Linux Mint downloads (briefly) compromised
lwn.net
lwn.net
I'm not bothered by the licensing issues mentioned, and I'm ambivalent about the namespace issues, but I've been increasingly uneasy for some time now about Mint's security practices. Serving downloads over http and not providing GPG signed SHA hashes like every other distro is fairly irresponsible in this day and age.
This recent security issue, and the poor response to it, are basically the straw that breaks the camel's back for me. I'm moving on to Ubuntu-Mate, since frankly Mate was the primary reason I was using Mint anyway. Serving downloads of the most popular Linux distro from the same machine as is running WordPress is cringeworthy, and failing to take the compromised machine totally offline until it's 100% sure the compromise has been mitigated (through reformatting, including boot sector) shows really poor judgment.
I'm a bit sad to be so critical, since I recognize that Clem has done a lot for the Linux world, and as a Mint user I've benefited personally from his work. But when you're distributing operating systems to so many users, you have to take security seriously. To do otherwise, even on a "hobby" project (although I'm fairly sure it's his full-time job now) is pretty irresponsible.
In many ways, I'd like to pitch in, but based on other interactions I've seen and read about, I'm not sure my input would be welcome, particularly wrt security issues.
Edit: I'm also playing around with FreeBSD for my development environment, since I can use Mate on there. To be honest, I don't really need a DE these days anyway, since I only use terminal and a web browser. I should look into just using a Windows Manager.
Edit 2: Apparently they do provide GPG signed hashes. I've been looking for them each time I've downloaded Mint distros, but never came upon them. So I stand corrected.
I would consider myself pretty "technical".
And yet, I am not willing to spend more effort than absolutely necessary for setting up my Linux OS.
Just b/c I am a programmer and even love to use zsh and Git from the CLI does not imply that I have any patience for fiddling with drivers and kernels.
In the "Linux Community" there only seems to exist the hacker (who loves to spend ages tinkering with config files and debugging hardware issues) and the technically incompetent user (who most likely uses Windows anyway).
There is a lot in between.
I really like the idea of Arch but I am intimidated to jump in. What was your experience like when you first booted up Arch?
If you want to quickly try something similar, I'd suggest Manjaro Linux, which is based on Arch. It really feels like Arch but with non-minimal defaults for those who don't want to set up everything themselves.
To make things worse, the general response I've heard from other folks that use Linux full time was, "oh yeah, why weren't you just using USB peripherals?" The general feeling I got was that I was a n00b for even trying to use a BT mouse and keyboard in the first place.
I genuinely wanted to make the switch work, and it's a shame that it just didn't (for me). Honestly, the last thing I need sprinkled into every few working days is 45 minutes trying to get some driver re-installed.
But I managed to solve almost all of them thanks to lots of very kind, to the point and fast responding pros on forum.linuxmint.com.
wow, that's a pretty elitist comment, even for HN. essentially what you're saying is that people who don't like spending time trying to make their computer work are technically incompetent?
I had personally given up on Fedora years ago, but recently was told I should give it a second look and I've not had time to try it out.
There's a move to give stuff generic names, rather than the obscure names they had in the past. For example, Nautilus has been renamed to Gnome Files, or just Files. When a non technical person needs to search for hep this new name makes it impossible for them to create a useful search term.
[files foo bar] is going to be different from [nautilus foo bar]. Frustratingly the old name works for searching, but it's not in any titlebars or about boxes or menu items, so the non-technical person has to just know that files is also sometimes called Nautilus.
Fedora 20 has an appstore. This has something like 4 different names - in the menu, in the title bar, in the about box, in the icon.
For what it is (a rapidly released testing distro) it's lovely - nice community (from what I could tell) and lots of activity.
That's not so much a Fedora thing but a GNOME move, as the RPM containing "Files" is still called Nautilus.
Also, I am a bit surprised since it goes contrary to your argument, because when a user looks for a file explorer he's much more likely to find that looking for "Files" rather than the (rather strange, really) name of "Nautilus".
I would see myself as a technical user and yet I have no idea how the apps on my Android device are called. One is called generically "Gallery" and another one even worse, "E-Mail".
Thing is, the move to generic names is basically an ego trip from Linux developers. Consistent products like Windows or OSX, which are monolithic and have bazillion of users with the exact same configuration, can get away with it; but the Linux world is a forest of different apps from random developers, haphazardly packaged by this or that distribution and continuously updated every few months. In this environment, thinking you can just refer to "Ubuntu files" or "Fedora files" is a pipe dream; often the solution to your problems will be on sources that are not specific to the distro you are actually using (see for example the Arch and Gentoo wikis).
Making the name basically irrelevant unless they need to ask a question about it in which case enter googlability.
It's a bad trend. It's really frustrating when you're trying to find out what the executable or package name is.
In Fedora 20 the name "Gnome Files" was hard to discover (that may have changed in later Fedoras) and non technical people just don't know how to search.
In your desktop environment, 'Open web browser' (as an action), can be associated with whichever browser you prefer. And perhaps a context menu on that to choose between many.
I prefer something like: Gnome file manager: 'Nautilus', to the browser: 'Web'. How ghastly.
To differentiate between many, like both of Windows' web browsers: Edge and Internet Explorer. You could say Windows web browser Edge. Or Edge; Windows' web browser. Windows itself is a confusing name, but that's another conversation.
I think the usability is miles ahead of Ubuntu atleast - I realize that is a personal opinion, but I love that Fedora is a tightly integrated Gnome (and soon Wayland distro).
On the technical I love OpenSUSE for zypper, build (Any software you need is probably on there and it will even build for other distros), rolling releases in Tumbleweed, and the best KDE default environment for over a decade..
That said, stay away from Tumbleweed (rolling release). In my experience it's been even less stable than Arch or Sid. In the past I've had kernel updates making the machine unbootable, though thankfully the distro does keep all previously installed kernels, easily selectable in GRUB. Just yesterday I banged my head against a year-old bug that pgadmin3 is broken because it hasn't been rebuilt against the distributed version of wx (come on).
I use Fedora @work and Ubuntu @home. The reason I use Ubuntu @home is that my roommates run Ubuntu too and we get all the same Versions on whatever software.
But @work I run Fedora. There aren't any particular reasons except that it just "feels" better to work on that on Ubuntu. I definitely recommend to give it a try.
Using something like Fedy or easyLife makes setting up Fedora fun and fast.
That said I've had many performance issues on GNOME - I like the way it looks and the "feel" and I got used to the UI over the last year or more but frankly it's constantly hogging my PC down, both desktop an laptop - when I switched to KDE/plasma 5 I saw my WebGL chrome app go from 40-50 FPS to consistent 60 FPS - both tests done after a clean start and simply starting the app letting it run for a while. The entire system feels more responsive - can't trace the issue but the results are measurable and noticeable
I've had flicker and stability issues with KDE 5 when I last tried it a year ago but now it appears quite stable. My only complaint is that themes/design community are nowhere near to Gnome.
Any distro with a release schedule is going to have caveats about not having prebuilt packages for the latest XYZ. The only things I can think of that might give you a faster update schedule than Ubuntu (in terms of newer versions, not just point releases) would be Fedora, Arch, or Gentoo.
I've forgot to mention I've moved to Fedora a year or two back for this reason - got tired of rebuilding/PPA hunting for every part of my OS when I want to use the latest version of tool/lib X.
And once dependencies are too old (very often) prepare to be rebuilding 5+ custom libs and figuring out the differences between debian package/path layout and what the library build uses ... so much wasted time.
They have an excellent testing/QA process, especially given the speed at which they're developing - this results in a very high quality.
I have lost hours debugging mysterious crashes because of SELinux, and it is really not safe to have components unexpectedly crashing when they are part of your core infra.
