Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #244324 > unrolled thread

Why is Debian not telling the truth about its security fixes?

Started bymax <maxwillb@mailfence.com>
First post2022-01-22 14:30 +0100
Last post2022-01-25 10:40 +0100
Articles 20 — 11 participants

Back to article view | Back to linux.debian.user


Contents

  Why is Debian not telling the truth about its security fixes? max  <maxwillb@mailfence.com> - 2022-01-22 14:30 +0100
    Re: Why is Debian not telling the truth about its security fixes? Jim Popovitch <jim@k4vqc.com> - 2022-01-22 14:50 +0100
      Re: Why is Debian not telling the truth about its security fixes? max  <maxwillb@mailfence.com> - 2022-01-24 04:50 +0100
    Re: Why is Debian not telling the truth about its security fixes? songbird <songbird@anthive.com> - 2022-01-22 15:30 +0100
    Re: Why is Debian not telling the truth about its security fixes? "Andrew M.A. Cater" <amacater@einval.com> - 2022-01-22 16:00 +0100
      Re: Why is Debian not telling the truth about its security fixes? max  <maxwillb@mailfence.com> - 2022-01-24 05:30 +0100
        Re: Why is Debian not telling the truth about its security fixes? Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-24 07:10 +0100
          Re: Why is Debian not telling the truth about its security fixes? <tomas@tuxteam.de> - 2022-01-24 07:10 +0100
            Re: Why is Debian not telling the truth about its security fixes? Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-24 07:40 +0100
        Re: Why is Debian not telling the truth about its security fixes? Pierre-Elliott Bécue <peb@debian.org> - 2022-01-24 22:50 +0100
    Re: Why is Debian not telling the truth about its security fixes? Tim Woodall <debianuser@woodall.me.uk> - 2022-01-22 20:10 +0100
      Re: Why is Debian not telling the truth about its security fixes? "Andrew M.A. Cater" <amacater@einval.com> - 2022-01-22 20:30 +0100
    Re: Why is Debian not telling the truth about its security fixes? Stefan Monnier <monnier@iro.umontreal.ca> - 2022-01-22 23:40 +0100
      Re: Why is Debian not telling the truth about its security fixes? Pierre-Elliott Bécue <peb@debian.org> - 2022-01-23 11:30 +0100
        Re: Why is Debian not telling the truth about its security fixes? max  <maxwillb@mailfence.com> - 2022-01-24 06:20 +0100
          Re: Why is Debian not telling the truth about its security fixes? Pierre-Elliott Bécue <peb@debian.org> - 2022-01-24 22:50 +0100
            Re: Why is Debian not telling the truth about its security fixes? The Wanderer <wanderer@fastmail.fm> - 2022-01-25 04:20 +0100
    Re: Why is Debian not telling the truth about its security fixes? max  <maxwillb@mailfence.com> - 2022-01-24 07:50 +0100
      Re: Why is Debian not telling the truth about its security fixes? Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-25 10:00 +0100
        Re: Why is Debian not telling the truth about its security fixes? Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-25 10:40 +0100

#244324 — Why is Debian not telling the truth about its security fixes?

Frommax <maxwillb@mailfence.com>
Date2022-01-22 14:30 +0100
SubjectWhy is Debian not telling the truth about its security fixes?
Message-ID<DIoCR-3Ln-1@gated-at.bofh.it>
This is a text-only version of my post on https://medium.com/@maxwillb/why-is-debian-not-telling-the-truth-about-its-security-fixes-85f0f85f19a0 
It is missing hyperlinks and illustrations. Comments, corrections and suggestions are very welcome.

---

WHY IS DEBIAN NOT TELLING THE TRUTH ABOUT ITS SECURITY FIXES?

Debian is a Linux distribution. As such, it repackages open-source software created by others. The packages distributed by Debian usually lag quite a bit behind the most up-to-date versions. This allows them to be better-tested. However, when security flaws are inevitably discovered, they usually get fixed only in the up-to-date versions. So someone must adapt and apply these fixes to the older versions redistributed by Debian. And this is precisely what Debian promises to do

[PIC]

On debian.org/security, linked from the front page, it states:

"Debian takes security very seriously. We handle all security problems brought to our attention and ensure that they are corrected within a reasonable timeframe. Many advisories are coordinated with other free software vendors and are published the same day a vulnerability is made public and we also have a Security Audit team that reviews the archive looking for new or unfixed security bugs."

Debian’s Wikipedia page echos and amplifies these claims, citing Debian itself:

"Debian security advisories are compatible with the Common Vulnerabilities and Exposures dictionary, are usually coordinated with other free software vendors and are published the same day a vulnerability is made public."

“Debian security advisories are published the same day a vulnerability is made public”?!

[PIC]

These claims are widely believed by Debian users, but they are false. On Debian’s own little-known security-tracker, we can see open security vulnerabilities that are quite old. For example this HIGH-severity vulnerability took 4.5 months to fix in Debian.

