4 ms·
Recently I was looking at DEs on Debian 11 and measured their relative number of installed packages. My reason was to get a first order approximation of "vulner
by intrepidhero 4y ago
Recently I was looking at DEs on Debian 11 and measured their relative number of installed packages. My reason was to get a first order approximation of "vulnerability surface" based on the assumption that more packages would probably imply more things to have vulnerabilities. I realize that's a gross oversimplification but I thought it was an interesting metric.
DE Added packages
Plasma: 964
XFCE: 417
Openbox: 103
Of course Plasma (and XFCE) give you way more functionality than OpenBox, and I found if you start installing other programs to replace all that (Network Config GUI, USB storage GUI, file manager, etc) you quickly start to approach at least XFCE levels of packages. Still I found it an interesting exercise. You could start with openbox and potentially make better choices, choosing more secure programs (for some measure of secure). Or assume that because Plasma has more developer energy behind it and therefore get security updates much faster.
It's nice to see number of packages and RAM usage correlate. That seems intuitive at least.
- melissalobos 4y ago> I realize that's a gross oversimplification In part especially since KDE deliberately breaks up their core libraries into multiple sub-libraries(https://develop.kde.org/products/frameworks/ https://develop.kde.org/products/frameworks/), in order to make them available for reuse by other Qt projects. Which is not the case for XFCE. KDE also depends on Qt which is similarly broken up into smaller packages(e.g. https://packages.debian.org/buster/libqt5gui5 https://packages.debian.org/buster/libqt5gui5 is depended on by https://packages.debian.org/buster/libkf5auth5 https://packages.debian.org/buster/libkf5auth5). Even though the actual attack surface in terms of exposed functionality is similar.
- TingPing 4y agoXFCE does have modularity in many ways. The reality is it has a tenth of the complexity of Plasma.
- lmm 4y ago> My reason was to get a first order approximation of "vulnerability surface" based on the assumption that more packages would probably imply more things to have vulnerabilities. Hmm, I'd think the opposite - DEs with a large number of dependencies are probably well factored and following good development practices, DEs that are a giant blob of undifferentiated C would seem much more likely to have vulnerabilities.