3 ms·
> All in all it's pretty irresponsible to allow the current situation in the first place. Don't ship vulnerability-prone internet-facing C apps that you can't p
by embik 10y ago
> All in all it's pretty irresponsible to allow the current situation in the first place. Don't ship vulnerability-prone internet-facing C apps that you can't patch.
I think it's even worse because they won't patch or remove it. They could, but they do not consider it a problem. Ubuntu just imports everything from Debian. Things not relevant to the core team at Canonical are just thrown at the community basically saying "if you want a safe OS, you have to support this by yourself now". All the while Canonical is building their in-house, partly closed-source solutions to already solved problems.
- slgeorge 10y agoThat description of how Ubuntu deals with repositories is factually wrong. There are two repositories (in essense), Main and Universe [0]. For packages in Main a core developer (could be Canonical or someone else) has to be assigned to look after it and the Ubuntu security team has to allow it into the repository on the basis of it having a good security record and being maintainable [1]: it is _true_ that the Ubuntu security team is basically all Canonical employees. Many of these packages follow the upstream and don't come from Debian: or in some cases it's the same Canonical employee who maintains both the Debian and the Ubuntu packages so they might upload to Debian and pull in, or upload to both [2]. For Universe, Ubuntu pulls and builds from Debian. Many packages are sponsored by a maintainer who can then choose to upload their own package rather than use the latest sync from Debian. They aren't "thrown" to the community, rather they are never "promoted" to Main. All distributions have to choose how they deal with the large 'Universe' of software out there: in the Debian/Ubuntu world there's always been a lot of packages, compared to commercial RPM world. In Ubuntu's case the decision was to build/provide those packages, and let users decide what they wanted to do: for a 100% secured environment you would only turn on Main which is why the tools show you the supported status. The next question is whether it's a problem. It's not a problem if you understand a bit about how your distribution works. We can also look at the fact that it's been this way since Ubuntu started - so from 2004 it's worked like this. Clearly you don't like Ubuntu, which is fair enough: but I have to ask what you mean by "partly closed-source solutions" when there's nothing involving desktop Ubuntu that is closed-source. I assume you don't like Unity or something, but it's very much open source. Unless you are thinking of something else I'm unaware of? [0] https://help.ubuntu.com/community/Repositories/Ubuntu https://help.ubuntu.com/community/Repositories/Ubuntu [1] https://wiki.ubuntu.com/MainInclusionProcess https://wiki.ubuntu.com/MainInclusionProcess [2] https://www.piware.de/tag/debian/ https://www.piware.de/tag/debian/ is an example of someone who does this.