Plus I guess that like every security frameworks it runs with priviledge, it has a lot of lines of code, is hard to audit, and thus highers the surface of vulnerability.
Hint: they use for instance strcmp a lot http://stackoverflow.com/questions/24353504/whats-wrong-with...
Their code mixes if(){} with the if() else (without braces)
They are sometimes using enums, sometimes #define sometimes magic values to refer to constant values.
You should really read the source code.
Definitively above the average of C code in the wild, still having well known code smell.
I would like to see if PVS studio could confirm my intuition.
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux....
I know I've been suggesting it to people who are considering Linux for the first time, with the caveat of disabling SElinux.
With that said, I'm not sure if it is good for non-technical people or people who aren't interested in learning about it. Getting certain things installed can be a bit of work, as they don't support things like Chrome or even Chromium by default. I also view it from the perspective of not knowing how to use any graphical installers (do they exist?). If I was aware of that stuff, I'd possibly consider it for non-technical users, but as it stands, I don't.
Yes, it exists and works pretty good when I installed it. Set up encrypted LUKS, EFI just fine and I found it reasonably pleasant to use.
1) strict licensing restrictions - lots of basic functionality/software missing from official repositories; there is rpmfusion of course, but that's not something my mom should know how to install
2) Very short support. You'll be stuck without updates in no time, and upgrading to possibly broken release (that might radically change things) every few months is ridiculous.
So.. if they were to offer LTS version, I'd happily recommend it to everyone. As it is, it's great if you don't mind the caveats mentioned above (especially everything that stems from 2nd point). CentOS is not a viable alternative, as it is "enterprise" OS stuck with archaic software.
New releases are out after around 6 months. If you find release upgrades risky you can always wait a whole year and stay one release behind (any bug would have been ironed out in that time).
I usually don't update in the first couple weeks and I hadn't any problem with a Fedora upgrade in the last two/three years.
For a long time back in the early teen releases there were no sane upgrade paths which pushed me to Debian.
Probably, if I move away from the convenience of a Debian derivative these days, it will be to FreeBSD.
My reason for choosing Fedora is because of its maturity, major player backing and SElinux implementation.
It works great, I feel like a modern Linux user in Fedora.
It's a very educational experience, but not really something the "average grandmother" is likely to have the patience for, particularly when they're just trying to watch a flash video on Facebook. That's the real strength of Mint, and I'm not sure what best fills that niche if Mint is off the table.
EDIT Write the post install script yourself don't use one of the many flawed ones that a search will show up.
I really don't see why the downvote? The OP wants an easy to use distro that their grandmother can use but seems happy to install it them-self.
FreeBSD has good support for DEs with XFCE and Lumina, anyways. At least I've never had a problem.
I was able to get a compositor (Compiz) working on Mate and this fixed the tearing issue. It had some issues where it just kept crashing and rebooting that I never figured out. So I switched back to Gnome3. Although Gnome3 comes with a compositor (I think? And I think it might be Compiz?), I can't seem to get rid of the screen going black when a video starts.
But it really doesn't make a big difference and it's not a big enough annoyance to matter. I don't really use FreeBSD for media anyway. It's just the auto-play videos on Facebook that triggers the infrequent frustration.
I think Lumina is looking really promising, though. I recommend giving it a try if you have the time.
https://micahflee.com/2016/02/backdoored-linux-mint-and-the-...
Deleted comment
Linux Mint sucks, but I'm pretty much OK with disabling autologin to root.
About that.
> It’s important to be aware that UAC elevations are conveniences and not security boundaries.
https://technet.microsoft.com/en-us/magazine/2007.06.uac.asp...
>unfortunately, this is also where we run into some of the limitations of UAC. Remember, there is no effective isolation; there is no security boundary that isolates processes on the same desktop. The OS does include some protective measures to keep the obvious and unnecessary avenues of communication blocked, but it would be impossible and undesirable to block them all. Therefore, Microsoft does not consider breaches of that nonexistent security boundary to be security breaches.
https://technet.microsoft.com/en-us/magazine/2007.09.securit...
