Ubuntu Pro Shenanigans
inteltechniques.com
inteltechniques.com
Funny to see Ubuntu offering "upgraded services" in the same vein.
Perception of value is an interesting thing.
Most normal users would not describe unpacking a Zip into a directory as "installing" - yet that's exactly what it is everywhere except Windows. Sometimes the unpacking isn't even necessary...
Of course it’s available on all OSes right now, but Windows has had incredible programmability (not comparable to Linux, but superior to MacOS), and since Powershell probably has a much more powerful scripting story than any other OS.
The ability to write quick scripts in Powershell, but also tap into C#, it’s massive standard library of code, and all the many 3rd party libraries and commingle that almost seamlessly with Powershell is tremendous.
Finally, Windows had probably the best toolkits to whip up a quick and dirty UI for anything you wanted to do with WinForms (name?) which was more powerful and yet quick and easy to use relative to any other toolkit on any other platform.
Unfortunately, what Windows has gained on the command line it appears to have lost in creating GUI driven scripts.
There was a TCL for Windows?
I believe the author is mistaken here; they are receiving updates only for "main" repository, and not for "universe". The example "ffmpeg" package belongs to "universe".
The UI seems bit confusing because it doesn't seem to show what the version available through ESM/Ubuntu Pro would be, but exploring the repository manually shows that for example for ffmpeg there is "Version: 7:4.4.2-0ubuntu0.22.04.1+esm2" available, a different version than what is available in the standard repositories.
Manually upgrading the source .deb to the (ABI compatible) ffmpeg 4.4.4 and compiling gets all the security fixes and seems to work. It looks like backporting just the security fixes was done incorrectly in Ubuntu's ESM release.
My main concern with ESM/Ubuntu Pro is that patches don't get as much community scrutiny and help as other updates. In this case it's broken a fairly major piece of software on what's supposed to be a super-stable LTS release.
Brave.
Ubuntu provides an opinionated workflow with self contained packages, with less work and more of an ecosystem, and more or less uses only concepts familiar to apt users already.
Nix still hasn't completed the Flakes transition, and it's not immediately clear at first glance what's declarative and what's not.
Snap is a lot simpler of a model. Include almost everything, except the base snap stuff, in a single package file, like an old school video game cartridge, rather than the UNIXy idea of software as part of the OS, carefully configured as part of a unique hand maintained system instance where all the parts have to work together perfectly.
NixOS has better reproducibility, because config files as well as apps are part of their declarative one file to rule them all system, but Ubuntu is easier to make changes on.
It's the first disto that doesn't feel like it's still built for the era of instances that would be maintained by a dedicated sysadmin for decades.
Everything should be declarative, just not pinned (plus the other nice features that flakes provides).
Ubuntu provides an opinionated workflow with self contained packages, with less work and more of an ecosystem, and more or less uses only concepts familiar to apt users already.
Nix still hasn't completed the Flakes transition, and it's not immediately clear at first glance what's declarative and what's not.
Snap is a lot simpler of a model. Include almost everything, except the base snap stuff, in a single package file, like an old school video game cartridge, rather than the UNIXy idea of software as part of the OS, carefully configured as part of a unique hand maintained system instance where all the parts have to work together perfectly.
If the only option is to pay, why pay a company that is using security to profit? Just get redhat and get it over with if you have to haggle with corporate purchasing, legal,etc... anyways.
When a package is available in any distro's maintained/mainline repo, users should expect security patches will be available as soon as humany possible for that package. If there was a premium repo, I get charging for that. But right now it is any packages and arbitrary CVE's, very upredictable.
Canonical says: "Here, enjoy these packages in our base repositories"
Many of those packages are completely third party/somehow qualify for 'universe', and such, no longer get security updates.
Why rebuild/test only a subset for the upsell? They've taken stewardship by offering them at all, in my opinion.
