|
|
Log in / Subscribe / Register

Linux Mint downloads (briefly) compromised

Linux Mint downloads (briefly) compromised

Posted Feb 22, 2016 20:43 UTC (Mon) by welinder (guest, #4699)
In reply to: Linux Mint downloads (briefly) compromised by glaubitz
Parent article: Linux Mint downloads (briefly) compromised

> But please be aware of the fact that Linux Mint does not provide any reasonable security
> support and in the end it's solely up to you to make sure all the necessary security updates
> are actually installed. If pre-installed multimedia codecs are more important to you than a
> secure system, it's your decision.

That is really just scare mongering.

I have yet to encounter a situation where a cve report has had Debian and Ubuntu
responses, but no patch for Mint has shown up in my patch queue immediately or
very soon thereafter. (I know about the "banned" packages and I have flipped the
switch so I can see them and decide; I am not worried over local attacks, so grub
can wait.)

Now, compare that non-situation to Debian's years of dragging feet regarding fixing
the package management's trust in the network and its resultant vulnerability to
man-in-the-middle attacks -- including those unintentional ones known as captive
portals -- which would *disable* security updates entirely. (Debian 710229;
Launchpad 1055614; and many others.)


to post comments

Linux Mint downloads (briefly) compromised

Posted Feb 22, 2016 20:57 UTC (Mon) by glaubitz (subscriber, #96452) [Link] (7 responses)

> That is really just scare mongering.

No, it's not. It's based on actual facts.

> I have yet to encounter a situation where a cve report has had Debian and Ubuntu responses, but no patch for Mint has shown up in my patch queue immediately or very soon thereafter. (I know about the "banned" packages and I have flipped the switch so I can see them and decide; I am not worried over local attacks, so grub can wait.)

You may be aware of blacklisted package updates, but many users are not. I'm sorry, but making security updates *optional* is not up for discussion, on any operating system. Period.

And, as I have explained before, Linux Mint does not issue security advisories, so you - as a Linux Mint user - have no immediate and easy way to quickly verify whether your particular version of Linux Mint is affected by a certain CVE.

On Debian, I open up Google and type "Debian CVE-2015-7547" and I am immediately presented with a website which shows me which versions of Debian are affected by the recent glibc vulnerability and which are not. You *cannot* do that on Linux Mint which therefore disqualifies itself for any professional use. End of discussion.

> Now, compare that non-situation to Debian's years of dragging feet regarding fixing the package management's trust in the network and its resultant vulnerability to man-in-the-middle attacks -- including those unintentional ones known as captive portals -- which would *disable* security updates entirely. (Debian 710229; Launchpad 1055614; and many others.)

Did you actually read the bug reports you linked? The original report for Debian's #710229 was filed on May 29, 2013 and on September, 01 2014, David Kalniskies [1] comments:

> As said, this isn't the fix for the problem of the initial reporter, though. This problem should be solved with earlier versions we released since the last Debian stable release, so I am closing this bug anyhow. I can't pin-point a specific version as there are many cornercases and we had various iterations fixing some (and opening new venues in the process).

So your argument is a strawman. And, even if it was valid, the problem would affect Linux Mint as since Mint uses most of Debian's packages unmodified, including apt, so I don't really understand why you would bring up in the first place.

> [1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=710229#17

Linux Mint downloads (briefly) compromised

Posted Feb 23, 2016 11:11 UTC (Tue) by Wol (subscriber, #4433) [Link] (6 responses)

> > I have yet to encounter a situation where a cve report has had Debian and Ubuntu responses, but no patch for Mint has shown up in my patch queue immediately or very soon thereafter. (I know about the "banned" packages and I have flipped the switch so I can see them and decide; I am not worried over local attacks, so grub can wait.)

> You may be aware of blacklisted package updates, but many users are not. I'm sorry, but making security updates *optional* is not up for discussion, on any operating system. Period.

So you'd be quite happy to see your *business* *critical* *application* taken down by an unrelated security update?

There are reasons why sysadmins blacklist ALL updates, *including* security ones. I'm not saying that's a good attitude. I'm not saying it's a wise attitude. I'm saying sometimes it's an extremely pragmatic one - after all, you wouldn't want your heart monitor in the ICU taken out by a security update, would you?

(And yes, I've had packages unexpectedly taken out by updates. Fortunately I don't have anything critical.)

Cheers,
Wol

Linux Mint downloads (briefly) compromised

Posted Feb 23, 2016 12:10 UTC (Tue) by glaubitz (subscriber, #96452) [Link] (2 responses)

> So you'd be quite happy to see your *business* *critical* *application* taken down by an unrelated security update?

If you're having *business* *critical* *applications*, you run your **OWN** test upgrades on a **TEST SYSTEM** anyway **prior rollout**, to make sure nothing breaks.

What a stupid strawman argument is that?

