7 ms·
Some Ubuntu security patches are now behind 'Ubuntu Pro', a paid product
- kstenerud 4y agoWow. Just wow. Now I'm REALLY glad I switched my entire infrastructure over to Debian last year.
- rockwotj 4y ago+1 I've always ran Debian and pitched for it and it hasn't let me down yet.
- DeepYogurt 4y agoWhy people use ubuntu over debian on servers will never cease to amaze me. Ubuntu is a literal downgrade.
- josephcsible 4y agoHow was Ubuntu worse than Debian on servers prior to this change?
- metadat 4y agoSnap. Just horrible. Constant source of headaches, frustration, and disappointment. Snap drives users away. Here are some recent relevant HN threads: Ubuntu Snap update spoiled my World Cup Final - https://news.ycombinator.com/item?id=34041272 https://news.ycombinator.com/item?id=34041272 Ubuntu: “How are we improving Firefox snap performance?” - https://news.ycombinator.com/item?id=32702062 https://news.ycombinator.com/item?id=32702062 Ask HN: Is it safe to remove snap from Ubuntu 22.04 LTS completely? - https://news.ycombinator.com/item?id=31198675 https://news.ycombinator.com/item?id=31198675 Firefox now only available via snap on Ubuntu - https://news.ycombinator.com/item?id=30776698 https://news.ycombinator.com/item?id=30776698 Ubuntu to Make Firefox Snap Default in 21.10 - https://news.ycombinator.com/item?id=28564600 https://news.ycombinator.com/item?id=28564600 Ubuntu 20.04 LTS’ snap obsession has snapped me off of it - https://news.ycombinator.com/item?id=24383276 https://news.ycombinator.com/item?id=24383276
- josephcsible 4y agoI agree snap is awful, but isn't it almost entirely a desktop problem, since you're not usually running Firefox or Signal Desktop on a server?
- metadat 4y agoMy issues with Snap involved LXC. I stopped using Ubuntu for that project because it was such crap. I couldn't even control what version was running unless I went to great lengths, because snap would automatically and silently upgrade to the latest available (which brought in breaking API changes). Once my current 20.04 snowflakes fall out of security patch support and need a major OS upgrade, I won't be using Ubuntu at all ever again. There's no advantage over Debian, quite the contrary. Sadly, now Ubuntu is the disadvantage OS.
- TheDong 4y ago> isn't it almost entirely a desktop problem, since you're not usually running Firefox or Signal Desktop on a server? snap is installed on ubuntu server too, and if some junior engineer comes in, how are they supposed to know not to use it? How are they supposed to know that after googling some variation on "install docker ubuntu" and getting "snap install docker" (https://snapcraft.io/docker https://snapcraft.io/docker), they should ignore those very official looking instructions which will give them a broken and buggy docker installation? Perhaps the problem's theoretical, but canonical certainly encourages using snaps on servers, such as in the microk8s docs (https://microk8s.io/docs/getting-started https://microk8s.io/docs/getting-started), and I expect if canonical keeps pushing it, it'll become more and more of a server problem in reality too.
- kstenerud 4y agoCreeping snapification of more and more packages (.debs that actually install a snap). It was somewhat bearable when it was only desktop, but they've been creeping more and more into server-side stuff. ZFS support: https://www.omgubuntu.co.uk/2023/01/ubuntu-zfs-support-status https://www.omgubuntu.co.uk/2023/01/ubuntu-zfs-support-statu... It's hard to put ones finger on a particular thing, but I've felt for some time now that Ubuntu is becoming increasingly user-hostile in the pursuit of money. It was a similar kind of user-hostility that drove me away from Red Hat (when they started locking user-supplied support forums behind subscriptions).
- metadat 4y ago16-17 years ago, Debian was infamous for having old versions of many popular packages (e.g. Python, gcc). Ubuntu caught on for being "just like Debian" except kept more up to date with the latest and greatest. Nowadays Debian isn't lagging behind anymore, thankfully.
- pxc 4y agoHave Debian Unstable and Testing ever really been that musty?
- qbrass 4y agoStable was mummified, Testing was musty, and Unstable had the opposite problem and was named Sid for a reason. Ubuntu used to fit between Testing and Sid.
- wink 4y agoI find that description overly negative. I was running Testing on my work laptop for years (up to 2017) and I only had to build like 5 packages myself where I needed a bleeding edge version. Definitely didn't feel worse than any Ubuntu release after a few months into the cycle.
