Thema 02 · Sicherheit · Linux Mint, Windows und macOSTopic 02 · Security · Linux Mint, Windows and macOS
Sicherheit ist kein Schalter.Security is not a switch.
Alle drei Systeme bringen wirksame Schutzmechanismen mit. Entscheidend ist, ob Updates, Verschlüsselung, Firewall, Konten, Softwarequellen und Sicherungen richtig eingerichtet und dauerhaft gepflegt werden.
All three systems include effective protection mechanisms. What matters is whether updates, encryption, firewall, accounts, software sources and backups are configured correctly and maintained over time.
Keines der Systeme ist grundsätzlich unangreifbar. Die Unterschiede liegen vor allem bei Voreinstellungen, Softwareverteilung, Hardwarebindung und darin, wie viel Verantwortung beim Nutzer verbleibt.
None of the systems is inherently invulnerable. The main differences concern defaults, software distribution, hardware integration and how much responsibility remains with the user.
Linux Mint
Update Manager · sudo · AppArmor · UFW
Linux Mint setzt stark auf gepflegte Paketquellen, getrennte Administratorrechte und transparente Konfiguration. Sicherheits- und Kernel-Updates kommen über die Aktualisierungsverwaltung; AppArmor kann Programme über Profile begrenzen und UFW steht als lokale Firewall bereit.
Linux Mint relies heavily on maintained package sources, separate administrator privileges and transparent configuration. Security and kernel updates arrive through Update Manager; AppArmor can restrict applications through profiles and UFW is available as a host firewall.
Besonders starkParticular strengths
Offene Komponenten, kontrollierte Paketquellen, wenig erzwungene Cloud-Bindung und gute Wiederherstellung mit Timeshift.
Open components, controlled package sources, little forced cloud dependence and effective system recovery with Timeshift.
Darauf achtenWatch for
Firewall und Verschlüsselung müssen bewusst eingerichtet werden. Fremde PPAs, Installationsskripte und ungeprüfte AppImages umgehen den Vorteil der offiziellen Paketquellen.
Firewall and encryption require deliberate setup. Third-party PPAs, install scripts and unchecked AppImages bypass the benefit of official package sources.
Windows
Defender · SmartScreen · UAC · TPM
Windows bündelt viele Schutzschichten: Microsoft Defender, Firewall, SmartScreen, Benutzerkontensteuerung, Secure Boot und TPM-Unterstützung. BitLocker beziehungsweise Geräteverschlüsselung schützt geeignete Geräte und Editionen bei Verlust.
Windows combines many protection layers: Microsoft Defender, Firewall, SmartScreen, User Account Control, Secure Boot and TPM support. BitLocker or device encryption protects suitable devices and editions when lost.
Besonders starkParticular strengths
Umfangreicher integrierter Malware-Schutz, hardwaregestützter Systemstart und zentrale Verwaltungsmöglichkeiten.
Comprehensive built-in malware protection, hardware-backed startup security and central management options.
Darauf achtenWatch for
Windows wird besonders häufig angegriffen. Alte Programme, Makros, unsichere Downloads und verlorene BitLocker-Wiederherstellungsschlüssel bleiben typische Problemstellen.
Windows is targeted particularly often. Legacy applications, macros, unsafe downloads and lost BitLocker recovery keys remain common weak points.
macOS
Gatekeeper · Notarization · XProtect · FileVault
macOS verbindet Hardware und Betriebssystem eng. Gatekeeper, Notarisierung und XProtect prüfen beziehungsweise blockieren bekannte Schadsoftware; App-Berechtigungen begrenzen Datenzugriffe und FileVault schützt lokale Daten.
macOS tightly integrates hardware and operating system. Gatekeeper, notarisation and XProtect check or block known malware; app permissions mediate data access and FileVault protects local data.
Besonders starkParticular strengths
Eng abgestimmte Hardware, sicherer Startvorgang und mehrere integrierte Prüfungen für Anwendungen.
Tightly coordinated hardware, secure startup and several integrated application checks.
Darauf achtenWatch for
Auch Macs sind nicht immun. Wer Gatekeeper-Warnungen umgeht, unnötige Rechte vergibt oder Updates aufschiebt, baut die Schutzschichten eigenhändig ab. Eine beeindruckend plattformunabhängige Fähigkeit.
