Thema 02 · Sicherheit · Linux Mint, Windows und macOSTopic 02 · Security · Linux Mint, Windows and macOS

Sicherheit ist kein Schalter.Security is not a switch.

Alle drei Systeme bringen wirksame Schutzmechanismen mit. Entscheidend ist, ob Updates, Verschlüsselung, Firewall, Konten, Softwarequellen und Sicherungen richtig eingerichtet und dauerhaft gepflegt werden.

All three systems include effective protection mechanisms. What matters is whether updates, encryption, firewall, accounts, software sources and backups are configured correctly and maintained over time.

DruckenPrint

Schutzmodelle

Protection models

Drei unterschiedliche Sicherheitsansätze.

Three different security approaches.

Keines der Systeme ist grundsätzlich unangreifbar. Die Unterschiede liegen vor allem bei Voreinstellungen, Softwareverteilung, Hardwarebindung und darin, wie viel Verantwortung beim Nutzer verbleibt.

None of the systems is inherently invulnerable. The main differences concern defaults, software distribution, hardware integration and how much responsibility remains with the user.

Linux Mint

Update Manager · sudo · AppArmor · UFW

Linux Mint setzt stark auf gepflegte Paketquellen, getrennte Administratorrechte und transparente Konfiguration. Sicherheits- und Kernel-Updates kommen über die Aktualisierungsverwaltung; AppArmor kann Programme über Profile begrenzen und UFW steht als lokale Firewall bereit.

Linux Mint relies heavily on maintained package sources, separate administrator privileges and transparent configuration. Security and kernel updates arrive through Update Manager; AppArmor can restrict applications through profiles and UFW is available as a host firewall.

Besonders starkParticular strengths

Offene Komponenten, kontrollierte Paketquellen, wenig erzwungene Cloud-Bindung und gute Wiederherstellung mit Timeshift.

Open components, controlled package sources, little forced cloud dependence and effective system recovery with Timeshift.

Darauf achtenWatch for

Firewall und Verschlüsselung müssen bewusst eingerichtet werden. Fremde PPAs, Installationsskripte und ungeprüfte AppImages umgehen den Vorteil der offiziellen Paketquellen.

Firewall and encryption require deliberate setup. Third-party PPAs, install scripts and unchecked AppImages bypass the benefit of official package sources.

Windows

Defender · SmartScreen · UAC · TPM

Windows bündelt viele Schutzschichten: Microsoft Defender, Firewall, SmartScreen, Benutzerkontensteuerung, Secure Boot und TPM-Unterstützung. BitLocker beziehungsweise Geräteverschlüsselung schützt geeignete Geräte und Editionen bei Verlust.

Windows combines many protection layers: Microsoft Defender, Firewall, SmartScreen, User Account Control, Secure Boot and TPM support. BitLocker or device encryption protects suitable devices and editions when lost.

Besonders starkParticular strengths

Umfangreicher integrierter Malware-Schutz, hardwaregestützter Systemstart und zentrale Verwaltungsmöglichkeiten.

Comprehensive built-in malware protection, hardware-backed startup security and central management options.

Darauf achtenWatch for

Windows wird besonders häufig angegriffen. Alte Programme, Makros, unsichere Downloads und verlorene BitLocker-Wiederherstellungsschlüssel bleiben typische Problemstellen.

Windows is targeted particularly often. Legacy applications, macros, unsafe downloads and lost BitLocker recovery keys remain common weak points.

macOS

Gatekeeper · Notarization · XProtect · FileVault

macOS verbindet Hardware und Betriebssystem eng. Gatekeeper, Notarisierung und XProtect prüfen beziehungsweise blockieren bekannte Schadsoftware; App-Berechtigungen begrenzen Datenzugriffe und FileVault schützt lokale Daten.

macOS tightly integrates hardware and operating system. Gatekeeper, notarisation and XProtect check or block known malware; app permissions mediate data access and FileVault protects local data.

Besonders starkParticular strengths

Eng abgestimmte Hardware, sicherer Startvorgang und mehrere integrierte Prüfungen für Anwendungen.

Tightly coordinated hardware, secure startup and several integrated application checks.

Darauf achtenWatch for

Auch Macs sind nicht immun. Wer Gatekeeper-Warnungen umgeht, unnötige Rechte vergibt oder Updates aufschiebt, baut die Schutzschichten eigenhändig ab. Eine beeindruckend plattformunabhängige Fähigkeit.