In default and probably usual configuration UAC does not represent security boundary between medium-il (user) an high-il (equivalent of linux's root). Only if you bother to run under non-admin account are you protected from escalations.
Leo Davidson then provided demonstrations of privilege escalation between those two integrity levels without triggering uac.
I haven't checked Windows 10, but at least until Windows 8 most machines running Windows had been running most software effectively under root.
After that, you have a trusted signature, and it doesn't matter if it the signature page is defaced.
If you're downloading the signature each time you're downloading a new version of a package or iso, and its SHAs, you're using GPG incorrectly.
I've had many signatures for package signers in my keyring for 5+ years. If and when they replace the key, they let the community know and we update our keyrings.
Yes, if you don't want to do that, fine, but for those of us who are careful users of GPG, it's a huge barrier against malware in packages and distros.
1. Get key id of the key used to sign the hashes. 2. Google for key id. Hmm, no one's used the key id before, that's odd. Not in my web of trust. And it doesn't match the key id mentioned on other forums/scripts/sites. I'll definitely hold off until I can verify the key directly with one of the distro maintainers.
Even if you haven't previously established trust, GPG can be an extremely valuable ally.
As linked in the blog post in my other comment, tails explains things quite well:
Ideally, the keys should be distributed in safe fashion too, so this whole question should be moot.
Though perhaps more trivial when the attacker has helpfully provided your operating environment.
I believe you're confusing a PGP public key with a PGP signature for a particular file (made using said public key).
My sentence about "trusted signature" could have been clearer, too. You have a public key that you trust, that you leverage to verify any new materials signed by the package/distro maintainer. So by extension, you can trust the signed hashes.
I've been using PGP/GPG on a regular basis since 1998, so I'm pretty used to the workflow by now and not at all confused about key pairs and signatures (although I will admit that I sometimes got confused about the point of subkeys until I read this a few years ago: https://alexcabal.com/creating-the-perfect-gpg-keypair/)
GPG is immensely useful for securely distributing packages and distros.
Seriously, with the rotten-ness of the US patent/copyright/political system, it's better for mankind to just say "ok, US users can't get this, but everyone else can".
E.g. many European banks do this for "US persons" - they simply cannot get accounts because the legal risks are just too high.
Edit: It's not just banks. E.g. BMW Group (and likely other huge non-US corps with US subsidiaries) refuse to allow US persons to look at financial statements, again due to regulatory hassle.
It's not legal risks, it's the cost of compliance.
https://en.wikipedia.org/wiki/Foreign_Account_Tax_Compliance...
I've gotten this vibe on Reddit, but it seems people seem to be against copyright unless it's Youtube not enforcing it vigorously enough when it comes to small channel owners getting their content stolen. Then suddenly everyone appears to be for copyright laws.
Setting aside for a minute that this isn't possible, it's like saying you won't release your app on iOS because of Apple's walled gardens. Sure, the walls suck, but the users inside are numerous and spend lots of money. Most product creators don't have the option to exclude US users.
Hmm, that was actually one of major selling points for Mint around me - it was the distro that "worked", with relevant software, codecs and drivers being preinstalled and not crippled due to strange laws on the other side of the ocean.
Suing in the rest of the world would be a rather wasted effort right now.
More pragmatically, it seems unlikely that Oracle or Adobe will sue a distro for helping them distribute the Java/Flash runtimes. They want their runtime to be on as many devices as possible.
As EU citizen I have zero influence on US politics. Complaining on HN to US citizens is literally all I can do.
> More pragmatically, it seems unlikely that Oracle or Adobe will sue a distro for helping them distribute the Java/Flash runtimes.
Then maybe those companies should change their license terms. Right now, Adobe does not even allow you to use a downloaded Flash installer on two computers, you must either download it separately on each PC or apply for a special license: http://www.adobe.com/products/players/flash-player-distribut...