Additionally, I noticed that the vulnerability severity ratings given by the National Vulnerability Database (NVD) are often shown incorrectly by Debian. For example, this vulnerability is rated “9.6 CRITICAL” by NVD, and there are in fact known exploits for it in the wild. But it’s still shown as having a “medium” NVD rating by Debian:

[PIC]

I suspected that at least some Debian developers (unlike its users) were aware that debian.org/security was taking liberties with the truth. It also seemed implausible that no one had noticed that the NVD ratings were often wrong. However, I try to assume good faith, so under the assumption that these problems were somehow an institutional oversight, rather than intentional lies, I submitted my concerns to the debian-security mailing list.

PRESS RELEASES

Debian likes its press releases. Directly on its front page, we can see a press release for a minor version bump, and another press release announcing that it excommunicated one of its 1000 members.

[PIC]

Surely, correcting a key falsehood that’s been told to countless users, undecided users, donors (Debian’s main source of revenue), and prominently relayed to Wikipedia readers, would at least warrant a press release also and require swift action to minimize continued damage?

DEBIAN'S RESPONSE

One Debian developer replied with a minor critique of my proposed new text (which I addressed) and asked me to send my concerns about wrong NVD ratings as a separate email (which I did). Another Debian developer replied to him, dismissing my concerns about wrong NVD ratings:

"We are going to stop anyway at some point displaying the NVD severity, for context see #992115."

I disagreed with his reasoning not to issue a correction and to continue showing wrong NVD ratings. And since he completely ignored my main concern, and it had been 17 days after my original post, without any action or discussion, I inquired about progress there. This is when something sociologically interesting happened: A third Debian developer, apparently irritated, decided to just shut me up:

"Maybe at some time you could just stop keeping on insisting on that matter?"

Note that I wasn’t flooding the mailing list. The messages linked above are all that I had sent to the mailing list up to that point. He followed up with a threat of a ban.

Will Debian ever live up to its “Social Contract” that includes “Not hiding problems with the software or organization”? Will it apologize for misleading countless people? Given Debian’s response so far, I’m not very hopeful.

-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [next] | [standalone]


#244325

FromJim Popovitch <jim@k4vqc.com>
Date2022-01-22 14:50 +0100
Message-ID<DIoWe-3Si-11@gated-at.bofh.it>
In reply to#244324
On Sat, 2022-01-22 at 14:23 +0100, max wrote:
> 
> WHY IS DEBIAN NOT TELLING THE TRUTH ABOUT ITS SECURITY FIXES?
> 

I was interested, until I realized your Medium post is that Google
Chrome is not updated fast enough by Debian.  

-Jim P.

[toc] | [prev] | [next] | [standalone]


#244489

Frommax <maxwillb@mailfence.com>
Date2022-01-24 04:50 +0100
Message-ID<DIYwF-9g-1@gated-at.bofh.it>
In reply to#244325
January 22, 2022 2:42:39 PM CET Jim Popovitch <jim@k4vqc.com> wrote:

> I was interested, until I realized your Medium post is that Google Chrome is not updated fast enough by Debian.  

Not at all. It's about the fact that the claims on debian.org/security are counterfactual.

-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [prev] | [next] | [standalone]


#244329

Fromsongbird <songbird@anthive.com>
Date2022-01-22 15:30 +0100
Message-ID<DIpyV-4kb-5@gated-at.bofh.it>
In reply to#244324
max wrote:
> This is a text-only version of my post on https://medium.com/@maxwillb/why-is-debian-not-telling-the-truth-about-its-security-fixes-85f0f85f19a0 
> It is missing hyperlinks and illustrations. Comments, corrections and suggestions are very welcome.
...
> Will Debian ever live up to its “Social Contract” that includes “Not hiding problems with the software or organization”? Will it apologize for misleading countless people? Given Debian’s response so far, I’m not very hopeful.

  every individual maintainer is on their own schedule, there are
very few paid and full time Debian Developers or Maintainers or other
people devoted solely to security fixes in all the various archives 
which Debian has available.

  since i know this i take it all with some amount of flex because
while the goal is admirable i know that reality is different.

  i also understand the limitations of each repository i use as a
source for packages.  testing may not get frequent security updates
but i am quite happy with the pace of how things go and for my own
needs i'm not doing any public facing high security projects which
might need more closely monitored security.  perhaps this is a
choice you need to figure out for yourself?


  songbird

[toc] | [prev] | [next] | [standalone]