On the other hand: Red Hat will support everything they offer during the lifetime of a release. They don't really pick and choose as far as I'm aware. Caveat: EPEL et al
They do have a limited lifetime release problem... but at least they support the whole release.
I mean, that's the distinction; Ubuntu just includes their EPEL equivalent in the default repos. If you leave out EPEL, then RHEL has far less packages (or did last time I was in that ecosystem), because RH does their pick-and-choose at the repo level.
Once in a while I think of giving them some money. Every time I look into paying them for my home server, every time I see it's enterprisely priced and totally out of the question.
Yeah I have the free ESM enabled. Still, they could let people pay 25/year for server updates for up to 3 machines or something.
Free tier can rightfully pound sand in the support expectations department.
Perhaps a nearly-free tier wouldn't bring in enough revenue to offset the increased expectations there.
They could have a no-support or per-incident support tier that’s only a license. IMO the reason that doesn’t happen is because everyone only wants billionaire customers where all costs get passed to the end consumer without question.
A little profit isn’t enough anymore. All these companies want massive margins and profits and won’t settle for less. I think a total collapse in tech might actually be good for the long term health of the industry.
But, they could reasonably just shut the free tier machines off when they fell out of their automatic update lifespan.
Or they could find their value-add elsewhere.
This struck me too!
The author made some comments I didn't understand, giving me the impression that these were updates for proprietary Ubuntu packages or something, and therefore not a matter for concern. That doesn't seem right - if it's a security matter, and you have a patch, then you ship it.
Before that they're free. ESM is free for personal use too - conditions seem to change yearly, I think it's for up to 5 machines this week.
Most normal people will just upgrade to the next LTS before the 5 years pass :)
I give 'em $25/year as I feel what they do is valuable.
... I may forget that it's active on one machine/VM when I activate another, however. Old age or something ....
- 10 years maintenance
- first dibs on critical patches
- s/landscape/satellite
- cve information in the package stream
They're trying to make it easy to switch from RHEL by providing the same stuff.
Their default typeface is my favorite in the libre world
Some time ago they were the only ones with a patched freetype that didn't make your eyes bleed.
Before the snap fiasco they were all upside with no downside. I understand that they still are for a decent chunk of people.
No other OS gives me the ability to set up a machine and forget about it other than updates like Debian does.
Let the enshittification commence...
It will take another while, but it looks like Debian is our last hope for community linux (in apt ecosystem).
Arch, Gentoo, and NixOS don't use apt. However, neither does OpenSUSE, which is probably a better choice for non-technical users.
And those are all rolling distros, so I don't think they're a fit for anyone with that class of enterprise needs. NixOS has supported releases, but as far as I'm aware, each one gets less than a year— 22.11 was just deprecated in favour of the current 23.05 and the upcoming 23.11.
It can be useful for very slow to move businesses like my employer
My feelings on the direction of present day Ubuntu:
"You were supposed to destroy The Sith (aka Windows), not join them!"
The system search used to go to amazon.
There is lots of messy forced upgrade stuff in the os.
If you try to apt-get remove ubuntu-advantage-tools, it will cripple your system.
the motd-news system does a lot of silly stuff under the covers, with plenty of contact with canonical's servers.
- Linux Mint (which is based off Debian)
- Debian
- Fedora
- Gentoo
Thoughts? Ubuntu since a while would no longer make this list (in my opinion).
The download for their Debian Edition is hidden away under "other editions" as "LMDE". If you click on "recommended" you will get to the main download page which doesn't even mention the Debian Edition: https://linuxmint.com/download.php
Ok, good addition
>An e-book version of this release is not currently available. This is due to many reasons, including rampant piracy, counterfeit prints, Kindle tracking, exclusivity requirements, and unpredictable content removal from Amazon. We believe this book is better served as a printed reference manual.
What a bullshit excuse. I don’t read printed books, as I like ebooks way more. Cannot believe anyone technological try to persuade me I want to have a real book on my desk.