If they want to shoot themselves in their feet, I'm not going to interfere.
What about making nice things that US citizens can't legally have? If you're legally in the clear in your own jurisdiction, you don't even need to take a risk yourself.
I'm not a lawyer and I don't know exactly what our situation is in the EU, so don't take my word that that's safe. Software patents may be technically banned, but I think people disguise them as 'business method' patents. And if you use US project hosting like Github, maybe someone can sue you there. I'm suggesting that, at the margins, we should take some risks.
I remember not long ago Mint included just about every browser media plugin ever made, including RealMedia, WindowsMedia etc., stuff that was obsolete 15 years ago. Maybe it still does.
All that stuff doesn't just mean bloat, but also significant security risks. You can somewhat get away with it because desktop Linux isn't a major target (yet), but it's just very bad practice that shows a lack of care.
Weren't those just VLC wrappers?
I remember the days before apt-get when there was only dpkg. Before Debian I used Slackware so I'm all too familiar with package management (or lack of).
The idea that someone would release a new distribution, based on Debian of all things, and it not be able to upgrade was repelling to my mind. Re-install Mint to upgrade? No thanks I'll install Ubuntu over it.
Cinnamon is nice but I never understood why it needs its own distribution. I should be able to apt-get install cinammon-desktop or whatever and it work like any other package.
On Debian you actually can 'apt-get install cinnamon' and have the full desktop.
I've been a Slackware-current user for most of a decade, and I love that it's so easy to upgrade the OS using slackpkg. I can (and do) often only upgrade a subset of packages, and never even need to reboot afterwards, not even after replacing the kernel (although, obviously...). A simple package system without dependency tracking has had many advantages for me. But installing stuff not in the standard system is more of a pain; there are third party repos but no where near as convenient as Debian/Ubuntu. I compile a couple SlackBuilds (packages) per week. I admit I've spent a huge amount of time learning how to do things like that manually and wouldn't recommend Slackware to those who won't want to learn sysadmin.
On the other hand my experience with upgrading between Ubuntu releases is terrible. A number of things have broken, permanently, every time, and I can't trivially upgrade from Ubuntu 14.10, because they purposefully break the package manager in old releases by breaking URLs. Also other pain points, like it not allowing installing both 32 and 64 bit devel libraries. I need those! The package manager is too complex and clever for me. (Honestly, I don't want to spend time learning how to override it.) I'm planning to format the drive and reinstall from scratch because it seems easier than fixing it.
Are you equating "simple package system" with "per-package service isolation" here? Because otherwise I don't see how your example about upgrades not requiring a reboot ties in with the package system. Debian has probably the most extensive package system, yet it still allows you to do upgrades without reboot. The major exception to this is dbus, because it still can't do stateful restarts. But I don't think that's a problem that Slackware is able to avoid, unless it avoids dbus completely.
Also: since Wheezy, Debian allows parallel installation of many development and shared library packages from all (10!) arches, for example to facilitate cross-compilation. It's still a work-in-progress, but I believe over 80% of the archive (not including packages with binaries) should be co-installable now.
I've never tried Debian, and my experience with Ubuntu is very limited. I guess my comment on reboots was off-base, and maybe more of it. I meant that packages aren't densely interconnected with dependencies. (macports has it really bad, seems every time I want to upgrade python I need to recompile gcc or something.) Anyway, the simplicity makes it easy to modify packages. E.g. last week I fiddled around with lua packages to allow parallel installing multiple versions (lua 5.1, 5.2, 5.3 are incompatible languages which are often mistaken for the same language by distro maintainers). However I realise creating .deb files is also easy, so I guess I could do just the same there. Also, Slackware's multiarch support is a very simple hack using a small script that works 100% of the time as far as I've seen. It's telling that Debian still only supports 80% of packages after who knows how much work put into it.