#244331

From"Andrew M.A. Cater" <amacater@einval.com>
Date2022-01-22 16:00 +0100
Message-ID<DIq1X-4tF-1@gated-at.bofh.it>
In reply to#244324
On Sat, Jan 22, 2022 at 02:23:48PM +0100, max wrote:
> This is a text-only version of my post on https://medium.com/@maxwillb/why-is-debian-not-telling-the-truth-about-its-security-fixes-85f0f85f19a0 
> It is missing hyperlinks and illustrations. Comments, corrections and suggestions are very welcome.
> 
> ---
> 
> WHY IS DEBIAN NOT TELLING THE TRUTH ABOUT ITS SECURITY FIXES?
> 
> Debian is a Linux distribution. As such, it repackages open-source software created by others. The packages distributed by Debian usually lag quite a bit behind the most up-to-date versions. This allows them to be better-tested. However, when security flaws are inevitably discovered, they usually get fixed only in the up-to-date versions. So someone must adapt and apply these fixes to the older versions redistributed by Debian. And this is precisely what Debian promises to do
> 
> [PIC]
> 
> On debian.org/security, linked from the front page, it states:
> 
> "Debian takes security very seriously. We handle all security problems brought to our attention and ensure that they are corrected within a reasonable timeframe. Many advisories are coordinated with other free software vendors and are published the same day a vulnerability is made public and we also have a Security Audit team that reviews the archive looking for new or unfixed security bugs."
> 
> Debian’s Wikipedia page echos and amplifies these claims, citing Debian itself:
> 
> "Debian security advisories are compatible with the Common Vulnerabilities and Exposures dictionary, are usually coordinated with other free software vendors and are published the same day a vulnerability is made public."
> 
> “Debian security advisories are published the same day a vulnerability is made public”?!
> 
> [PIC]
> 
> These claims are widely believed by Debian users, but they are false. On Debian’s own little-known security-tracker, we can see open security vulnerabilities that are quite old. For example this HIGH-severity vulnerability took 4.5 months to fix in Debian.
> 

This discussion has been had several times: you've raised it several times
and been answered several times. Debian does fix security problems - and is
open about them. 

> Additionally, I noticed that the vulnerability severity ratings given by the National Vulnerability Database (NVD) are often shown incorrectly by Debian. For example, this vulnerability is rated “9.6 CRITICAL” by NVD, and there are in fact known exploits for it in the wild. But it’s still shown as having a “medium” NVD rating by Debian:
> 
> [PIC]
> 

Debian can feel free to set its own ratings based on how straightforwardly ti
affects Debian packages as a whole: a kernel vulnerability that affects 
10,000 users at medium _might_ be higher impact than a vulnerability
affecting one browser for far fewer users, as an example.

> I suspected that at least some Debian developers (unlike its users) were aware that debian.org/security was taking liberties with the truth. It also seemed implausible that no one had noticed that the NVD ratings were often wrong. However, I try to assume good faith, so under the assumption that these problems were somehow an institutional oversight, rather than intentional lies, I submitted my concerns to the debian-security mailing list.
> 
> PRESS RELEASES
> 
> Debian likes its press releases. Directly on its front page, we can see a press release for a minor version bump, and another press release announcing that it excommunicated one of its 1000 members.
> 
> [PIC]
> 
> Surely, correcting a key falsehood that’s been told to countless users, undecided users, donors (Debian’s main source of revenue), and prominently relayed to Wikipedia readers, would at least warrant a press release also and require swift action to minimize continued damage?
> 

You use the term falsehood - as if [all of] Debian were consistently lying to
all its users. I don't think that is justifiable here - I'd remind you of 
the Debian Code of Conduct which applies here as in all Debian mailing lists
and IRC channels.

> DEBIAN'S RESPONSE
> 
> One Debian developer replied with a minor critique of my proposed new text (which I addressed) and asked me to send my concerns about wrong NVD ratings as a separate email (which I did). Another Debian developer replied to him, dismissing my concerns about wrong NVD ratings:
> 
> "We are going to stop anyway at some point displaying the NVD severity, for context see #992115."
> 
> I disagreed with his reasoning not to issue a correction and to continue showing wrong NVD ratings. And since he completely ignored my main concern, and it had been 17 days after my original post, without any action or discussion, I inquired about progress there. This is when something sociologically interesting happened: A third Debian developer, apparently irritated, decided to just shut me up:
> 
> "Maybe at some time you could just stop keeping on insisting on that matter?"
> 
> Note that I wasn’t flooding the mailing list. The messages linked above are all that I had sent to the mailing list up to that point. He followed up with a threat of a ban.
> 
> Will Debian ever live up to its “Social Contract” that includes “Not hiding problems with the software or organization”? Will it apologize for misleading countless people? Given Debian’s response so far, I’m not very hopeful.
> 
> -- 
> Sent with https://mailfence.com  
> Secure and private email
> 

There are other threads about problems with web browsers - specifically
Firefox and Chromium, the pace of change of upstream and the difficulties
with support for all Debian distributions. It's noteworthy that Debian
will supply the latest browsers available but these have to be built
using a toolchain available in each distributon - so stable, oldstable
[oldoldstable] and this can take time. It's also true that Debian builds
these packages for more architectures than others - it may be that 
upstream only really cares about 64 bit Intel / Android for example.

It's also not unknown for packages to be dropped in point releases
because they become unmaintainable and, in fact, that's one of the
reasons that Debian (and others) switched to the Firefox ESR releases.

