3 ms·
Use a reputable Linux distro and install from the official repos, problem solved. To date the Debian maintainers have proven more trustworthy than 99.99% of the
by d110af5ccf 5y ago
Use a reputable Linux distro and install from the official repos, problem solved. To date the Debian maintainers have proven more trustworthy than 99.99% of the software vendors out there. They also appear to have better security practices than most commercial shops.
- 8bitsrule 5y agoThat's a little difficult for 'official repo's that don't include ESR versions.
- 5ESS 5y agoIt’s a shame debian flushed their reputation down the drain recently.
- lmm 5y agoDebian has a deliberate policy of extensively modifying upstream code, including security-critical code, without any dedicated security review. This (predictably) resulted in quite possibly the worst general-purpose software security bug of all time, where SSH and TLS keys generated on Debian machines were effectively blank and supposedly encrypted communications were readable by anyone. Debian has not changed its practices to prevent a reoccurrence and continues to follow the same policy. I agree that most Debian maintainers are trustworthy and have good intentions, but I would not consider them as having good security practices.
- jraph 5y agoHow many times did this happen since Debian's inception? How much time did it take to fix it when it happened? Because "few" and "not much" would be fantastic. Nothing is perfect.
- lmm 5y agoThat particular outstandingly bad security bug, once. (There are other cases of bugs in Debian that aren't present in upstream - in particular, Debian packagers introduced enough bugs in cdrecord that the maintainer made future versions non-open-source as he felt that these bugs that were not his fault were hurting his reputation - but I don't have any stats, and I don't feel that the rate of bugs in Debian is particularly high compared to other projects if we set aside the security-specific aspects). Regarding time to fix it, the bug was fixed about 2 weeks after it was reported, but it had been present for about 20 months (affecting all DSA keys generated on Debian systems during that time) - since security audits and researchers only look at the original upstream source, the bug was only spotted when a user noticed that two of the servers they were logging into had the same SSH key.