• Maestro@fedia.io
    link
    fedilink
    arrow-up
    75
    ·
    2 days ago

    Remember: update early, update often - no matter how painful that sounds.

    Not anymore! Supply chain attacks have become so common that it’s prudent to wait at least 7 days before updating to prevent installing malware from compromised update infrastructure.

      • dgdft@lemmy.world
        link
        fedilink
        English
        arrow-up
        16
        ·
        2 days ago

        Debian + unattended upgrades + modern package managers for non-system-installed software covers your bases very well.

        Debian packages are downstream enough from their sources that the packaging delay keeps you safe (and means the updates have had human eyes on them before they hit you). Unattended upgrades means you don’t have to worry about running the upgrades yourself.

        Pip, npm, and the other big package managers now also support dependency cooldowns on their recent releases, but uv and pnpm pioneered that and cover you for older release environments.

        • XiJinpingStanAccount@lemmy.ml
          link
          fedilink
          arrow-up
          8
          ·
          2 days ago

          Also I would heavily advocate for Debian Testing if you need a rolling release distro. It is less vetted than stable but is still more vetted than many other rolling release options and you can just stay on testing as versions change while getting features pretty fast compared to stable.

    • nroth@lemmy.world
      link
      fedilink
      arrow-up
      8
      ·
      2 days ago

      I really like Arch because I have a very custom setup and like to try the newest things, but this really worries me as Arch-based user-friendly distros that use the same packages make the repos a bigger target.

      • DevDave@piefed.social
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 days ago

        I switched from Debian to an arch based distro. holy shit is it weird reading about some new things latest release only to have it pushed to the repo the same month or even the same day! I use btrfs so when things break its a 5 minute rollback and reboot.

      • dgdft@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        2 days ago

        You’d still be fine if you’re not exposing public services or visiting actively-malicious websites.

        • Speiser0@feddit.org
          link
          fedilink
          arrow-up
          1
          ·
          2 days ago

          You are underestimating things. Unmalicious websites can still host malicious content by users, for example.

          • dgdft@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            2 days ago

            Okay, wanna give me a link to a PoC example you set up?

            I’ll reimage my laptop to an old Ubuntu ISO of your choice, and visit your link. Happy to be proven wrong.

              • dgdft@lemmy.world
                link
                fedilink
                English
                arrow-up
                3
                ·
                2 days ago

                Fair enough!

                But I can tell you as a cybersecurity expert that you’d have a hard time finding a way to get any sort of remote execution from user-generated content on any major site, much less an exploitable browser sandbox escape.

                • Speiser0@feddit.org
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  17 hours ago

                  I think web browser exploits wouldn’t be an issue on ubuntu anyways, as major web browsers do get regular upgrades there (or are not even installed via apt but snap nowadays). Also web browsers use sandboxes. I’m more worried about users downloading any kind of content and interacting with it via more niche software, like image viewers (though with glycin they nowadays also do sandboxing).