Macs are not immune. Bypassing Gatekeeper warnings, granting needless permissions or delaying updates dismantles the protection layers by hand. A remarkably cross-platform human skill.

Direkter Vergleich

Direct comparison

Sicherheit nach Schutzschichten.

Security by protection layer.

BereichLinux MintWindowsmacOS
UpdatesAktualisierungsverwaltung für Software-, Sicherheits- und Kernel-Updates; Zeitpunkt weitgehend kontrollierbarWindows Update und Defender-Aktualisierungen integriert; feste Supportfristen je VersionSoftwareupdate und Hintergrund-Sicherheitsdaten; neue Hauptversionen an unterstützte Modelle gebunden
Programme und MalwareOffizielle Paketquellen und Signaturen; AppArmor profilabhängig; freie Downloads benötigen eigene PrüfungDefender, SmartScreen, Reputationsprüfung und weitere Anwendungssteuerung integriertGatekeeper, Notarisierung und XProtect bilden mehrere Prüf- und Sperrschichten
Rechte und KontenStandardbenutzer, Unix-Rechte und sudo; zusätzliche Abschottung hängt von Profilen und Paketformat abBenutzerkontensteuerung, Standard-/Administratorkonten und hardwaregestützte AnmeldungAdministratorbestätigung, App-Sandbox bei geeigneten Programmen und feinere Datenschutzberechtigungen
FirewallUFW/Gufw verfügbar; sollte bewusst aktiviert und auf benötigte Dienste beschränkt werdenWindows-Firewall ist in die Sicherheitsoberfläche integriert und nach Netzwerkprofil steuerbarAnwendungsfirewall verfügbar; Freigaben und Netzwerkdienste separat kontrollieren
Datenträger-VerschlüsselungVollverschlüsselung beziehungsweise Home-Verschlüsselung bei der Installation; Passwort sicher verwahrenBitLocker oder Geräteverschlüsselung je nach Gerät und Edition; Wiederherstellungsschlüssel unverzichtbarModerne Macs verschlüsseln Daten hardwaregestützt; FileVault bindet den Zugriff an Anmeldung oder Wiederherstellung
Sicherer SystemstartSecure Boot möglich, bei Treibern und Sonderhardware vorher Kompatibilität prüfenSecure Boot und TPM 2.0 bilden die Hardwarebasis unterstützter Windows-11-GeräteStark integrierter sicherer Start auf Apple-Silicon- und T2-Systemen
WiederherstellungTimeshift für das System; persönliche Daten benötigen zusätzlich eine getrennte SicherungWiederherstellungsumgebung, Dateiversions- und Sicherungsoptionen; Cloud-Sicherung optionalRecovery-System und Time Machine; zweite unabhängige Kopie bleibt sinnvoll
Typische SchwachstelleUngeprüfte Skripte/PPAs, verspätete Updates, offene Dienste und das Märchen „Linux braucht keine Sicherheit“Phishing, Schadsoftware, Ransomware, Altprogramme und hohe AngriffshäufigkeitPhishing, umgangene Warnungen, zu viele App-Rechte und aufgeschobene Updates
AreaLinux MintWindowsmacOS
UpdatesUpdate Manager handles software, security and kernel updates; timing remains largely controllableWindows Update and Defender updates are integrated; each release has fixed support datesSoftware Update plus background security data; major releases depend on supported models
Applications and malwareOfficial repositories and signatures; AppArmor depends on profiles; arbitrary downloads require personal verificationDefender, SmartScreen, reputation checks and further application controls are integratedGatekeeper, notarisation and XProtect form several checking and blocking layers
Privileges and accountsStandard users, Unix permissions and sudo; extra isolation depends on profiles and package formatUser Account Control, standard/administrator accounts and hardware-backed sign-inAdministrator confirmation, app sandboxing where applicable and granular privacy permissions
FirewallUFW/Gufw is available; it should be deliberately enabled and limited to required servicesWindows Firewall is integrated into the security interface and controlled by network profileAn application firewall is available; sharing and network services are controlled separately
Disk encryptionFull-disk or home encryption during installation; keep the passphrase safelyBitLocker or device encryption depending on device and edition; the recovery key is essentialModern Macs encrypt data in hardware; FileVault ties access to login or recovery
Secure startupSecure Boot is possible; check driver and specialist-hardware compatibility firstSecure Boot and TPM 2.0 provide the hardware baseline for supported Windows 11 devicesStrongly integrated secure startup on Apple silicon and T2 systems
RecoveryTimeshift protects the system; personal files also require a separate backupRecovery environment, file history and backup options; cloud backup is optionalRecovery system and Time Machine; a second independent copy remains sensible
Typical weaknessUnchecked scripts/PPAs, delayed updates, exposed services and the myth that “Linux needs no security”Phishing, malware, ransomware, legacy applications and a high volume of attacksPhishing, bypassed warnings, excessive app permissions and delayed updates

Mindestschutz

Baseline protection

Was auf jeden Fall umgesetzt werden sollte.