Macs are not immune. Bypassing Gatekeeper warnings, granting needless permissions or delaying updates dismantles the protection layers by hand. A remarkably cross-platform human skill.
Direkter Vergleich
Direct comparison
Sicherheit nach Schutzschichten.
Security by protection layer.
Bereich
Linux Mint
Windows
macOS
Updates
Aktualisierungsverwaltung für Software-, Sicherheits- und Kernel-Updates; Zeitpunkt weitgehend kontrollierbar
Windows Update und Defender-Aktualisierungen integriert; feste Supportfristen je Version
Softwareupdate und Hintergrund-Sicherheitsdaten; neue Hauptversionen an unterstützte Modelle gebunden
Programme und Malware
Offizielle Paketquellen und Signaturen; AppArmor profilabhängig; freie Downloads benötigen eigene Prüfung
Defender, SmartScreen, Reputationsprüfung und weitere Anwendungssteuerung integriert
Gatekeeper, Notarisierung und XProtect bilden mehrere Prüf- und Sperrschichten
Rechte und Konten
Standardbenutzer, Unix-Rechte und sudo; zusätzliche Abschottung hängt von Profilen und Paketformat ab
Benutzerkontensteuerung, Standard-/Administratorkonten und hardwaregestützte Anmeldung
Administratorbestätigung, App-Sandbox bei geeigneten Programmen und feinere Datenschutzberechtigungen
Firewall
UFW/Gufw verfügbar; sollte bewusst aktiviert und auf benötigte Dienste beschränkt werden
Windows-Firewall ist in die Sicherheitsoberfläche integriert und nach Netzwerkprofil steuerbar
Anwendungsfirewall verfügbar; Freigaben und Netzwerkdienste separat kontrollieren
Datenträger-Verschlüsselung
Vollverschlüsselung beziehungsweise Home-Verschlüsselung bei der Installation; Passwort sicher verwahren
BitLocker oder Geräteverschlüsselung je nach Gerät und Edition; Wiederherstellungsschlüssel unverzichtbar
Moderne Macs verschlüsseln Daten hardwaregestützt; FileVault bindet den Zugriff an Anmeldung oder Wiederherstellung
Sicherer Systemstart
Secure Boot möglich, bei Treibern und Sonderhardware vorher Kompatibilität prüfen
Secure Boot und TPM 2.0 bilden die Hardwarebasis unterstützter Windows-11-Geräte
Stark integrierter sicherer Start auf Apple-Silicon- und T2-Systemen
Wiederherstellung
Timeshift für das System; persönliche Daten benötigen zusätzlich eine getrennte Sicherung
Wiederherstellungsumgebung, Dateiversions- und Sicherungsoptionen; Cloud-Sicherung optional
Recovery-System und Time Machine; zweite unabhängige Kopie bleibt sinnvoll
Typische Schwachstelle
Ungeprüfte Skripte/PPAs, verspätete Updates, offene Dienste und das Märchen „Linux braucht keine Sicherheit“
Phishing, Schadsoftware, Ransomware, Altprogramme und hohe Angriffshäufigkeit
Phishing, umgangene Warnungen, zu viele App-Rechte und aufgeschobene Updates
Windows Update and Defender updates are integrated; each release has fixed support dates
Software Update plus background security data; major releases depend on supported models
Applications and malware
Official repositories and signatures; AppArmor depends on profiles; arbitrary downloads require personal verification
Defender, SmartScreen, reputation checks and further application controls are integrated
Gatekeeper, notarisation and XProtect form several checking and blocking layers
Privileges and accounts
Standard users, Unix permissions and sudo; extra isolation depends on profiles and package format
User Account Control, standard/administrator accounts and hardware-backed sign-in
Administrator confirmation, app sandboxing where applicable and granular privacy permissions
Firewall
UFW/Gufw is available; it should be deliberately enabled and limited to required services
Windows Firewall is integrated into the security interface and controlled by network profile
An application firewall is available; sharing and network services are controlled separately
Disk encryption
Full-disk or home encryption during installation; keep the passphrase safely
BitLocker or device encryption depending on device and edition; the recovery key is essential
Modern Macs encrypt data in hardware; FileVault ties access to login or recovery
Secure startup
Secure Boot is possible; check driver and specialist-hardware compatibility first
Secure Boot and TPM 2.0 provide the hardware baseline for supported Windows 11 devices
Strongly integrated secure startup on Apple silicon and T2 systems
Recovery
Timeshift protects the system; personal files also require a separate backup
Recovery environment, file history and backup options; cloud backup is optional
Recovery system and Time Machine; a second independent copy remains sensible
Typical weakness
Unchecked scripts/PPAs, delayed updates, exposed services and the myth that “Linux needs no security”
Phishing, malware, ransomware, legacy applications and a high volume of attacks
Phishing, bypassed warnings, excessive app permissions and delayed updates
Mindestschutz
Baseline protection
Was auf jeden Fall umgesetzt werden sollte.
