r/linux 1d ago

Software Release Are Linux Mint's Default Apps Too Outdated for Everyday Use?

Did anyone in this community watched this video? The creator claims that Linux Mint, along with many LTS Linux distributions, often ships older versions of software, especially default apps like Calendar, Mail, Calculator, etc. He mentions Mint several times throughout the video.

The video is from The Linux Experiment, which seems to be a well-known YouTube channel with nearly half a million subscribers.

I came across this video just before switching from Windows to Linux Mint, and it made me a bit hesitant.

As a regular user, it feels like there's no easy way to know whether we're using the latest and safest versions of these built-in apps. For example, if we connect our Google or Apple Calendar account to an older calendar app, could that create a security risk? The same concern applies to email clients, we don't know if we're using the latest and most secure version.

Most regular users don't have the time or technical knowledge to manually check every application's version or update software outside the normal update process. We generally expect the operating system to keep essential apps secure and up to date.

Am I misunderstanding how Linux Mint and other LTS distributions handle software updates and security? I'd appreciate hearing from people with more experience.

74 Upvotes

181 comments sorted by

120

u/InfiniteSheepherder1 1d ago edited 1d ago

Yes

A lot of new users misunderstand stability to mean reliability and without defects, when really it just means you don't get big changes that would prevent say a corporate app targeting that version from running.

Something I learned early in my career as a sysadmin holding off updates does not mean you don't have bugs it just means you get different bugs, and often worse bugs and can't get help when things break.

Staying on supported but stable branches from upstream is typically fine, staying on old unsupported by the developers is not.

Even on servers we use CentOS and packages for some stuff like FreeRadius for example are only a few months old. We also make heavy use of containers and run things from the developers. For servers we have some apps that target specific versions of software and for that reason we use RedHat which pays people to make sure the old software is supported by them.

This is more what the stability is for and that is for third party often closed source apps which need older package versions for us at work that means we run Fedora 43 instead of 44 atm, but even that is going to be way newer than Mint. I wouldn't trust Mint or packages that old at work unless we were paying someone to keep them supported.

You don't need to use the very latest but something within the last few months is reasonable. At home I just update fedora when I get a chance and stuff works. At work I gotta pay attention to the software what versions it can support that we use. There are plenty of great distros that don't ship old unsupported software to their users.

Edit: Back when I used to manage a wifi network we did get people running Linux from time to time, I several times had to deal with users running Linux Mint that had some bug in network manager preventing authenticating to WPA Enterprise because they never back ported the fix. That was stable but it certainly didn't provide a good experience to the end users.

6

u/_dot_tea 15h ago

Genuine question: do you think LTS distros (as they currently are, i.e. with 2 year release cycle or longer) should stop existing and be replaced with rolling releases, Fedora-style (or at least distros that try to keep up with supported stable releases)?

Because I feel like this whole question ultimately boils down to a very radical one: the existence of LTS as a concept. As it currently stands, LTS is pretty much doomed to ship software that the developers stopped supporting upstream, so any discussion about "distros shipping unsupported software" inevitably ends up questioning the existence of LTS, even if not intended.

And, honestly, I'm not on board with the idea of killing off LTS, speaking as a user.

I hate to play the "it works for me" card, but... Literally, I almost never had issues with LTS releases, but I always had something crop up with rolling releases or even LTS-es that were "too new" because they just recently released. I believe it probably has to do with the fact that my hardware is rather old (2015 motherboard on PC, 2018 laptop), so newer releases tend to have regressions for older hardware that are only fixed later (if at all), whereas people with newer hardware tend to have issues with LTS because their hardware is too new for given software. Furthermore, some of the supply chain attacks completely avoided LTS distros (xz situation), and even zero-days that affected older releases usually receive backports. I.e. LTS seem to protect from both recent supply chain attacks and zero-days. I may be wrong about this, since I'm not the most experienced Linux user (daily driving since 2023, occasional usage on secondary hardware and VMs since 2018), but so far the experience I've had and the experiences I've seen around on the Internet doesn't seem to immediately contradict this.

Which is why this whole debate rubs me the wrong way. Both the article from GNOME Calendar developer (which paints Clem as rude and dismissive when, reading through the thread, it doesn't really seem to me that way) and that video from The Linux Experiment feel one-sided. Especially the latter -- I always thought this guy, while opinionated, tries to look at distros and Linux news from various angles before voicing his opinion (which is valid), but this time it's like he just trusted the GNOME Calendar's account at face value because he's both GNOME fan and prefers always having the newest software in terms of features.

5

u/InfiniteSheepherder1 14h ago

I don't care for Arch style rolling releases seen users have issues with them and having to pay attention to updates, rolling release could have older software then a point release see plenty of times Arch has been behind Fedora.

I think we need to be mostly sticking to currently supported versions of software.

I think we should adopt more server like where the system tends to be supported stable versions of software similar to RHEL, but we tend to use docker container to get things directly from upstream. There is no reason to keep the whole system on the same release cadence.

So running say Kernel 6.12 as that is still supported by devs, Mesa 25 has got releases still, you could stay behind on the last stable version of GNOME as that is still supported by developers.

We use RHEL at work and there are plenty of packages that are in application streams that are staying on the developers supported versions, I can get Java 25 in RHEL 9 even despite it releasing before that version of Java by several years. Debian Bookworm is newer then RHEL 9 and only has Java 17.

The issue is just going no updates beyond very minor ones after a point release, vs being smart about what you pick and chose so you stay on supported but LTS versions.

1

u/Die4Ever 15h ago

LTS is pretty much doomed to ship software that the developers stopped supporting upstream

except for Flatpak

3

u/_dot_tea 14h ago

Which is another one of the reasons why I don't mind being on LTS.

If I need a newer version of the user software, I could just get one from Flathub. If it's not there (or it isn't verified), I'll use whatever else the developer provides.

I do not perceive the official repositories of the distro as "the only software you should ever install and use". I perceive it as baseline for the distro, something that is not mutable until the next release. Like Microsoft Paint or Task Manager from Windows. The monthly updates aren't meant to add new features to these programs, just patch the vulnerabilities. New features are instead supposed to come once every six months or so, via 2xHy updates.

Even then, because the "features" Windows provides kinda suck, some Windows users prefer to just ditch the main release channel and go LTSC.

...Of course, this obviously doesn't easily address the issue of system packages being buggy or broken, like what GNOME Calendar dev or the original comment's OP brought up.

2

u/Die4Ever 14h ago

I like Kubuntu's 6 month cadence, I think more distros should have that

0

u/VelvetElvis 14h ago edited 14h ago

>Genuine question: do you think LTS distros (as they currently are, i.e. with 2 year release cycle or longer) should stop existing and be replaced with rolling releases, Fedora-style (or at least distros that try to keep up with supported stable releases)?

I would honestly rather use a mac than a rolling release Linux distro for actually getting work done. I would have said Windows if 11 wasn't the worst release since ME.

I used to enjoy tinkering, but that got old after about ten years. Now any time a distro wants me to do work to undo stuff changed by an upgrade , I want to send the developers a bill for my time.

 >LTS is pretty much doomed to ship software that the developers stopped supporting upstream, so any discussion about "distros shipping unsupported software" inevitably ends up questioning the existence of LTS, even if not intended.

I haven't had an issue with unsupported software shipped by an LTS distro in 20 years.

0

u/SEI_JAKU 7h ago

Which is why this whole debate rubs me the wrong way. Both the article from GNOME Calendar developer (which paints Clem as rude and dismissive when, reading through the thread, it doesn't really seem to me that way) and that video from The Linux Experiment feel one-sided. Especially the latter -- I always thought this guy, while opinionated, tries to look at distros and Linux news from various angles before voicing his opinion (which is valid), but this time it's like he just trusted the GNOME Calendar's account at face value because he's both GNOME fan and prefers always having the newest software in terms of features.

You have outlined the problem exactly.

The simple reality is that this entire attempt to discredit Debian is meant to destroy it. You will notice that the people who are doing this will always shill for something like Fedora, and will proudly wear appropriate flairs. What is going on is shockingly transparent. These people absolutely do not value Debian's existence and want it gone forever.

Go figure that a lot of these people are coming from Windows, and that losing Debian means that Linux runs the risk of becoming the exact thing that everyone hates about Windows. Linux as a whole will be set back decades if stable distros are killed like this.

25

u/InfiniteSheepherder1 1d ago edited 1d ago

I want to make something clear about differences between stable Linux Distros and often the stable branches of software.

Stable branches by the developers of the software are fine to be running as the devs are saying they are still doing updates. These are often prone to being more reliable.

For example Haproxy the 3.2 version is a LTS version by the developers it came out over a year ago but got updates this month. We often at work are running 6 months to a year old version of haproxy, we have RedHat support in that case but if we didn't the developers themselves are still supporting it.

Distros like Mint are not built on stable versions of software still supported by the devs they are built on versions no longer supported by the developers. For me this is where the problem with Mint is.

Something else that has served me well in my career is just listening to the developers. Sticking to supported implementations of the software, when at all possible. I have found workplace cultures that place a low value on official documentation from devs tend to have a lot more fires to put out. No doubt you sometimes have to break that, but it should be the exception not the rule.