- raggi 4y agoMost of the software that is in the Debian release from this December was released in 2020. Examples include: go 1.15, gcc 10.2, postgresql 13, systemd 247. Ubuntu 20.04.1 has go 1.18.1 and gcc 9.4. It's all a mixed bag and somewhat disappointing.
- noncoml 4y agoZFS I only have Ubuntu server on my NAS. Everything else is Debian. Considering switching the NAS to FreeBSD
- nortonham 4y agodebian has zfs support no? That being said a nas running freebsd is probably the best choice
- poolopolopolo 4y agoI dont because of documentation. I know I can google anything about ubuntu and I dont want to spend a lot of time figuring it out myself. Safe reason I moved back to x86 from ARM, had a lot of issues with ZFS on a Pi4b. Specifically about Debian. I find more than 1 year old versions pretty outdated. I couldn't try Go generics because the version was too old... that pissed me off.
- steelframe 4y agoMy solution is to run Debian stable as the host operating system and to build containers on the occasion that I want a more recent version of something. The learning curve for something like podman really isn't that steep, and a relatively small investment in learning that has paid many dividends for me through the last few years.
- re9 4y ago[flagged]
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- EdwardDiego 4y agoOkay, way to start a conversation in good faith.
- dang 4y agoUsers flagged that post. I guess you can call users "censors" if you want (people mostly use that word to express dislike nowadays), but they're not doing it with any special authority.
- metadat 4y agoWhat's the difference? Anything controversial seems to get flagged and die off quickly, whether mods or the hive execute it doesn't make a net difference. The heated discussions are often of dubious quality. But it also sucks some of the fun out of HN when the pile-ons die so quickly. Sometimes companies deserve to fry and HN is probably a healthy outlet. In this case Canonical has earned it by not putting users first. Curiosity killed the cat.
- josephcsible 4y agoAuthor of said flagged post here. I agree with you. I wish HN worked such that if a post has more upvotes from high-rep users than flags, that the flags would have no effect whatsoever.
- metadat 4y agoI would personally like that, too. But Dang's bonzai tree that is HN is curated a very particular way which increasingly mostly murders any dramatic posts. I blame Elon, because the Twitter shit really fucked with this site in a way I'd not previously observed. Just another (probably incorrect) theory. I'm sympathetic in that poor Dang is already grinding it day in and out to keep things afloat, the dumpster fire threads can get out of control pretty quickly and can get ugly and abusive. It's a fine a line.
- smcnally 4y agoStarting seeing these messages earlier this week. It also says Pro is gratis for up to 5 machines.
- uSoldering 4y ago$25 a year for me.
- YPPH 4y agoIs there anything preventing someone with a subscription simply pulling those patches down and putting them in a freely accessible APT repo?
- josephcsible 4y agoTechnically probably not, but expect Canonical to sue you if they find out you do.
- YPPH 4y agoOn what basis? Most software is GPL which has redistribution rights.
- josephcsible 4y agoPresumably for violating the contract you agree to when you sign up for Pro. As for the GPL being supposed to block this, it doesn't seem to have stopped grsecurity from pulling the same nonsense.
- drdaeman 4y agoThis could work for MIT, BSD and alike. But in case of GPL and other strong copyleft-licensed software - how this is supposed to work? They just can't throw some ToS over it and say "nah, you can't share it", that'd be a violation of GPL (and the only question is if there'd be a developer who would bother to sue for illegally distributing their work).
- josephcsible 4y agoThey shouldn't be able to do that, but that's exactly what grsecurity has been doing to the GPL'd Linux kernel for years, and they've gotten away with it, at least so far.
- tzs 4y agoWhat is grsecurity doing that violates GPL? I’ve never used it (or even heard of it before now) but just took a quick look at their website, download page, and FAQ. I didn’t see anything that appears to violate GPL.
- kyelewis 4y agoThere's not much context here- Is this an EOL ubuntu release? In which case this is expected (arguable whether it's good practise or not). If not, y'know, bugs are also a thing that happens. Let's see how it plays out.
- josephcsible 4y ago> Is this an EOL ubuntu release? No, it's happening in 22.04 to me. > If not, y'know, bugs are also a thing that happens. I don't think it's a bug, because what's actually happening matches what Canonical's website says is happening.
