Live data from Hacker News

Why does Debian change software?

blog.liw.fi

71–80 of 210 posts

Re: Why does Debian change software?

#71
post #49

Earlier quoted context omitted.

I'll admit that I haven't inspected the patch, but how could that warning possibly work without checking version information somewhere on the internet? That was listed in OP.

IIRC it just hardcodes the release date and complains if it is more than 2 or 3 years later. It’s somewhat reasonable. I agree Debian should patch out phone-home and autoupdate (aka developer RCE). They should have left the xscreensaver local-only warning in, though. It is not a privacy or system integrity issue. jwz however is also off the rails with entitlement. They’re both wrong.

> jwz however is also off the rails with entitlement.

Always remember to not link to his site from HN because you'll get a testicle NSFW image when you click on a link to his site from HN. dang used to have rel=noreferrer on outgoing links, but that led to even more drama with other people...

Some people in the FOSS scene just love to stir drama, and jwz is far from the only one. Another person with such issues IMHO is the systemd crowd, although in this case ... IMHO it's excusable to a degree, as they're trying to solve real problems that make life difficult for everyone.

Re: Why does Debian change software?

#72
post #64

Earlier quoted context omitted.

I second that. Not only are there not infrequent cases of package maintainers breaking software, it's effectively nothing but the "app store" model, having an activist distributor insert themselves between the user and software. It's why I'm really glad flatpaks/snaps/appimages and containerization are where they are at now, because it's greatly dis-intermediated software distribution.

Since this is the FOSS world, you are of course free to eschew distributions. But: > it's effectively nothing but the "app store" model, having an activist distributor insert themselves between the user and software. is just factually wrong. Distributions like Debian try to make a coherent operating system from tens of thousands of pieces of independently developed software. It's fine not to like that. It's fine to i…

I'm using Arch and, AFAIK, it tries to use upstream code as much as possible. That's much better model IMO.

Re: Why does Debian change software?

#73
post #4

Debian will remove code that “calls home” or tries to update software in a way that bypasses the Debian packaging system. Thank god. I'm so happy that such a distro exists.

Most good stuffed Distros do this. For example SUSE recently banned a package because of "calling home" e.g. did side-leading. https://security.opensuse.org/2025/05/07/deepin-desktop-remo...

Debian indeed does this. In release FF has disabled telemetry: https://wiki.debian.org/Firefox

Re: Why does Debian change software?

#74
post #64

Earlier quoted context omitted.

Since this is the FOSS world, you are of course free to eschew distributions. But: > it's effectively nothing but the "app store" model, having an activist distributor insert themselves between the user and software. is just factually wrong. Distributions like Debian try to make a coherent operating system from tens of thousands of pieces of independently developed software. It's fine not to like that. It's fine to i…

I'm using Arch and, AFAIK, it tries to use upstream code as much as possible. That's much better model IMO.

Why do you assume Debian packagers don’t do the same?

Re: Why does Debian change software?

#75
post #64

Earlier quoted context omitted.

Since this is the FOSS world, you are of course free to eschew distributions. But: > it's effectively nothing but the "app store" model, having an activist distributor insert themselves between the user and software. is just factually wrong. Distributions like Debian try to make a coherent operating system from tens of thousands of pieces of independently developed software. It's fine not to like that. It's fine to i…

I'm using Arch and, AFAIK, it tries to use upstream code as much as possible. That's much better model IMO.

It's a better model until you fix a bug, but upstream is unresponsive.

Re: Why does Debian change software?

#76

Not the best name for the article. My first guess was version changes, or software being added/removed from repo. Turns out this is about source code modification.

Me too. I was hoping for an explanation of why the software I have got used to and works very well and isn't broken keeps being removed from Debian in the next version because it is "unmaintained".

Re: Why does Debian change software?

#77
post #75

Earlier quoted context omitted.

I'm using Arch and, AFAIK, it tries to use upstream code as much as possible. That's much better model IMO.

It's a better model until you fix a bug, but upstream is unresponsive.

Don't fix bugs, leave it to developers.

Re: Why does Debian change software?

#78

Earlier quoted context omitted.

I'm using Arch and, AFAIK, it tries to use upstream code as much as possible. That's much better model IMO.

Why do you assume Debian packagers don’t do the same?

Because it's well known that debian packagers alter software they package with unnecessary patches.

Re: Why does Debian change software?

#79
post #66
post #8

Earlier quoted context omitted.

Do you have any statistics that show that Debian patches introduce more CVE worthy bugs than the software already contains? OpenSSL doesn't really have a pristine history. Let's not forget that the patch had been posted on the OpenSSL mailing list and had received a go ahead comment before that. Having said that, if you're asking if there's a penetration test team that reviews all the patches. No there isn't. Like th…

The patch was posted on the wrong OpenSSL mailing list, and frankly that particular Debian bug was worse than anything else we've seen even from OpenSSL. Last I knew Debian didn't do dedicated security review of patches to security-critical software, which is normal practice for other distributions.

It was plausibly the worst computer security bug in human history, but by the same token, it's hard to see it as indicating a systemic problem with either Debian or OpenSSL. When we're dealing with a once-in-history event like that, where it happens is pretty random. It's the problem of inference from a small sample.
Post reply on HN