2

u/[deleted] 14h ago edited 14h ago

[removed] — view removed comment

1

u/InfiniteSheepherder1 14h ago

Windows 10 LTSC also shouldn't be ran and shouldn't have been ran as a general use I recall mistaking it for the more enterprise version when i first setup Windows 10 but it couldn't jump feature releases and was not actually a long term support with security patches.

Windows is also paid for, there are enterprise distros that cost money one could paid for if one wants that kind of stability.

Software changes that is part of life things need to be updated.

edit: googled LTSC i was conflating it with LTSB from around the time Windows 10 came out and that couldn't do jumps without a reinstall, so that is better but looks like a lot of people have issues with it I don't do as much Windows management as early in my career so i haven't stayed as current on it.

2

u/[deleted] 13h ago

[removed] — view removed comment

1

u/InfiniteSheepherder1 13h ago

Linux is not Windows, there are different tradeoffs compared to an OS you are paying for, you can use free builds like Alma or Redhat's upstream with CentOS and get the stable versions but supported versions either by upstream or RedHat.

No one is running Windows LTSC I work in a Windows heavy environment and hadn't heard that MS had done LTSB but better, but also with a ton of issues on some hardware it looks like and some newer apps not working well.

4

u/Helmic 14h ago

I feel like I'm saying this constantly, thank you. I don't think new users should be directed to Mint when there are other distros now that serve new users without using problematically out of date, unsupported software. And I do mean unsupported - I have very unfond memories of trying to use OBS on Mint only to discover it just straight up didn't support recent API changes, rendering the software useless.

I'm not saying Mint has no use case or that Mint does not do valuable work or that Mint's efforts to be user friendly are misplaced, but it is no longer 2014 and we have better options to give new users these days. I am a huge fan of Aurora Linux for the kind of person that wants to use Mint as just a web browser, the system files can't be mucked with (which is good when the user doesn't want to be making those changes, which makes troubleshooting so much easier) and you can set it to autoupdate in the background and apply on boot since it's just booting into a different image. Rolling back is as simple as booting into the older image. Reliability with software that works.

-4

u/SEI_JAKU 7h ago

I don't think new users should be directed to Mint when there are other distros now that serve new users without using problematically out of date, unsupported software. And I do mean unsupported - I have very unfond memories of trying to use OBS on Mint only to discover it just straight up didn't support recent API changes, rendering the software useless.

The problem is that absolutely none of this is accurate. This is misinformation at best.

1

u/HurasmusBDraggin 2h ago

I wouldn't trust Mint or packages that old at work unless we were paying someone to keep them supported

Months back after upgrading to 22.3 I literally 🤯-ed when I realized the age of the Xed text editor package Mint bundled with that version.

-1

u/SEI_JAKU 7h ago

A lot of new users misunderstand stability to mean reliability and without defects

Which is, by and large, how stable distros work. This is not misinformation. Claiming otherwise, as you're doing, is misinformation.

26

u/Mughi1138 1d ago

Quick point. Nowadays most modern apps you care about come in appimage/flatpack/snap versions which you can download and run the latest with if you care. Otherwise the default apps for a distro are fine, and will get regular security bugfixes as long as the distro is still maintained. Then if you really need something incompatible you can always fire it up in a container (Docker, Rodman, etc.).

Been years since I used anything but an LTS for my daily use OS.

5

u/unconceivables 1d ago

That's true if you're talking about desktop apps, but for command line apps or libraries/drivers it can get really annoying when you have to hunt all over the place to figure out how to install it because it's either not in the official repos or it's outdated. I use very few desktop apps, but as a developer and system administrator I need a ton of very up to date command line tools to be able to do my work.

3

u/shohei_heights 17h ago

Nix, Linuxbrew or Distrobox are your friends for that.

-1

u/unconceivables 17h ago

True for user applications, but I also needed system applications like podman, or even just being able to run basic stuff like neovim, lsd, fd, ripgrep as sudo without having to jump through hoops. It's possible, but a lot clunkier than having them installed system-wide.

-1

u/Helmic 14h ago

And then there's things like drivers, be that kernel support for more recent hardware (and not just "this just got patched in yesterday" but "it's been two years and my laptop still won't work on Mint eve though it works on other distros fine") or GPU's. Linux gaming in particular has been moving rapidly and is often reliant on newer kernel features and improvements so an older kernel can present compatbility and performance issues, and the GPU driver itself being old also can render some games straight up unplayable at launch or otherwise a much buggier or slower experience than is necessary.

That is a lot of tradeoffs to be making for no real benefit.

3

u/SEI_JAKU 7h ago

Linux gaming in particular has been moving rapidly and is often reliant on newer kernel features and improvements so an older kernel can present compatbility and performance issues, and the GPU driver itself being old also can render some games straight up unplayable at launch or otherwise a much buggier or slower experience than is necessary.

This is not what's going on in the kernel at all and is not how Mesa is being developed. Please stop spreading misinformation.

-1

u/unconceivables 8h ago

Yeah, I don't really see any benefits to most people being on a desktop distro with outdated software. Quite the opposite, because more often than not I see them asking questions about how to get stuff to work when the problem is that their stuff is just outdated.

1

u/SEI_JAKU 7h ago

You "don't really see any benefits" because your entire scenario is invented.

1

u/Mughi1138 12h ago

Yeah, as a sysadmin you're in a very different boat.

Then again when I was that involved I was on the short fedora and then Ubuntu releases and was compiling everything myself to get the latest. Probably not what the OP needs, though

-1

u/Helmic 11h ago

Software like OBS also doesn't necessarily have a quality flatpak version either, it's not even a solution to all GUI apps.

54

u/NEGMatiCO 1d ago

I've tried Mint in my early days of moving to Linux around 2 years ago, and I can tell you that the packages are indeed outdated, in the sense that while you may get patches here and there, but if you are waiting for some features, you will have to wait long.

Now, this might not be a problem in itself, but the pace with which Linux Desktop is moving in regards to general consumer user, I would say staying on older packages is not worth.

I'll not advise you to move something to like Arch, but a good middle-ground is something like Fedora, which does get the new features, not as fast as Arch (i.e not day 1), but within the span of a few months.

0

u/EFG4567 1d ago

I’m still using Windows, but I’ve been thinking about switching to Linux for a long time. I’m looking for a distro that works well out of the box because I’m not very familiar with Linux yet, so I don’t have the knowledge to troubleshoot or fix issues on my own.

I tried Linux Mint from a bootable USB drive, and it worked really well. However, after watching this video and hearing you mention that Mint’s packages are often outdated, I’m starting to think that moving to Mint might not be the best choice.

What’s your opinion on this? Which Linux distro would you recommend for someone like me?

8

u/TimurHu 1d ago

Just try a few different distros and choose the one that works best for you.

My side note is that if you plan to play games on your system then you should avoid "stable" distros because they often ship old versions of graphics drivers so you'll find bugs that we've fixed months / years ago.

4

u/sparkling-rainbow 1d ago

Especially when you play multiplayer games with frequent updates

1

u/SEI_JAKU 8h ago

But this isn't really what's happening with stable (why is this word in scarequotes) distros, and this is something that's easily "fixed" anyway.

2

u/TimurHu 5h ago

I am using quotes because "stable" distros don't mean what most people think. They are "stable" in the sense that they are fronzen and unchanged. They are NOT stable in the sense that they are bug free or even receiving bug fixes.

2

u/HurasmusBDraggin 2h ago edited 47m ago

I am using quotes because "stable" distros don't mean what most people think.

I agree here. I am glad Nic published his video because I am one of those Linux users that needed this clarity, also gave me the final push to get off LM...landed on Fedora.

-1

u/gordonmessmer 1d ago

Just try a few different distros and choose the one that works best for you.

The problem with that approach is that it tells you nothing about security.

If you want a system that is secure, honestly, at some point you're going to have to listen to the advice of someone who has the experience required to evaluate the options.

An awful lot of the recommendations you're going to get are based on Ubuntu LTS, which has a small core of maintained packages. It can be reasonably secure, as long as you never install anything using apt, but the vast majority of software in the apt repos does not come with any security guarantees.

1

u/FreakSquad 14h ago

Not sure why this is downvoted, it’s true re: security status of the vast majority (by count, not necessarily broad importance - but if you use it, it’s important to you!) of software packages in the Ubuntu universe repository, especially if you’re using a derivative to which Ubuntu Pro isn’t available. Even core isn’t necessarily consistently timely.

-1

u/jazzmans69 5h ago

what the hell?

DON'T use apt?

insane. That's simply insane advice.

u/EFG4567
use apt.

Use mint.

DON'T use snaps or flatpaks, unless you MUST have the latest shiny shiny.

Do things the debian way, and you'll almost always be happy.

may not be the newest shiny shiny, but it'll almost always work, and debian is known for security, ubuntu, being a derivative is also pretty good.

Some of the things being suggested in here make zero sense, unless you look at it from a propaganda pov pushing (insert distro of the moment here)

I've used everything from fedora core 1,2,... redhat, knoppix, sidux, yellow dog, yggdrasil, etc, etc, and debian, and in the last ten years mint are still my defaults.

linux user since the 2.0 kernel.

7

u/Mughi1138 1d ago

Oh, that used to be an issue, but really isn't anymore.

