This is my concern with windows, does Linux do a better job?
So being a casual PC user as I am, I like to explore the many programs made available to me. When I installed some programs, such as OBS, discord, ManyCam(so I can use my phone as a Mic), etc. and I realized the capability programs could exploit to record your screen, record keystrokes, look at your browsing history etc. with no confirmation from windows that what devices or programs an app is using.
One thing I enjoy about iOS and android software is that it gives you confirmation stating the permissions an app can do such as what it reads, writes, or other apps it utilizes. Firefox even has this where it confirms you want to use your microphone or camera with websites like discord so you are not constantly streaming yourself to foreign websites. But Windows on the other hand, just doesn't tell you.
When I downloaded discord, I was greeted with a login screen that said "checking if you are signed in" or something of the sorts. Little did I know it checked my browser to see if I was. Why doesn't windows prevent this or allow me to confirm giving permissions to applications to read other apps? This could easily be used to sell off data and to grab your email, passwords, what you browse, etc.
I also downloaded a mouse macro that allowed my to have my mouse move so I remain online on some of my apps. This had to ability to shut down my PC with no confirmation and could put it into an infinite boot loop. (Then I would have to go into secure mode to delete it)
Please don't suggest to just not download unfamiliar programs , or use solely open source programs, because I am already aware of these options . I feel like I could make a program that would seemingly be harmless, but is recording screens, looking at apps behavior, or browsing a users file system, and have it all sent to my database for data collection.
Perhaps I am being paranoid, and maybe windows defender is making sure these programs are safe, but how? What precautions can I take to see if I am being exploited? How is Linux handling this?
[link] [comments]