With every good wish, as ever,

Andrew Cater

[toc] | [prev] | [next] | [standalone]


#244491

Frommax <maxwillb@mailfence.com>
Date2022-01-24 05:30 +0100
Message-ID<DIZ9n-Bo-1@gated-at.bofh.it>
In reply to#244331
January 22, 2022 3:51:28 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:

> Debian does fix security problems 

The question is when: 0 days or 6 months after the CVE announcement? I mean, if you need 6 months, that's fine. Just don't claim that you do it in 0 days. That's dishonest. Does this make sense?

> Debian can feel free to set its own ratings 

But you can't call them "NVD severity", because NVD refers to the National Vulnerability Database. They do their own analysis of vulnerabilities, that some people find trustworthy. You can't just make up your own numbers and claim that they are the NVD ratings. That name is taken.

> You use the term falsehood - as if [all of] Debian were consistently lying to all its users. 

Debian is an organization. It's publishing certain statements on its web site that are false. How the misdeeds of an organization are shared among its members is an interesting philosophical question, but I don't believe I opined on it.


-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [prev] | [next] | [standalone]


#244493

FromPolyna-Maude Racicot-Summerside <debian@polynamaude.com>
Date2022-01-24 07:10 +0100
Message-ID<DJ0I9-1Hp-1@gated-at.bofh.it>
In reply to#244491

[Multipart message — attachments visible in raw view] — view raw

Hi,

On 2022-01-23 23:26, max wrote:
> January 22, 2022 3:51:28 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:
> 
>> Debian does fix security problems 
> 
> The question is when: 0 days or 6 months after the CVE announcement? I mean, if you need 6 months, that's fine. Just don't claim that you do it in 0 days. That's dishonest. Does this make sense?
> 
>> Debian can feel free to set its own ratings 
> 
> But you can't call them "NVD severity", because NVD refers to the National Vulnerability Database. They do their own analysis of vulnerabilities, that some people find trustworthy. You can't just make up your own numbers and claim that they are the NVD ratings. That name is taken.
> 
>> You use the term falsehood - as if [all of] Debian were consistently lying to all its users. 
> 
> Debian is an organization. It's publishing certain statements on its web site that are false. How the misdeeds of an organization are shared among its members is an interesting philosophical question, but I don't believe I opined on it.
> 
> 

For a new user it's quite odd that you don't have much positive to say
about using Debian and seem more interested in the management and the
organization than in really using the software.

Don't you have real life question ? Any technical problem that need some
help ?

Maybe you shall start your own blog about the subject you raise because
I don't see much people sharing your interest. The only answer you raise
are one reminding you of false and misinterpretation.

If you are not happy with the service provided may I suggest you start
searching for something better and please don't share it with us.

-- 
Polyna-Maude R.-Summerside
-Be smart, Be wise, Support opensource development

[toc] | [prev] | [next] | [standalone]


#244494

From<tomas@tuxteam.de>
Date2022-01-24 07:10 +0100
Message-ID<DJ0I9-1Hp-3@gated-at.bofh.it>
In reply to#244493

[Multipart message — attachments visible in raw view] — view raw

On Mon, Jan 24, 2022 at 01:01:57AM -0500, Polyna-Maude Racicot-Summerside wrote:

[...]

Polyna,

with due respect for your patience... I have the impression that you are
feeding trolls here.

Cheers
-- 
tomás

[toc] | [prev] | [next] | [standalone]


#244495

FromPolyna-Maude Racicot-Summerside <debian@polynamaude.com>
Date2022-01-24 07:40 +0100
Message-ID<DJ1bd-1RW-7@gated-at.bofh.it>
In reply to#244494

[Multipart message — attachments visible in raw view] — view raw

Hi

On 2022-01-24 01:07, tomas@tuxteam.de wrote:
> On Mon, Jan 24, 2022 at 01:01:57AM -0500, Polyna-Maude Racicot-Summerside wrote:
> 
> [...]
> 
> Polyna,
> 
> with due respect for your patience... I have the impression that you are
> feeding trolls here.
> 
Tomas @ TuxTeam,
Thanks for reminding me that those type of trolls are not cute and happy
has we're the figures of the mid 1990. Remember those little happy face
with fluorescent hair ?

> Cheers

-- 
Polyna-Maude R.-Summerside
-Be smart, Be wise, Support opensource development

[toc] | [prev] | [next] | [standalone]


#244543

FromPierre-Elliott Bécue <peb@debian.org>
Date2022-01-24 22:50 +0100
Message-ID<DJfnQ-1Xx-11@gated-at.bofh.it>
In reply to#244491

[Multipart message — attachments visible in raw view] — view raw

max  <maxwillb@mailfence.com> wrote on 24/01/2022 at 05:26:45+0100:

> January 22, 2022 3:51:28 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:
>
>> Debian does fix security problems 
>
> The question is when: 0 days or 6 months after the CVE announcement? I
> mean, if you need 6 months, that's fine. Just don't claim that you do
> it in 0 days. That's dishonest. Does this make sense?

Nowhere in what you quoted form security.debian.org had this claim been
made. Stop wasting people's time.