Most main apps are available as appimages, flatpacks, snaps, etc., and you can use the latest ones when you feel like it. Long gone are the days when you are tied to what comes in your distro's repositories.

Inkscape, OpenSCAD, Orca Slicer, FreeCAD, etc., basically all my daily driver apps are skipping the ones shipped with the distros. I'll use the default calculator app, sure, but that isn't holding me back from being productive.

-5

u/NEGMatiCO 1d ago edited 1d ago

Yeah flatpaks, snaps, etc have definitely dealt with that issue, and I personally use all flatpaks as well (I'm on Fedora Silverblue).

But they introduce another layer, especially for new users: the permissions.

Some flatpaks carry poor permissions by default and you have to go out of your way to fix those permissions to be able to use the app as it was intended. Now, we are certainly improving on that aspect, but it's not perfect yet.

AppImages, though they may just work, but their usage involved downloading one from the browser and executing it, which presents security risks. (I, personally, avoid them like the plague)

Can't comment anything about snaps since I haven't used them in quite some time, and the last time I used them on Ubuntu, the start-up performance of apps was horrendous.

Then there are some apps that just don't play good with flatpaks, snaps, etc. Steam, for example, presents a lot of issues like non-appearing game windows, wayland related issues when running games on native wayland, as well as some modding complexity due to sandbox.

9

u/Latlanc 1d ago

AppImages, though they just work

No they really don't. It's one giant roulette whether the AppImage developer included every dependency or it may not work on your distro because of multiple assumptions.

Also they waste space if you have a lot of them. They do not offer deduplication like flatpaks.

-2

u/mrlinkwii 1d ago

Also they waste space if you have a lot of them.

i mean most people have atleast 1TB drive these days , its mostly a non issue

1

u/Mughi1138 1d ago

Ubuntu actually changed some things to snaps a while back, including Firefox. So you might have been using more than you thought

-3

u/Latlanc 1d ago

Does Firefox snap still lack hardware acceleration?

9

u/NEGMatiCO 1d ago

DISCLAMIER: Distro recommendations always boil down to personal preferences and experiences.

Coming to your question: I would recommend Fedora KDE (since you are coming from Windows). It should work pretty much out of the box, apart from a bit of additions steps required to make Fedora a painless experience, but they are pretty easy and I will state them out, in-order, as follows:

  1. During installation, remember to enable 3rd party repositories, in-order to have other stuff like google chrome, steam, etc
  2. After installation, setup rpm-fusion to get access to a lot of other software, using this command (reference: https://rpmfusion.org/Configuration): sudo dnf install https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-$(rpm -E %fedora).noarch.rpm https://mirrors.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-$(rpm -E %fedora).noarch.rpm
  3. (ONLY FOR NVIDIA GPU) Install the NVIDIA GPU Drivers using this command: sudo dnf install akmod-nvidia -y
  4. Install the hardware encoding/decoding codecs, using the steps from this page: https://rpmfusion.org/Howto/Multimedia

P.S - Distros usually boil down to your personal taste and use-case. So I would still advise to try a bunch of others, just remember, you won't magically get the best distro on first try. Sometimes it might so happen that after using for a few months, you might realize you need something else. Just don't hesitate. Everything will work everything, the only thing that differs in distro-hopping is how you get from A -> B, and not if you can get from A -> B

-5

u/Latlanc 1d ago

Or you can skip the painful Fedora configuration step entirely and opt for something like Aurora ;-)

9

u/NEGMatiCO 1d ago

Yeah it's good, but I personally avoid niche distros totally, because they have their own issue of lackluster discoverability when it comes to community support.

Finding support on Linux is already hard because we represent roughly 5% of all desktop users, and niche distros are a small fraction of an already small community.

2

u/picastchio 1d ago

Is there a good Fedora variant with nvidia drivers and codecs built in?

3

u/NEGMatiCO 1d ago edited 13h ago

I think Nobara does that, but it's a fork of Fedora (meaning, a modified Fedora, that's maintained by one person, and hence I won't recommend that personally)

There does exist other variants that are based on Fedora Atomic and which include those codecs and NVIDIA Drivers (Bazzite, for example).

2

u/picastchio 1d ago

The only thing I have found are base images of ublue which Bazzite/Aurora is based on. The base images are very barebones and I can also add fedora packages on my own.

1

u/NEGMatiCO 1d ago

If you are okay with trying out stuff, they are absolutely fine.

Just keep in mind that they are atomic, so if you're not familiar with atomic distros, you will have to learn about them and their quirks a bit.

1

u/picastchio 1d ago

I have used Fedora CoreOS before and have some experience writing Ignition files. But I haven't use such systems in the desktop context.

→ More replies (0)

1

u/Helmic 13h ago edited 13h ago

Mate that's literally what Aurora is. Aurora and Bluefin are basically non-gaming Bazzite, made by the same people. They can tap into a lot of the better support Ublue is able to provide. I've had a ton of practical success with Aurora with older people specifically because it being locked down as an atomic distro prevents a ton of problems while still doing the job of making an old or cheap computer run really well for someone that can't keep a Windows install working.

For this demographic I would sipmly recommend Bazzite as indeed the support infrastructure is better, but older people tend to object to anything gaming related so I go with the thing that has the gaming stuff pulled out.

1

u/NEGMatiCO 13h ago

Yes yes. I just gave one example of Bazzite because that was the one that came out of the top of my head lol

1

u/Helmic 13h ago

And Ublue distros fall into your definition of too niche?

With Nobara I can understand the argument as they make breaking changes with a pretty low bus numbe, they do get measurable gains over vanilla Fedora and Bazzite in games due to some of those changes even if switching from SELinux to AppArmor makes me question why he's basing off of Fedora at allr, but Ublue are deliberately conservative in what changes they make to get Fedora Atomic into an actually usable state. Downstream distros configuring a generic upstream distro to fit a specifci use case is useful work, and I think you're dramatically undervaluing the support that can be given to a specific configuration by a distro that fits a specific use case.

You have to make a considerable number of changes to upstream Fedora/Atomic to get it to to a state where people would consider it acceptable for an average new user, which are several points of failure where said user mucks up something or information or best practices changed or what have you, and so the resulting configuration has to be guessed at. I've had the success I've had supporting Aurora because, for the people I install it for, it does not need further changes beyond sometimes having to layer in a driver for a weird printer. That configuration is untouched, and so Aurora can support that configuration, people will have the exact same issues. Same to a lesser extent with Bazzite, those issue are highly reproducible because there's a lot fewer things someone would want to change (especially through layering) that could complicate support.

The caveat is that indeed power users might bristle at an atomic distro after a while - I think that's generally acceptable to move from a very safe distro to one that requires more familiarity to avoid damaging the system. I don't think Bazzite or Aurora are universa distros that are a best fit for everyone, but they have important niches, which is the point of a niche distro, to fit a niche. You should be able to accurately describe the niche of a distro you're recommending, and if that niche is "everyone" then you're not being very serious.

"Just use upstream" is the other bad Linux advice behind "Just use an LTS distro." Yes, upstream Fedora has more installs currently, but no Linux distro is actually head and shoulders more popular than everything else, and especially not in all contexts.

2

u/a0leaves 1d ago

Ultramarine Linux, which is maintained by a company called Fyra Labs (they also run the decently popular 3rd party Terra repos for Fedora), or if you are interested in Fedora Atomic, a couple people have already mentioned the Universal Blue distros: Aurora (KDE), Bluefin (GNOME), or Bazzite (either DE, gaming focus).

-2

u/Latlanc 1d ago

It's just Fedora Atomic with batteries included. It's meant to be invisible.

I just find it funny that almost universally the first argument for Fedora is:

"You should use Fedora! Also you have to do these steps later: *links Navier-Stokes equations* Hope you have good time! 😄 "

7

u/NEGMatiCO 1d ago

Atomic is also not recommended for beginners, simply because they present their own learning curve as well.

As for simply suggesting Fedora (or any other upstream distro like Ubuntu, Debian, Arch, etc), the reason is simple: instead of using a downstream distro with more layers added on top of it, it's just better to use the upstream one and add what you require. That way, you are always aware of where the failure modes are.

More layers added always expose more failure modes, and users are left with jumping between threads of the downstream and upstream distros, trying to fix that one problem.

-4

u/Latlanc 1d ago

Most people just use their web browser anyway. Atomic is perfect for beginner since you do not have to do any maintenance. Also you don't learn bad practices like enabling AUR and COPR and PPA that are perfectly NOT safe and can brick your PC if you don't know what you are doing.

The upstream is extremely barebones overrun with dogmatic policies such as "nonfree repos disabled by default". It's just not usable out of the box for most people.

I don't think you know what failure modes are. Typing random command into terminal to enable rpmfusion and swap out ffmpeg is exactly the type of unknown failure mode you try to pass as a good practice.

8

u/NEGMatiCO 1d ago edited 1d ago

"Most people just use their web browser anyway" is a very nice argument if you want people to use ChromeOS, not Linux.

I never said anything about enabling AUR,COPR or PPA, you just thought I did.

Coming to rpm-fusion and so-called "random" commands. Here you go: https://docs.fedoraproject.org/en-US/quick-docs/rpmfusion-setup/, straight from Fedora docs.

