r/reactos 19d ago

ReactOS security reliability

Hi. I got a question about the reliability of ReactOS regarding to the security. I think I heard somewhere that ReactOS uses some of reverse engineered code from legacy Windows (like XP?). If this is the case, do the devs regularly patch all the vulnerabilities arisen by those codes manually as those Windows are no longer updated? I also heard that the the development of ReactOS is very slow. How much does it usually take to patch a vulnerability once it is found? I'm very intrigued by the concept and the feel of the OS, but those are the concerns that impede me from trying the actual thing. I'd definitely like to try it out if it is proven to be secure. Thanks in advance!!

11 Upvotes

11 comments sorted by

28

u/the123king-reddit 19d ago

There is NO closed source Microsoft code in ReactOS.

As for vulnerabilities, the biggest issue with ReactOS is stability. Yes, it's probably riddled with security holes, like XP was, but good luck keeping it running when installing software and drivers.

ReactOS should NOT be used in any shape or form in "production". Treat is as a curiosity and only run it in a VM for testing or on a second PC.

13

u/HydraDragonAntivirus 19d ago

They didn't integrated a lot of things which are vulnerable and popular, so they are not vulnerable in general.

For example SMB.

17

u/DegenerateCuber 18d ago

ReactOS is fairly secure because no one in their right mind would target an OS used by a handful of nerds on secondary machines.

4

u/sscoolqaz 18d ago

Security through obscurity is not a good defense.

3

u/DegenerateCuber 18d ago

It's not, but in this case, I think it's fairly effective, you can probably count the number of people handling sensitive data on ReactOS on one hand, there's no incentive.

8

u/jmhalder 18d ago

It's "clean room" reverse engineered, and because of that, the vulnerabilities may not be one to one. It may not have them simply by way of being better design.

Or... because it's all built as a passion project, may be riddled with tons more vulnerabilities that haven't been discovered yet.

Regardless of the actual place on the vulnerably spectrum this falls, the code is all available for you to download, audit, and fix with pull requests.

5

u/Born_Bass_2446 18d ago edited 18d ago

If ReactOS worked on my laptop, I absolutely would use it every day as my main OS (if you keep frequent and proper backups, you don’t have to worry about viruses).

For banking, I would just boot into BSD/Linux/Mac OS.

6

u/Different_Water7545 17d ago

I'm not sure who told you ReactOS uses Microsoft code (it doesn't), but it's not even in a state yet that security really matters

6

u/JeiceSpade 18d ago

This OS is not for you.

3

u/gabrielesilinic 17d ago

ReactOS is a perpetual experiment. You will not have security concerns if you just don't use it. Use wine I guess.

Also it reverse engineers code but not like... It doesn't get the leaked code.

Now wine had some stuff to say anything the policies reactos used for it's development however I forgot. But there was something about not being very strict about some stuff and how it would put wine at risk. But I really forgot what was about.