-- 
PEB

[toc] | [prev] | [next] | [standalone]


#244349

FromTim Woodall <debianuser@woodall.me.uk>
Date2022-01-22 20:10 +0100
Message-ID<DItVT-73X-7@gated-at.bofh.it>
In reply to#244324
On Sat, 22 Jan 2022, max wrote:

>
> WHY IS DEBIAN NOT TELLING THE TRUTH ABOUT ITS SECURITY FIXES?
>
snip rant.

I could have the opposite rant. WHY IS DEBIAN NOT TELLING THE TRUTH
ABOUT ITS STABLE DISTRIBUTION.

Because I have a machine (actually more than one) sat running buster
that has SSH listening but can only be reached via limited routes.

And the installed browser is able to connect only to the local network
too. On that local network there is a proxy - but that proxy does not
let this machine connect anywhere.

This machine runs xvnc (or something like that, off the top of my head I
forget exactly which vnc service it is running) and in order to actually
connect to the vnc server you have to use ssh forwarding via public key
authentication.

That machine has exactly one use, and that is to enable me to connect to
the IPMI console on two servers. The ipmi itself is presumed not safe to
expose and so is also firewalled from everything else.

For obvious reasons these machines are required rarely, but when
everything else is breaking it is critical that they work. (This is my
home network so techically pysically plugging in a screen and keyboard
is only a 10 minute job rather than a remote hands request)

I want to keep ssh up to date, that's the one thing that does need to be
remotely accessible. but I'm laid back about everything else. And yet,
java updates, firefox updates *regularly* break things because the (no
updates available) IPMI firmware is using "insecure" security settings.


I would rather debian stable continued to carry a version of the various
major browsers than they dropped it completely. But dropping it is the
most likely thing to happen if the people who complain the loudest don't
step up and do the work to keep it completely up to date.

I'm pretty sure that if someone steps up to do all the work to package
each esr release of chromium/firefox then debian will be likely to take
them (expecially if they're fixing known security issues) even if
they're going to break the normal debian stable compatibility rules. But
this is a lot of work. All this ranting is going to achieve is moving
firefox debs to a third party repo, making it more difficult for those
of us who have a use case for a "good enough" browser and have other
ways to avoid security issues in the browser.


FTAOD, I think the debian volunteers are doing a great job and while I
might wish that their efforts were focused on exactly MY needs, I'll
take whatever they're willing to give with a thank you (and an
occasional, unwarranted, moan).

[toc] | [prev] | [next] | [standalone]


#244351

From"Andrew M.A. Cater" <amacater@einval.com>
Date2022-01-22 20:30 +0100
Message-ID<DIuff-7aw-3@gated-at.bofh.it>
In reply to#244349
On Sat, Jan 22, 2022 at 07:01:24PM +0000, Tim Woodall wrote:
> On Sat, 22 Jan 2022, max wrote:
> 
> > 
> > WHY IS DEBIAN NOT TELLING THE TRUTH ABOUT ITS SECURITY FIXES?
> > 
> snip rant.
> 
> I could have the opposite rant. WHY IS DEBIAN NOT TELLING THE TRUTH
> ABOUT ITS STABLE DISTRIBUTION.
> 
> Because I have a machine (actually more than one) sat running buster
> that has SSH listening but can only be reached via limited routes.
> 
> And the installed browser is able to connect only to the local network
> too. On that local network there is a proxy - but that proxy does not
> let this machine connect anywhere.
> 
> This machine runs xvnc (or something like that, off the top of my head I
> forget exactly which vnc service it is running) and in order to actually
> connect to the vnc server you have to use ssh forwarding via public key
> authentication.
> 
> That machine has exactly one use, and that is to enable me to connect to
> the IPMI console on two servers. The ipmi itself is presumed not safe to
> expose and so is also firewalled from everything else.
> 
> For obvious reasons these machines are required rarely, but when
> everything else is breaking it is critical that they work. (This is my
> home network so techically pysically plugging in a screen and keyboard
> is only a 10 minute job rather than a remote hands request)
> 
> I want to keep ssh up to date, that's the one thing that does need to be
> remotely accessible. but I'm laid back about everything else. And yet,
> java updates, firefox updates *regularly* break things because the (no
> updates available) IPMI firmware is using "insecure" security settings.
> 
> 
> I would rather debian stable continued to carry a version of the various
> major browsers than they dropped it completely. But dropping it is the
> most likely thing to happen if the people who complain the loudest don't
> step up and do the work to keep it completely up to date.
> 
> I'm pretty sure that if someone steps up to do all the work to package
> each esr release of chromium/firefox then debian will be likely to take
> them (expecially if they're fixing known security issues) even if
> they're going to break the normal debian stable compatibility rules. But
> this is a lot of work. All this ranting is going to achieve is moving
> firefox debs to a third party repo, making it more difficult for those
> of us who have a use case for a "good enough" browser and have other
> ways to avoid security issues in the browser.
> 

I might suggest netsurf as a very lightweight browser that is very
well maintained by a dedicated bunch of folk - it's also cross platform
though I've no idea whether it will work with your IPMI.