Guess that’s your only option if the product you want is an ebook.
I absolutely love Fedora and run it on my main desktop. That being said I also cut my teeth on CentOS so I’ve always had a soft spot for the RHEL approach to Linux. As for the bleeding edge aspect, I’ve rarely encountered issues with the latest updates. I had to do a bit of troubleshooting with pipewire and my HDMI output, and once a Gnome update caused the hertz setting on my monitor to bug out and cause a black screen.
None of it was really traumatizing though, and I have my system set to run a DNF update automatically on every login since I like to run as up to date as possible, and generally trust the packages won’t be overly buggy by the time they get pushed live.
—————————
After looking at your profile I realize you probably already are familiar with the philosophical differences of the two. Leaving the above for the potential benefit of anyone else who isn’t familiar.
Recently, I switched to Linux from Windows and it has been a good experience so far. I went with POPos because of how they integrated steam and the video drivers into the distro. It works great except shit breaks like booting and other things some times when they release major updates. I actually really like way Arch is designed. I was thinking of switching to Manjaro for stability reasons and I dont want to rip my hair out trying to get gaming to work in other distros. Im really looking for release stability with the ability to keep my gaming environment working. Any suggestions?
Personally I have separate gaming and Linux machines because I play games with Windows-specific anti-cheats.
If you've got an Nvidia card, then I have no experience with that on Arch, but here's the docs on Nvidia installation, it's easy: https://wiki.archlinux.org/title/NVIDIA
Linux Mint could also be a good alternative option. It has easy Nvidia drivers installation as well.
With bleeding edge comes instability though, so it's not all up-side. Personally, I've settled on Fedora Silverblue/Kinoite, which is an immutable version of Fedora. Basically, it gives me the best of both worlds: up-to-date software and stability. Since the system is immutable, it's really difficult to break it even if you try.
Another good, non-IBM alternative to that is OpenSuse Aeon/Kalpa/MicroOS. Or just Tumbleweed/Leap if you don't care about immutability.
This was the case with older versions of Debian, but these days it is quite nice.
But honestly, it depends on what you're using Ubuntu for. As a server or a VM for some work-adjacent purpose like this, Fedora's release cycle is too fast. I prefer Debian simply because there's no bullshit to it, it will always be there, its the base for most Docker images. I also consider most VMs ephemeral which gets around my annoyance with apt not having anything nearly as cool as dnf history.
I'm actually fine with modern CentOS but "I'll stick it on Debian" has been a really good default for me for the past 20 years.
As a desktop/workstation, Fedora's pretty good! Good package manager, good release cadence, strong commitment to upstreaming everything. GNOME has started to annoy me but Fedora's KDE release is great.
Just thought I'd chime in, given that there's over a 100 distros, this topic is going to get long plenty quick.
Yes, it was my favourite one during the Mandrake days, mostly because of KDE and being compiled for i586.
Nowadays I just stick with Ubuntu on VMs, and whatever is the default install on cloud.
> We feel that Ubuntu is being aggressively misleading with the rollout of Ubuntu Pro, and we do not recommend any OSINT users attach this service to their investigative VMs.
Or, you know, you could stop recommending Ubuntu as the preferred distro of choice. This is clearly user-hostile and there are numerous good alternatives available.
Doesn’t take much of that before it’s easier to just use a different distro.
2) Spying is opt-in, to their credit, and only at install, so you just have to make sure you aren’t auto-piloting your way through the installation and enable it by accident, but that’s still another thing to worry about that may not exist in other distros. Not much of an issue in automated-deployment situations.
I’m not optimistic canonical is going to just turn back from this path of Snaps and DRM.
you mean Linux Mint Debian Edition, yes it is exactly the reason they keep it going; who knows what Canonical might do tomorrow. Ubuntu is no longer "Linux for Human Beings"
Now, I get the impression that Ubutnu is far more important for backend than frontend. So, yea, “for humans” not so much. That is what I think Pop and Mint are doing well with.
