4 ms·
I feel like this confuses a lot of things by assuming an extremely sophisticated end user. Sure, if you're a double-threat dev/sysadmin using linux, then when
by paultopia 6y ago
I feel like this confuses a lot of things by assuming an extremely sophisticated end user. Sure, if you're a double-threat dev/sysadmin using linux, then when some vulnerability gets discovered in some dynamically linked library on your system, you have the capacity to (a) receive information about that fact, and (b) update it.
But now suppose you're an ordinary person. You use software. Maybe you even have a windows machine.[1] Which is more likely to actually get a security update to you?
(a) You have to update a single piece of software, which you know you've installed, though a recognized distributional channel like an app store or something, and all its dependencies come with it.
(b) You have to either learn what a DLL is and learn how to update it and then hope that nothing you rely on breaks in some mysterious way because of some dependency on a dependency on a dependency on a dependency. Or you have to accept a whole operating system update, assuming that the operating system comes with a DLL update---and hence accepting all of the other crap that comes with operating system updates from Microsoft (and Apple), such as bugginess from complex updates, incompatibilities between new versions of operating systems and software (or hardware) that you rely on, new obnoxious security rules that you might not agree to (looking at you, Cupertino), and massive disruptions to your ability to actually use your computer to do your work.
No thanks.
[1] Maybe this article is specifically targeted against the linux ecosystem? If so, perhaps this issue is ameliorated somewhat, but it still seems to put a fairly substantial burden on end users, that seems to be inconsistent with actually letting non-experts use linux OSes.
- regularfry 6y agoAlternatively, realise that the problems in (b) are largely solved for reasonable OSes where the vendor takes responsibility both for automatically getting you security patches and for keeping you working without major disruptions. I'm not sure where you've got the idea that updates are all-or-nothing, but some of us have been living a life you seem to think can't exist for decades at this point.
- deadbunny 6y agoThat sounds like a good argument for using package managers with automatic security updates. The user doesn't need to be an expert, just reboot when the system tells them to.
- nwallin 6y ago> (b) You have to either learn what a DLL is and learn how to update it ... That's not at all what the process is for the ordinary person. The ordinary person sees a notification pop-up from "Ubuntu Software Center" that says 8 packages or whatever need to updated, with one button that says "update everything now" or whatever and one that says "remind me later" or whatever. It's up to you to choose a distro that applies the appropriate amount of rigor with regards to testing dynamic library updates. For bleeding edge distros like Gentoo or Arch, it's not that much. Upstream publishes an upstream, and the Gentoo package maintainer chucks it into the testing branch. After 30 days, if no one complains, it gets marked stable. The user chooses a certain amount of risk. (although it's been several years at least since ABI breakage has been an issue for me on Gentoo testing) (note that security critical updates are fast tracked into stable) For other distros like RHEL and Debian stable, the package maintainer spends considerably more effort ensuring a random update of openssl-1.1.1i to openssl-1.1.1j doesn't break stuff. The user chooses a certain amount of stability at the expense of not having the latest version of whatever. On the other hand, on my Windows computer at work, the process for updating is significantly more intrusive. Few OS updates can be applied without a reboot, Visual Studio updates do not permit me to continue working during an update, there are half a dozen auto-updaters, and some programs which don't get updated unless I manually go to their website and check for an update. I don't know when the last time I updated 7-zip is? Within the past week, there was a bug report that Python has an RCE with untrusted floats or something. On my linux systems, the package manager had an update within hours, and because there is only one Python installation on each of my linux machines, I know that all applications leveraging Python are now protected from that RCE. On my Windows work machine, I have not been notified that any of the applications I use which embed Python need to be updated. Presumably, this means my Windows machine is vulnerable.
- fomine3 6y agoIt's happy that you only use system's Python package. You need manual version management if you install multiple Pythons.
- nwallin 6y agoYou do not need manual version management if you have multiple versions of Python installed. By default, it will use whichever interpreter supported by the application is listed first in PYTHON_TARGETS. If you want, you can override that by calling the python interpreter you want manually, eg `python3.8 <program name>` or `pypy <program name>`. But if python3.9 is the "default" interpreter (because it's listed first) but the application only claims support for python3.8 in the ebuild, if you just run the application with no qualifiers it will start the python3.8 interpreter. Obviously there were many, many years when python2 and python3 needed to be installed side by side, and it's reasonably common for people to have multiple versions of python3 installed side by side. My VPS has both python3.9 and python3.8 installed side by side, for instance, because apparmor is slow to pick up python3.9 support.
- progval 6y agoIn addition to the other answers to your comment pointing out that the way you wrote (b) is very unfair; I'd like to point out that (a) assumes that the developer of the application is aware of the security update of their dependency and pushes a fix quickly.