Debian perforce has to adopt the upstream decisions of the originators
of  Firefox/Chromium - but the requirement of having to build on each
release is not negotiable, I think, or the oldstable releases end
up as a mess of incompatible libraries. Buster, of course, is not the
current stable but is still supported by the main Debian security team
to 2022-08-14 and the LTS team until 2024.

With every good wish, as ever,

Andy Cater

> 
> FTAOD, I think the debian volunteers are doing a great job and while I
> might wish that their efforts were focused on exactly MY needs, I'll
> take whatever they're willing to give with a thank you (and an
> occasional, unwarranted, moan).
> 

[toc] | [prev] | [next] | [standalone]


#244361

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2022-01-22 23:40 +0100
Message-ID<DIxd8-rG-9@gated-at.bofh.it>
In reply to#244324
> These claims are widely believed by Debian users, but they are false. On
> Debian’s own little-known security-tracker, we can see open security
> vulnerabilities that are quite old. For example this HIGH-severity
> vulnerability took 4.5 months to fix in Debian.

Chrome is proprietary, hence not part of Debian.
This has been pointed out to you already in the past.  This makes me
feel like you do not write in good faith (tho maybe you just don't
understand the concept of Free Software and confuse it with software
that's distributed free of charge).

> Additionally, I noticed that the vulnerability severity ratings given by
> the National Vulnerability Database (NVD) are often shown incorrectly by
> Debian. For example, this vulnerability is rated “9.6 CRITICAL” by NVD, and
> there are in fact known exploits for it in the wild. But it’s still shown as
> having a “medium” NVD rating by Debian:

Huh... this is about Chrome, again.  Is your post about Debian or about Chrome?

> I suspected that at least some Debian developers (unlike its users) were
> aware that debian.org/security was taking liberties with the truth.

I think you're just misreading the official statement.
The statement does not say that bugs are fixed within a day.  It says
that advisories are sent within a day.  And then says that bugs are
fixed "within a reasonable timeframe".

What's reasonable is obviously in the eye of the beholder, but of course
the focus will be on packages considered important for Debian.
I don't think Chrome is considered as an important package for Debian.
Maybe it is for Ubuntu, and it definitely is for Google, but it's
clearly quite secondary for Debian.

So I don't see any factual errors or "taking liberties with the truth"
in Debian's statement.

> Will Debian ever live up to its “Social Contract” that includes “Not hiding
> problems with the software or organization”? Will it apologize for
> misleading countless people? Given Debian’s response so far, I’m not
> very hopeful.

I don't know.  But I wonder if Max will apologize for misleading
their readers by focusing on bugs that only affect packages which aren't
even in Debian.


        Stefan

[toc] | [prev] | [next] | [standalone]


#244401

FromPierre-Elliott Bécue <peb@debian.org>
Date2022-01-23 11:30 +0100
Message-ID<DIIid-7bW-7@gated-at.bofh.it>
In reply to#244361
Stefan Monnier <monnier@iro.umontreal.ca> wrote on 22/01/2022 at 23:35:39+0100:

>> These claims are widely believed by Debian users, but they are false. On
>> Debian’s own little-known security-tracker, we can see open security
>> vulnerabilities that are quite old. For example this HIGH-severity
>> vulnerability took 4.5 months to fix in Debian.
>
> Chrome is proprietary, hence not part of Debian.

I wonder if these bugs aren't also impacting chromium? I did not have
time to look into it so I may be wrong.

> This has been pointed out to you already in the past.  This makes me
> feel like you do not write in good faith (tho maybe you just don't
> understand the concept of Free Software and confuse it with software
> that's distributed free of charge).
>
>> Additionally, I noticed that the vulnerability severity ratings given by
>> the National Vulnerability Database (NVD) are often shown incorrectly by
>> Debian. For example, this vulnerability is rated “9.6 CRITICAL” by NVD, and
>> there are in fact known exploits for it in the wild. But it’s still shown as
>> having a “medium” NVD rating by Debian:
>
> Huh... this is about Chrome, again.  Is your post about Debian or about Chrome?
>
>> I suspected that at least some Debian developers (unlike its users) were
>> aware that debian.org/security was taking liberties with the truth.
>
> I think you're just misreading the official statement.
> The statement does not say that bugs are fixed within a day.  It says
> that advisories are sent within a day.  And then says that bugs are
> fixed "within a reasonable timeframe".
>
> What's reasonable is obviously in the eye of the beholder, but of course
> the focus will be on packages considered important for Debian.
> I don't think Chrome is considered as an important package for Debian.
> Maybe it is for Ubuntu, and it definitely is for Google, but it's
> clearly quite secondary for Debian.
>
> So I don't see any factual errors or "taking liberties with the truth"
> in Debian's statement.
>
>> Will Debian ever live up to its “Social Contract” that includes “Not hiding
>> problems with the software or organization”? Will it apologize for
>> misleading countless people? Given Debian’s response so far, I’m not
>> very hopeful.
>
> I don't know.  But I wonder if Max will apologize for misleading
> their readers by focusing on bugs that only affect packages which aren't
> even in Debian.