At least that's what I understand.
However on a server I use Debian (stable) as I purposefully don't want to be at the 'cutting edge'. [I also use Debian on my laptop because it just works.]
Capitalising the first letter of each package name makes it look jarring.
I have to click on the line to see the actual package name in the more info section.
Ubuntu is my default choice. It's very easy to use, polished and doesn't require tweaking.
I just installed Ubuntu Server earlier this week on my home server, and I was surprised at how nice the installer has gotten.
It’s pretty good, but adding two ESP devices gives the impression you’re getting boot redundancy and you’re not. Only one of them will end up with GRUB. Then, once you fix that, only the primary device will have an entry in fstab and SystemD will have a nervous breakdown if you try to boot off the secondary with the primary missing. Good luck supplying the root password for emergency mode because you probably don’t have one.
How do you do that? The only way I know of is to use mdadm to RAID1 the partitions[0], but I wouldn't expect that to break the way you've described.
[0] This is also a bit fiddly; IME you have to pick a specific configuration so the firmware will read the result.
They aren't content to just make a good product, it has to be disgustingly profitable. Once a company starts down that path, it's only a matter of time until the end user experience becomes completely intolerable. We've seen it happen so many times we had to coin the word enshittification to describe it.
Apart from very specific complaints like snaps, the hate is not for Ubuntu, the hate is for Canonical the company. People obviously still like and use Ubuntu, it's one of the pillars of the Linux community. Canonical has forgotten that in their plays for more money.
Really, Canonical has been going downhill for a long time. It just hasn't been bad enough to provoke this kind of outcry until the premium ads in the apt package manager.
If Canonical continues what they're doing, they'll see a prodigious loss of free users. That won't hurt them directly, but it will begin a slow and steady decline in enterprise usage. If it's so unpleasant to use Ubuntu at home, why would you use it at work if given the option? Ubuntu will stick around for a good long while and slowly get worse and worse as Canonical becomes more and more desperate.
Canonical as a whole has some very serious problems and I really don't expect them to survive long term. I'm not sure it's possible to fix a company once they're in that state.
Oh well, at least we have ten thousand other Linux distros to choose from.
It turns out many don't like trying out thousand of other Linux distros and how each of them decides to be different from everyone else.
I've used Debian, but the installs feel so barebones. I love that Ubuntu has many of the common packages I need, yet it doesn't feel bloated.
Additionally, most software that supports Linux has instructions for Ubuntu, or Ubuntu just feels better supported.
FlatPak instead of Snap. No telemetry or DRM.
IMO you get to “stay with Ubuntu” but are also isolated from Canonical’s increasingly strange decisions.
I personally use OpenSUSE and Manjaro as my daily drivers after switching from Ubuntu 3 years ago, and have yet to encounter any package problems that directly stemmed from not using Ubuntu. For everything else, there's always Flatpak.
These are hypothetical scenarios and irrelevant to the context of this thread, which is about asking for Ubuntu alternatives now. The alternative doesn't have to be 100% community driven or completely detached from Ubuntu. It just needs to be usable without the nonsense of Ubuntu Pro or Snap.
Personally I've been using Arch for a long time. I prefer it in basically every way, except the pacman interface is hot garbage compared to apt. I wouldn't recommend Arch for everyone, and I don't recommend the base Arch distro for anyone. Get one of the nicer arch variants like Garuda or Cinnamon.
Then install the packages you want? If it's not in Debian repos then yeah that's compelling, but otherwise you're describing one extra apt-get command (per OS install) that you stick in your notes and reuse every few years.
It's free for individuals for 5 machines.
This isn't unique to Ubuntu. So there's no strong incentive for users to stick with Ubuntu in the face of repeated alienating acts like this.
But I thank them, they helped me move to Debian and I haven't looked back.