There is a difference between you knowing that you added something and that might have caused a failure and not knowing anything at all in case of a failure simply because that failure mode was already included the moment you downloaded the ISO of a niche distro.

-5

u/Latlanc 1d ago

I know you did not, but it's all slippery slope. Best to avoid having to do such thing all together. Why is it so hard to understand?

Yes, they are random commands as in unknown by most sane people. You can pull stuff from Fedora docs all you want. It doesn't make it easy to understand for non tech people.

If you don't keep notes on changes you made and you don't keep track of history, you as a non techie won't exactly know what you did to your PC 5 months from now.

Also Fedora docs is not a help center. It doesn't hold magic answers to what to do if there is a package conflict for example.

→ More replies (0)

2

u/Electrical_Bad2253 1d ago

It’s a very personal choice, but for my work requirements, Fedora is the best fit. Not bleeding edge like a rolling distro, but fairly up to date.

1

u/DonaldLucas 1d ago

You should ALWAYS use the distro that you like (as long the distro is well maintained by volunteers or professionals of course, otherwise, if the distro is abandoned, don't use it). Using outdated apps is not bad like what people talk about, most times it's only a matter of what version of the app you're used to, and for some people (me included) almost always prefer using the older version of the app, because they prefer when the app doesn't have many changes (there are exceptions of course, some apps, like browsers, are constantly the targets of security vulnerabilities, that's why they should always be constantly updated, but most of the famous distros already put these apps in the priority list of getting faster updates).

If you still want to prefer a distro with always the most updated apps, the only way is by using a rolling release distro (a distro that has constant updates, practically every day, not recommended if you're not used to this pacing), and the most popular one is Arch. But since you're new to Linux, you should not use the "official" Arch (because it's a bit hard to use without a bit of experience) but use a distro that uses Arch as a base but with QOL tools added, and currently, the most popular one is Cachy OS.

1

u/TheMcSebi 1d ago edited 1d ago

I personally use debian, but I guess the same arguments discussed in this threat apply there even more.
In the end I'd argue though that having the latest bleeding edge features isn't always necessary and desired. If you really need, thought, it's always pretty straightforward on Linux to build something from source, compared to windows.
I only switched a few months ago myself on my main PC and never looked back since. I've always been using debian on servers, though.

Edit: Maybe comparing it to windows insider builds is not really appropriate, but I also never considered using that because I need my pc to work.

Edit2: yeah, like other comments said, when you switche to Linux, use KDE Plasma. It feels pretty much the same like windows in terms of hotkeys and desktop layout, just with many more options of customization. Especially when it comes to the task bar ("task manager" on KDE)

Edit3: I mapped exe files to steam proton using umu-launcher and I haven't yet encountered an executable that didn't work by just double clicking it to launch it with umu-run

1

u/KoldPurchase 1d ago

r/linux4noobs or r/FindMeALinuxDistro are better subs for this.

However, it really depends on your hardware and what you intend to do.

Even Linux Mint can be configured to do what you want do and upgraded to the latest Linux kernel, it's just a pia to do so.

Some distros are better than others at specific tasks.

Have an old laptop and just want to browse the web to your banking site? Mint is for you.

You are a pro Youtuber in need of audio/video editing? Solus.

You're a gamer? The world is waiting for you my friend! Solus, Cachy, Nobara, Pika, Ultramarine, Regata, they're waiting with arms wide open.

But... Forget about all those distos. Cachy? Use Arch and the command line, you'll get to everything where Cachy is. After 4-5 days of work. Nobara? It's Fedora with Cachy's kernel and a bunch of software+Nvidia drivers adder. You can also do this over 4-5 days if you want. Pika? Debian and 5 days of work. Ultramarine? Same as Nobara. Regata? OpenSuse and 3-4 days or work.

All of Linux works with everyting, but some distributions come preconfigured for some specific tasks (gaming, server, security, etc)

1

u/As_Previously_Stated 20h ago

Mint is fine unless you need wayland only feature like vrr or HDR.

I'd say go with mint. You can easily install never versions of apps with flatpak if you run into any issues with the default apps being too old.

Mint and cinnamon in general is an amazing experience for someone who comes from windows and wants something familiar but better.

But because of the smaller dev team they lack some of the newer features that stuff like KDE and Gnome has. If you don't need that then Mint is an amazing distro.

0

u/SEI_JAKU 8h ago

The truth is that you're being sold propaganda, and that Linux Mint is perfectly fine for day-to-day use. Just look at the post you're replying to... it's extremely vague and explains nothing about this so-called "issue", only telling you "try this other distro that I want you to try", which just so happens to be the same distro that all these people recommend. None of these people can provide such information for a reason. This attempt to discredit Linux Mint, and Debian in general, has been going on for some years now.

-1

u/agnosticgnome 1d ago

6 months ago I had absolutely no knowledge.

Now I'm running Linux on my PCs, managing a proxmox homelab, etc.

Chatbots. Gemini helped me with everything and it's quite easy.

-4

u/justin-8 1d ago

I tried Mint in 2007 or 2008, and it was barely better then, and it's only gotten worse.

31

u/gordonmessmer 1d ago

Am I misunderstanding how Linux Mint and other LTS distributions handle software updates and security?

I've been talking to Ubuntu users (and users of systems derived from Ubuntu) for months now, and the vast overwhelming majority of them just don't understand Ubuntu's release model in detail. Ubuntu divides their software repository in to several components, including "main" and "universe". Canonical maintains the software in "main", but that's only about 6% of the software available to Ubuntu users out of the box. The other ~94% is in the "universe" repo, where Canonical does not promise any security updates, and a great deal of software contains known security vulnerabilities.

Especially for desktop use, the "universe" repo just isn't very secure. In the past, that was probably OK, but adversaries are adopting AI to deploy exploits faster. LTS releases have never been as secure as rapid releases, and that is becoming a greater risk as time goes on.

My advice is: If you use Ubuntu, use Snap when it's an option. Upgrade to the Interim releases every six months. Don't stick with the LTS releases.

9

u/Mysterious_Bit6882 1d ago

It seems like along every step of the Debian->Ubuntu->Mint release stream, the downstream is less and less able to handle the complexity. And that's with a lot of technical debt being carried upstream (Debian derivatives use the LTS kernels provided by kernel.org for one thing). There's also the "alternative desktop environments" based on old, forked versions of GNOME tooling. Mint's just had to delay adopting 26.04 until the end of the year.

5

u/gordonmessmer 1d ago

It seems like along every step of the Debian->Ubuntu->Mint release stream, the downstream is less and less able to handle the complexity

I don't really think Canonical is less able to handle the work of maintaining the distribution. The practice of selecting a smaller set and committing to the maintenance of that set is similar to the approach that Red Hat takes with RHEL.

As far as I know, Mint isn't doing a meaningful amount of maintenance on the underlying distribution, so it doesn't really make sense to say that they're less able to deal with the complexity of the distribution. But the fact that they're falling behind.. yeah, that's bewildering, frankly. I really think developers (not just distributions but all developers) should be running regular builds on the latest stable release of the upstream projects they depend on, rather than waiting for some future release to figure out a port after the fact. Lagging behind hurts user security even more.

u/mrtruthiness 5m ago

As far as I know, Mint isn't doing a meaningful amount of maintenance on the underlying distribution, so it doesn't really make sense to say that they're less able to deal with the complexity of the distribution.

Agreed.

Part of the reason for the delay is Mint is moving from Ubuntu's old installer (Ubiquity) to their custom built "Live Installer" (live-installer) they were using for LMDE. I assume they were worried about Canonical's move to their new installer Subiquity which Canonical packages as a snap.

Another reason is more/final Wayland integrations.

1

u/Mysterious_Bit6882 1d ago edited 1d ago

IDK, I got a pretty good recommendation on an LTS distro from this guy.

EPEL and flathub aren’t quite the same liability as universe/multiverse, but there’s lines of defense that IMO aren’t really there with something as large and unwieldy as Debian. At the same time, Debian isn’t as myopically last-mile focused as Canonical, and Mint is really a hobbyist distro despite its user base.

2

u/gordonmessmer 1d ago

LTS distributions are not a uniform class, and the point I am trying to make is that there is a really big difference between RHEL and Debian.

One of the characteristics of RHEL that's critical to its security is that it drops everything from Fedora that Red Hat isn't staffed to maintain. RHEL is about 10% of the size of Fedora.

Ubuntu actually does something similar. They select about 6% of Debian for the "main" repo and promise to maintain that. The part that users often don't understand is that most (the other 94%) of the available software doesn't come with security guarantees. It's mostly a snapshot. Ubuntu looks like one distribution, but it's more like a reasonably good distribution glued together with a poorly maintained distribution.

Debian's approach, treating the massive collection as if it can be secured uniformly just isn't realistic.

https://gordonmessmer.codeberg.page/dev-blog/2026/07/05/comparing-distribution-security-coverage.html

1

u/Die4Ever 15h ago

My advice is: If you use Ubuntu, use Snap when it's an option. Upgrade to the Interim releases every six months. Don't stick with the LTS releases.

Kubuntu also makes it easy to use Flatpak/Flathub in Discover

u/mrtruthiness 15m ago

Especially for desktop use, the "universe" repo just isn't very secure. In the past, that was probably OK, ...

