this post was submitted on 09 Oct 2026
612 points (98.7% liked)
linuxmemes
33033 readers
917 users here now
Hint: :q!
Sister communities:
Community rules (click to expand)
1. Follow the site-wide rules
- Instance-wide TOS: https://legal.lemmy.world/tos/
- Lemmy code of conduct: https://join-lemmy.org/docs/code_of_conduct.html
2. Be civil
- Understand the difference between a joke and an insult.
- Do not harrass or attack users for any reason. This includes using blanket terms, like "every user of thing".
- Don't get baited into back-and-forth insults. We are not animals.
- Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
- Bigotry of any kind will not be tolerated. This is an LGBTQ+-friendly community -- if that is a problem for you, you should leave.
3. Post Linux-related content
- Including Unix and BSD.
- Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of
sudoin Windows. - No porn, no politics, no trolling or ragebaiting.
- Don't come looking for advice, this is not the right community.
4. No recent reposts
- Everybody uses Arch btw, can't quit Vim, <loves / tolerates / hates> systemd, and wants to interject for a moment. You can stop now.
5. π¬π§ Language/ΡΠ·ΡΠΊ/Sprache
- This is primarily an English-speaking community. π¬π§π¦πΊπΊπΈ
- Comments written in other languages are allowed.
- The substance of a post should be comprehensible for people who only speak English.
- Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
6. (NEW!) Regarding public figures
We all have our opinions, and certain public figures can be divisive. Keep in mind that this is a community for memes and light-hearted fun, not for airing grievances or leveling accusations. - Keep discussions polite and free of disparagement.
- We are never in possession of all of the facts. Defamatory comments will not be tolerated.
- Discussions that get too heated will be locked and offending comments removed. Β
Please report posts and comments that break these rules!
Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't remove France.
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Not anymore! Supply chain attacks have become so common that it's prudent to wait at least 7 days before updating to prevent installing malware from compromised update infrastructure.
So, what's the solution? Debian Stable?
Debian + unattended upgrades + modern package managers for non-system-installed software covers your bases very well.
Debian packages are downstream enough from their sources that the packaging delay keeps you safe (and means the updates have had human eyes on them before they hit you). Unattended upgrades means you donβt have to worry about running the upgrades yourself.
Pip, npm, and the other big package managers now also support dependency cooldowns on their recent releases, but uv and pnpm pioneered that and cover you for older release environments.
uv is owned by openai fun fact
Also I would heavily advocate for Debian Testing if you need a rolling release distro. It is less vetted than stable but is still more vetted than many other rolling release options and you can just stay on testing as versions change while getting features pretty fast compared to stable.
N-1
I really like Arch because I have a very custom setup and like to try the newest things, but this really worries me as Arch-based user-friendly distros that use the same packages make the repos a bigger target.
On the other hand, AI has made the patch to exploit code as short as 45 minutes.
What if you use for example ubuntu and wait 3 years?
I switched from Debian to an arch based distro. holy shit is it weird reading about some new things latest release only to have it pushed to the repo the same month or even the same day! I use btrfs so when things break its a 5 minute rollback and reboot.
Youβd still be fine if youβre not exposing public services or visiting actively-malicious websites.
You are underestimating things. Unmalicious websites can still host malicious content by users, for example.
Okay, wanna give me a link to a PoC example you set up?
Iβll reimage my laptop to an old Ubuntu ISO of your choice, and visit your link. Happy to be proven wrong.
No, I will not spend hours of my time to win an irrelevant internet argument. :P
Fair enough!
But I can tell you as a cybersecurity expert that youβd have a hard time finding a way to get any sort of remote execution from user-generated content on any major site, much less an exploitable browser sandbox escape.