this post was submitted on 01 Jul 2024
429 points (90.1% liked)

linuxmemes

19733 readers
1065 users here now

I use Arch btw


Sister communities:

Community rules

  1. Follow the site-wide rules and code of conduct
  2. Be civil
  3. Post Linux-related content
  4. No recent reposts

Please report posts and comments that break these rules!

founded 1 year ago
MODERATORS
 
top 50 comments
sorted by: hot top controversial new old
[–] CrayonRosary@lemmy.world 2 points 2 days ago

I by way the Debian use.

[–] TheGingerNut@lemmy.blahaj.zone 24 points 4 days ago (1 children)

well at least they aren't trying to make me install snaps, and patching apt so if I sudo apt install firefox it installs the snap version.

[–] noisypine@infosec.pub 11 points 4 days ago (1 children)

This should be a jailable crime.

[–] TheGingerNut@lemmy.blahaj.zone 1 points 3 days ago* (last edited 3 days ago)

especially as the hack flows downriver to distros with actual dignity like mint. Like this is pollution of the water supply dog!

[–] germanatlas@lemmy.blahaj.zone 78 points 6 days ago (4 children)

no real-world use found for staying more than one version behind

The ssh vulnerability didn’t affect Debian because the packages were too many versions behind

[–] azvasKvklenko@sh.itjust.works 42 points 6 days ago

AFAIK, the xz vulnerability was designed for Debian based on its workaround fixing systemd service status detection. Even if it shipped to something like Arch, the malicious code wouldn’t load.

[–] acockworkorange@mander.xyz 18 points 5 days ago (1 children)

Isn’t this meme format completely written in sarcasm?

[–] renzev@lemmy.world 0 points 1 day ago

We're on a meme page. There is little difference between sarcasm and being serious here. It doesn't matter whether OP is being fully sarcastic or fully serious, people in the comments may hold the same opinion seriously, sarcastically, or with a mixture of both. The format is irrelevant

[–] bisby@lemmy.world 19 points 5 days ago

Except this isn't true at all.

https://security-tracker.debian.org/tracker/CVE-2024-6387

Regresshion impacted bookworm and trixie both. Buster was too old.

With the downside of me doing an apt update and seeing that openssh-server was on 1:9.2p1-2+deb12u3 and I had no idea at a glance if this included the fix or not (qualys's page states version 8.5p1-9.8p1 were vulnerable).

If you are running debian bookworm or trixie, you absolutely should update your openssh-server package.

[–] cygnus@lemmy.ca 20 points 5 days ago

Security through Geriatricity

[–] crispy_kilt@feddit.de 13 points 4 days ago

Btw I use Debian

[–] hemko@lemmy.dbzer0.com 9 points 4 days ago

I use Debian btw

[–] Tundra@lemmy.ml 21 points 5 days ago (1 children)
[–] Pyroglyph@lemmy.world 1 points 4 days ago
[–] marduk@lemmy.sdf.org 26 points 6 days ago (1 children)

The "install lib-blah-blah-blah" bit doesn't bother me 'cause whenever I need to make something work, I just copy and paste the "sudo apt install ..." commands straight from the internet :)

[–] steersman2484@sh.itjust.works 5 points 6 days ago

I also never used version pinning in debian

[–] MNByChoice@midwest.social 24 points 6 days ago* (last edited 6 days ago)

This is great! No better way to demonstrate how perfect Debian is! Debian for the win!

[–] LeroyJenkins@lemmy.world 26 points 6 days ago

Don't

Erupt

Before

I

Am

Nevada

[–] AlexisFR@jlai.lu 19 points 6 days ago (2 children)

Truly the dumbest meme template of the year.

[–] stepan@lemmy.cafe 33 points 6 days ago (1 children)
[–] Norgur@fedia.io 12 points 5 days ago

I don't. So... uhm... you're wrong I guess.

[–] abbotsbury@lemmy.world 6 points 5 days ago (1 children)

This is a pretty old template iirc

[–] rc__buggy@sh.itjust.works 4 points 4 days ago

It's so old it's still shipping in bookworm

[–] NathanClayton@lemmy.world 4 points 4 days ago (1 children)

KDE? Who needs anything other than FVWM2 or CDE?

[–] OsrsNeedsF2P@lemmy.ml 2 points 4 days ago

As someone who loves the old designs (I've run Chicago95 for years now), the only thing stopping me from running CDE is it lacks first-class support from any distro I've used

[–] lemmyvore@feddit.nl 10 points 5 days ago (1 children)

I would uninstall the screensaver so fast if I saw a nag screen. Wtf it's a screensaver, what does it matter? I'll use a version that's 50 years old if I want to.

[–] bisby@lemmy.world 21 points 5 days ago (1 children)

Because the dev gets a huge number of bug reports for bugs that were resolved 5 versions ago.

They actually asked debian to stop shipping the screensaver, because they were getting tired of saying "this is already fixed, debian is just not going to ship the fix for another year". Debian didn't want to stop, so the dev added the nag screen, because it was the only way to stop the flood of bug reports for things that were already fixed.

[–] user224@lemmy.sdf.org 3 points 5 days ago* (last edited 5 days ago) (3 children)

Do people not check what version of software they have and what's newest (and if the issue exists is a good idea too) before reporting a bug?

[–] bisby@lemmy.world 8 points 5 days ago

Should they? Yes. They should also be searching for previous bug reports. I'm sure a lot of people do. But if you have enough users, even if 1% of people don't use good reporting behaviors, you wind up with a lot of duplicate or bad reports.

There are plenty of blog posts out there that basically can be summarized as talking about how grueling open source work can be because users are often aggressive in their demands.

But this is a prime example of debian "stable" doesn't mean "no crashes" but instead it means "unchanging, which means any bugs and crashes will remain for the whole release"

[–] Malfeasant@lemmy.world 2 points 4 days ago

Lololololololol. No, they do not. I support a product that gets updated roughly quarterly, and the number of times people complain about their vulnerability scanner finding something when they're on a 4 year old version is too damn high.

[–] OsrsNeedsF2P@lemmy.ml 1 points 4 days ago

Lots of people simply don't know.

Source: I filed bug reports to Fcitx when I first installed Debian, because I didn't realize Debian shipped packages from the before the stone ages

[–] rtxn@lemmy.world 1 points 4 days ago (1 children)

NO REAL-WORLD USE FOUND for staying more than ONE VERSION behind

Joke's on you, my servers are largely unaffected by regreSSHion because they're too outdated.

[–] Rainb0wSkeppy@lemmy.world 1 points 3 days ago

so old that they are still vulnerable to the same vurnability

[–] Engywuck@lemm.ee 8 points 6 days ago (3 children)

I know this is just a meme, but the "Stop using xxx!" posts are really annoying.

Whaaat, i love them. They are so unpredictable. Sometimes they are fully serious opinions, sometimes only half serious and sometimes just fully ironic shitposts.

[–] SpaceNoodle@lemmy.world 24 points 6 days ago

I think the comments calling them annoying are more annoying

I think it is a funny format

[–] GravitySpoiled@lemmy.ml 8 points 6 days ago* (last edited 6 days ago) (1 children)
[–] possiblylinux127@lemmy.zip 4 points 6 days ago

Oh, Debian!

1000002612

load more comments
view more: next ›