3 ms·
Honestly, I can't remember the last time I had Debian stable go wrong in any application[server,desktop,laptops or raspian]. I use it everywhere and it is pret
by tempfs 6y ago
Honestly, I can't remember the last time I had Debian stable go wrong in any application[server,desktop,laptops or raspian]. I use it everywhere and it is pretty fantastic.
Despite Debian being phenomenal in many ways, it doesn't offer up a head for the chopping block to replace yours if things go wrong in a corporate application. Good luck getting IT folks to deploy anything that doesn't offer them an out.
Using CentOS knowing that it is downstream from RedHat but that RedHat would step up and fix things in a semi-timely manner was good enough for many enterprises....at least until IBM got involved.
Ubuntu is also a weird choice generally speaking because Ubuntu just uses Debian's testing repo as a base and really only significantly varies in the kernels that they roll for various products/services.[cloud,live patching,etc.] They used to maintain their own desktop[Unity] and service management[upstart] and a bunch more variances from Debian...but that ain't really the case today.
- pabs3 6y agoUbuntu is actually based on Debian unstable, they do their own QA rather than relying on the Debian's testing migration QA.
- chaz6 6y agoDebian was responsible for one of the, if not the, biggest security disasters in Linux distributions' history. A Debian developer thought they knew better than the OpenSSL developers and made a change that compromised every SSH and SSH private key you generated. https://threatpost.com/how-debian-openssl-bug-almost-spawned-disaster-051809/72669/ https://threatpost.com/how-debian-openssl-bug-almost-spawned...
- kodah 6y agoI remember this bug. It was what made my interest in systems engineering soar. Unfortunately your characterization of it falls quite short. Here's the mailing list email that inspired the bug: https://marc.info/?l=openssl-dev&m=114651085826293&w=2 https://marc.info/?l=openssl-dev&m=114651085826293&w=2 I kind of doubt that some guy that thinks he "knows better than the OpenSSL developers" is saying things like this on their mailing list: > What I currently see as best option is to actually comment out those 2 lines of code. But I have no idea what effect this really has on the RNG. The only effect I see is that the pool might receive less entropy. But on the other hand, I'm not even sure how much entropy some unitialised data has. The result was something like 32k sources of entropy which is not enough. Here's the bug Kurt was trying to fix: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=363516 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=363516