5 ms·
I think web browsers should be the exception to Distro's "stable" release rules. Browsers do not work at all like every other package. There are so many securit
by dyingkneepad 3y ago
I think web browsers should be the exception to Distro's "stable" release rules. Browsers do not work at all like every other package. There are so many security implications, everything is so complex that I really think having whatever is the newest release is actually the most stable strategy. New releases tend to be pretty stable considering how much testing they get everywhere.
- r9295 3y agoDebian regularly dispatches security patches in the form of updates for firefox/chromium. It's the same as running "apt upgrade"
- Sander_Marechal 3y agoDebian ships Firefox ESR, not Firefox stable. As a web developer I cannot work on just ESR.
- Sunspark 3y agoWhy not? I'm writing on ESR as I type this. The most current version of ESR is based on FF 115. The general release is 119. At this late date in web history, you shouldn't be dependent on some niche feature or implementation that only exists between 115 and 119.
- jauntywundrkind 3y agoDev tooling moves pretty quick. I find a nice to have feature every other version release that makes life better. ESR's significant lag misses out on a lot of these.
- csdreamer7 3y agoAnd feature and standards support, when I was writing a web app using HTML5 video Firefox would freeze on Android. This was years ago. Thankfully do not have to worry about ESR for Android.
- ksherlock 3y agoThe world would be a better place if web developers used old browsers on old computers with dial-up internet access.
- LargoLasskhyfv 3y agoAs a web surfer FF-ESR is sufficient for my use cases. Besides that it's good 'Anti-FOMO'.
- ploxiln 3y agoThey are. Debian provides latest major release of Chromium, just a week or so behind. For Firefox it uses the LTS releases, but still with major LTS release updates in the same Debian Stable release, when the older LTS is no longer supported.
- ComputerGuru 3y agoI just want to clarify that the week delay is for non-security-relevant updates (which is why it’s important for vendors to always be open about when they patch privately disclosed zero days).
- hackideiomat 3y agoI recently accidentally triggered a years old vuln in my Firefox, because ESR is shit and Debian is shit and why on earth would people want to use outdated software? I regret installing Debian :D
- LtWorf 3y agoWhich specific vulnerability are you talking about?
- hackideiomat 3y agoIt was a CSP bypass involving javascript URLs and using your mouse wheel... none of the big RCEs or so, but still shit
- ravenstine 3y agoBrowsers prove that stable distros for the desktop are a failed approach. It's one thing for stable server distros because the goal there should be software that changes infrequently and only needs to be updated with security patches most of the time. For desktop Linux, a user can and should be able to install and run lots of complicated code frequently. A browser is running and doing all sorts of complicated and arbitrary things all the time, sometimes like an OS in and of itself, and that's just one piece of software the user is running. I've never had a problem running an "unstable" or "testing" version of a Linux distro.
- xorcist 3y agoDebian testing strikes a good balance between integration tested and up to date software, and is a really good general purpose desktop. The main downside is that security updates is on a best-effort basis. The security team's focus is on stable and unstable. Testing will get them, but sometimes a few days late. While I understand their priorities, I also wish that would change.
- fsflover 3y agoI solved this problem by using Qubes OS. It doesn't matter if my browsing VM gets compromised, since there is ni data in it.
- JohnFen 3y agoPersonally, I don't want a nightly release of a browser (or any other software). Not because of stability or bug concerns, but because I don't want my software to change often. I strongly prefer long-term releases, and even then tend to put off updating for as long as I can get away with. Updates are pain unless they're security-only ones.
- pornel 3y agoFirst, this is an illusion of choice. The software changes anyway, and you can't realistically opt out of it changing by opting out of updates, since compatibility with the external world will force you to keep updating. Secondly, if you don't like change, putting off upgrades may actually make it worse for you. You will have an "OMG, they've changed everything!" shock when you upgrade rarely. OTOH if you run regular updates, you'll get small changes one at a time, boil-the-frog style. You can't opt out of changes, you can only get them in small drops, or a whole bucket at a time.
- JohnFen 3y ago> you can't realistically opt out of it changing by opting out of updates, since compatibility with the external world will force you to keep updating Long term, this has truth (although it's usually overstated -- most software, even internet software, that I have still works even after many years). But what I can do is decide for myself when to make that change. This is particularly important when features I need are removed, as it lets me still have working software while I look for an alternative. > if you don't like change, putting off upgrades may actually make it worse for you. It doesn't. UI changes, particularly, are disruptive. Having frequent small ones is far more disruptive to me than infrequent large ones.
- almatabata 3y agoGiven that web browsers have snuck into tons of applications nowadays with electron the list becomes quite a lot longer. The Webp fiasco also showed just how critical it is to keep all your electron applications up to date (https://blog.cloudflare.com/uncovering-the-hidden-webp-vulnerability-cve-2023-4863/ https://blog.cloudflare.com/uncovering-the-hidden-webp-vulne...).
- mr_toad 3y agoDownload it from Mozilla and use the auto update. I like package managers in general, but for a select few tools I’ll use a more timely update process.
- hulitu 3y ago> Browsers do not work at all like every other package. Of course not. There are no other programms on my linux system, executing remote code. (ok, there is rust (crates), but i avoid it). > There are so many security implications, everything is so complex that I really think having whatever is the newest release is actually the most stable strategy. If they would only fix bugs, then yes. In reality they introduce new ones.