Schleswig-Holstein, Germany’s most northern state, is starting its switch from Microsoft Office to LibreOffice, and is planning to move from Windows to Linux on the 30,000 PCs it uses for local government functions.

Concerns over data security are also front and center in the Minister-President’s statement, especially data that may make its way to other countries. Back in 2021, when the transition plans were first being drawn up, the hardware requirements for Windows 11 were also mentioned as a reason to move away from Microsoft.

Saunders noted that “the reasons for switching to Linux and LibreOffice are different today. Back when LiMux started, it was mostly seen as a way to save money. Now the focus is far more on data protection, privacy and security. Consider that the European Data Protection Supervisor (EDPS) recently found that the European Commission’s use of Microsoft 365 breaches data protection law for EU institutions and bodies.”

    • naticus@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      I wouldn’t say that Windows is malware itself, but rather it wasn’t created with a security-first stance, which we absolutely need for all OSes going forward. I say this as someone who ditched Windows as my DD (“I use Arch, btw”). I left Windows more for their policies and subscription models that are becoming increasingly anti-consumer.

      With that said, let’s not pretend that Linux is immune as has been proven in the past week with xz and liblzma being compromised. Yes, it took 3 years to get to the point their long game paid off, but it still happened through a series of credibility social engineering steps by a single person. (Yes I know others were also trying to do exactly this, but only Jia Tan was successful)

      • shortwavesurfer@monero.town
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        Of course, there can be malware for open-source systems such as Linux, but it’s generally caught and patched a lot faster.

      • 0x0@programming.dev
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        (Yes I know others were also trying to do exactly this, but only Jia Tan was successful)

        The reason you know is because the target software is FOSS. Care to bet other similar schemes have been successfully pulled off with proprietary software?

        • baseless_discourse@mander.xyz
          link
          fedilink
          English
          arrow-up
          0
          ·
          7 months ago

          I think because there is so many surveillance built into proprietary software, companies like U.S. probably can just ask for any information from Apple, Google, Facebook, Microsoft when they need it.

          On the other hand, countries like China and Russia would need to compromise these product like Jia Tan did. Except for Apple, because every apple service in China is maintained by a Chinese company with no encryption allowed.

        • Blaster M@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          7 months ago

          You only know this happened because one dev was benchmarking their system and noticed a 0.5s anomaly in resource usage, and was able to track it down to this. For every one of these that are caught, there are countless more that slip past.

          • Cataphract@lemmy.ml
            link
            fedilink
            English
            arrow-up
            0
            ·
            7 months ago

            I actually look at it a completely different way. There are so many users optimizing and digging into the core of open source versus proprietary that with so many randoms actions there’s less “vulnerable” dark spots available. If we think there’s a limitless X amount of vulnerabilities (since we don’t know the true ceiling limit), open source will always be “X (vulnerabilities) - 1” compared to proprietary. Completely a math metaphor but gets the point across, It’s a path that lessens the impact which we should be striving for over profit/monopoly motives.

    • BearOfaTime@lemm.ee
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      7 months ago

      In the enterprise space, Windows isn’t an issue at all.

      This is because enterprise manages security properly - layered, minimum perms to perform a task, etc.

      Windows laptops have been tightly locked down since the early 2000’s, including USB ports.

      I’ve never seen a virus or malware on a machine in enterprise, and if it were to occur, the most it can damage is the local machine, as network shares are minimal (most data is kept in databases), the shares with write access are limited to small user groups, etc.

      Users simply lack permissions to change stuff, so malware lacks it too.