looking for a decent balance of security and privacy. Of course, each case is different, and at least for my threat scenario, Linux offers this aforementioned balance.

