Live data from Hacker News

Linux Mint downloads (briefly) compromised

lwn.net

101–110 of 236 posts

Re: Linux Mint downloads (briefly) compromised

#101

Earlier quoted context omitted.

I'm curious- what do you think of Fedora? It's in the top 5 distros along with OpenSUSE, Ubuntu, Debian, and Mint, and yet I hardly ever hear people talk about it. I had personally given up on Fedora years ago, but recently was told I should give it a second look and I've not had time to try it out.

I use Fedora and I truly do love it. I find it to be far more stable than other distros I've tried, and it really does "just work." I know I've been suggesting it to people who are considering Linux for the first time, with the caveat of disabling SElinux. With that said, I'm not sure if it is good for non-technical people or people who aren't interested in learning about it. Getting certain things installed can be a…

> I also view it from the perspective of not knowing how to use any graphical installers (do they exist?)

Yes, it exists and works pretty good when I installed it. Set up encrypted LUKS, EFI just fine and I found it reasonably pleasant to use.

Re: Linux Mint downloads (briefly) compromised

#102
post #21

I've used Mint in the past, and it was my go-to distro for family members who aren't so technical. I'm not bothered by the licensing issues mentioned, and I'm ambivalent about the namespace issues, but I've been increasingly uneasy for some time now about Mint's security practices. Serving downloads over http and not providing GPG signed SHA hashes like every other distro is fairly irresponsible in this day and age.…

> Edit: I'm also playing around with FreeBSD for my development environment, since I can use Mate on there. To be honest, I don't really need a DE these days anyway, since I only use terminal and a web browser. I should look into just using a Windows Manager.

FreeBSD has good support for DEs with XFCE and Lumina, anyways. At least I've never had a problem.

Re: Linux Mint downloads (briefly) compromised

#103
post #36
post #7

Earlier quoted context omitted.

I've found Xubuntu to be a pretty decent albeit simple environment. Runs great on my VM too.

Indeed. I never got why people are not just sticking with Xubuntu. It is the most solid, reliable, balanced and beautiful distro I have ever tried. Everytime I tried something else, I finally came back to Xubuntu, and try to remind myself to never switch away again.

Maybe because the company behind Ubuntu has practically declared the desktop dead and we want a desktop that is really a desktop and not some future(already dead)fantasy all in one? Yes Xubuntu is a desktop but i'm not waiting around for the axe to fall and try again to force unity on everyone... I had to change once, better change to distro that is commited to the desktop.

Re: Linux Mint downloads (briefly) compromised

#104
post #97
post #59

Earlier quoted context omitted.

I absolutely love the concept of NixOS, but I haven't tried it out. Is it well-supported enough to use day-to-day as a developer? Do you often have to build things from source?

> Is it well-supported enough to use day-to-day as a developer? Speaking as someone who knows the developer: no. > Do you often have to build things from source? There's ~6500 packages, so it's likely you'll be installing some stuff from source. It's really hard to predict without knowing specifics though. http://hydra.nixos.org/eval/1237359

If you track 'unstable' you generally don't need to build from source as that branch (or channel as Nix calls it) is updated only after everything has been successfully built on Hydra. There are sets of packages excluded from the build but I think those are mostly interpreted languages (emacs packages, etc).

Re: Linux Mint downloads (briefly) compromised

#105
post #44

Earlier quoted context omitted.

I'm curious- what do you think of Fedora? It's in the top 5 distros along with OpenSUSE, Ubuntu, Debian, and Mint, and yet I hardly ever hear people talk about it. I had personally given up on Fedora years ago, but recently was told I should give it a second look and I've not had time to try it out.

Fedora isn't for non technical family members. Here's a bit of mild whinging that's only relevant if you want to give it to non-technical people. There's a move to give stuff generic names, rather than the obscure names they had in the past. For example, Nautilus has been renamed to Gnome Files, or just Files. When a non technical person needs to search for hep this new name makes it impossible for them to create a u…

> There's a move to give stuff generic names

That's not so much a Fedora thing but a GNOME move, as the RPM containing "Files" is still called Nautilus.

