TranslateProject/sources/Canonical Dev Calls Linux Mint ‘Vulnerable’, Wouldn’t Use it For Online Banking.md

3.5 KiB
Raw Blame History

Canonical Dev Calls Linux Mint Vulnerable, Wouldnt Use it For Online Banking

Linux Mint has since responded to the comments by Oliver Grawert. [You can read them here][1].

Users of the popular Ubuntu-based operating system Linux Mint should not use it for online banking, a Canonical [engineer has advised][2].

Mints decision to prevent packages with known security issues from updating from the kernel and browser to the boot-loader and Xorg display server leaves its users with a “vulnerable system”, says Oliver Grawert.

“Instead of just integrating changes properly with the packages in the ubuntu archive they instead suppress doing (security) updates at all for them. i would say forcefully keeping a vulnerable kernel browser or xorg in place instead of allowing the provided security updates to be installer makes it a vulnerable system, (sic)”.

“I personally wouldnt do online banking with it.”

Grawert certainly isnt alone in considering Mint a sub-par choice for the security conscious. Mozilla contributor and former Ubuntu member Benjamin Kerensa feels the same:*

“It is unclear why Linux Mint disables all of their security updates. I can say that it took them many months to get a fixed version of Firefox packaged while Ubuntu and Debian had already had security fixes in their package.

This puts Linux Mint users at risk and is one of the key reasons I never suggest Linux Mint to anyone as an alternative to Ubuntu.”

Oliver Grawert is no fly-by-night contributor. As one of Canonicals Ubuntu Engineering bods hes better placed than most to know what hes talking about.

But are Mint users in actual risk? Yes and no…

But are Mint users in actual risk?

Yes and no. The majority of security “holes” (for want of a better word) of the kind present in the packages that Mints developers steadfastly refuse to update are both documented and known, but rarely exploited by those of a nefarious breed. As such the “actual threat” posed to users remains, at least for now, largely a theoretical one.

Thats to say that there are no known incidents of identify theft or worse resulting from use of Mint (or any other Ubuntu-based distribution with unpatched packages) through any of the exploits referenced by Grawert on the Ubuntu Dev Mailing List.

But just because no-one has entered through the window left ajar thus far, isnt to say someone wont ever do it.

**After seeing Ubuntu given a long and sustained kicking about its own (largely theoretical) privacy issues, it will be interesting to see if, now the boot is placed firmly on the other foot, the vehement concern for users wellbeing will extend to other distributions. **

Notice: We reached out to Linux Mint for comment & clarification but received no reply.


via: http://www.omgubuntu.co.uk/2013/11/canonical-dev-dont-use-linux-mint-online-banking-unsecure

译者:译者ID 校对:校对者ID

本文由 LCTT 原创翻译,Linux中国 荣誉推出

[1]:这个地址在发布的时候填写成“Linux Mint Respond to Ubuntu Developers Vulnerable Claim”这篇文章的发布的地址 [2]:https://lists.ubuntu.com/archives/ubuntu-devel-discuss/2013-November/014770.html