And if you're running a *business* *critical* *applications* on something as unsupported as Linux Mint as compared to Debian, RHEL or SLES, you should be fired from your job anyway!

> There are reasons why sysadmins blacklist ALL updates, *including* security ones. I'm not saying that's a good attitude. I'm not saying it's a wise attitude. I'm saying sometimes it's an extremely pragmatic one - after all, you wouldn't want your heart monitor in the ICU taken out by a security update, would you?

Again, if your heart rate monitor in the ICU runs Linux Mint, you would be fired immediately. Particularly medical environments require **CERTIFIED** hard- and software and I can **guarantee** that you would never get **ANY** certification for a hobbyist Linux distribution.

> (And yes, I've had packages unexpectedly taken out by updates. Fortunately I don't have anything critical.)

Then you were not doing your job properly and testing the updates in a testing environment prior rollout which is what **every responsible system administrator** will do.

Can we please stop with these idiotic strawman arguments? Seriously!

Linux Mint downloads (briefly) compromised

Posted Feb 23, 2016 21:58 UTC (Tue) by Wol (subscriber, #4433) [Link] (1 responses)

> > So you'd be quite happy to see your *business* *critical* *application* taken down by an unrelated security update?

> If you're having *business* *critical* *applications*, you run your **OWN** test upgrades on a **TEST SYSTEM** anyway **prior rollout**, to make sure nothing breaks.

> What a stupid strawman argument is that?

You're assuming that updates are *optional* - that, as sysadmin, I can block them til *I'm* ready, which may be never. Yet a post ago you were saying that they should NOT be optional, that they get force installed. Either you're happy with the sysadmin delaying them (ie they're optional), or they get force-installed and who cares if it crashes a critical system.

> And if you're running a *business* *critical* *applications* on something as unsupported as Linux Mint as compared to Debian, RHEL or SLES, you should be fired from your job anyway!

What if the boss won't pay for support? What if it's not your decision? Unfortunately, the real world isn't as nice and clean cut as you'd like.

And note, I didn't say I thought deferring security updates was a good idea. But I certainly don't think *forcing* security updates is a good idea. I was just making the pragmatic observation that updates break systems. And if a security update breaks a critical application - where you cannot fix the app - then that security update MUST be ignored.

Oh - and who said I was actually running that app on Mint? There are an awful lot of - critical - apps that run on RHEL or SLES but are not supported by Red Hat or Novell. So what do I do if an RHEL update is forced on me that breaks my critical app - for which the *boss* won't pay support? And I've been there - it is a COMMON real-world scenario :-( (Bosses not paying support, that is, not updates breaking systems, fortunately.)

Cheers,
Wolo

Linux Mint downloads (briefly) compromised

Posted Feb 24, 2016 8:45 UTC (Wed) by Felix (subscriber, #36445) [Link]

> You're assuming that updates are *optional* - that, as sysadmin, I can block them til *I'm* ready, which may be never. Yet a post ago you were saying that they should NOT be optional, that they get force installed. Either you're happy with the sysadmin delaying them (ie they're optional), or they get force-installed and who cares if it crashes a critical system.

I think you're conflating separate issues in your argument. First of all I guess everyone agrees that a sysadmin must be able to choose the best time to install updates (including security fixes) if he should be in control of the system.

However there is a separate issue of default settings especially when these defaults are unlikely to be changed by users. I think it is dangerous of omitting security updates by default. Of course (and that can be done in any Linux distro I know) users/admins can disable updates themselves but at least you can hope they know what they are doing.

And the "update breaks business critical application" argument is a strawman for sure. If you have such an important software you must be able to deal with updates one way or another. Either you can rollback quickly or you test beforehand. Your boss might not give you the resources necessary to do that but some businesses don't do backups either. Still this isn't an argument to suppress security updates by default.

Linux Mint downloads (briefly) compromised

Posted Feb 23, 2016 12:18 UTC (Tue) by tao (subscriber, #17563) [Link] (2 responses)

If your heartrate monitor is connected to the Internet allowing it to download security updates, please let me know what brand it is so I can make sure that any hospital I might end up in uses another.

Linux Mint downloads (briefly) compromised

Posted Feb 23, 2016 19:36 UTC (Tue) by hitmark (guest, #34609) [Link]

Likely by that time you are so out of it from pain or similar that you can't really make a reasoned decision anyways...

Linux Mint downloads (briefly) compromised

Posted Feb 23, 2016 21:47 UTC (Tue) by Wol (subscriber, #4433) [Link]

Problem is, if you look at places like comp.risks, it seems most of this stuff IS ALREADY connected to the internet :-(

And yes, hospitals have had nasty shocks when their equipment (running, eg, XP) has rebooted unexpectedly thanks to an internet fix. I suspect the reason we don't hear much about it is a combination of "well, what do you expect, it's a computer", and the usual health service cover-ups of any problems. Plus, I'm not aware of any serious problems - yet!

Cheers,
Wol


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds