linux isnt immune to viruses even though its not as bad as windows

what should i do to be safe if i have a safe browser, vm, but pirate and download risky things? i know its a vm but i still dont want to have to delete everything in the vm if something happens. also the malware doesnt go to the router and spread rigt???

  • gandalfthewhite@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    53 minutes ago

    Honestly the biggest things are don’t run shit as root and don’t expose port 22. Especially don’t run things you downloaded from some website as root but in general just don’t run things as root. That’ll handle most problems that are likely to arise.

  • TrollAccount69@lemmy.ml
    link
    fedilink
    arrow-up
    4
    arrow-down
    1
    ·
    2 hours ago

    You could make backups and practice restoring from them so you can not lose everything when you screw up.

    You could learn not to screw up, which would go hand in hand with the above.

    You could switch to a mac and enable all the security and privacy stuff in macos (there’s quite a bit, it’s well documented and very extensive!).

    You could stop downloading from public sites and trackers and instead get on private trackers and use them exclusively.

    • lemmingsareawesome@sh.itjust.worksOP
      link
      fedilink
      arrow-up
      2
      ·
      2 hours ago

      1 does it take a lot of space usually?

      2 how to do screw up (you need to screw up to learn how not to) and not get screwed with the consequences

      3 thx

      • SayCyberOnceMore@feddit.uk
        link
        fedilink
        English
        arrow-up
        1
        ·
        57 minutes ago

        1 - there’s 2 things to consider here… A) Your files (documents, photos, etc) B) Everything else (the Windows / Linux mac operating system, applications, your screensaver, printer defaults, etc)

        You only need to backup A.

        It’s up to you if you want / have space for B

        But, 1st time, backup everything. Then do item 2 (screw up) big time and do a full restore.

        Once you’ve done that, you’re set for life

      • TrollAccount69@lemmy.ml
        link
        fedilink
        arrow-up
        2
        ·
        1 hour ago

        It either takes up a lot of space or it doesn’t. I don’t know how much you’re backing up or how much space is a lot to you.

        You can’t screw up and learn without the consequences. That’s how you learn. Without the consequences you don’t take things seriously. Backups will help you to recover when you do screw up.

  • mazzilius_marsti@lemmy.world
    link
    fedilink
    arrow-up
    8
    ·
    6 hours ago

    compartmentalization

    top reasons why GrapheneOS is highly praised: ability to create different profiles with different encryption keys, and hardened codes.

    on Linux, the top choice is QuebeOS. But i tried it 4 times and still couldnt go with it. My laptop couldnt handle quebeos…

    The other choice is SecureBlue. I heard that is called the Graphene of Linux. They have hardened codes, secure browser and very strict secure defaults. The downside? You need to be able to use distrobox, flatpak, rpm-ostree, brew to maintain your apps. So in a way, it is the same compartmentalization, but a bit messy.

    If u cant deal with these 2, then maybe use TailOS to do your download. Not sure if it saves the data?

    Using VM is also great. But i think a “super VM” is the only answer and that is QuebeOS. You can literally control everything inside each VM.

  • Lettuce eat lettuce@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    5 hours ago

    Idk what software you’re using, but most VM software has an easy way to take a snapshot of the VM state. If you’re about to download something risky, take a quick VM snapshot, so if it ends up being some kind of malware, you can just roll the VM back to its earlier state without issue, takes like 2 minutes.

    If you’re worried about malware spreading through your network, you need to isolate your devices. The most common way to do this is with VLANs, but I don’t know what your home network looks like, and if you just have a typical home setup with your ISP’s modem/router and all your devices plugged into it or on the default wireless network, you won’t be able to do that.

    You could also use something like UFW on Linux to only allow internet traffic and block any traffic inbound or outbound to your LAN network, isolating your PC from all other devices on your LAN. This isn’t great, because if your host is compromised, then your host-based firewall could also be compromised and the malware could then get out to the rest of your network.

    You could invert this and have all your other devices on LAN set to block all traffic from your specific PC, which would be more secure, but also a pain to configure, plus it assumes all the other devices are able to be configured in that way on your LAN.

    There are a bunch of other solutions, but it depends on your setup, your technical skill level, and your threat profile. If you’re just torrenting cracked games and random software, that’s somewhat risky, but not really that crazy if you are running it in a VM with rollback snapshots.

      • Lettuce eat lettuce@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        3 hours ago

        Let’s step back actually.