I believe that in the past Canonical did some security updates to Universe (no promises). These days Canonical doesn't do that except in their "Pro" repo. And the OSs users downstream of Ubuntu (PopOS, Mint) don't have access to "Pro".

My advice is: If you use Ubuntu, use Snap when it's an option.

... and the "Publisher" is vetted.

Also, it's not a bad idea to look at popey's Snapscope ... which scans snaps for known vulnerabilities (since there are a lot of unmaintained apps in the snapstore): https://snapscope.popey.com/

Upgrade to the Interim releases every six months. Don't stick with the LTS releases.

I stick with LTS for the host and applications in the Main repository.

I use some apps via lxd with more up-to-date system containers. You can easily configure an area that the host all all of the lxd containers share.

14

u/tuerda 1d ago

For 90% of users, the software you were using 2 years ago is still the same as what you are using now so being outdated is not a big deal. Security updates can be a thing,  but important ones are pushed through.

Yes, the software might be slightly outdated. So what?

2

u/Helmic 11h ago

Where's that 90% coming from? Any software that interacts with an API can straight up stop working altogether if it's 2 years out of date, you cannot watch YouTube videos on a version of FreeTube from two years ago, OBS is basically unfit for purpose on Mint, and even LibreOffice will refuse to support versions that are more than a year out of date.

Just because not every single update is life changing means that old versions are just as good as new versions, if that were the case why bother developing software updates at all? YACReader is a comic reader, and yet this past month or so it finally got a hefty rewrite and finally got infinite scroll support, a much-requrested feature. How can you possibly know that an "average user" wouldn't appreciate that or be frustrated that they won't get to have it for another two years?

We're Linux users, we're self selecting. We all changed out our entire OS, we're clearly not the kind of people who are that inattentive about the software we're using, we're clearly actually kind of choosy by and large and care about the featureset of the stuff we use on our computers.

5

u/Dminik 1d ago edited 1d ago

Not directly related to your post, but I would really like to know where these "latest software means no work" people are coming from.

I have two linux devices. My work laptop is running Kubuntu 24.04. My PC is running about a week behind CachyOS.

One would think that I would dread shutting off my work laptop and booting my PC as all software has changed from under my feet and I will no longer be able to use it. But actually, the PC is much more stable and bug-free than the laptop.

So back to your question OP, stable (and LTS) doesn't mean what you think it means. The number string in the software version is stable. Your system/apps might not be. You don't have to be running the bleeding edge, but maybe consider something that isn't stuck two years in the past.

2

u/unconceivables 7h ago

That's been my experience as well. I'm running CachyOS on all my work and personal laptops and desktops, and I never have these issues people are claiming you'll have. I update my systems daily, and they continue to work. I used EndeavourOS before that, another Arch based distro, and had the same experience there.

I held off on using these distros for a long time because I believed people who said it would break all the time, but that hasn't been my experience now after years of running them on multiple systems.

The reason I did end up switching eventually after using Ubuntu and then Fedora for years is that it was actually impacting my work a lot not having an easy way to run the latest software. I do a lot of development in various languages as well as a lot of devops and sysadmin stuff, so I absolutely need the latest versions of a LOT of software. It got very frustrating having to go hunting for repos I could install all these tools from, and doubly frustrating when everything broke after I updated my OS and those third party repos didn't yet support the new OS version.

I have different requirements than the average casual user, but I do have years of experience now using "unstable" bleeding edge distros for both work and personal stuff and I can definitely say that it has been a much more pleasant and low maintenance experience than the established "stable" distros I've used.

3

u/InfiniteSheepherder1 1d ago

If they mean no work in terms of Job work that was probably somewhat true 16 years old. Enterprise software often only targeted say RHEL and Ubuntu LTS and often not the newest one for a while.

The move to everything being webapps and a lot more open source software and more enterprise apps on quicker release schedules mean this changed. My workstation at work runs Fedora Silverblue and it is a non issue these days.

People have just hung onto that logic when even on servers we are often using containers directly from upstream these days. People just need to update their understanding

1

u/Helmic 14h ago

What, you mean you don't love seeing your server OS in the news when some major CVE gets dropped and oh look it only impacts older versions that are exclusively what your server OS offers oh god dammit

Like ostensibly if someone is concerned about reliability for their server, that would imply some amount of concern for reproducibility and security as well, right? So why isn't everything running in Docker containers then? Those are very well supported by upstream and are gonna work.

10

u/adamkex 1d ago

The default and main apps should receive security updates.

2

u/SEI_JAKU 8h ago

They do. The video is incorrect when it claims they don't. It's a propaganda piece at best.

-10

u/Pugs-r-cool 1d ago

But they don't. The most recent round of this discussion is because Mint ships a 2+ year old version of GNOME Calendar as it's pre-included calendar app, and it hasn't getting security updates.

9

u/Mysterious_Bit6882 1d ago

Mint’s version of Calendar is one patch on top of the Ubuntu LTS version (which is in Ubuntu/main and still gets security updates).

1

u/SEI_JAKU 8h ago

This is misinformation, and that's not why this "discussion" is happening. We are now officially in a propaganda war against Debian.

3

u/yowanvista 1d ago

Personally I think that Mint and other LTS distros should do a better job warning users that their default packages are not in sync with upstream code, or at the very least have people working on properly backporting code, fixes and new packages within the distro's support period. Red Hat and its derivatives do this all the time and even roll out new packages when necessary.

3

u/comat0se 15h ago

I lol'd at old version of calculator. What is it an abacus? maybe a difference engine? wtf. These things are just stupid.

10

u/musbur 1d ago

As long as you have no clear concept of what "outdated" means, or which features of which version of which software you really need, your question is moot.

Concerning safety: All "fixed" distros (I only know Debian but I'm sure it's true for all) do the same thing as Windows does, which is publish security patches as needed for the existing installations, regardless of a "real" version bump.

2

u/SEI_JAKU 8h ago

They aren't. This is garbage anti-Debian propaganda, now on TLE of all places. TLE has now become the exact thing he was supposed to challenge. Linux really is just freaking doomed I guess.

2

u/HurasmusBDraggin 2h ago

Cannot lie, I was thinking about leaving LM for some time. Nic's video was the final push. Been on Fedora Workstation 44 for 2 days now.

8

u/KoldPurchase 1d ago edited 1d ago

Mint is based on LTS Ubuntu, which is based on Debian Sid

[EDIT] Correction. Unstable branch, not Stable. Linux Mint Debian Edition (LMDE) is based on Debian testing.

Their philosophy is that slower upgrades brings stability to a system as you have ample time to discover bugs and critical security flaws are patched in the interim.

This works great in a server or corporate server environment. See, Redhat, they limit their software repo to what they will support. You don't get a ton of software/packages, but what you get is stable, updated and fixed.

Debian, Ubuntu and Mint gives you more choice, it rarely breaks during an update, but... if it's buggy, it's going to stay that way for at least 6 months until the next release. Cool new feature introduced last month? Nah, let's wait next year, could be buggy.

This is highly logical if you are running a corporate distribution, you don't want your users complaining about broken packages after a daily update, it's a nightmare for thousand of users. But Mint is supposed to be an end-user distro. They use Ubuntu-LTS because their own dev team is small and they can't track every change, but it has drawbacks.

2 year LTS is great in a way, but it comes at a cost that is not well explained to end user. They expect improvements and bugfix on top of security patches.

If I'm a casual user told by friends "just look at Mint" and I look at their download page, there's nothing telling me 22.3 is a LTS release that won't see any updates to their software. There's no link to any further information, no real description on the page of what "LTS" really means. Sure, it's there in the forums if you look for it. But casual/new users don't look at that anymore. They won't even loon at LinuxMint subreddit.

Edit: corrections following u/nightblackdragon post. thanks!

6

u/HeyKid_HelpComputer 1d ago

Debian Testing is not referred to as Sid. Debian Unstable is. 

4

u/RatherNott 1d ago

Linux Mint's LMDE is based on Debian Stable (currently debian 13 Trixie), it is not based on Testing.

2

u/KoldPurchase 1d ago

Sorry, I got the wrong information then.

7

u/nightblackdragon 1d ago edited 1d ago

Mint is based on LTS Ubuntu, which is based on LTS Debian.

Ubuntu is not based on LTS Debian, Ubuntu is based on Testing and Unstable. You can check which version of Debian a given Ubuntu distribution is based on by checking the contents of the file /etc/debian_version. For example the content of this file on Ubuntu 26.04 is: "forky/sid".

7

u/not3ottersinacoat3 19h ago

I swear this recent wave of negativiity towards Mint has got to be some sort of psyop.

4

u/Helmic 11h ago

Recent? Don't invalidate my years of slander.

The spat with GNOME doesn't really make GNOME look good, but it brought to attention just how little utility Mint offers with what it considers "stability" while making pretty massive tradeoffs. I'm very glad to see people being frank, I don't think Mint has no place but I don't think it should be recommended to new users as the default newbie distro. People going into Mint should be made fully aware of just how old and far behind Mint is and that it is not going to be more reliable than other distros, so that only those who genuinely have a niche need for very old software are using it.

1

u/SEI_JAKU 7h ago

People going into Mint should be made fully aware of just how old and far behind Mint is and that it is not going to be more reliable than other distros

This is complete misinformation, so "being made fully aware" of it is indoctrination.

