01The Principle of Least Privilege, Taken Seriously

Windows has had user accounts for decades, but its culture has long defaulted to administrator-level access. Installers demand elevation; software expects to write wherever it likes; the operating system itself has historically run critical services in contexts that own the machine. Linux inherited a different reflex from Unix: the assumption that no process should have more access than it needs.

Permissions, package trust, and a smaller attack surface.

On a typical Linux system, your daily-use account cannot touch /etc, install system packages, or write to another user's home directory. Privilege escalation is explicit — you reach for sudo, the system logs it, and you drop back down when you're done. This isn't theatre. When a piece of malware lands in your browser or a document viewer, it inherits the permissions of the process that launched it. On Linux, that ceiling is low. On a default Windows install, it has historically been much higher.

The kernel enforces this through a mature discretionary access-control model and, on most modern distributions, through mandatory access-control frameworks layered on top: SELinux (shipped and enforced by default on Red Hat and Fedora), AppArmor (the default on Canonical's Ubuntu and SUSE's openSUSE), and seccomp profiles that restrict which system calls a process may even attempt. A compromised application confined by a tight AppArmor profile cannot simply reach out to /etc/passwd or open a raw network socket. The damage is contained before it begins.

02Where Your Software Actually Comes From

The Windows software model has a fundamental trust problem: you find an installer on the internet, you run it, and you hope the developer's signing certificate is legitimate and that their build pipeline hasn't been tampered with. Supply-chain attacks against Windows software — trojanised update servers, certificate theft, compromised installers — are a recurring class of real-world incident.

Linux distributions solve this differently. Packages in the official repositories of Debian, Arch Linux, Fedora, and every other mainstream distribution are reviewed, built in controlled environments, and signed by the distribution's own key. When apt, dnf, or pacman installs software, it verifies that signature before touching a single file. You are not trusting the upstream developer's server or their build machine — you are trusting the distribution's chain of custody. That chain is auditable; the Debian Project and the Arch Linux project, for example, publish their build infrastructure and signing policies publicly.

Flatpak and Snap extend this into sandboxed packaging for third-party software, adding a second layer: applications run in restricted containers with declared permissions that the user can inspect, and a clear separation from the host system. It is not a perfect model, but it is structurally sounder than downloading an .exe and running it as administrator.

Linux desktop sharesmall fraction of the total desktop market, reducing commodity malware targeting

03Attack Surface and Monoculture

Windows dominates the desktop. That dominance makes it the profitable target: malware authors write for the audience, and the audience is Windows. Linux's desktop share is small enough that commodity malware almost never bothers targeting it. This is not a security argument on its own — security through obscurity is not security — but it is a real, practical reduction in day-to-day exposure.

The more durable argument is monoculture. The Windows ecosystem is architecturally uniform: one kernel codebase, one shell, one update mechanism, one registry. A single critical vulnerability can be weaponised across essentially the entire installed base simultaneously. Linux is structurally diverse — different kernels at different patch levels, different init systems, different distributions with different default configurations. The Arch Linux project and Red Hat ship fundamentally different security policies. That diversity raises the cost of a single exploit achieving widespread effect.

Open-source development also means that the kernel, the core libraries, and the toolchain are under continuous, public scrutiny. Bugs are found and fixed by parties who have no commercial incentive to downplay them. A vulnerability in glibc or the Linux kernel typically has a patch on the mailing list before it has a CVE number. The audit surface is wide open — which cuts both ways, but on balance, sunlight beats a closed room.

None of this means Linux is invulnerable. A misconfigured system, an exposed SSH daemon with a weak password, a user who types their root password into a phishing page — architecture does not save you from yourself. But the structural defaults are better, the software supply chain is sounder, and the privilege model actually has teeth. That combination matters.

The players

Canonical

Company

company behind Ubuntu Linux

Red Hat

Company

company behind RHEL and Fedora; develops SELinux

SUSE

Company

company behind openSUSE and SLES; ships AppArmor by default

the Debian Project

Community

volunteer organisation maintaining Debian Linux