What should always be implemented.

Die folgenden Maßnahmen bringen mehr als wahllos installierte „Security Tools“. Sicherheit ist Wartung, nicht Dekoration.

The following measures achieve more than a random pile of “security tools”. Security is maintenance, not decoration.

SchwerpunktPrimary focus

Linux Mint

  • Alle Sicherheits- und Kernel-Updates zeitnah über die Aktualisierungsverwaltung installieren.
  • Timeshift mit automatischen täglichen und Start-Schnappschüssen einrichten; persönliche Daten zusätzlich separat sichern.
  • UFW beziehungsweise Gufw aktivieren und nur tatsächlich benötigte Netzwerkdienste freigeben.
  • Bei Neuinstallation Vollverschlüsselung verwenden, wenn Diebstahl oder Verlust ein realistisches Risiko ist; Kennwort sicher verwahren.
  • Software bevorzugt aus offiziellen Paketquellen, der Anwendungsverwaltung oder vertrauenswürdigen Flatpak-Quellen installieren.
  • PPAs, fremde DEB-Pakete, AppImages und Installationsskripte nur nach Prüfung von Herkunft und Zweck verwenden.
  • Mit normalem Benutzerkonto arbeiten, sudo nur gezielt einsetzen, starkes Kennwort und automatische Bildschirmsperre verwenden.
  • Browser und Erweiterungen aktuell halten, Erweiterungen sparsam wählen, Passwortmanager und Mehrfaktor-Anmeldung nutzen.
  • Nicht verwendete Freigaben, Fernzugriffe, Serverdienste und Funkverbindungen deaktivieren.
  • Install all security and kernel updates promptly through Update Manager.
  • Configure Timeshift with automatic daily and boot snapshots; back up personal files separately as well.
  • Enable UFW or Gufw and expose only network services that are actually required.
  • Use full-disk encryption on new installations where theft or loss is a realistic risk; keep the passphrase safely.
  • Prefer official repositories, Software Manager or trusted Flatpak sources for applications.
  • Use PPAs, third-party DEB packages, AppImages and install scripts only after checking their origin and purpose.
  • Work from a standard account, use sudo deliberately, choose a strong password and enable automatic screen locking.
  • Keep the browser and extensions updated, minimise extensions, and use a password manager plus multi-factor authentication.
  • Disable unused shares, remote access, server services and wireless connections.

Windows

  • Nur eine unterstützte Windows-Version verwenden und Windows Update vollständig ausführen.
  • Microsoft Defender, Firewall und SmartScreen aktiviert lassen; kein zweites Echtzeit-Antivirenprogramm ohne konkreten Grund installieren.
  • BitLocker beziehungsweise Geräteverschlüsselung aktivieren und den Wiederherstellungsschlüssel unabhängig vom Gerät sichern.
  • Secure Boot, TPM und Windows Hello verwenden, sofern die Hardware sie unterstützt.
  • Standardkonto und Benutzerkontensteuerung beibehalten; Administratorrechte nicht dauerhaft benutzen.
  • Browser, Office, PDF-Programme, Treiber und sonstige Drittsoftware ebenfalls aktualisieren.
  • Regelmäßige Sicherungen mit getesteter Wiederherstellung einrichten und Freigaben sowie Remotedesktop prüfen.
  • Use only a supported Windows release and complete Windows Update fully.
  • Keep Microsoft Defender, Firewall and SmartScreen enabled; do not install a second real-time antivirus without a specific reason.
  • Enable BitLocker or device encryption and store the recovery key independently of the device.
  • Use Secure Boot, TPM and Windows Hello where the hardware supports them.
  • Retain a standard account and User Account Control; do not work permanently with administrator rights.
  • Update the browser, Office, PDF tools, drivers and all other third-party software as well.
  • Set up regular backups with tested recovery and review shares plus Remote Desktop.

