|
|
Log in / Subscribe / Register

Linux Mint downloads (briefly) compromised

Linux Mint downloads (briefly) compromised

Posted Feb 23, 2016 12:10 UTC (Tue) by glaubitz (subscriber, #96452)
In reply to: Linux Mint downloads (briefly) compromised by Wol
Parent article: Linux Mint downloads (briefly) compromised

> So you'd be quite happy to see your *business* *critical* *application* taken down by an unrelated security update?

If you're having *business* *critical* *applications*, you run your **OWN** test upgrades on a **TEST SYSTEM** anyway **prior rollout**, to make sure nothing breaks.

What a stupid strawman argument is that?

And if you're running a *business* *critical* *applications* on something as unsupported as Linux Mint as compared to Debian, RHEL or SLES, you should be fired from your job anyway!

> There are reasons why sysadmins blacklist ALL updates, *including* security ones. I'm not saying that's a good attitude. I'm not saying it's a wise attitude. I'm saying sometimes it's an extremely pragmatic one - after all, you wouldn't want your heart monitor in the ICU taken out by a security update, would you?

Again, if your heart rate monitor in the ICU runs Linux Mint, you would be fired immediately. Particularly medical environments require **CERTIFIED** hard- and software and I can **guarantee** that you would never get **ANY** certification for a hobbyist Linux distribution.

> (And yes, I've had packages unexpectedly taken out by updates. Fortunately I don't have anything critical.)

Then you were not doing your job properly and testing the updates in a testing environment prior rollout which is what **every responsible system administrator** will do.

Can we please stop with these idiotic strawman arguments? Seriously!


to post comments

Linux Mint downloads (briefly) compromised

Posted Feb 23, 2016 21:58 UTC (Tue) by Wol (subscriber, #4433) [Link] (1 responses)

> > So you'd be quite happy to see your *business* *critical* *application* taken down by an unrelated security update?

> If you're having *business* *critical* *applications*, you run your **OWN** test upgrades on a **TEST SYSTEM** anyway **prior rollout**, to make sure nothing breaks.

> What a stupid strawman argument is that?

You're assuming that updates are *optional* - that, as sysadmin, I can block them til *I'm* ready, which may be never. Yet a post ago you were saying that they should NOT be optional, that they get force installed. Either you're happy with the sysadmin delaying them (ie they're optional), or they get force-installed and who cares if it crashes a critical system.

> And if you're running a *business* *critical* *applications* on something as unsupported as Linux Mint as compared to Debian, RHEL or SLES, you should be fired from your job anyway!

What if the boss won't pay for support? What if it's not your decision? Unfortunately, the real world isn't as nice and clean cut as you'd like.

And note, I didn't say I thought deferring security updates was a good idea. But I certainly don't think *forcing* security updates is a good idea. I was just making the pragmatic observation that updates break systems. And if a security update breaks a critical application - where you cannot fix the app - then that security update MUST be ignored.

Oh - and who said I was actually running that app on Mint? There are an awful lot of - critical - apps that run on RHEL or SLES but are not supported by Red Hat or Novell. So what do I do if an RHEL update is forced on me that breaks my critical app - for which the *boss* won't pay support? And I've been there - it is a COMMON real-world scenario :-( (Bosses not paying support, that is, not updates breaking systems, fortunately.)

Cheers,
Wolo

Linux Mint downloads (briefly) compromised

Posted Feb 24, 2016 8:45 UTC (Wed) by Felix (subscriber, #36445) [Link]

> You're assuming that updates are *optional* - that, as sysadmin, I can block them til *I'm* ready, which may be never. Yet a post ago you were saying that they should NOT be optional, that they get force installed. Either you're happy with the sysadmin delaying them (ie they're optional), or they get force-installed and who cares if it crashes a critical system.

I think you're conflating separate issues in your argument. First of all I guess everyone agrees that a sysadmin must be able to choose the best time to install updates (including security fixes) if he should be in control of the system.

However there is a separate issue of default settings especially when these defaults are unlikely to be changed by users. I think it is dangerous of omitting security updates by default. Of course (and that can be done in any Linux distro I know) users/admins can disable updates themselves but at least you can hope they know what they are doing.

And the "update breaks business critical application" argument is a strawman for sure. If you have such an important software you must be able to deal with updates one way or another. Either you can rollback quickly or you test beforehand. Your boss might not give you the resources necessary to do that but some businesses don't do backups either. Still this isn't an argument to suppress security updates by default.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds