logoalt Hacker News

tentacleunoyesterday at 11:23 PM1 replyview on HN

Yeah, there's definitely a happy middle ground. I'm a firm believer in gaining a good understanding of your threat model before taking steps to protect it -- quite a surprising amount of people use Qubes, Graphene, Kicksecure and such without really understanding what they want to protect themselves against. In a lot of cases, that just adds unnecessary friction and overcomplexity that ends up doing more harm than good. I was guilty of this myself.

On paper, I'm sure Windows does have stronger userspace and kernel-space protections against intrusion and such, though I most certainly wouldn't use it.


Replies

g-b-ryesterday at 11:46 PM

It's not about a middle ground, their idea of security is wrong.

They largely ignore any threat that could come from US agencies, and are very presumptuous about some of their convictions (e.g. that open source is irrelevant for security).

There is a balance to be made, given that there often isn't any ideal option, but they often get that balance assessment wrong, in my opinion.

I appreciate exposing the security weaknesses of other products, but they end up adding threats that they don't have with some of their drastic views.

show 1 reply