In 2016, Linux celebrated its 25th anniversary. It started as a student project and is now everywhere: from smartphones, supercomputers, web servers and cloud boxes, to the latest smart cars.
Even the exception, the end user, is moving towards Linux, considering that Android is currently the most popular operating system for mobile devices. In addition, Chromebooks are becoming increasingly popular.
Even traditional Linux desktops like Arch, Debian, Fedora, openSUSE, Mint, and Ubuntu seem to be finally gaining ground. Of course, the Linux desktop market share is still very small compared to other operating systems, although there have always been Linux users.
On the other hand, almost all websites and many, many Software-as-a-Service (SaaS) run on this particular operating system.
Even Microsoft has reportedly finally made a move towards the penguin, after becoming an official member of the Linux Foundation last year
So, with everything that's been happening lately, why should we worry?
Because now any hacker who is truly a hacker and not just some script-kiddie can attack Linux as open-source, hunting for vulnerabilities.
Open-source community leader Eric S. Raymond pointed out years ago in Linus's Law that: “Givenenough eyeballs all bugs are shallow.” This is one of the key concepts that has made open source operating systems the success they are today as they empower open source software.
But it only works if there are enough eyes looking for bugs to fix the code. Estimates for the number of bugs per thousand lines of code (KLOC) range from 15 to 50 bugs per KLOC, and as low as three if the code has been very rigorously tested and verified. The Linux kernel alone currently comes with over 16 million lines of code. Do the math….
In 2016 alone, we saw two major Linux security flaws explode before they were fixed. These were in LUKS disk encryption and Dirty Cow, a problem with Linux memory. There were other less significant Linux bugs in 2016, but to the developers' credit, these issues were fixed almost as soon as they appeared.
In fixing problems in its code, Linux has broken all records, and the support it provides is far superior and much more immediate than that of Apple, Microsoft, or any other closed-source software vendor.
But let's do the math:
There are at least 3,000 bugs that need to be discovered and fixed…
Of course, there are top Linux security programmers tasked with hunting down these bugs. There are also guidelines for how to report bugs when you find them. But there are never enough programmers to fix even the reported bugs.
One of the leaders of Linux, Jon “Maddog” Hall, observed a few years ago:
“Some people argue that Free Software has unlimited resources, but every product or project is resource-constrained in one way or another. The number of people who can work on free software is limited to the people who have the ability, time, and willingness to contribute.”
When he wrote that in 2009, that many users of the operating system are also developers, that may have been true, but that is no longer the case. Yes, many developers use the operating system, but there are also hundreds of millions of “users” who couldn’t tell the difference between Java and JavaScript, let alone fix a bug.
At the same time, hackers have more incentive than ever to break the open source operating system. Irish developer Donncha O'Cearbhaill, who recently disclosed two bugs in the Ubuntu desktop saidhe was offered $10,000 by a malware company.
“These financial incentives only increase as software becomes more secure and bugs are harder to discover,” he said.
As you can see from the above, the popular open source operating system has gained great power. And because great power also entails great responsibility, developers must take it upon themselves to maintain its security.
The idea for the publication came from ZDNet and the article by Steven J. Vaughan-Nichols