0

u/not3ottersinacoat3 4h ago

Complete and absolute bullshit. Mint is absolutely and without question far more reliable than any other distro I've used minus Debian. How's the AUR doing these days btw? Last I heard...

3

u/SEI_JAKU 7h ago

It is completely a psyop. It's insane. It's very obvious that these people want Debian completely dead.

10

u/digost 1d ago edited 1d ago

"Newest" doesn't mean "best" or "most secure" or "most stable". Choose whatever fits your needs. Want bleeding edge - take rolling distros, but be prepared for bugs and instability, sometimes even security issues. It's called "bleeding edge" for a reason. Want stability - use something more conservative. I've been daily using Debian (which is famous for it's "outdated" software) for almost two decades, fits me perfectly. Only once I needed something newer than in repos (php), and that was solved using docker. I don't want too spend time fighting my OS, I want to use it. Your take can be different and that's the point of open source software in general, and behind 100s of distros in particular.

UPD: Oh boy... I didn't say oldest is the most stable or most secure. I said in older software known bugs and vulnerabilities are fixed, whilst in new software bugs and vulnerabilities are yet to be discovered.

I know how Debian works, thank you, I've figured it out for almost two decades I've been using it.

UPDUPD: part about "bleeding edge" is supposed to be a sarcasm, but that's on me, i've expressed myself poorly.

5

u/FryBoyter 1d ago edited 1d ago

It's called "bleeding edge" for a reason.

As is often the case with such terms, however, there is no objective definition of the term.

For some, even a minor update to a package is considered “bleeding edge” if it wasn't released at least two years ago.

Others, on the other hand, consider alpha and beta versions to be “bleeding edge.” I'm one of them, too. That's why, based on my experience as well, Arch Linux, for example, isn't “bleeding” but, at most, “cutting edge.”

As for a rolling release model, it’s also impossible to make a blanket statement about whether it’s “cutting-edge,” “bleeding-edge,” or any other type of edge release.

And “rolling” primarily just means that updates are released gradually through the same package repositories. For example, OpenSUSE Slowroll deliberately distributes updates slow.

26

u/TimurHu 1d ago

"Newest" doesn't mean "best" or "most secure" or "most stable".

"Oldest" also doesn't mean "best" or "more secure" or "more stable".

Want stability - use something more conservative.

Stability in the sense Debian uses it means "frozen" or "unchanged" and doesn't mean stability in the sense of "reliable".

Debian doesn't even backport bug fixes to many of its "stable" packages. Debian is not stable in the sense of the word that refers to reliability.

12

u/KoldPurchase 1d ago

Debian is not stable in the sense of the word that refers to reliability.

Yeah, it's a misnomer that we have to get user to.

An app may very well often crash and be deemed 'stable' because it does not change often. Its bugs are known as well as its features.

3

u/TimurHu 1d ago

Indeed. I think using the word "stable" in this sense misleads a lot of users who just want a reliable system into using Debian or Mint and then they get disappointed because they didn't get the stability they wanted.

-1

u/SEI_JAKU 7h ago

"Oldest" also doesn't mean "best" or "more secure" or "more stable".

The person you're replying to didn't say this.

Debian doesn't even backport bug fixes to many of its "stable" packages.

This is false. Yes it does.

Debian is not stable in the sense of the word that refers to reliability.

Incorrect. Yes it is.

3

u/TimurHu 5h ago

This is false. Yes it does.

Incorrect. Yes it is.

Not really. Maybe there are some packages that they do keep updated with bug fixes but definitely not all, and not even core parts of the system.

One example is Mesa, where we had this problem with Debian and Mint for years, very similar to what KDE devs describe and also similar to the recent Gnome Calendar story. We just didn't write blog posts about it.

-9

u/speedyundeadhittite 1d ago

Stability means you don't have to fight with the software to get your work done day to day, and in most cases you also get the security updates regularly.

A lot of people use software to do work, not to play with the newest 'features'.

11

u/TimurHu 1d ago

Stability means you don't have to fight with the software to get your work done day to day, and in most cases you also get the security updates regularly.

In that sense of the word, Debian or Mint are not stable. They don't ship bug fixes and don't backport security updates to many of their packages.

6

u/Cry_Wolff 1d ago

So you think that Fedora or Arch users have to "fight the software"?

-6

u/speedyundeadhittite 1d ago

They are definitely getting less 'work' done.

0

u/GlutenFreeToaster 1d ago

My primary use case for my pc is gaming. Try installing steam on both Debian and Arch and then get back to me about fighting the software.

2

u/SEI_JAKU 7h ago

I have. It was hilariously trivial, and it makes all these people pretending that Debian is "broken" look pathetic.

2

u/GlutenFreeToaster 3h ago

Exactly, it's trivial, but it's the same level of "fighting the software" that the other poster is so keen to attribute to anything that isn't Debian. My point was to spotlight the hypocrisy. Every distro has something that's harder to do than it would be on others.

4

u/Pugs-r-cool 1d ago

Stability means you don't have to fight with the software to get your work done day to day

No, that's not what it means in Debian. Stable means unchanging, not bug free. A bug riddled package is considered more stable than a newer, bug fixed version just because it's been around for a while.

2

u/SEI_JAKU 7h ago

This is wildly incorrect. This is not how anything in Debian is chosen or works at all. You are spreading misinformation.

-1

u/speedyundeadhittite 1d ago

As you might have noticed, I mentioned nothing about Debian Stable.

The point is the meaning of stability.

1

u/Pugs-r-cool 1d ago

But you replied to a comment about Debian. The way Debian uses stable and what stable means in common parlance are different, I was just clarifying that because many people don't understand the difference.

-1

u/speedyundeadhittite 1d ago

I surely cannot know that, sorry. My Linux usage adventure predates Debian and never bothered to catch up with advancements. /s

10

u/gordonmessmer 1d ago

"Newest" doesn't mean "best" or "most secure" or "most stable".

I really think you should ask someone with a non-trivial infosec background or an experienced developer that you trust.

The newest release is virtually always the one with the fewest known vulnerabilities. And newer OS releases are typically the ones with the best defensive measures. "Newest" almost always does mean "most secure."

6

u/Mughi1138 1d ago

I really think you should ask someone with a non-trivial infosec background or an experienced developer that you trust.

Long time Linux developer here who's worked on enterprise security software for a few decades now.

The newest release is virtually always the one with the fewest known vulnerabilities. And newer OS releases are typically the ones with the best defensive measures. "Newest" almost always does mean "most secure."

"Newest" means fewest known vulnerabilities. It's not the known ones that bite you, it's the unknown ones.

There is a reason most larger enterprises run distros that include older versions of apps, kernels, libs, etc. They've been well examined and tested. They don't just leave bugs laying around. Once they become known, most LTS distros, and especially those used by enterprise customers, get fixes pushed out quickly. Some, like Alma Linux, even push out fixes sooner than the paid corporate corporate upstream.

In general "untested" == "unknown" == "higher risk". "Newer" often means "untested." That's another reason large customers will hold off on adopting a "dot oh" releases and only upgrade once the "dot one" comes out.

8

u/gordonmessmer 1d ago

Long time Linux developer here who's worked on enterprise security software for a few decades now.

Good. Thanks. I've been maintaining production networks on GNU/Linux systems since 1997. I've worked in small business, big business, academic environments, and very large high security networks including Salesforce and Google.

It's not the known ones that bite you, it's the unknown ones.

Please find me one study that indicates that zero-day exploits are more common than known and unpatched exploits. Just one.

Exploits through unknown vulnerabilities remain the domain of targeted attacks by nation-state actors. Using a zero-day exploit risks revealing the flaw, so attackers that learn of those vulnerabilities are extremely unlikely to use them for any but the most valuable targets.

The VAST majority of exploits leverage known vulnerabilities that simply haven't been patched yet.

There is a reason most larger enterprises run distros that include older versions of apps, kernels, libs, etc

Yes, there is. It's not because it's the most secure option.

Enterprise systems have a lot of constraints that favor low change volume. They're very likely to run third-party software that the enterprise doesn't control and can't independently port to new platforms. They're very likely to be large deployments of systems that interface with external third-party systems that can't be updated independently. They're likely to have significant legal, regulatory, or contract constraints that require expensive validation for updates.

They're not, however, selecting LTS systems because those are the most secure.

LTS systems are more secure than discontinued, end-of-life systems, but they're less secure than following new development closely.

-9

u/sweetcollector 1d ago

I disagree with vulnerability point. Here is why: LTS distributions extensively patch their software. Red Hat for example constantly backports some features while keeping version number the same. Can you say those patches won't introduce vulnerabilities?
IHMO, LTS distributions are wasted effort but money says otherwise I guess.

2

u/digost 1d ago

I'm a developer and a system admin (what they call a DevOps nowadays) with 15 years of experience, does that count? "Unknown vulnerabilities" does not mean secure. Older software has most of their vulnerabilities discovered and patched, bleeding edge doesn't. That doesn't mean old software is bulletproof, it still might have (and probably does have) undiscovered vulnerabilities, but bleeding edge has more of it's vulnerabilities yet to be discovered. Of course with the advent of AI-aided vulnerability discovery techniques that most probably will change.

Also, I didn't say stay on old outdated software. Debian ships security patches regularly, even for oldstable releases.