- quadrifoliate 4y agoKind of, but it's sneakily hidden. This is the webpage I'm looking at: https://ubuntu.com/security/esm https://ubuntu.com/security/esm In the "Security Patching" comparison between Ubuntu LTS and Ubuntu Pro for the 23,000 Ubuntu Universe packages, they say "Best effort" for Ubuntu LTS v/s "10 years for Ubuntu Pro". This would lead a reasonable person to think "Okay, maybe it's 2-3 years at least for LTS?" But in the graphic below for Universe, there is no orange section (unlike the 5 year line for Ubuntu Main). Which I think that Ubuntu LTS will now never guarantee any security patches for Universe, even if the distro came out yesterday. Am I reading this wrong? I hope I am, but it seems to match people's experience.
- captn3m0 4y agoYou're correct. Packages in universe were never marked as supported, and never got any updates. The LTS definition has always been "main"+"restricted".
- temptemptemp111 4y ago[dead]
- stolen_biscuit 4y agoWhat is Ubuntu Pro and how will this affect me as a regular Ubuntu user? Linked post has no context
- josephcsible 4y agoUbuntu Pro is a paid* subscription that Canonical offers. It affects you if you've installed any packages in universe, e.g., ImageMagick, in that you'll be running known-vulnerable versions of them unless you sign up for Pro. * Individual users can use it for free on up to 5 machines.
- chrsig 4y agoif it's gpl software, can they actually enforce that? if they're distributing under gpl, that means they 1) have to make the source available, 2) the user maintains the ability to redistribute. So provided that the user makes their own apt repo, they should be able to distribute it to as many machines as they see fit. That's essentially how centos operated. I'm sure there's some exceptions, around assets that ubuntu may own or any trademarks. But I shouldn't be learning this from an HN link to a twitter post of a screenshot that references ubuntu.com/pro. So I have the sense they haven't done much if any advertising for it? Maybe I've just been oblivious? It is somewhat concerning that they're kinda holding security packages hostage...but I don't think it's unreasonable for ubuntu to want corporations to chip in. Gotta keep the operation running somehow, and bills don't just pay themselves. I don't know what else they can offer to make anyone actually shell out some cash.
- josephcsible 4y ago> if it's gpl software, can they actually enforce that? In practice, I think they probably will be able to, since grsecurity can for their patches (at least they've been able to so far) even though the Linux kernel is GPL. I agree that they shouldn't be able to.
- captn3m0 4y agoI've filed a PR[0] for endoflife.date/ubuntu, (Preview[1]). Would appreciate feedback if this helps understand the mess. [0]: https://github.com/endoflife-date/endoflife.date/pull/2424 https://github.com/endoflife-date/endoflife.date/pull/2424 [1]: https://deploy-preview-2424--endoflife-date.netlify.app/ubuntu https://deploy-preview-2424--endoflife-date.netlify.app/ubun...
- Caligatio 4y agoThe package in question is libjs-jquery-ui which is in the universe repository. The universe repository is explicitly community supported only and needs to be enabled as it's not on by default. Ubuntu Pro promises 10 years of security updates to some of the packages in the universe repo. In Redhat speak, this is like RH supporting some EPEL packages if you have a subscription.
- josephcsible 4y agoI don't think Red Hat has ever said anything like "A known-vulnerable version of this package is free. We did the work of making a security patch for it, but to get that, you have to pay." for any of their releases prior to EOL.
- Caligatio 4y agoSo Ubuntu offering some support where RH offers no support is worse? To the best of my knowledge, RH won't touch EPEL with a 10 foot pole.
- josephcsible 4y ago> So Ubuntu offering some support where RH offers no support is worse? Which is worse: putting asbestos in everything because you don't know it's harmful yet, or once everyone learns that it is harmful, having a cheap product line that you put asbestos in and an expensive product line that you don't?
- Caligatio 4y agoOpen source: if it isn't perfect, don't bother.
- markshuttle 4y agoEmotive analogy, but lets run with it. We've all decided to build with sustainable local materials, which anybody can dig up without harming the environment. That's wonderful! Unfortunately, the materials sometimes turn out to have asbestos in them. Canonical and a large number of friends enjoy digging, and they make those local materials available for free, no digging required, as Ubuntu. So Ubuntu happens to be a free source of pre-dug materials which is popular for lots of reasons. People with big buildings who like using Ubuntu need the asbestos removed if its found, and Canonical has started to do that for them commercially. Canonical have also said they are happy to remove the asbestos for free for small buildings, as long as the big-building people keep funding them to do it. The more big building people choose Canonical to sort out this issue, the better it will be for everyone using Ubuntu, even if they don't do any digging themselves. Seems like a great deal for people with smaller buildings, as long as people with big buildings also think it's a good deal. Since I happy to like helping people with smaller buildings, I think this is all pretty square.
