Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #244351

Re: Why is Debian not telling the truth about its security fixes?

Path csiph.com!newsfeed.xs4all.nl!newsfeed7.news.xs4all.nl!bofh.it!news.nic.it!robomod
From "Andrew M.A. Cater" <amacater@einval.com>
Newsgroups linux.debian.user
Subject Re: Why is Debian not telling the truth about its security fixes?
Date Sat, 22 Jan 2022 20:30:01 +0100
Message-ID <DIuff-7aw-3@gated-at.bofh.it> (permalink)
References <DIoCR-3Ln-1@gated-at.bofh.it> <DItVT-73X-7@gated-at.bofh.it>
X-Original-To debian-user@lists.debian.org
X-Mailbox-Line From debian-user-request@lists.debian.org Sat Jan 22 19:24:28 2022
Old-Return-Path <amacater@einval.com>
X-Amavis-Spam-Status No, score=-9.2 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, FOURLA=0.1, LDO_WHITELIST=-5, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham autolearn_force=no
X-Policyd-Weight using cached result; rate: -4.6
MIME-Version 1.0
Content-Type text/plain; charset=us-ascii
Content-Disposition inline
X-Mailing-List <debian-user@lists.debian.org> archive/latest/785146
List-ID <debian-user.lists.debian.org>
List-URL <https://lists.debian.org/debian-user/>
List-Archive https://lists.debian.org/msgid-search/YexZ200oSIXk96Bk@einval.com
Approved robomod@news.nic.it
Lines 74
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Sat, 22 Jan 2022 19:24:11 +0000
X-Original-Message-ID <YexZ200oSIXk96Bk@einval.com>
X-Original-References <1234584452.548394.1642857828702@ichabod.co-bxl> <alpine.DEB.2.21.2201221826300.24926@einstein.home.woodall.me.uk>
Xref csiph.com linux.debian.user:244351

Show key headers only | View raw


On Sat, Jan 22, 2022 at 07:01:24PM +0000, Tim Woodall wrote:
> On Sat, 22 Jan 2022, max wrote:
> 
> > 
> > WHY IS DEBIAN NOT TELLING THE TRUTH ABOUT ITS SECURITY FIXES?
> > 
> snip rant.
> 
> I could have the opposite rant. WHY IS DEBIAN NOT TELLING THE TRUTH
> ABOUT ITS STABLE DISTRIBUTION.
> 
> Because I have a machine (actually more than one) sat running buster
> that has SSH listening but can only be reached via limited routes.
> 
> And the installed browser is able to connect only to the local network
> too. On that local network there is a proxy - but that proxy does not
> let this machine connect anywhere.
> 
> This machine runs xvnc (or something like that, off the top of my head I
> forget exactly which vnc service it is running) and in order to actually
> connect to the vnc server you have to use ssh forwarding via public key
> authentication.
> 
> That machine has exactly one use, and that is to enable me to connect to
> the IPMI console on two servers. The ipmi itself is presumed not safe to
> expose and so is also firewalled from everything else.
> 
> For obvious reasons these machines are required rarely, but when
> everything else is breaking it is critical that they work. (This is my
> home network so techically pysically plugging in a screen and keyboard
> is only a 10 minute job rather than a remote hands request)
> 
> I want to keep ssh up to date, that's the one thing that does need to be
> remotely accessible. but I'm laid back about everything else. And yet,
> java updates, firefox updates *regularly* break things because the (no
> updates available) IPMI firmware is using "insecure" security settings.
> 
> 
> I would rather debian stable continued to carry a version of the various
> major browsers than they dropped it completely. But dropping it is the
> most likely thing to happen if the people who complain the loudest don't
> step up and do the work to keep it completely up to date.
> 
> I'm pretty sure that if someone steps up to do all the work to package
> each esr release of chromium/firefox then debian will be likely to take
> them (expecially if they're fixing known security issues) even if
> they're going to break the normal debian stable compatibility rules. But
> this is a lot of work. All this ranting is going to achieve is moving
> firefox debs to a third party repo, making it more difficult for those
> of us who have a use case for a "good enough" browser and have other
> ways to avoid security issues in the browser.
> 

I might suggest netsurf as a very lightweight browser that is very
well maintained by a dedicated bunch of folk - it's also cross platform
though I've no idea whether it will work with your IPMI.

Debian perforce has to adopt the upstream decisions of the originators
of  Firefox/Chromium - but the requirement of having to build on each
release is not negotiable, I think, or the oldstable releases end
up as a mess of incompatible libraries. Buster, of course, is not the
current stable but is still supported by the main Debian security team
to 2022-08-14 and the LTS team until 2024.

With every good wish, as ever,

Andy Cater

> 
> FTAOD, I think the debian volunteers are doing a great job and while I
> might wish that their efforts were focused on exactly MY needs, I'll
> take whatever they're willing to give with a thank you (and an
> occasional, unwarranted, moan).
> 

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Why is Debian not telling the truth about its security fixes? max  <maxwillb@mailfence.com> - 2022-01-22 14:30 +0100
  Re: Why is Debian not telling the truth about its security fixes? Jim Popovitch <jim@k4vqc.com> - 2022-01-22 14:50 +0100
    Re: Why is Debian not telling the truth about its security fixes? max  <maxwillb@mailfence.com> - 2022-01-24 04:50 +0100
  Re: Why is Debian not telling the truth about its security fixes? songbird <songbird@anthive.com> - 2022-01-22 15:30 +0100
  Re: Why is Debian not telling the truth about its security fixes? "Andrew M.A. Cater" <amacater@einval.com> - 2022-01-22 16:00 +0100
    Re: Why is Debian not telling the truth about its security fixes? max  <maxwillb@mailfence.com> - 2022-01-24 05:30 +0100
      Re: Why is Debian not telling the truth about its security fixes? Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-24 07:10 +0100
        Re: Why is Debian not telling the truth about its security fixes? <tomas@tuxteam.de> - 2022-01-24 07:10 +0100
          Re: Why is Debian not telling the truth about its security fixes? Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-24 07:40 +0100
      Re: Why is Debian not telling the truth about its security fixes? Pierre-Elliott Bécue <peb@debian.org> - 2022-01-24 22:50 +0100
  Re: Why is Debian not telling the truth about its security fixes? Tim Woodall <debianuser@woodall.me.uk> - 2022-01-22 20:10 +0100
    Re: Why is Debian not telling the truth about its security fixes? "Andrew M.A. Cater" <amacater@einval.com> - 2022-01-22 20:30 +0100
  Re: Why is Debian not telling the truth about its security fixes? Stefan Monnier <monnier@iro.umontreal.ca> - 2022-01-22 23:40 +0100
    Re: Why is Debian not telling the truth about its security fixes? Pierre-Elliott Bécue <peb@debian.org> - 2022-01-23 11:30 +0100
      Re: Why is Debian not telling the truth about its security fixes? max  <maxwillb@mailfence.com> - 2022-01-24 06:20 +0100
        Re: Why is Debian not telling the truth about its security fixes? Pierre-Elliott Bécue <peb@debian.org> - 2022-01-24 22:50 +0100
          Re: Why is Debian not telling the truth about its security fixes? The Wanderer <wanderer@fastmail.fm> - 2022-01-25 04:20 +0100
  Re: Why is Debian not telling the truth about its security fixes? max  <maxwillb@mailfence.com> - 2022-01-24 07:50 +0100
    Re: Why is Debian not telling the truth about its security fixes? Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-25 10:00 +0100
      Re: Why is Debian not telling the truth about its security fixes? Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-25 10:40 +0100

csiph-web