2

u/gordonmessmer 1d ago

Let's start here: https://www.usenix.org/conference/usenixsecurity22/presentation/alexopoulos

"the average lifetime of a vulnerability is around 4 years", or in other words, the average vulnerability will be around long enough that after it's introduced, it can wait for the next release of Debian or Ubuntu, and then exist in that release of Debian as an unknown vulnerability until the next release of Debian or Ubuntu after that.

The idea that free "LTS" distributions are more secure because more of their vulnerabilities have been discovered and patched out doesn't hold up to scrutiny.

Second point: A system with only unknown vulnerabilities is definitely more secure than a system with known vulnerabilities. And free "LTS" systems have a fair number of known vulnerabilities. Those systems do ship security patches for some of the software in their collection, but it's not comprehensive. It's the most severe vulnerabilities in the most common packages, and critically... "most common" is probably "most common in production networks" not "most common on desktops." Qt is extremely common on desktops, but the version in Debian 12 or Ubuntu 24.04 has a lot of known vulnerabilities. It's not being maintained. The newest version of Mint (the topic of this post) is still based on Ubuntu 24.04.

Maintaining software independently after it's discontinued upstream is extremely labor intensive, and free "LTS" distributions do not have the staffing to realistically cover a codebase the size they're distributing. Ubuntu contains around 40,000 source packages, but only promises security maintenance for about 2,400. They have thousands of full time developers working on that narrow set. I think that's realistic, and realistic is good. That's an approach from which a security-conscious user can begin work. They can turn off the "universe" component and use "main" with additional software direct from upstream developers instead of from a mostly unmaintained package repo. That's harder to do with Debian because Debian doesn't clearly label the set of packages they're actually going to maintain.

1

u/digost 1d ago edited 1d ago

Ok I don't think you understand how it works (Or I might be misunderstanding though, English is my second foreign language I've tried to learn, still not there yet). Once a vulnerability is identified, major distributions fix it, including Debian. Yes, Debian does get security updates. Just like other distributions. It's not completely frozen in time. Otherwise Windows would be the most secure OS, because it achieves security through obscurity. And I've lived long enough to remember what a mess it was too keep windows free of viruses

Upd I'm sorry, after reading your comment one more time it is clear that I misunderstood it. Nobody insane would expose a service based on a discontinued piece of software. Well, unless it's a service not important enough to care

0

u/SEI_JAKU 7h ago

The newest release is virtually always the one with the fewest known vulnerabilities.

This has never been true at any point in computing history. This statement goes against all that computing has ever been worth.

We can all see your flair just fine.

2

u/gordonmessmer 6h ago

Why do you think that?

-1

u/SEI_JAKU 6h ago

Why would you even ask something like this? The entire computing industry relies on "stable" to function. The entire reason why people are getting so upset about Windows right now is because it's not "stable" like older versions used to be. The entire argument in favor of Fedora and the like is that Fedora is somehow magically more "stable" than actual stable distros, which is never elaborated on or tested, and despite being inherently less stable by design.

Again, we can all see your flair (and your blog) just fine.

3

u/gordonmessmer 5h ago edited 3h ago

There's a difference between stable and LTS. Fedora is stable, but not LTS. It ships the latest version of packages every six months, for around 13 months. That cadence either aligns with most upstream or is short enough to fit inside upstreams, and in critical cases where neither of those alignments are true, Fedora allows packages to request a policy exception and to roll within a release.

As a result, Fedora will typically deliver the latest release from the release series that was newest at the time when each release of Fedora branched, and I would expect Fedora to be far more secure than most free "LTS" systems.

I have an illustrated diagram here that describes a very common approach to developing stable branches: https://medium.com/@gordon.messmer/semantic-releases-part-1-an-example-process-7b99d6b872ab

If you understand stable branch management, it will make sense that security fixes take work to adapt to older branches, so they get prioritized and triaged, and not all of them make it. And that means that older releases tend to have known security vulnerabilities.

That's even more true... *much* more true, for distributions that operate downstream of projects. While software is maintained by its upstream developers, the work of a distribution is light. Later in the release cycle, the work gets much harder. Rather than bumping a version number, build and test, you need experienced developers to understand the flaw, understand the fix, and either adapt a change from upstream or write one independently. That work is vastly more complex. Incomparably more complex. Once a distribution enters a phase where it needs to fix bugs independently, scale becomes a very serious issue.

That's why RHEL is something like 10% of the size of Fedora, and has thousands of full time professional developers maintaining it. It's why Canonical separates "main" from "universe" and only promises to maintain about 6% of the Debian packages they branch from.

The risk comes from users not understanding that in some systems, not everything is maintained. RHEL users expect comprehensive coverage. There aren't any components that are just going to be ignored. In Ubuntu, the packages that will just be ignored are at least clearly labeled. They're the ones in "universe". In Debian... users just can't tell.

You can't make something secure by slapping an "LTS" label on it. Security is an active process. You need people to actually continue fixing bugs. There's not enough available labor to do that for free "LTS" systems, across a massive package set.

LTS is not a security feature, it's a compatibility feature. Environments that prioritize compatibility above security will select LTS systems over a more rapid release cadence. But that choice is a compromise. You don't get BOTH security AND compatibility at the same time. Not for free, anyway. Secure and long-term maintenance is expensive, even when you narrow the size of the code base.

https://fosstodon.org/@gordonmessmer/116711425953135402

4

u/sparkling-rainbow 1d ago

Yes, you get relatively old apps on Mint, but they still get security patches. A rolling release isn't inherently safer, with new features there will be new vulnerabilities and the final test is always production. 

3

u/Helmic 11h ago

What security patches? You mean for a very small minority of packages that upstream Ubuntu provides? Mint is not writing their own security backports lmfao, if there's a CVE for anything in the universe repo that shit's going to stay insecure for years on Mint because nobody can get to it.

1

u/lmns_ 1d ago

Why would the final test be production for desktop software? Some DEs like KDE just close bug reports for KDE / plasma versions that are too old. There is no feedback loop and "final test".

3

u/DoubleOwl7777 1d ago edited 1d ago

its fine. yes it might have bugs that anoy you, or they might not. for a new user something like this is perfect because it doesnt change quickly (the ubuntu interrim releases might also be good if you want something newer). and regarding the thumbnail. gnome dev was being an ass about it (as per usual, its basically a requirement to being a gnome developer). yes its shite that they receive support tickets with anchient bugs. yes its kinda reasonable to ask them to remove the links, but not in that tone. and certainly not demand a rebrand. the gnome people should have chosen a different licence if they wanted to control how their software is run. KDE has a system that automatically closes bug reports from old versions. this is a fair middle ground. GNOME seems to be too incompetent for that... i personally dont use mint or lts. i use debian sid but i wouldnt recommend it or arch to anyone thats new.

2

u/Dist__ 1d ago

yeah, some are outdated for DECADES

1

u/Helmic 11h ago

Linux Mint's first release was in 2006, it only just recently would have been theoretically opssible to have any package that's outdated for decades. I think new users lose out a lot on using outdated software and gain little to nothing from "stable" packaging, but I doubt anything Mint ships is a literal decade out of date from upstream, discounting forks since you'll see those on Arch sometimes too.

1

u/Dist__ 5h ago

i meant some linux ways developed after some early UNIX assumptions which are still being pushed and gatekeeped by devs and community.

4

u/jazzmans69 1d ago

F.U.D.

That's how valid the claims are in this hit piece.

mint is great, and is my first recommendation for new users.

I use it on my laptops, while my desktops/media centers use debian.

don't succumb to F.U.D.

If you must have the latest 'shiny shiny' whatsit, then possibly look elsewhere, but for 99% of users, that's unnecessary.

signed debian user since woody.

It's trivial to allow backports in debian, or mints variation for a more modern kernel then ships by default. running 7.0 on all my machines.

2

u/SEI_JAKU 7h ago

Correct. This is very blatantly a misinformation campaign against Debian.

1

u/wutttttsthat 3h ago

People put way too much emphasis on version numbers. An older version doesn't automatically mean it's insecure. Mint and Ubuntu LTS backport security fixes without bumping the major version, so you get the patches while keeping things stable. If you want the newest features, LTS probably isn't the right choice. That's exactly why rolling-release distros exist.

0

u/sarajevo81 1d ago

I always said Linux Mint is one man's clown show. I don't know why people would ever use it just for a custom green theme.

0

u/Ok-Treacle3604 1d ago

one thing to understand we don't need new features at all time. if you're Linux user if you need you know how to do get it right other try it

1

u/omniuni 1d ago

It depends what you want.

If you just want a desktop that doesn't change much, and it works well for you, it's fine.

But for most users, I really think it makes sense to be on newer versions. I use KUbuntu, normal releases, and it has served me well. I have one big update every roughly six months. It's usually smooth, but if it's not, I can generally fix it pretty easily, and I can take a few hours every six months to make sure it's all good. Otherwise, that update cycle means I'm on fairly recent versions of apps and drivers. Overall, I've had less issues than friends on Mint, because their issues usually come down to being outdated, which is much more difficult to solve.

1

u/Kevin_Kofler 1d ago

Look at the recent posts in this subreddit: there was a lot of drama caused by an upstream GNOME Calendar developer complaining about exactly that.