I understand what you mean about tightly integrated package dependencies, and for me Debian is the rare exception in that it mostly works. My main irk with it is that dpkg only allows one version of a package to be installed, so you end up with package names like gcc-4.9 to allow parallel installation. Or in your example, there's a lua5.1, lua5.2 and lua5.3 in the archive -- but that doesn't mean that every lua library is also available in all three versions.
But the package compatibility is still way better than ecosystems like Maven/Gradle or Stackage, where dependencies can be so tightly coupled that you end up working around old bugs in one package, or new bugs in another.
The compromise on their site with Wordpress was sad, but the best description I've heard for Wordpress was that it was "a rootkit with a blogging package ride along." It is so hard to secure a wordpress install and keep it that way.
I don't think that's true any more. I think they allow you to upgrade in place.
Modularity has its price.
"Secondly, they are mixing their own binary packages with binary packages from Debian and Ubuntu without rebuilding the latter. This creates something that we in Debian call a "FrankenDebian" which results in system updates becoming unpredictable <https://wiki.debian.org/DontBreakDebian#Don.27t_make_a_Frank.... With the result, that the Mint developers simply decided to blacklist certain packages from upgrades by default thus putting their users at risk because important security updates may not be installed."
while from <https://news.ycombinator.com/item?id=11131081>:
"Nobody else requires that you rebuild every package before you can redistribute it in a modified distribution - such a restriction is a violation of freedom 2 of the Free Software Definition, and as a result the binary distributions of Ubuntu are not free software."
I appreciate that the latter one is discussing a hard requirement as a result of Canonical's IP licensing. But the former seems to indicate that it would be bad practice to just copy all of Ubuntu's (or Debian's) binary packages and build a new derivative distribution on top of it. Is the latter piece arguing in part for a freedom that would be a really bad idea in practice?
This is okay. However, copying Ubuntu’s and Debian’s packages into the same repository and then mixing them willy-nilly is not.
You can either:
a) Base your derivative on binaries from Debian xor Ubuntu, then add source packages compiled with these binaries as you like.
or
b) Base your derivative on sources from Debian and/or Ubuntu, then compile everything together with your custom packages to make sure that all ABIs match.
Everybody else here is recommending 'safer' options, but seriously I don't want to pay the cost of fighting with my OS (which is what every Linux experience has been for me since 1996). Linux Mint has been the only OS which makes me forget that I am using Linux. It beats OS X in almost everything.
I hope then that you don't use you computer for developing software or for work or anything remotely important, because otherwise using insecure software is most egregiously unethical towards your users/customers/employers because you are consciously choosing to exposing them to unnecessary risks.
This is interesting because Debian itself encourages derivative projects to use their binary packages[1]:
> For those derivatives that re-use Debian binary packages, add some source packages and modify some source packages, where possible we encourage them to use standard Debian mirrors and add a second repository containing only the source and binary packages that have been added or modified.
Or maybe they don't encourage that behaviour but still give guidelines in case you want your derivative to work that way? I'm not 100% sure.
There was recently an article on HN about the "Web of Hashes" and this article got me thinking about it. Why not give each application an UUID and let that be it's name space? Give the user an option to still use- they're example- xedit while having another xedit installed along side?
I can see how this could also get messy. Just spit balling here.
That's not what was exactly written but is illuminating none-the-less (the original quote only says "name," which is a very different thing to "namespace"). Why do package managers have a single namespace to begin with? I should be able to install packages regardless of name conflicts, by using a namespace, e.g.
$> apt-get install mdm
Found org.debian.mdm and com.linuxmint.mdm.
$> apt-get install com.linuxmint.mdm
$> apt-get install org.debian.mdm
There's obviously the chance for a file system conflict, but the package manager should be able to keep track of that for you and abort if it would occur (or allow you to install it to a different prefix).It's incredibly naive to believe that name conflicts would never occur, especially with the 3-letter acronyms/contractions that are so prevalent in Unix. I'd pin the blame this specific problem squarely on Debian, it shouldn't be happening in the first place.
In Fedora (and most distros), programs with an executable name overlapping another program will be renamed to a unique name as part of the distro packaging. (Putting aside programs intentionally named the same thing because they provide the same function, which are managed differently via "alternatives".)
This puts some implicit pressure on creators of software to not reuse names that are already in use, which seems to work for the most part.
dev-lang/crystal (The Crystal Programming Language) games-mud/crystal (The crystal MUD client) x11-themes/crystal (Crystal decoration theme for KDE4.x)
When installing packages, if a package having a unique name across all categories, a simple "emerge vim" will install it. Otherwise, the category can be specified with "emerge dev-lang/crystal".
That is you can run both:
/opt/appfs/linuxmint.com/mdm/platform/latest/bin/mdm
and /opt/appfs/debian.org/mdm/platform/latest/bin/mdm
They are both always accessible (in other packaging systems you would refer to them as a "installed" since all their files may be read).Speaking as someone who knows the developer: no.
> Do you often have to build things from source?
There's ~6500 packages, so it's likely you'll be installing some stuff from source. It's really hard to predict without knowing specifics though. http://hydra.nixos.org/eval/1237359
Note that building from source is exactly the same process as building from binary - i.e. "nix-env -i firefox" will try to install from "cache" (the output of the continuous integration system's build process) and if it can't find something, build from source. Most important things are in the cache, some things aren't (mostly obscure packages and things with no-redistribution licenses), but in general it works out well.
You are blaming Mint for things that are wrong in some context with Debian/Ubuntu or Linux or even unsolved in computing as such. And the small team of developers simply can't respond to every single issue within minutes as you wish, they have their plate full.
I would gladly use KDE - I like it, but this https://bugs.kde.org/show_bug.cgi?id=162211 is still not fixed after so many years (and no - the title is not updated - it doesn't affect only remote media)
That said, no it should not excuse poor security.
GNOME and Unity also have that, probably KDE too.
Does Linux have a standard API for surfacing interactive icons and menus in the menu bar? An ICCCM extension, perhaps -- set some properties on the root window and cross you fingers? Or would you have to do it differently for every different Linux desktop environment or window manager that supported such a feature?
[1] https://developer.apple.com/library/mac/documentation/Cocoa/...
Exactly. Unity has libappindicator, KDE has Plasma, GNOME Shell also has its own plugin API and there's still the old tray API in Gtk+ and Qt.
Given this, what are the best alternatives to Mint GUI that offer the same level of comfort?
And add minimize/maximize buttons and applications ("start") button. I have no idea why Gnome has to experiment, they have lost so many users unnecessarily. At least it's configurable to something sane. They are far from catering to the same feature-averse audience of iPad so there's no use in trying to (poorly) emulate its minimalist design language.
I prefer taskbar from 7+ and in my experience only KDE can mimic it, albeit clunkily. From screenshot it seems Mint is closer to XP. I think GNOME can be beaten to look more familiar and I can tolerate it. At least it now respects Windows key convention and runs its search functionality.
I've been playing with Mint for the past few weeks and experimenting with full-Mint-on-a-VM versus Ubuntu-with-Cinnamon-desktop, and I don't really notice much of a difference. After reading about all of Mint's problems this morning, I'm tempted to stick with Cinnamon exclusively as a DE unless someone offers a compelling reason to use the full distro.
No. Switch to another DE. Cinnamon is developed by the same gung-ho cowboys that develop Mint so that's a poor indication that it's managed any better than Mint itself.
This was my shortlist at the end of all my adventurism and testing.
1. Linux Mint
2. Ubuntu MATE
3. Antergos Cinnamon
Pretty short list but those are what I found I settled on as possible choices for my own use. If the goal is getting down to business and getting work done rather than fiddling with the system I think those 3 would fit most people's needs. I was a longtime Xubuntu user prior to this adventurism, and IMO there are just better alternatives though it would probably be #4 if I had one, but I'm just not a fan any longer. MATE man handles XFCE.
