Linux Users Talk a Big Game About Security and Privacy
-And they routinely sabotage both through culture‑driven habits that are objectively insecure.
Linux's security reputation is mostly cultural mythology, not technical reality. The same culture that repeats the myth also encourages behaviors that directly undermine security and privacy.
They put blind trust in package maintainers while declaring "Windows has malware because people download random EXEs." They proceed to install random PPAs, Pipe curl scripts into bash, trust maintainers they never met, and treat distro repos as holy. -It takes a special person to trust (actually have faith) in 'free stuff'.
Linux users think "sudo is safe because it asks for a password." -They become desensitized to it and enter sudo for everything. They'll run installers with sudo because the README said so, use chmod 777 as a debugging technique, and disable AppArmor/SELinux because it "gets in the way". It's simply not conducive to what a desktop computing experience should be.
They say, "I care about privacy.", then use Discord, Steam, Chrome, VS Code, proprietary drivers, and sync everything to GitHub. They'll use VPNs run by unknown companies (found in some YouTuber ad), post screenshots of their desktops with username visible, and run random GitHub scripts that exfiltrate critical system info.
"No one targets Linux." - Attackers target servers, not desktops. Supply chain attacks don't care about your OS, browser exploits don't care, phishing works on everyone, and misconfigurations are universal. Linux users behave like they're immune to physics.
"Linux is secure because it's niche" (obscure distros with unpatched kernels.) AUR packages are maintained by ghosts. They'll run outdated software because "rolling release broke something", and disable auto‑updates because "I want control"
They assume open source is safe, but no one audits most code, maintainers burn out, projects get abandoned, malicious commits slip through all the time, and dependencies chain in the distance. Transparent doesn't mean secure. -I think this 'all eyes on code' myth, they're finally starting to drop.
No replies yet