        • What is your current PC running for an OS?
        • What VM software are you using?
        • What is your level of technical experience? (1 through 10)
        • What are you the most worried about happening to your computer and home network?
          • Lettuce eat lettuce@lemmy.ml
            link
            fedilink
            arrow-up
            1
            ·
            14 minutes ago

            If you’ve already got Qubes and Xen Hypervisor running, your technical level is high enough for sure. And honestly, your security is already probably good enough.

            Qubes has very secure defaults, I don’t think you need to do anything else, honestly what you have already might be overkill, but idk your use case.

            Make sure you can’t see your torrent/download machine VM from any other devices on your network. Use Nmap as long as it’s your network. Don’t use it on a corporate or university network, it will likely get your device totally locked out and you in big trouble.

  • Clark@lemmy.ml
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    6 hours ago

    Use Qubes OS. Do not update anything including Tor browser and the OS. Just install the new version as soon as it is released on Qubes OS website. Otherwise you will probably get a virus. I know this from experience, please take this into account

    • lemmingsareawesome@sh.itjust.worksOP
      link
      fedilink
      arrow-up
      1
      ·
      4 hours ago

      i have it but theres problems on framework 12

      it boots and u can log in but its so slow and unresponsive and the mouse doesnt work (it flies off the screen) and the ui doesnt appear most of the time

      do u think its a hardware issue or did i install wrong

      • Clark@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        3 hours ago

        A usb mouse wont work to start the OS, so it’s a hardware issue but you are very close. If you have a laptop, you could use the touchpad for the start up

          • Clark@lemmy.ml
            link
            fedilink
            arrow-up
            1
            ·
            edit-2
            2 hours ago

            It should be working normally but I’m not an expert at that. You could buy a desktop computer with a PS/2 keyboard input. You wouldn’t need a mouse with such a setup. But still you should buy a usb mouse to be comfortable

        • distal@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          3 hours ago

          You know you can build Qubes from source right? You know you have checksums? Do you know how difficult it is to compromise something like fucking Qubes, thee OS built by people who spend upwards of 12 hours a day obsessing about cyber security? There are too many eyes on it. It’s like saying Emacs is compromised.

          • Clark@lemmy.ml
            link
            fedilink
            arrow-up
            2
            ·
            2 hours ago

            I’m not blaming Qubes OS, I’m blaming fedora. I know that Qubes OS itself is reputable and reliable. What do you mean with building from source? So you don’t use the default updater?

            • distal@lemmy.ml
              link
              fedilink
              arrow-up
              2
              ·
              2 hours ago

              I’m sorry, I misread. I thought you wrote to not use Qubes. Do you have any sources regarding the stuff about Fedora? I don’t mean to deboonk you, I am genuinely curious and I dislike fedora anyway for being so commercially oriented.

              • Clark@lemmy.ml
                link
                fedilink
                arrow-up
                1
                ·
                2 hours ago

                I myself have experienced it. Of course it would be a very big event if something like that came out from a youtuber but I assure you that Im sure of it because of cosmetic changes in fonts and a lot of slow downs

                • distal@lemmy.ml
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  1 hour ago

                  I mean fonts can change due to updates. Let’s say I update KDE, I might break my theming completely.

    • Vittelius@feddit.org
      link
      fedilink
      arrow-up
      4
      ·
      15 hours ago

      And if you need an app from a third party repo, pick one that includes at least rudimentary sand boxing such as flatpak/flathub

  • MangoCats@feddit.it
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    8 hours ago

    Mirror, keep a clean copy of your setup offline. Make periodic backups. If you ever get into an unpleasant state, nuke it and go back to one you like better.

    • hirihit640@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      5
      ·
      15 hours ago

      very rare for exploits that can breach a VM. Like once-every-10-years kind of rare.

      One important thing to be aware of. By default your VM will have access to the same network resources as the host. So, say, if you use tailscale or some other secure VPN to protect your NAS, but you give your host access, the VM will be able to access it too! You can use firewall rules or bridge networking to fix this, but tbh it isn’t trivial.

      • nyan@sh.itjust.works
        link
        fedilink
        arrow-up
        2
        ·
        11 hours ago

        Depends on your VM. qemu, by default, isolates each VM on a subnet. It’s a PITA when you actually need the VM to be able to see the LAN.

    • MonkderVierte@lemmy.zip
      link
      fedilink
      arrow-up
      1
      ·
      14 hours ago

      Rather, malware detect the vm, assume a security lab testing environment and hold still. Don’t take that stuff outside.