macOS

  • Automatische System-, Sicherheits- und App-Updates aktivieren und zeitnah neu starten.
  • Gatekeeper-Warnungen nicht routinemäßig umgehen und Programme nur aus nachvollziehbaren Quellen installieren.
  • FileVault aktivieren und Wiederherstellungsinformationen unabhängig vom Mac verwahren.
  • Firewall einschalten und Freigaben wie Dateifreigabe, Bildschirmfreigabe oder entfernte Anmeldung nur bei Bedarf aktivieren.
  • Starkes Kennwort, Touch ID und Mehrfaktor-Anmeldung für den Apple-Account verwenden.
  • App-Berechtigungen, Browser-Erweiterungen, Anmeldeobjekte und Systemerweiterungen regelmäßig prüfen.
  • Time Machine einrichten und wichtige Daten zusätzlich auf einem zweiten unabhängigen Ziel sichern.
  • Enable automatic system, security and app updates and restart promptly when required.
  • Do not routinely bypass Gatekeeper warnings; install applications only from traceable sources.
  • Enable FileVault and keep recovery information independently of the Mac.
  • Enable the firewall and activate file sharing, screen sharing or remote login only when needed.
  • Use a strong password, Touch ID and multi-factor authentication for the Apple Account.
  • Review app permissions, browser extensions, login items and system extensions regularly.
  • Configure Time Machine and keep important data on a second independent target as well.

Häufige Denkfehler

Common misconceptions

Die Plattform löst nicht jedes Problem.

The platform does not solve every problem.

×

„Linux bekommt keine Schadsoftware.“

“Linux cannot get malware.”

Falsch. Weniger Desktop-Massenangriffe bedeuten nicht null Risiko. Phishing, Browser-Lücken, schädliche Erweiterungen, kompromittierte Konten und fremde Skripte funktionieren auch unter Linux.

False. Fewer mass desktop attacks do not mean zero risk. Phishing, browser flaws, malicious extensions, compromised accounts and unsafe scripts work on Linux too.

×

„Der Virenscanner erledigt den Rest.“

“The antivirus handles everything else.”

Falsch. Echtzeitschutz hilft, ersetzt aber weder Updates noch Verschlüsselung, vorsichtige Softwareauswahl, Mehrfaktor-Anmeldung oder eine funktionierende Sicherung.

False. Real-time protection helps, but it does not replace updates, encryption, careful software selection, multi-factor authentication or a working backup.

×

„Ein Administrator-Kennwort macht den Befehl sicher.“

“An administrator password makes the command safe.”

Falsch. sudo, UAC und macOS-Kennwortabfragen bestätigen nur die Berechtigung. Sie prüfen nicht, ob der kopierte Terminalbefehl oder Installer eine vernünftige Idee ist. Das wäre auch zu bequem.

False. sudo, UAC and macOS password prompts only confirm authorisation. They do not decide whether a copied terminal command or installer is sensible. That would be far too convenient.

Dogtruck-Fazit:Dogtruck conclusion:

Linux Mint bietet viel Kontrolle und ein sauberes Paketmodell, verlangt aber bewusste Entscheidungen bei Firewall, Verschlüsselung und Fremdsoftware. Windows hat ein sehr umfangreiches integriertes Schutzpaket, wird jedoch besonders häufig angegriffen und bleibt durch Altsoftware komplex. macOS verbindet starke Schutzschichten eng mit Apple-Hardware, ist aber weder unangreifbar noch besonders offen. Der praktische Sieger ist das unterstützte System, das aktualisiert, verschlüsselt, sparsam konfiguriert und zuverlässig gesichert wird.

Linux Mint offers substantial control and a clean package model, but requires deliberate choices for firewall, encryption and third-party software. Windows provides a very comprehensive built-in protection suite, yet is targeted especially often and remains complex because of legacy software. macOS tightly integrates strong protection layers with Apple hardware, but is neither invulnerable nor especially open. The practical winner is the supported system that is updated, encrypted, conservatively configured and reliably backed up.

Nächstes ThemaNext topic

Den richtigen PC kaufen.Buy the right PC.

Was wirklich zählt, was nur glänzt und welche Angaben Händler erstaunlich gern zwischen drei Fußnoten verstecken.

What genuinely matters, what merely shines and which details retailers mysteriously prefer to hide between three footnotes.

Thema 03 öffnenOpen topic 03

Bilder & QuellenImages & sources

Quellen zum Sicherheitsthema.Sources for the security topic.

Die offiziellen Sicherheitsdokumentationen aller drei Systeme stehen gesammelt im Quellenverzeichnis.

Official security documentation for all three systems is collected in the source directory.

Quellen öffnenOpen sources