I leave Mint at the top because other than these security concerns, it remains the best distro for me. I love their LTS update policy, continually delivering updates to Mint during the entire support span of Ubuntu LTS. Their desktop env is also just better IMO than alternatives.
Ubuntu MATE is pretty good and for the type of person like myself who is drawn to Mint, would be a really good alternative. It's missing a few features of Cinnamon, which is superior in general for me to MATE. But overall this is what I'll install if I decided to ditch Mint.
Antergos is just Arch with a nice installer. I didn't spend a long time testing this but it would be my choice for a rolling distro. Many people I know want that and they offer Cinnamon as a main, supported environment. Might be the best of every world for some. I prefer the slower updates of LM and UM, and install newer packages through PPAs or compiling it.
As an aside, I have completely given up installing other desktop environments onto distros that didn't originally ship with them. I see people recommending that, and it may work out but it's a mess if you want to switch back in my experience. I prefer to pick a distro that ships with the DE of your choice. I would not run for example, 'sudo apt-get install cinnamon-desktop-environment', anywhere at any point. :)
Hopefully this helps someone out there looking to migrate off of Mint. I'm still using it (on 17.2 here) but may move to UbuntuMATE or Antergos Cinnamon, depending on Clem's response.
For what I'm paying for Mint ($0.00) and what I get out of it in terms of productivity, I find it quite a decent distribution.
Open source projects need to be held to the very highest security standards.
How these security breaches are handled today set a precedent for how such security breaches are handled in the future. So it's a good idea to learn and improve from such security breaches and set a positive precedent.
The problem is that Mint allows users to trust it. It would be better if they didn't work on the distro at all if they're not going to take security seriously.
People on HN become furious about antivirus programs and routers and whatever else that are discovered to be laughably insecure. An OS is no less of security product than A/V or a router. In fact, it's the first line of defense for an end user.
> Once his bills are paid off
What bills are you talking about? As a result of this incident?
The last time I tried I couldn't get it to work in a painless/reliable way.
Also I like to be able to take a theme and modify components one by one like changing the colour of title bars or the font in menus without having to wade through 2k lines of CSS and non-existent documentation and then spend half an hour debugging why it's changed things all over the place. The v3 theming interface might as well let theme creators use obfuscation DRM to prevent users from modifying their themes.
It installed really smoothly, and was really quick and easy to set up for me, and my not-so-techy wife.
It installed the nvidia drivers when I asked it to without having to touch the commandline (there's a "drivers" or something like that tool in the system settings). I'd had some problems with them before on a pure debian install, so I was quite impressed.
In general, it was a pretty good experience. I'm thinking I may well switch over to fedora at home though. With my home machine I want something that just works, that I don't need to go faffing with config files any more. I have enough of that at work.
That said, in light of Mint's issues I'm seriously considering moving back to Xubuntu or some other disto that has Xfce as a first class citizen. I'd be interested in suggestions.
When my daughter asked what Linux distro she should install on her laptop, I didn't hesitate in recommending Mint.
Everytime I tried something else, I finally came back to Xubuntu, and try to remind myself to never switch away again.
* Linux Other 2,170 M 0.84%
* Linux Ubuntu 1,238 M 0.48%
* Linux Fedora 53.6 M 0.02%
* Mac PowerPC 49.7 M 0.02%
* Linux Mint 6.4 M 0.00%
* Linux Mips 4.6 M 0.00%
* Linux SUSE 3.9 M 0.00%
* Linux Debian 3.1 M 0.00%
etc
http://stats.wikimedia.org/wikimedia/squids/SquidReportOpera...
It's a desktop environment theme at best, and could be packaged as such. Maintaining a distro for general consumption (it's pitched to new users as "Windows like"), is very hard work and carries a lot of responsibility.
Cinnamon is more than just a desktop theme, and Mint is more than just Cinnamon. Worth looking into it further.
Linux Mint downloads (briefly) compromised
More ontopic: Having your Wordpress instance compromised is rather expected with the amount of security bugs Wordpress gets.