  • minty@aussie.zone
    link
    fedilink
    arrow-up
    11
    ·
    23 hours ago

    Malware could go to the router and spread absolutely. However other devices firewalls should be pretty good at stopping that. Also I dont know how common that is for malware tbh

    • hoshikarakitaridia@lemmy.world
      link
      fedilink
      arrow-up
      7
      ·
      23 hours ago

      I think most common is phishing attacks, scammers, and then shady downloads.

      Less common is probably dependency attacks, xss, and exploiting servers in the traditional way, and probably a bunch of other attack vectors.

  • Hakuso@scribe.disroot.org
    link
    fedilink
    arrow-up
    8
    arrow-down
    1
    ·
    23 hours ago

    I have always kept everything airgapped, the best security is isolation.

    I download stuff to a tablet, with nothing of value or interest on it, dump it to the sd card, then move it to the offline systems with a USB card reader.

    Even my servers (mostly ARM SBCs with one RISC-V) were set up to work over a wired offline network.

    Also most of my pirated stuff is things I own that I yarred for the crack if it was more convenient than cracking it myself.

    • WeirdGoesPro@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      11
      arrow-down
      3
      ·
      19 hours ago

      Not gonna lie, that sounds like overkill unless you’re doing something massively illegal. Your system makes no sense for preventing detection of torrent downloading since the download to the tablet could be detected just like the download to a server, and any precaution to avoid torrent surveillance on the tablet could easily be done on the server itself.

      So…are you doing something massively illegal? Take a seat…

      Chris Hansen looking like he knows what you did

  • Sapphy@lemmy.ml
    link
    fedilink
    arrow-up
    2
    arrow-down
    10
    ·
    19 hours ago

    You can just use a VM and an antivirus on Windows. Linux isn’t really necessary for your scenario

    • Manalith@midwest.social
      link
      fedilink
      arrow-up
      2
      ·
      7 hours ago

      Windows VM in Linux is a better choice from a performance perspective since Windows already is pretty bad at managing its RAM usage.

      • Sapphy@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        7 hours ago

        Yes but we are talking about security and the risk of cross contamination. Would you really set up a VM and download risky files on the exact same Linux machine that holds all your personal data? I wouldn’t.

    • Sapphy@lemmy.ml
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      18 hours ago

      It’s best to start using different OSs for different things assuming that no single OS is truly safe

      • oopsgodisdeadmybad@lemmy.zip
        link
        fedilink
        arrow-up
        2
        ·
        7 hours ago

        Well you can just some windows is always unsafe.

        I’d argue it’s literally the worst virus, tbh. It’s terrible at literally EVERYTHING, annnnd (for activated versions that didn’t come with your hardware) costs money.

        And after all that, you still gotta deal with the Windows virus itself.

        • Sapphy@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          7 hours ago

          Windows is always unsafe.

          That is exactly the point. You want to create a psychological boundary, you treat it as a disposable system so you never put any valuable data on it in the first place

          • oopsgodisdeadmybad@lemmy.zip
            link
            fedilink
            arrow-up
            1
            ·
            7 hours ago

            That’s not a good enough reason to use it, even disposably, even as a throwaway, ever. Unless your producing music or video and can’t adapt to the alternatives, or something like that, there’s no reason to use Windows at all.

            No matter how many different layers of virtualization you use, then just different fistros. Never Windows.

        • Sapphy@lemmy.ml
          link
          fedilink
          arrow-up
          3
          ·
          15 hours ago

          OP is the kind of user who used Tails on his own computer to log into his Gmail account. He has grammar issues and thinks Linux is this hacker OS that makes you anonymous and impossible to hack

          Let’s be real, do you think this is the best thing for OP who is presumably a child?

          • hexagonwin@lemmy.today
            link
            fedilink
            arrow-up
            8
            ·
            14 hours ago

            i mean if op is a legit kid, i’d rather lead them to the world of linux than windows. at least that’s what worked nicely for me

            and please don’t accuse people of grammar issues unless it’s very obvious they’re trolling. english is not everyone’s first language. i’m also not a native speaker and struggle writing basic shits quite occasionally

            • Sapphy@lemmy.ml
              link
              fedilink
              arrow-up
              3
              ·
              7 hours ago

              I’m not a native speaker either. I mentioned his writing to point out he is literally a kid, not to mock his grammar. You can look at his account and see his posts

              ​You want to “lead him to Linux” but he clearly just wants to pirate stuff and we all know this community will mock him the second he breaks his system

              ​Instead of naively thinking about how this elitist community will “nourish” him, it would be infinitely more useful to teach him about attack surfaces and keeping personal data off a risky system entirely