What should always be implemented.
Die folgenden Maßnahmen bringen mehr als wahllos installierte „Security Tools“. Sicherheit ist Wartung, nicht Dekoration.
The following measures achieve more than a random pile of “security tools”. Security is maintenance, not decoration.
SchwerpunktPrimary focus
Linux Mint
Alle Sicherheits- und Kernel-Updates zeitnah über die Aktualisierungsverwaltung installieren.
Timeshift mit automatischen täglichen und Start-Schnappschüssen einrichten; persönliche Daten zusätzlich separat sichern.
UFW beziehungsweise Gufw aktivieren und nur tatsächlich benötigte Netzwerkdienste freigeben.
Bei Neuinstallation Vollverschlüsselung verwenden, wenn Diebstahl oder Verlust ein realistisches Risiko ist; Kennwort sicher verwahren.
Software bevorzugt aus offiziellen Paketquellen, der Anwendungsverwaltung oder vertrauenswürdigen Flatpak-Quellen installieren.
PPAs, fremde DEB-Pakete, AppImages und Installationsskripte nur nach Prüfung von Herkunft und Zweck verwenden.
Mit normalem Benutzerkonto arbeiten, sudo nur gezielt einsetzen, starkes Kennwort und automatische Bildschirmsperre verwenden.
Browser und Erweiterungen aktuell halten, Erweiterungen sparsam wählen, Passwortmanager und Mehrfaktor-Anmeldung nutzen.
Nicht verwendete Freigaben, Fernzugriffe, Serverdienste und Funkverbindungen deaktivieren.
Install all security and kernel updates promptly through Update Manager.
Configure Timeshift with automatic daily and boot snapshots; back up personal files separately as well.
Enable UFW or Gufw and expose only network services that are actually required.
Use full-disk encryption on new installations where theft or loss is a realistic risk; keep the passphrase safely.
Prefer official repositories, Software Manager or trusted Flatpak sources for applications.
Use PPAs, third-party DEB packages, AppImages and install scripts only after checking their origin and purpose.
Work from a standard account, use sudo deliberately, choose a strong password and enable automatic screen locking.
Keep the browser and extensions updated, minimise extensions, and use a password manager plus multi-factor authentication.
Disable unused shares, remote access, server services and wireless connections.
Windows
Nur eine unterstützte Windows-Version verwenden und Windows Update vollständig ausführen.
Microsoft Defender, Firewall und SmartScreen aktiviert lassen; kein zweites Echtzeit-Antivirenprogramm ohne konkreten Grund installieren.
BitLocker beziehungsweise Geräteverschlüsselung aktivieren und den Wiederherstellungsschlüssel unabhängig vom Gerät sichern.
Secure Boot, TPM und Windows Hello verwenden, sofern die Hardware sie unterstützt.
Standardkonto und Benutzerkontensteuerung beibehalten; Administratorrechte nicht dauerhaft benutzen.
Browser, Office, PDF-Programme, Treiber und sonstige Drittsoftware ebenfalls aktualisieren.
Regelmäßige Sicherungen mit getesteter Wiederherstellung einrichten und Freigaben sowie Remotedesktop prüfen.
Use only a supported Windows release and complete Windows Update fully.
Keep Microsoft Defender, Firewall and SmartScreen enabled; do not install a second real-time antivirus without a specific reason.
Enable BitLocker or device encryption and store the recovery key independently of the device.
Use Secure Boot, TPM and Windows Hello where the hardware supports them.
Retain a standard account and User Account Control; do not work permanently with administrator rights.
Update the browser, Office, PDF tools, drivers and all other third-party software as well.
