Live data from Hacker News

Ubuntu Security Updates Are a Confusing Mess

gld.mcphail.uk

21–30 of 40 posts

Re: Ubuntu Security Updates Are a Confusing Mess

#21
post #4

I don't care they're gating this behind a subscription but the fact that they won't even tell you that you're missing an important security update? That's bad. I wonder how many people think they are fully up to date while being vulnerable to known bugs.

> I don't care they're gating this behind a subscription I rather not have them push an ad to my face when I open the settings. I had to install Ubuntu on an embedded board last week and the "Ubuntu Pro" ad is like a greyed out tab in the settings widget if I remember correctly. Worse than the Amazon ad they had some decade ago.

I have recently had a lot of unfortunate interactions with 24.04, and it really makes me hate debians.

Re: Ubuntu Security Updates Are a Confusing Mess

#22
post #7
post #3

Is it not possible to fix the one package from the debian sources vs waiting for ubuntu to allow him to get it from them?

It's possible to fix anything from the sources but I guess the Tomcat version in 22.04 didn't have a corresponding stable Debian version? (vs. the 20.04 version)

Confirmed, the tomcat 9.0.58 in Ubuntu 22.04 is not in bookworm/stable (which is on 9.0.70) or bullseye/oldstable (which is on 9.0.43), and the 9.0.31 in Ubuntu 20.04 is the same as the version in Debian buster.

Re: Ubuntu Security Updates Are a Confusing Mess

#23
post #4

I don't care they're gating this behind a subscription but the fact that they won't even tell you that you're missing an important security update? That's bad. I wonder how many people think they are fully up to date while being vulnerable to known bugs.

They do tell you that you are missing now. On ubuntu 24.04, apt now reports/nags me about security updates behind esm-apps. They also publish an oval xml for use with openscap tools to get a list of unpatched CVEs. The issue is not enough people know about those tools. https://security-metadata.canonical.com/oval/

They finally agreed to publish OSV data in addition to OVAL. OVAL XML files are terrible to use, and OSV is amazing in comparison, so this will get more tool adoption.

Re: Ubuntu Security Updates Are a Confusing Mess

#25
I maintain https://endoflife.date/ubuntu. Ubuntu security policies are indeed a hot mess, and opaquely documented on their own website. I use it as an example of how not to document your support policies at https://endoflife.date/recommendations.

At one point Ubuntu changed the EOL tables on their Wiki from 5 years to 10 with no explanation about applicability/ESM - just calling it LTS.

It is among the longest pages on our website.

Re: Ubuntu Security Updates Are a Confusing Mess

#27

I'd argue we wouldn't have Snap [for the better] if their LTS releases weren't visually bound to years... saving overhead they regularly create for cosmetic reasons. Wouldn't have to create it to consolidate platforms if they stopped making them so often! They have three concurrent LTS releases when they need one. Maybe two. 18.04 is the python2 of distributions. Let it go. Having worked in several places that relied…

> They have three concurrent LTS releases when they need one. Maybe two. 18.04 is the python2 of distributions. Let it go. > Having worked in several places that relied on it... ESM is being the bad kind of enabler. The business proposition is 10 years of support with minimal package changes. Are you asking them to just stop selling that product? Fewer LTS releases wouldn't change that core question, since if they ne…

I suppose I doubt the proposition of '10 year support' - admittedly I haven't done anyone else's job for them.

I don't know if that necessarily means stop selling the product... but tighten up the terms, I guess? Anyone choosing to stay on something that old has chosen those gremlins.

The build of systemd and firewalld on 18.04 are both categorically broken. I don't know whatever people are solving with that old release (and Canonical in support)... but it's less than what those two things do for me when working properly.

The illusion of support for something so decrepit creates more problems than it solves in my experience. Either bite the bullet and modernize/upgrade... or keep playing with the unsupported sands of time

Re: Ubuntu Security Updates Are a Confusing Mess

#28
> ...what are my options? > ...Maybe it is time to go back to Debian, as they seem to release these fixes to their users?

