3 ms·
It matters when there's a security bug which needs patching in an underlying library. With shared libraries, only one library needs updating. With each package
by devdas 16y ago
It matters when there's a security bug which needs patching in an underlying library.
With shared libraries, only one library needs updating. With each package proving it's entire ecosystem, every package on your system needs such updates.
- coffeeaddicted 16y agoThen again if a library is patched who will test if all applications using it still work? I never had updates messing up my system as bad on Windows as it happened a few times already on several of my Linux systems (with different distributions). To stay with Java - the reason I gave up on Eclipse was when it got broken the second time after an Java-VM update and I just didn't want to fight the package system anymore. I trust application developers usually to do better tests than distributors. And certainly distributors don't even care about 3rd party packages. I would prefer a system where application developers are responsible for which libraries link against their applications. And a complete different mechanism for security. For example a list of libraries+versions with known security-problems against which shared libs can be tested on start. And I'm sure there are other solutions, for example searching my system for all versions of a certain library and asking me which to replace (and maybe keep me informed about not-updated versions). Preferably while keeping the old version around for a while to make it easy for me to switch back for the applications which do break now. It's not like having a single version of a library is the only way security can be handled - it's just the current way of doing things. And one can discuss what is preferably - a secure system which occasionally breaks working applications or insecure applications which at least do work. edit: Btw., this might even be in the interest of free software. Ever had a problem with a certain library which won't be patched in the official sources for whatever reason? Right now - basically you're fucked. Because even if you patch it yourself, the chances you will get distributors to add a second nearly identical library with 1-2 simply patches is basically zero. So although you have those free libraries with source, it doesn't really matter because you can't change those sources yourself if you still want to be in official distributions. A real free system would be one where changing sources is made easy.
- devdas 16y agoWhich is why I like systems which are mostly from the vendor, with very few custom applications. IME, application vendors only test on a few common systems, not across the board. Try running something which isn't common (say a 64bit Linux distribution three years ago), on even with newer hardware. My Linux experience has been with third party packages breaking, not anything shipped by the vendor.