- michrassena 4y agoSo if I'm reading sources.list correctly, universe repositories don't receive security updates from the Ubuntu team. Is it now the case that they do, as long as you've enrolled in Ubuntu Pro? That makes it sound as if Canonical has taken some kind of responsibility for making these packages secure at a cost for more than five devices.
- josephcsible 4y agoSecurity patches for universe used to be "best-effort". Now they're intentionally withholding all of them from everyone who's not subscribed to Pro.
- michrassena 4y agoThanks, that explains things a bit better. It sounds like it's better to not use the universe repository at all in that case. I don't suppose I can just switch over to Debian for those packages, can I?
- Dylan16807 4y agoWould this patch have existed without the Pro program?
- josephcsible 4y agoI think so. So far, haven't they only cherry-picked existing patches into their packages? Have they written any new patches yet?
- michrassena 4y agoSo is this in fact a good thing reframed as something negative because Canonical is asking for money?
- leidenfrost 4y agoFOSS advocates: "It's free not as in Free Beer but as in freedom!" FOSS users: "I'm gonna take it for granted and if someone ever wants to charge me money for anything open source I'm gonna be very angry".
- ndiddy 4y agoFurther context: Ubuntu Pro is an extended support subscription for Ubuntu. Previously, Canonical would only provide security updates for packages in the "main" repo, while packages in the "universe" repo were solely updated by community package maintainers. It looks like subscribing to Pro will grant access to a new stream of security updates by Canonical for the "universe" repo, while not subscribing will leave you in the same state you were previously. It seems like the main problem here is Canonical completely messing up how they're communicating this to users (also, I would be pissed off if I kept seeing the nag messages every time I checked for package updates).
- josephcsible 4y agoI don't think it's just a communication issue. There's something really slimy about offering known-vulnerable versions of software for free and then charging for the security patches.
- michrassena 4y agoIt's a perverse incentive for sure.
- dyingkneepad 4y agoPreviously things made sense, as no one was actually working on Universe so it was a best effort thing. But now, Canonical is indeed working to make those packages secure, but is withholding the patches and only publishing to people who pay? That's not very much Open Source philosophy if you ask me...
- mattl 4y agoThey’re offering 5 machines for free on Pro to sweeten the deal a little bit but I agree this is communicated poorly.
- elderbarry 4y agoI think you’ve got it the wrong way around. They can only make these patches because large enterprises wanted them and were willing to pay for them, and they have found a nice way to make the patches available free to you and me. If they made them free for large enterprises too, that funding would go away and we would all lose them. Also, the extra security work on universe means there are more people who can handle the main repo even better. So even non-Pro users have benefitted.
- re9 4y agoCanonical is indeed liked by many: https://old.reddit.com/r/assholedesign/comments/yg97tk/ubuntu_includes_ads_in_system_update_theyre/ https://old.reddit.com/r/assholedesign/comments/yg97tk/ubunt...
- josephcsible 4y agoI think those ads are entirely reasonable. I had nothing against Pro until it led to them withholding security patches from people running the latest versions of their distros.
- re9 4y agoMe like them too, long time. Soon these Canonical shenanigans piss off enough of their users... Happy for you ubuntu and your fanbois.
- dang 4y agoA previous submission on this topic was flagged by users: https://news.ycombinator.com/item?id=34580360 https://news.ycombinator.com/item?id=34580360. I think this was because people felt it was misleading? Unfortunately it's nigh impossible for a casual observer (moi) to make sense of this from a URL like https://cloudisland.nz/@drV/109786183082845131 https://cloudisland.nz/@drV/109786183082845131. If this is a significant story, presumably there's a more substantial writeup of it somewhere?
- kennu 4y agoUbuntu Pro pricing (https://ubuntu.com/pro/subscribe https://ubuntu.com/pro/subscribe) seems pretty weird for a power user with a few desktops and a bunch of servers at home. Apparently it would cost thousands of dollars per year to subscribe them all, and require strictly counting the number of devices used. If it was something simple like $99 for unlimited usage, I would probably subscribe right away.