Now that I read the press release paragraph and the reference to
Pocock's "excommunication", I start wondering if Max, who never wrote on
any Debian List before last month is yet another trollesque incarnation
of the forementioned Pocock.

-- 
PEB

[toc] | [prev] | [next] | [standalone]


#244492

Frommax <maxwillb@mailfence.com>
Date2022-01-24 06:20 +0100
Message-ID<DIZVM-16D-3@gated-at.bofh.it>
In reply to#244401
January 23, 2022 11:21:31 AM CET "Pierre-Elliott Bécue" <peb@debian.org> wrote:

> I wonder if these bugs aren't also impacting chromium? I did not have time to look into it so I may be wrong.

But of course they were. Otherwise why would Debian fix them, after a long wait? Why would it list them on its security-tracker? Have you thought of that at all?

> Now that I read the press release paragraph and the reference to Pocock's "excommunication", I start wondering if Max, who never wrote on any Debian List before last month is yet another trollesque incarnation of the forementioned Pocock.

M-W defines it as "exclusion from fellowship in a group or community", so I think that word was perfect. It seems odd of you to question my command of English, all things considered.

And no, I'm not Pocock. He seems to be obsessed with certain alleged misdeeds of sexual nature. I never brought those up. Your accusation is baseless.

And if I were Pocock, what would be the master plan, according to you? Get more people to try to learn about who the heck he is? Debian has already done that. I didn't know about who this guy was until I read that press release and googled him. Talk about the Streisand effect. So, again, what was the plan, according to you?




-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [prev] | [next] | [standalone]


#244544

FromPierre-Elliott Bécue <peb@debian.org>
Date2022-01-24 22:50 +0100
Message-ID<DJfnQ-1Xx-15@gated-at.bofh.it>
In reply to#244492

[Multipart message — attachments visible in raw view] — view raw

max  <maxwillb@mailfence.com> wrote on 24/01/2022 at 06:15:12+0100:

> January 23, 2022 11:21:31 AM CET "Pierre-Elliott Bécue" <peb@debian.org> wrote:
>
>> I wonder if these bugs aren't also impacting chromium? I did not have
>> time to look into it so I may be wrong.
>
> But of course they were. Otherwise why would Debian fix them, after a
> long wait? Why would it list them on its security-tracker? Have you
> thought of that at all?

Have you read the sentence you're quoting at all?

>> Now that I read the press release paragraph and the reference to
>> Pocock's "excommunication", I start wondering if Max, who never
>> wrote on any Debian List before last month is yet another trollesque
>> incarnation of the forementioned Pocock.
>
> M-W defines it as "exclusion from fellowship in a group or community",
> so I think that word was perfect. It seems odd of you to question my
> command of English, all things considered.

The cambridge dictionary defines it as "the act of refusing to to allow
someone to be involved in the Church". I don't know what M-W stands for,
but for English definitions, I'll stick with Cambridge University Press'
work.

> And no, I'm not Pocock. He seems to be obsessed with certain alleged
> misdeeds of sexual nature. I never brought those up. Your accusation
> is baseless.

Wondering is not accusing.

> And if I were Pocock, what would be the master plan, according to you?
> Get more people to try to learn about who the heck he is? Debian has
> already done that. I didn't know about who this guy was until I read
> that press release and googled him. Talk about the Streisand
> effect. So, again, what was the plan, according to you?

How would I know? I'm not on anyone's head except mine.

-- 
PEB

[toc] | [prev] | [next] | [standalone]


#244559

FromThe Wanderer <wanderer@fastmail.fm>
Date2022-01-25 04:20 +0100
Message-ID<DJkxc-5eX-3@gated-at.bofh.it>
In reply to#244544

[Multipart message — attachments visible in raw view] — view raw

On 2022-01-24 at 16:35, Pierre-Elliott Bécue wrote:

> max  <maxwillb@mailfence.com> wrote on 24/01/2022 at 06:15:12+0100:
> 
>> January 23, 2022 11:21:31 AM CET "Pierre-Elliott Bécue"
>> <peb@debian.org> wrote:

>>> Now that I read the press release paragraph and the reference to 
>>> Pocock's "excommunication", I start wondering if Max, who never 
>>> wrote on any Debian List before last month is yet another
>>> trollesque incarnation of the forementioned Pocock.
>> 
>> M-W defines it as "exclusion from fellowship in a group or
>> community", so I think that word was perfect. It seems odd of you
>> to question my command of English, all things considered.
> 
> The cambridge dictionary defines it as "the act of refusing to to
> allow someone to be involved in the Church". I don't know what M-W
> stands for,

Merriam-Webster.