Also, I am a bit surprised since it goes contrary to your argument, because when a user looks for a file explorer he's much more likely to find that looking for "Files" rather than the (rather strange, really) name of "Nautilus".

I would see myself as a technical user and yet I have no idea how the apps on my Android device are called. One is called generically "Gallery" and another one even worse, "E-Mail".

Re: Linux Mint downloads (briefly) compromised

#106
post #19

> Add to that, that they do not care about copyright and license issues and just ship their ISOs with pre-installed Oracle Java and Adobe Flash packages and several multimedia codec packages which infringe patents and may therefore not be distributed freely at all in countries like the US. Hmm, that was actually one of major selling points for Mint around me - it was the distro that "worked", with relevant software,…

OTOH, it's exactly what pushed me away from Mint.

I remember not long ago Mint included just about every browser media plugin ever made, including RealMedia, WindowsMedia etc., stuff that was obsolete 15 years ago. Maybe it still does.

All that stuff doesn't just mean bloat, but also significant security risks. You can somewhat get away with it because desktop Linux isn't a major target (yet), but it's just very bad practice that shows a lack of care.

Re: Linux Mint downloads (briefly) compromised

#107
post #50
post #19

> Add to that, that they do not care about copyright and license issues and just ship their ISOs with pre-installed Oracle Java and Adobe Flash packages and several multimedia codec packages which infringe patents and may therefore not be distributed freely at all in countries like the US. Hmm, that was actually one of major selling points for Mint around me - it was the distro that "worked", with relevant software,…

It's user friendly, yes, but also reckless. The distro won't "work" any more if it gets sued into oblivion by Oracle, Adobe, Nvidia, AMD and whoever else feels like kicking puppies.

IF, IF ,IF... meanwhile we are going by just fine while the others wait for Hypothetical Risks and Hypothetical all in one interfaces (this last one is just my rant against Canonical).

Re: Linux Mint downloads (briefly) compromised

#108
post #53

> Add to that, that they do not care about copyright and license issues and just ship their ISOs with pre-installed Oracle Java and Adobe Flash packages and several multimedia codec packages which infringe patents and may therefore not be distributed freely at all in countries like the US. Seriously, with the rotten-ness of the US patent/copyright/political system, it's better for mankind to just say "ok, US users ca…

> "ok, US users can't get this, but everyone else can" Setting aside for a minute that this isn't possible, it's like saying you won't release your app on iOS because of Apple's walled gardens. Sure, the walls suck, but the users inside are numerous and spend lots of money. Most product creators don't have the option to exclude US users.

Nobody is saying to not release for US (in fact you can choose to use the noCodex version) but Why Should problems in US or anywhere else limit the experience that everyone else can get?

Re: Linux Mint downloads (briefly) compromised

#110
post #24

I remember installing it when it was relatively new and people were gushing over it. A few weeks later a new version came out. I tried upgrading when I found there was no upgrade path. Upgrading Mint means reinstalling Mint. I remember the days before apt-get when there was only dpkg. Before Debian I used Slackware so I'm all too familiar with package management (or lack of). The idea that someone would release a new…

I'm sorry for the rant, it's a bit off topic and not called for, but would like to say my experience is sort of the opposite: I've been a Slackware-current user for most of a decade, and I love that it's so easy to upgrade the OS using slackpkg. I can (and do) often only upgrade a subset of packages, and never even need to reboot afterwards, not even after replacing the kernel (although, obviously...). A simple packa…

A simple package system without dependency tracking has had many advantages for me.

Are you equating "simple package system" with "per-package service isolation" here? Because otherwise I don't see how your example about upgrades not requiring a reboot ties in with the package system. Debian has probably the most extensive package system, yet it still allows you to do upgrades without reboot. The major exception to this is dbus, because it still can't do stateful restarts. But I don't think that's a problem that Slackware is able to avoid, unless it avoids dbus completely.

Also: since Wheezy, Debian allows parallel installation of many development and shared library packages from all (10!) arches, for example to facilitate cross-compilation. It's still a work-in-progress, but I believe over 80% of the archive (not including packages with binaries) should be co-installable now.

Post reply on HN