Live data from Hacker News

Ubuntu Security Updates Are a Confusing Mess

gld.mcphail.uk

11–20 of 40 posts

Re: Ubuntu Security Updates Are a Confusing Mess

#11
post #5

If I was looking for a distro with paid support (a la RHEL/Ubuntu) that's also not incredibly behind bleeding edge (maybe not as bleeding edge as Arch, but also not running patched-to-hell-and-back software like Ubuntu), what are my options? Thankfully I'm not personally looking for this at the moment, I'm more than happy being my own sysadmin and running anything from Arch to Fedora CoreOS to OpenSUSE on my machines…

I've heard good things about AlmaLinux but I haven't used it personally.

https://almalinux.org

Re: Ubuntu Security Updates Are a Confusing Mess

#12
post #4

I don't care they're gating this behind a subscription but the fact that they won't even tell you that you're missing an important security update? That's bad. I wonder how many people think they are fully up to date while being vulnerable to known bugs.

They do tell you that you are missing now. On ubuntu 24.04, apt now reports/nags me about security updates behind esm-apps.

They also publish an oval xml for use with openscap tools to get a list of unpatched CVEs. The issue is not enough people know about those tools. https://security-metadata.canonical.com/oval/

Re: Ubuntu Security Updates Are a Confusing Mess

#13
post #10
post #5

If I was looking for a distro with paid support (a la RHEL/Ubuntu) that's also not incredibly behind bleeding edge (maybe not as bleeding edge as Arch, but also not running patched-to-hell-and-back software like Ubuntu), what are my options? Thankfully I'm not personally looking for this at the moment, I'm more than happy being my own sysadmin and running anything from Arch to Fedora CoreOS to OpenSUSE on my machines…

On desktop/laptop? Only Arch. On servers I'd say RHEL/Rocky (don't disable selinux!) or SuSE; and the deployed services in podman or incus.

I wish people would stop recommending Rocky. It's a ticking time bomb IMHO caused by their decision to not play nicely with Red Hat and go for questionable tactics like renting temporary RHEL instances to download premade source packages, instead of working together as RH asked them to do. Anybody reading this, do yourself a favor and use Alma, or skip the RHEL ecosystem altogether if you don't absolutely need it.

Otherwise you're building on an operating system which rebuilds a commercial upstream while explicitly refusing to follow that upstream's rules. IBM has lots of experienced lawyers, as I've heard.

It's also slower at releasing updates, including security updates.

------

Sorry SSLy, I can't reply to you directly because I'm rate limited, it's very late here, and I'm not waiting for the rate limit to expire. So here's my reply:

I think previous decisions made by IBM have shown that they're fine at burning some community goodwill for short-term profit. People were called paranoid for worrying about the future of CentOS when it was taken up by Red Hat for "improved maintenance", and look where we are now.

Maybe you're right, but I personally wouldn't want to build anything serious on top of that "maybe". If something happens, lateral migration should theoretically work, of course..

https://almalinux.org/elevate

Re: Ubuntu Security Updates Are a Confusing Mess

#14
post #4

I don't care they're gating this behind a subscription but the fact that they won't even tell you that you're missing an important security update? That's bad. I wonder how many people think they are fully up to date while being vulnerable to known bugs.

They do tell you that you are missing now. On ubuntu 24.04, apt now reports/nags me about security updates behind esm-apps. They also publish an oval xml for use with openscap tools to get a list of unpatched CVEs. The issue is not enough people know about those tools. https://security-metadata.canonical.com/oval/

Aha, thanks. I'm trying to look up the CVE on https://ubuntu.com/security/notices and the site's search responds with "504 Gateway Time-out" or "500: Server error". Come on Ubuntu.

Re: Ubuntu Security Updates Are a Confusing Mess

#15
post #3

Is it not possible to fix the one package from the debian sources vs waiting for ubuntu to allow him to get it from them?

Ubuntu is merely reusing apt to connect to its own repositories. You could manually install packages from Debian's repositories, but it's probably inadvisable.

Re: Ubuntu Security Updates Are a Confusing Mess

#16
post #11
post #5

If I was looking for a distro with paid support (a la RHEL/Ubuntu) that's also not incredibly behind bleeding edge (maybe not as bleeding edge as Arch, but also not running patched-to-hell-and-back software like Ubuntu), what are my options? Thankfully I'm not personally looking for this at the moment, I'm more than happy being my own sysadmin and running anything from Arch to Fedora CoreOS to OpenSUSE on my machines…

I've heard good things about AlmaLinux but I haven't used it personally. https://almalinux.org

RHEL ecosystem is no less patched than Debian and its derivatives. Especially the kernel has only some resemblance to its stated version.

Re: Ubuntu Security Updates Are a Confusing Mess

#17
post #10

Earlier quoted context omitted.

On desktop/laptop? Only Arch. On servers I'd say RHEL/Rocky (don't disable selinux!) or SuSE; and the deployed services in podman or incus.

I wish people would stop recommending Rocky. It's a ticking time bomb IMHO caused by their decision to not play nicely with Red Hat and go for questionable tactics like renting temporary RHEL instances to download premade source packages, instead of working together as RH asked them to do. Anybody reading this, do yourself a favor and use Alma, or skip the RHEL ecosystem altogether if you don't absolutely need it. Ot…

IBM suing Rocky for what they're doing means industry wide crisis about what the FOSS provisions really mean. Their competition would welcome such self sabotage with arms wide open.

Of course they could release the code just for the *GPL packages, but it's an option only slightly less bad socially.

Now, I wonder why there's no one rebuilding Ubuntu Pro like folks are rebuilding RHEL.

Re: Ubuntu Security Updates Are a Confusing Mess

#18
post #5

If I was looking for a distro with paid support (a la RHEL/Ubuntu) that's also not incredibly behind bleeding edge (maybe not as bleeding edge as Arch, but also not running patched-to-hell-and-back software like Ubuntu), what are my options? Thankfully I'm not personally looking for this at the moment, I'm more than happy being my own sysadmin and running anything from Arch to Fedora CoreOS to OpenSUSE on my machines…

afaik, your want of relatively fresh software with few patches excludes pretty much everything there is, except for really niche stuff. All other major options with good commercial support have been mentioned by siblings; I'll add Debian + Freexian to the list.

https://www.freexian.com

Re: Ubuntu Security Updates Are a Confusing Mess

#19
post #4

I don't care they're gating this behind a subscription but the fact that they won't even tell you that you're missing an important security update? That's bad. I wonder how many people think they are fully up to date while being vulnerable to known bugs.

> I don't care they're gating this behind a subscription

I rather not have them push an ad to my face when I open the settings.

I had to install Ubuntu on an embedded board last week and the "Ubuntu Pro" ad is like a greyed out tab in the settings widget if I remember correctly. Worse than the Amazon ad they had some decade ago.

Re: Ubuntu Security Updates Are a Confusing Mess

#20

I'd argue we wouldn't have Snap [for the better] if their LTS releases weren't visually bound to years... saving overhead they regularly create for cosmetic reasons. Wouldn't have to create it to consolidate platforms if they stopped making them so often! They have three concurrent LTS releases when they need one. Maybe two. 18.04 is the python2 of distributions. Let it go. Having worked in several places that relied…

> They have three concurrent LTS releases when they need one. Maybe two. 18.04 is the python2 of distributions. Let it go.

> Having worked in several places that relied on it... ESM is being the bad kind of enabler.

The business proposition is 10 years of support with minimal package changes. Are you asking them to just stop selling that product?

Fewer LTS releases wouldn't change that core question, since if they never had a 2018 LTS release those users would be on the 2016 release instead.

Post reply on HN