-- 
   The Wanderer

The reasonable man adapts himself to the world; the unreasonable one
persists in trying to adapt the world to himself. Therefore all
progress depends on the unreasonable man.         -- George Bernard Shaw

[toc] | [prev] | [next] | [standalone]


#244496

Frommax <maxwillb@mailfence.com>
Date2022-01-24 07:50 +0100
Message-ID<DJ1kR-1V8-5@gated-at.bofh.it>
In reply to#244324
January 22, 2022 2:23:48 PM CET max <maxwillb@mailfence.com> wrote:

> https://medium.com/@maxwillb/why-is-debian-not-telling-the-truth-about-its-security-fixes-85f0f85f19a0

I've updated the post taking into account the feedback so far (There weren't any corrections, but there were misunderstandings, and I try to avoid those). Please don't share (on reddit or HN) until it's perfect. Let me know if there is anything else that can be improved. Thanks.


-- 
Sent with https://mailfence.com  
Secure and private email

[toc] | [prev] | [next] | [standalone]


#244572

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2022-01-25 10:00 +0100
Message-ID<DJpQd-8jB-3@gated-at.bofh.it>
In reply to#244496

[Multipart message — attachments visible in raw view] — view raw

On Lu, 24 ian 22, 07:47:01, max wrote:
> January 22, 2022 2:23:48 PM CET max <maxwillb@mailfence.com> wrote:
> 
> > https://medium.com/@maxwillb/why-is-debian-not-telling-the-truth-about-its-security-fixes-85f0f85f19a0
> 
> I've updated the post taking into account the feedback so far (There 
> weren't any corrections, but there were misunderstandings, and I try 
> to avoid those). Please don't share (on reddit or HN) until it's 
> perfect. Let me know if there is anything else that can be improved. 
 
If your intention is to troll (Debian? d-u subscribers?), or demonstrate 
basic misunderstanding of disclaimers, then it's too "in your face".

Really good trolling requires more subtlety ;)


If neither was your intention the article only reflects badly on you, 
without helping in any way improve the matter you're upset about[1].


In any case, it's probably better to just take it down completely.


[1] Debian's security support is imperfect - what a surprise. If you're 
unhappy with that please do contact Debian's Customer Relations 
department for a full refund of the license fee you paid[2].

[2] Yes, the above is intended as humorous, but Poe's law...


Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#244573

FromPolyna-Maude Racicot-Summerside <debian@polynamaude.com>
Date2022-01-25 10:40 +0100
Message-ID<DJqsW-jP-3@gated-at.bofh.it>
In reply to#244572

[Multipart message — attachments visible in raw view] — view raw

Hi,

On 2022-01-25 03:58, Andrei POPESCU wrote:
> On Lu, 24 ian 22, 07:47:01, max wrote:
>> January 22, 2022 2:23:48 PM CET max <maxwillb@mailfence.com> wrote:
>>
>>> https://medium.com/@maxwillb/why-is-debian-not-telling-the-truth-about-its-security-fixes-85f0f85f19a0
>>
>> I've updated the post taking into account the feedback so far (There 
>> weren't any corrections, but there were misunderstandings, and I try 
>> to avoid those). Please don't share (on reddit or HN) until it's 
>> perfect. Let me know if there is anything else that can be improved. 
>  
> If your intention is to troll (Debian? d-u subscribers?), or demonstrate 
> basic misunderstanding of disclaimers, then it's too "in your face".
> 
> Really good trolling requires more subtlety ;)
> 
> 
> If neither was your intention the article only reflects badly on you, 
> without helping in any way improve the matter you're upset about[1].
> 
> 
> In any case, it's probably better to just take it down completely.
> 
> 
> [1] Debian's security support is imperfect - what a surprise. If you're 
> unhappy with that please do contact Debian's Customer Relations 
> department for a full refund of the license fee you paid[2].
> 
> [2] Yes, the above is intended as humorous, but Poe's law...
> 
Great answer Andrei,
Now to the original poster (Max aka, whatever).

On the blog post you created on medium.com you mention a press release
regarding the "excommuniation" of one of the developers.

What's the link between this and security vulnerabilities.

For me this smell quite bad, like a old fish that sat in the sun for
days on end.

First of all you appear from nowhere with complains regarding you
inability to understand properly disclaimers and the conditions in which
Debian is released (and the no imply warranties)

Second, you put lots of energy into this, not accepting the answer you
get from eminent member of the community (the ones that have been part
of the project for many years and can surely answer you with what's
really going on).

And thirdly, you link this up with a press release regarding a developer
who's wasn't "kicked out" but that got changed access to servers.

Seems like the third reason is mostly what took you here first and now
you are both trolling and spreading falsehood around.

We all know that someone who's mature won't act this way.

And we all saw in the answer of the unhappy developer that he sure
doesn't seem to be someone who has any respect for rules or that know
what the term moral means. And this by simply answering that because he
perceive a world lacking of moral this would justify him to do anything.

Seems like what we teach a 5 years old.

Don't do to others what you wouldn't like to get.
And if you feel they are bad with you, act like if you are the oldest
one and just ignore them.

And this is now exactly what I'll do with you.

So have fun and try to max-out your life experiences.
> 
> Kind regards,
> Andrei

-- 
Polyna-Maude R.-Summerside
-Be smart, Be wise, Support opensource development

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web