- cross-posted to:
- programmer_humor@programming.dev
- cross-posted to:
- programmer_humor@programming.dev
no real-world use found for staying more than one version behind
The ssh vulnerability didn’t affect Debian because the packages were too many versions behind
AFAIK, the xz vulnerability was designed for Debian based on its workaround fixing systemd service status detection. Even if it shipped to something like Arch, the malicious code wouldn’t load.
Security through Geriatricity
Except this isn’t true at all.
https://security-tracker.debian.org/tracker/CVE-2024-6387
Regresshion impacted bookworm and trixie both. Buster was too old.
With the downside of me doing an apt update and seeing that openssh-server was on
1:9.2p1-2+deb12u3
and I had no idea at a glance if this included the fix or not (qualys’s page states version 8.5p1-9.8p1 were vulnerable).If you are running debian bookworm or trixie, you absolutely should update your openssh-server package.
Isn’t this meme format completely written in sarcasm?
Don’t
Erupt
Before
I
Am
Nevada
The “install lib-blah-blah-blah” bit doesn’t bother me 'cause whenever I need to make something work, I just copy and paste the “sudo apt install …” commands straight from the internet :)
I also never used version pinning in debian
This is great! No better way to demonstrate how perfect Debian is! Debian for the win!
Truly the dumbest meme template of the year.
I like it
I don’t. So… uhm… you’re wrong I guess.
This is a pretty old template iirc
I know this is just a meme, but the “Stop using xxx!” posts are really annoying.
Whaaat, i love them. They are so unpredictable. Sometimes they are fully serious opinions, sometimes only half serious and sometimes just fully ironic shitposts.
I think the comments calling them annoying are more annoying
I think it is a funny format
.
’
™
Goodbye
I would uninstall the screensaver so fast if I saw a nag screen. Wtf it’s a screensaver, what does it matter? I’ll use a version that’s 50 years old if I want to.
Because the dev gets a huge number of bug reports for bugs that were resolved 5 versions ago.
They actually asked debian to stop shipping the screensaver, because they were getting tired of saying “this is already fixed, debian is just not going to ship the fix for another year”. Debian didn’t want to stop, so the dev added the nag screen, because it was the only way to stop the flood of bug reports for things that were already fixed.
Do people not check what version of software they have and what’s newest (and if the issue exists is a good idea too) before reporting a bug?
Should they? Yes. They should also be searching for previous bug reports. I’m sure a lot of people do. But if you have enough users, even if 1% of people don’t use good reporting behaviors, you wind up with a lot of duplicate or bad reports.
There are plenty of blog posts out there that basically can be summarized as talking about how grueling open source work can be because users are often aggressive in their demands.
But this is a prime example of debian “stable” doesn’t mean “no crashes” but instead it means “unchanging, which means any bugs and crashes will remain for the whole release”
3debian5me
Okay… No.
Oh, Debian!
Debian was the first distro I tried when switching to Linux. Didn’t ever make it through the install process…
History will not remember Debian users well