Ubuntu LTS: many vulnerabilities despite long-term support
wilderssecurity.com
wilderssecurity.com
https://security-tracker.debian.org/tracker/status/unreporte...
And CentOS doesn't even publish that data because it would probably terrify you...
The fact is that not all vulnerabilities are equal. Some silly crashing bug in Wireshark cannot be equated to an easily-exploitable RCE in some widely used library. I am pretty sure most of the latter are fixed everywhere, whereas the former should be ignored. If your use case really really requires fixing such low importance issues, then patch it yourself, or pay support fees to someone who will do it for you.
And the fact that Debian patches some issues but Ubuntu does not is simply a question of how much work has been put into it. If a Debian pkg maintainer releases a new version, there is no guarantee that it doesn't break some other functionality. Simply patching without putting serious work into it is the trait of community distros like Debian and Fedora. Ubuntu, I assume, must go through a much more grueling process to get fixes out. Use whichever fits your use case...
Stable release maintenance of Debian and Ubuntu are thus independent in principle.
In practice patches for one are likely to be similar to what is needed on the other, issues affecting one are likely to affect the other, there are Debian developers who are also Ubuntu developers, Canonical employees who are also Debian developers, everyone is working towards a common goal of stable maintenance, and so forth, so there is quite a bit of communication and cross-pollination between the two. For example: I'm a Canonical employee and Debian maintainer; today I've spent quite a bit of time working on a security fix for a package I maintain in Debian that I'm effectively being paid to do by Canonical.
That seems like an unfair statement. Debian is a stable distro and I'd say has a pretty good track record of doing what it does. It seems disingenuous to suggest they're patching willy nilly.
Either way, I don't think we should compare either on anything other than what they produce. You're free to think Ubuntu providers a better distro but please base it on something that isn't meta such as number of paid employees, because that does a disservice to those who give up their free time.
Sometimes it's not what went wrong, it's your approach to fixing it.
Why can't Canonical move these fixes to Ubuntu LTS then? Seems the majority of the work (finding the cause, patching the code) was already done and corrections are sitting on some development branches from other distros.
This might make sense for core packages that need to present a stable API throughout the lifecycle of an LTS release, but it creates a whole bunch of needless work for maintainers of other packages (who are often the same people who work upstream). Frozen distros are essentially telling them to create a frankenversion of their own program, one for each distro, based on some arbitrary version from several months or even years ago.
Until a few years ago, most distros shipped a frozen version of Firefox and only backported important fixes. Ubuntu finally gave up and started shipping new versions of Firefox as soon as Mozilla releases them. I think they need to do the same with most of the packages in "universe", too, including the vast majority of GUI apps. No backporting, just pull the new version, build it, and run some tests. It would save a lot of duplicate work that every upstream is already doing, at negligible cost to the stability of the LTS release as a whole.
The "majority of the work" is done by upstream really, not other distros. The remaining work is backporting and QA which is distribution-specific, since the target versions (both of the package being updated and interactions with other packages that might be affected) are not necessarily the same.
All in all it's pretty irresponsible to allow the current situation in the first place. Don't ship vulnerability-prone internet-facing C apps that you can't patch.
I wonder what the patch situation in practice is with CentOS installs that enable EPEL?
I think it's even worse because they won't patch or remove it. They could, but they do not consider it a problem. Ubuntu just imports everything from Debian. Things not relevant to the core team at Canonical are just thrown at the community basically saying "if you want a safe OS, you have to support this by yourself now". All the while Canonical is building their in-house, partly closed-source solutions to already solved problems.
For packages in Main a core developer (could be Canonical or someone else) has to be assigned to look after it and the Ubuntu security team has to allow it into the repository on the basis of it having a good security record and being maintainable [1]: it is _true_ that the Ubuntu security team is basically all Canonical employees. Many of these packages follow the upstream and don't come from Debian: or in some cases it's the same Canonical employee who maintains both the Debian and the Ubuntu packages so they might upload to Debian and pull in, or upload to both [2].
For Universe, Ubuntu pulls and builds from Debian. Many packages are sponsored by a maintainer who can then choose to upload their own package rather than use the latest sync from Debian. They aren't "thrown" to the community, rather they are never "promoted" to Main.
All distributions have to choose how they deal with the large 'Universe' of software out there: in the Debian/Ubuntu world there's always been a lot of packages, compared to commercial RPM world. In Ubuntu's case the decision was to build/provide those packages, and let users decide what they wanted to do: for a 100% secured environment you would only turn on Main which is why the tools show you the supported status.
The next question is whether it's a problem. It's not a problem if you understand a bit about how your distribution works. We can also look at the fact that it's been this way since Ubuntu started - so from 2004 it's worked like this.
