Live data from Hacker News

Ubuntu 23.04 – 'Lunar Lobster'

zdnet.com

51–60 of 62 posts

Re: Ubuntu 23.04 – 'Lunar Lobster'

#51

Earlier quoted context omitted.

Simply not necessary for normal applications running on my local desktop. And yes, I do work in security.

I don't care if you work in security - the fact is that I have to completely trust every application that I want to run on Linux, which is unacceptably bad, and "Simply not necessary for normal applications running on my local desktop" is factually false (unless you're using some "gotcha" convoluted definition of "normal"). A sanely-designed OS will provide either capabilities or sandboxing - the tech has been around…

Well, each to his own I guess. I don't see the need for myself. Data is backed up, critical data is encrypted and I've never had a malware infection. I'm pretty careful.

You can run something like Qubes if you want better isolation.

Re: Ubuntu 23.04 – 'Lunar Lobster'

#52

Snaps are BS. I did couple of months ago clean ubuntu 22.10 install. Somehow curl was installed from snap - of course I had problem saving curled files due sandboxing. Installed mosquitto2 (MQTT server) - of course it did not read my custom confs from /etc/... anymore - due sandboxing. Installed Libreoffice from snap - it Calc (excel alternative) was exctremely slow somehow - switched to Libreoffice from APT repo - i…

I currently run a small research cluster, and snaps are great. They make spinning up for instance a new redis instance super quick and painless. I think that snaps are mostly a server use, and the desktop users don't like it because they're not server admins and have different needs.

It looks like that flatpaks have mostly won the desktop market, but on the server side docker and snaps are both really nice.

Re: Ubuntu 23.04 – 'Lunar Lobster'

#53

Earlier quoted context omitted.

I don't care if you work in security - the fact is that I have to completely trust every application that I want to run on Linux, which is unacceptably bad, and "Simply not necessary for normal applications running on my local desktop" is factually false (unless you're using some "gotcha" convoluted definition of "normal"). A sanely-designed OS will provide either capabilities or sandboxing - the tech has been around…

Well, each to his own I guess. I don't see the need for myself. Data is backed up, critical data is encrypted and I've never had a malware infection. I'm pretty careful. You can run something like Qubes if you want better isolation.

> Well, each to his own I guess. I don't see the need for myself.

That's not an attitude that someone working in security would have.

It doesn't matter if "critical data is encrypted" if a keylogger is present when you enter your password. It doesn't matter that you've "never had a malware infection" because millions of other people have. And it doesn't matter that you're "pretty careful" because one of the core tenets of information security is that people are imperfect and it's best to remove as much of the human element as possible.

These are relatively basic facts that someone with a few years of experience would know.

> You can run something like Qubes if you want better isolation.

Qubes is sandboxing - but the thread topic is about sandboxing on Linux, and the need for it in OSes in general. Security should come built-in, not as something you use a special OS for.

Re: Ubuntu 23.04 – 'Lunar Lobster'

#54

Since everyone is complaining about snap. I have to ask : what is wrong with apt and dpkg ? I just want that, I guess it means back to Debian? I’m not excited or interested about spending time dealing with a package manager.

There is nothing wrong with apt and dpkg. It’s just that Ubuntu infected apt with their poison by making ‘apt install firefox’ install a snap package and they’re poised to do it with more packages (maybe they already have).

I personally can’t think of anything software related that Ubuntu provides over Debian for normal desktop users. Only the Ubuntu 6-month release schedule can be a bit nicer.

Re: Ubuntu 23.04 – 'Lunar Lobster'

#55
I switched to Arch as soon as ubuntu started pushing snaps and never looked back. Of all the reasons to hate snaps what did it for me was the loopback device spam when trying to list block devices. Canonical has a track record of doing things the community doesn't agree with, carefully reading all the feedback, and then doubling down on whatever terrible idea they had and continuing anyway.

Re: Ubuntu 23.04 – 'Lunar Lobster'

#56

Earlier quoted context omitted.

Well, each to his own I guess. I don't see the need for myself. Data is backed up, critical data is encrypted and I've never had a malware infection. I'm pretty careful. You can run something like Qubes if you want better isolation.

> Well, each to his own I guess. I don't see the need for myself. That's not an attitude that someone working in security would have. It doesn't matter if "critical data is encrypted" if a keylogger is present when you enter your password. It doesn't matter that you've "never had a malware infection" because millions of other people have. And it doesn't matter that you're "pretty careful" because one of the core tene…

We are talking about different things. I was talking about my own reasons for not wanting snap on my desktop. You are talking about the need for better security on operating systems in general.

Security is never an absolute, it's always a trade off between many different factors, such as usability, protection, and cost. You have to take a risk based approach. People who work in security have to do this on a daily basis.

For myself, the sand-boxing trade off is not worth it on my own desktop. Everything I have tried has significantly interfered with being able to do what I need to. If we were talking about what was needed on a critical, internet-exposed system, my answer might be different.

On the subject of what a good secure OS would look like, I studied capabilities extensively when I did my MSc in Info Sec. The E language and the EROS operating system were absolutely fascinating. Getting rid of ambient authority would be awesome. I have worked with people who worked on CHERI, which is also a really promising approach to use capabilities for better memory protection - and has the advantage that it can work with code not written for it.

When something like that is available, I'll be one of the first people trying it out!

Re: Ubuntu 23.04 – 'Lunar Lobster'

#57
I didn't mind the snaps since I always was able to disable them on every update, but somehow I started to get a lot of kernel freezes when running some IO heavy unit tests, it was getting really annoying. It may have been a btrfs bug or some other bug but I blamed ubuntu and installed archlinx instead.

Same btrfs/snapshotting configuration on arch and never had any issues so far...

Re: Ubuntu 23.04 – 'Lunar Lobster'

#58

Earlier quoted context omitted.

What exactly is wrong with snaps?

It's worth noting that, in addition to Snaps starting up slower (a common complaint on this thread), they actually cause the OS to boot up slower . Every Snap application adds a small amount of startup time. I think I shaved a third off my total time by removing a bunch of Snaps, which is atrocious, unacceptable, and unjustifiable.

So every couple of weeks when you boot your PC, it's a few seconds faster now?

Re: Ubuntu 23.04 – 'Lunar Lobster'

#59

Earlier quoted context omitted.

It's worth noting that, in addition to Snaps starting up slower (a common complaint on this thread), they actually cause the OS to boot up slower . Every Snap application adds a small amount of startup time. I think I shaved a third off my total time by removing a bunch of Snaps, which is atrocious, unacceptable, and unjustifiable.

So every couple of weeks when you boot your PC, it's a few seconds faster now?

This is a ridiculous assumption. I'll boot my PC multiple times per day because I dual-boot and I'll sometimes need to switch between OSes repeatedly.

This is also a ridiculous dismissal. Snaps don't increase your startup time because it's an intrinsic limitation of the technology (e.g. like how internet connectivity necessitates higher power draw), but because they're designed badly. There's no reason for them to act like that, and people are rightly upset at it.

Re: Ubuntu 23.04 – 'Lunar Lobster'

#60

Earlier quoted context omitted.

What exactly is wrong with snaps?

Snap server is non-free software. Without reverse engineering the protocol, it is impossible to host your own snap repository.

This is not true.

Other companies have and do most their own snap stores.

Post reply on HN