Curious if this would actually be a solution. They state that fixes in Debian are down-streamed regardless of support, so if this fix wasn't down-streamed, then why would it be in Debian ?

Re: Ubuntu Security Updates Are a Confusing Mess

#29

Earlier quoted context omitted.

> They have three concurrent LTS releases when they need one. Maybe two. 18.04 is the python2 of distributions. Let it go. > Having worked in several places that relied on it... ESM is being the bad kind of enabler. The business proposition is 10 years of support with minimal package changes. Are you asking them to just stop selling that product? Fewer LTS releases wouldn't change that core question, since if they ne…

I suppose I doubt the proposition of '10 year support' - admittedly I haven't done anyone else's job for them. I don't know if that necessarily means stop selling the product... but tighten up the terms, I guess? Anyone choosing to stay on something that old has chosen those gremlins. The build of systemd and firewalld on 18.04 are both categorically broken. I don't know whatever people are solving with that old rele…

> The build of systemd and firewalld on 18.04 are both categorically broken.

Were they categorically broken back in 2018? What would you have recommended companies do around that time frame, if they wanted to use Ubuntu?

If it was acceptable at the time, then it's not a reason to rush off onto a new release where something else might be categorically broken. Even if it sucks, you already figured out how to deal with it during the first couple years you had it deployed.

If it was completely unacceptable at the time, then what do you do? You can't not have servers.

> something so decrepit

Most server code is not going to get very out of date over the course of several years. It's not significantly more decrepit than the day it was deployed.

Node.js code would be one of the things outside this "most". Though I don't know if those users would have had the distro version of node to begin with.

Re: Ubuntu Security Updates Are a Confusing Mess

#30

Earlier quoted context omitted.

I suppose I doubt the proposition of '10 year support' - admittedly I haven't done anyone else's job for them. I don't know if that necessarily means stop selling the product... but tighten up the terms, I guess? Anyone choosing to stay on something that old has chosen those gremlins. The build of systemd and firewalld on 18.04 are both categorically broken. I don't know whatever people are solving with that old rele…

> The build of systemd and firewalld on 18.04 are both categorically broken. Were they categorically broken back in 2018? What would you have recommended companies do around that time frame, if they wanted to use Ubuntu? If it was acceptable at the time, then it's not a reason to rush off onto a new release where something else might be categorically broken. Even if it sucks, you already figured out how to deal with…

> Were they categorically broken back in 2018? What would you have recommended companies do around that time frame, if they wanted to use Ubuntu?

They were and still are. The irony: the fix need not be breaking/demand a new major release.

> Most server code is not going to get very out of date over the course of several years. It's not significantly more decrepit than the day it was deployed.

That's my point. It was broken from the beginning.

Reminder: 'firewalld' is a management daemon for N firewalls. You use it exactly because you don't care about implementation details like the backend. It's not even part of the default Ubuntu install. Just offered.

Most users wouldn't see it, I don't judge that. I judge how Canonical behave{s,d}.

I would have recommended they, the integrator/procurer of the distribution, avoid the 'iptables' backend for 'firewalld'... a release or two before 18.04. Not even this one. It was well on the way out already/communicated/ignored.

If they wanted to fix it 'breaking upgrade' style, they had at least two chances. They could also avoid the rake-kickflip of the '--wait' option.

Final point being: I'm not here to do their work. A distribution is a collection of software. They chose to offer it, not me.

Just because I - the seasoned administrator can find/fix the problem - I shouldn't have to. I like a compelling experience too. This odd mixing isn't it.

I will fully admit to seeking out the problem in... asking to install firewalld. Not offering the packages at all, instead of poorly joined, would be an improvement. I'm not without options. I don't need poor ones.

To be clear: I'm not yelling into the void. This was reported to their bug tracker in at least 2019. I escalated it to them through $EMPLOYERS. Several. Canonical's support means jack to me.

"Vendor support" is largely a Bogeyman and compliance racket IMO. I've, outside this wild thread, otherwise moved on to nicer pastures!

Post reply on HN