- elderbarry 4y agoYou get a free personal subscription which can be used on up to 5 machines that you personally own. Canonical are letting home users, community, power users and small businesses benefit free of charge from the extra security work that much larger enterprise customers had asked for, and funded. If Canonical made it free for the large enterprises, they would stop funding it and we would all lose the best and broadest security coverage in the market. Also, the Canonical security team has grown a lot to do this work, so the security coverage of Ubuntu ‘main’ which has always been there is now even better. So this is pure win for you, me, and everybody else on Ubuntu too. If you don’t change anything, you get more free security fixes in Ubuntu than any other Linux you could pay for, for 5 years, and that keeps improving as more big companies use Ubuntu Pro. With a free subscription you get personal / small biz coverage that’s miles better than any other enterprise offering. And if you are a large business, Ubuntu Pro is an incredibly cost-effective way to get full coverage and things like FIPS and FedRAMP coverage while letting your developers use any of the tens of thousands of Ubuntu packages. It’s 3-4% of the cost of the cloud VM, a total no-brainier for any CISO. There is a reason the fast-moving companies are building new stuff on Ubuntu.
- kennu 4y agoThat's all nice, but I have more than 5 machines, so there doesn't seem to be a well fitting pricing option for this kind of home power users.
- failsecure 4y agoI think this discourse comment by a Canonical employee should be read by everyone before making a judgement. It's really easy to make assumptions as an end user, myself included. https://discourse.ubuntu.com/t/why-is-extended-security-maintenance-needed-for-apps-in-ubuntu-20-04-x-lts-in-2021/25871/39 https://discourse.ubuntu.com/t/why-is-extended-security-main... ``` Canonical has never provided security updates for universe packages until this week, so nothing has changed for you if you decide to simply ignore the message ```
- josephcsible 4y ago> Canonical has never provided security updates for universe packages until this week Is that true, though? Until now, wasn't it just that they weren't guaranteed? Didn't Canonical make security patches available in universe on a "best-effort" basis, or at least say they did?
- failsecure 4y agoI'm not sure as I've never followed how OSS projects get patched w.r.t security in particular. I've always groaned at my employer for running EOL operating systems and tell them about upgrading to a supported OS to prevent getting into this type of situation. My reasoning was that if we were running a supported version of $oss_project then we'd get security updated naturally.
- voakbasda 4y agoThat seems deliberately misleading. They may not have “provided” security updates, but they did “distribute” them when they were provided by community package maintainers.
- failsecure 4y agoThe way I interpret that paragraph is that now with an additional revenue stream (Pro/ESM) they can develop security patches and only subscribers will get them. I think their attempt to get the conversation started (putting ambiguous sentences inside of apt) has back fired however.
- svc0 4y agoPerspective from someone who maintains Debian packages in the community repo here: Package maintenance is time consuming and difficult. It requires a lot of volunteer work. Individual maintainers are overworked and unpaid. Packaging software often requires managing complex dependencies, writing documentation, developing packaging toolchains, and patching software. Furthermore, stable release of a particular software version is even more of a challenge for package maintainers. Often upstream FOSS maintains only patch HEAD and release a new version. The responsibility of backporting changes to previous versions is left to package maintainers. To provide secure versions of old software, you're asking maintainers to have intimate familiarity with the OSS code bases and follow the dev process etc. If I had community supported software exposed to the internet, I would be very concerned with the current state of things. I would want to ensure that individuals are invested with maintaining this software in a full-time capacity. It is important that "main" receives free Updates. Ubuntu Pro seems like it enhances the OSS ecosystem. As an personal user, you can get a free subscription courtesy of Canonical. It is important to remember that as the end user, you are choosing to enable the community repo. Without Canonical, you wouldn't even know this version of the software is vulnerable.
- sacnoradhq 4y agoUbuntu is the delusional cult of convenience that doesn't scale well to extremely large operations. Their whole premise was they released a completely free distro that was identical to the commercial support version, as opposed to RHEL. If this is this case, then they've footgun fireworks factory fired themselves. Debian is fine, but RHEL-derivates are most reliable because they run at scale and have the most stable kernel going. CentOS (5 year lifecycle) is patched more often than Alma and Rocky (10 year lifecycle), so there's no "perfect" alternative free to RHEL. Large enterprises should be purchasing RHEL because most multibillion dollar companies run Cent or one copy of RHEL. Also, I wouldn't use RPMs because they muddy the boundaries between OS and app: nix, microdnf, or habitat where all of "your" stuff is isolated and vendored separately. At the boundaries, it's important to sanitize environment variables, PATH, and shebangs that could cause bleed through. When in doubt, create a minimal chroot environment (even within containerization, and use SELinux) because apps shouldn't be able to run wild over a system. Then s6 or a daemon tools-derivative non-init process supervisor that doesn't replace init is also important since Systemd is unreliable for real apps.
- addajones 4y agoFree for up to 5 machines… for now. Lol.