Clearly you don't like Ubuntu, which is fair enough: but I have to ask what you mean by "partly closed-source solutions" when there's nothing involving desktop Ubuntu that is closed-source. I assume you don't like Unity or something, but it's very much open source. Unless you are thinking of something else I'm unaware of?
[0] https://help.ubuntu.com/community/Repositories/Ubuntu
[1] https://wiki.ubuntu.com/MainInclusionProcess [2] https://www.piware.de/tag/debian/ is an example of someone who does this.
As far as security goes, Ubuntu really should work together with Debian to leverage each other to better the situation. My sites run either LTS or Debian and now I'm more worried.
If you stick with official packages, you are fine. It is the front-facing services that are important, and these are updated for security issues.
PPAs were supposed to solve this problem, and the official line is that Snap packages are supposed to solve this problem, but better.
A rare few vendor ppas are frequently updated with the newest major version of the app for latest 1 or 2 LTS releases until they aren't, that's about the best I've seen.
At least in terms of package format, the difficulty with dpkg is that a) general software developers don't understand it, and b) it's not transactional in the sense you can't reverse what's happened easily.
Trying to get commercial developers onto Linux is very difficult: on the desktop side they often don't see the point of such a small platform, and on the server side they feel it's super complicated and difficult. It might be stating the obvious but most developers aren't system administrators, so they really, really struggle with packaging and complain about dpkg/rpm a lot. Appstores are both tools and a process: Ubuntu did developer.ubuntu.com to provide an easy process for developers, and snap packages are another step along that way.
Lets not let the perfect get in the way of the improved!
Please support the bug report on Launchpad:
https://bugs.launchpad.net/ubuntu/+source/network-manager-op...
I think a fair comparison would be to show other distros too rather than judge Ubuntu based on a single data-point.
For instance, a user stuck with ancient packages on CentOS may quickly reach out to alternative repos and pull in tons of packages with questionable security.
The article is a post on a bulletin board by someone stating two facts:
a. Canonical "claims" they provide Long Term Support b. That support is for the "Main" repository only.
Neither of these points is incorrect: though "claim" clearly implies their opinion. All the Linux distributions need to draw the line somewhere on what software they will provide security for: Ubuntu comes from the Debian tradition which packages a large swathe of software, so to differentiate levels of support/origin they are separated into repositories. Other distributions reduce the total amount of packaged software made available, to deal with the same issue.
The title is misleading because it implies that Ubuntu LTS' security record is poor: which this article is not discussing.
Currently I am running 14.04 which I keep regularly updated. The only other software I have installed is plex media server and chrome. Seems like I would be more at-risk if I were running more 'non-main' packages, but I am not really sure what that means.
As a desktop user, you interact with the hostile Internet through your browser, which is updated as soon an issue appears. You might open PDF documents, so this is evince. Or Libreoffice for .doc. Both are in main and get security updates.
(1) Edit: Removed "disability" from here, autocorrect accident.
In general, I've seen developer preference for two reasons:
1. Debian & Ubuntu both share a massive collection of packages which have frequently been packaged in a manner which is amenable for automated system configuration (compare e.g. the tendency to use a combination of debconf and the preference for `.d` layouts so you don't have to modify files which will be overwritten by updates).
2. Ubuntu adds the entire PPA ecosystem which supports the very common case where people want LTS + a small number of packages which are updated more frequently.
http://fossbytes.com/ubuntu-linux-is-the-most-popular-operat... https://duh6oa3w9hopv.cloudfront.net/uploads/pdfs/RightScale... etc.
The must be doing something right, but of course as quickly as they rose, they could loose the market equally quickly. I do see interesting directions, though: Ubuntu seems to be the default choice on OpenPOWER servers (at least for now) and it will likely be a strong contender; see e.g. https://www-03.ibm.com/press/us/en/pressrelease/47791.wss
One group that has certainly contributed and needs to be given credit is Debian!
People want working devices/peripherals (admittedly, I'm not very familiar with the state of the drivers on FreeBSD today, but I know it has been an issue) and many prefer to be productive too rather than hack away at their OS. These OSes have moved out of the garage and are running a large part of this damn Internet :)
FreeBSD is certainly perfect for some niche uses but, I believe, it isn't realistic for many if not most GNU/Linux server uses today.
And that's where I'd come back to your initial point on Ubuntu's lacking server benefits: you may not see them, but many do, and for better or worse they vote with their choice. Even if many don't like it, let's be honest, many do benefit from it indirectly.
- http://unix.stackexchange.com/questions/tagged/debian - 5K questions
- http://stackexchange.com/sites?view=list#traffic - 224K questions
If you need maas, juju (whitch of course can run on others distro), a system with 5 years of security updates without extra fees,