Set up regular backups with tested recovery and review shares plus Remote Desktop.
macOS
Automatische System-, Sicherheits- und App-Updates aktivieren und zeitnah neu starten.
Gatekeeper-Warnungen nicht routinemäßig umgehen und Programme nur aus nachvollziehbaren Quellen installieren.
FileVault aktivieren und Wiederherstellungsinformationen unabhängig vom Mac verwahren.
Firewall einschalten und Freigaben wie Dateifreigabe, Bildschirmfreigabe oder entfernte Anmeldung nur bei Bedarf aktivieren.
Starkes Kennwort, Touch ID und Mehrfaktor-Anmeldung für den Apple-Account verwenden.
App-Berechtigungen, Browser-Erweiterungen, Anmeldeobjekte und Systemerweiterungen regelmäßig prüfen.
Time Machine einrichten und wichtige Daten zusätzlich auf einem zweiten unabhängigen Ziel sichern.
Enable automatic system, security and app updates and restart promptly when required.
Do not routinely bypass Gatekeeper warnings; install applications only from traceable sources.
Enable FileVault and keep recovery information independently of the Mac.
Enable the firewall and activate file sharing, screen sharing or remote login only when needed.
Use a strong password, Touch ID and multi-factor authentication for the Apple Account.
Review app permissions, browser extensions, login items and system extensions regularly.
Configure Time Machine and keep important data on a second independent target as well.
Häufige Denkfehler
Common misconceptions
Die Plattform löst nicht jedes Problem.
The platform does not solve every problem.
×
„Linux bekommt keine Schadsoftware.“
“Linux cannot get malware.”
Falsch. Weniger Desktop-Massenangriffe bedeuten nicht null Risiko. Phishing, Browser-Lücken, schädliche Erweiterungen, kompromittierte Konten und fremde Skripte funktionieren auch unter Linux.
False. Fewer mass desktop attacks do not mean zero risk. Phishing, browser flaws, malicious extensions, compromised accounts and unsafe scripts work on Linux too.
×
„Der Virenscanner erledigt den Rest.“
“The antivirus handles everything else.”
Falsch. Echtzeitschutz hilft, ersetzt aber weder Updates noch Verschlüsselung, vorsichtige Softwareauswahl, Mehrfaktor-Anmeldung oder eine funktionierende Sicherung.
False. Real-time protection helps, but it does not replace updates, encryption, careful software selection, multi-factor authentication or a working backup.
×
„Ein Administrator-Kennwort macht den Befehl sicher.“
“An administrator password makes the command safe.”
Falsch. sudo, UAC und macOS-Kennwortabfragen bestätigen nur die Berechtigung. Sie prüfen nicht, ob der kopierte Terminalbefehl oder Installer eine vernünftige Idee ist. Das wäre auch zu bequem.
False. sudo, UAC and macOS password prompts only confirm authorisation. They do not decide whether a copied terminal command or installer is sensible. That would be far too convenient.
Dogtruck-Fazit:Dogtruck conclusion:
Linux Mint bietet viel Kontrolle und ein sauberes Paketmodell, verlangt aber bewusste Entscheidungen bei Firewall, Verschlüsselung und Fremdsoftware. Windows hat ein sehr umfangreiches integriertes Schutzpaket, wird jedoch besonders häufig angegriffen und bleibt durch Altsoftware komplex. macOS verbindet starke Schutzschichten eng mit Apple-Hardware, ist aber weder unangreifbar noch besonders offen. Der praktische Sieger ist das unterstützte System, das aktualisiert, verschlüsselt, sparsam konfiguriert und zuverlässig gesichert wird.
Linux Mint offers substantial control and a clean package model, but requires deliberate choices for firewall, encryption and third-party software. Windows provides a very comprehensive built-in protection suite, yet is targeted especially often and remains complex because of legacy software. macOS tightly integrates strong protection layers with Apple hardware, but is neither invulnerable nor especially open. The practical winner is the supported system that is updated, encrypted, conservatively configured and reliably backed up.
Nächstes ThemaNext topic
Den richtigen PC kaufen.Buy the right PC.
Was wirklich zählt, was nur glänzt und welche Angaben Händler erstaunlich gern zwischen drei Fußnoten verstecken.
What genuinely matters, what merely shines and which details retailers mysteriously prefer to hide between three footnotes.