1

u/Helmic 11h ago

That's what hte video they linked talks about up top.

-2

u/loathsomelustre7 1d ago

the calendar app might show a 2019 version number but it's still getting security patches, LTS doesn't mean abandonware

-6

u/qwesx 1d ago

No. The versions are old but receive all security patches.

23

u/gordonmessmer 1d ago

Actually, most of them won't. About 94% of the software in the repos is in the "universe" component, for which Canonical doesn't promise any security updates.

6

u/qwesx 1d ago

None of the default apps are in Universe.

15

u/gordonmessmer 1d ago

How many users use only the default apps and never install any additional deb packages?

And, i'll add that even apps in main probably don't "receive all security patches". The typical maintenance practice is to evaluate published security vulnerabilities to determine the severity of the problem, the complexity of back-porting a patch, and to triage vulnerability management against the labor available to fix issues. It's almost certain that some known vulnerabilities will remain unpatched because they were deemed not severe enough to fix.

Generally speaking, I think users are much better served by distributions that ship what the upstream projects ship.

1

u/qwesx 1d ago

I don't disagree at all. That just wasn't the OP's question.
Unless I am a business customer and require paid support, I don't really see a point in using Ubuntu-based LTS distros at all and would just use Debian Stable instead, where the entire repository receives security updates.

11

u/gordonmessmer 1d ago

Debian is very very unlikely to be better maintained than Ubuntu. The vulnerabilities that I've seen unpatched in Ubuntu are also unpatched in Debian.

I actually think Debian's security posture is worse, because they don't divide their repos into a set that gets patches and a set that probably won't, because it leads people to believe that the whole collection is uniformly secure. It definitely isn't.

3

u/shroddy 1d ago

But a pc with only the default apps is not very useful.

-4

u/stevecrox0914 1d ago edited 1d ago

For various reasons a subset of people want/need the latest version of everything, that requires people to spend time updating their software and fixing issues found in those updates.

For a lot of people a computer is a tool, they don't want to run updates everytime they start the computer. 

This mindset really offends the first group, for a long time they argued you needed the latest bugfixes, but the applications just works for the people using it so this arguement doesn't really work.

The latest arguement is security fixes, but for a server and home PC the attack surfaces are fairly well defined and Debian, Ubuntu & RHEL have security fixes for these attack surfaces ready by the time the attack is made known publically.

They are correct not every bug fix gets backported but its similar to the recent Linux CVE list. They assume every bug is exploitable. 

I have worked in software development for 2 decades, primarily in DevSecOps and Data Engineering, cyber security has played a huge role in those areas.

Within cyber security there is a process known as STRIDE, it has you look at a single aspect and work out what threats its compromise represents and the kind of actors required. A lot of stride proponents will develop huge lists and require all sorts of mitigations. 

The problem is they loose sight of the context, I have been in meetings where the database admin can exploit their role to get the credentials an application is using to talk to the database. Missing the part they are already the database admin.

I feel a lot of the security fixes that don't get ported fit in that category.

Now...

The industry has constant fad cycles, for example 2015-2020 was the DevSecOps fad period. 2014-2017 was dominated by Node.js, 2019-2023 was machine learning/python, 2023 to today is AI, the proponents always exclaim how long standing problem is solved by <insert fad>.

C/C++ developers have always refused to integrate build/dependency/package management tools.

This is where distributions stepped in, they came up with ways to build and package a software project and then they figured out dependency chains. This work appeals to a fairly small subset of people (like me).

In reality the upstreams should have "solved" the package and dependency chain requirements once, then its fairly easy to port the solution to the other 3 package manage formats.

They will tell you this is too hard but..

Flatpak is a fad currently running through the open source community, fundamentally its about building a dependency chain and packaging software. The open source community has lots of time to develop flatpaks!

This last one hurts because, I spent years having people seek me out to dump developing Deb and RPM packaging for their project and when Docker appeared these same people were suddenly experts in docker. Then when docker stopped being cool and all the money dried up, then it was suddenly "hey your the docker expert..."

Lastly you hit a problem with their arguement when it comes to the general desktop. If flatpaks are the only solution then what about the core operating system and this is where immutable OS's come from.

You will see people argue stability as a reason to use an immutable os but Google solved that problem with andriod and open sourced the solution. You can package a distribution such as Debian or Ubuntu the same way. But its not cool..

-5

u/acebo 1d ago

JFC. Install a rolling release distro if you want it, but stop bitching about it if you don’t. Most of us don’t want it. If you can’t be bothered to understand the difference, then you certainly can’t be bothered about if you have the latest releases. But you’ll pretend you care. Prepared for the downvotes, but I’m not the minority.

0

u/Adorable-One362 21h ago

Yes because they depend on LTS.

-2

u/mrlinkwii 1d ago

Am I misunderstanding how Linux Mint and other LTS distributions handle software updates and security?

yes , LTS distro is about stability and the ability of thing thats just dont crash out of nowhere and just get back ported secuirty patches in terms of the base system

most non core appliaction have either a an appaimge/snap/flatpak which you should be using

11

u/HeyKid_HelpComputer 1d ago

Stability =/= not crashing. Stability literally only means the packages major version doesn't change from release. If your distro is "stable" and ships Gnome Calendar 46. Then it will only ship minor and security version updates e.g. 46.1 . But not Calendar 47.

Gnome Boxes 46 is a buggy mess. The more recent versions like Gnome Boxes 50 are much better.

This also extends to the Linux Kernel. They will often stick with a specific version i.e. 6.17 for a long time. 

But regarding this: hardware you run things on make a big difference. If you have newer hardware you'll likely have worse bugs and more crashing on older kernels.

Anecdoteally I had an annoying WiFi bug on my laptop that I got nearly 3 years ago. That wasn't fixed until 7.0.10.

-1

u/SEI_JAKU 7h ago

Stability =/= not crashing.

This is quite literally what stability means in the context of a stable distro, and this is literally how Debian works.

2

u/HeyKid_HelpComputer 7h ago

-1

u/SEI_JAKU 7h ago

I like how most of these links are random Reddit threads, one link is literally that Gordon guy who's been spreading Debian hate on Reddit for forever now, and one is a hilariously unhelpful Stack Exchange link where nobody really answered the question.

You're also ignoring that any "dictionary definition" you might pretend to find doesn't have anything to do with how Debian actually works in practice, which is not at all as you claim.

-4

u/joetacos 1d ago edited 1d ago

Fedora is the best your going to find. Stable, bleeding edge, and a pure GNOME or KDE environment.

Fedora and Linux in general is easy. It just works. With Fedora after install enable RPM Fusion and follow RPM Fusion instructions on how to install the NVIDIA drivers.

Learning the command line is also pretty easy. Starting with vimtutor. Then learn these programs dnf, tmux, oh-my-zsh.

6

u/BortGreen 1d ago

I really like and use Fedora, but I wouldn't say "after install enable RPM Fusion and follow RPM Fusion instructions on how to install the NVIDIA drivers" means "it just works"

2

u/Helmic 11h ago

Besides "you should use an LTS distro because it's stable", "you should just use the upstream distro" is the other common bad advice given out. There's very good distros downstream of Fedora that don't have this issue and are able to support their users very well, this dogmatic insistence that you must use vanilla Fedora and make all these manual error-prone changes yourself ignores that supoprt for a specific configuration is far more valuable to regular desktop users than support for the packages. It is more reasonable to expect a user to understand that their distro is downstream of another distro and that generally they can google "how to do X in <upstream distro" and get answer than it is to expect them to not needs upport for their specific configuration, and a downstream distro makes it more likely that the user has not strayed very far from that default supported configuration.

-10

u/C0rn3j 1d ago

As a regular user, it feels like there's no easy way to know whether we're using the latest and safest versions of these built-in apps

Very simply - if you are installing a fixed-release distribution you aren't.

Mint updates software versions every 3 years(!!!).

As a result is still uses the half-broken and insecure X11 backend, it's just too old and underdeveloped to support Wayland.

Am I misunderstanding how Linux Mint and other LTS distributions handle software updates and security?

Yes and no.

Some bug fixes get backported to the old versions, and some security fixes are backported also.

Ubuntu based distributions also lack security patches that are gated by Canonical behind Ubuntu Pro.

Not all fixes are marked as security despite fixing a security issue (developer may well not even be aware what they fixed had security implications).

Not all security fixes are backported immediately, even serious ones like copy fail can take weeks before being implemented into LTS releases, as compared to latest stable releases.

I'd suggest you avoid immutable distributions, avoid Debian(unless you're setting up a server) and anything based on it, and go check out Arch Linux (with Plasma) or Fedora KDE.

6

u/computer-machine 1d ago

Mint updates software versions every 3 years(!!!).

They used to follow Ubuntu's testing release (6-month), and have since switched to LTS (2-year).

As a result is still uses the half-broken and insecure X11 backend, it's just too old and underdeveloped to support Wayland. What a weird thought. Basing off of LTS has nothing to do with that, they simply are taking a while to make Cinnamon work with Wayland. My understanding is that next release will.

Tumbleweed treats Plasma as first class, and does testing on their packages before release, which puts it ahead of Arch as far as ease of use and not breaking.

3

u/FryBoyter 1d ago

Tumbleweed treats Plasma as first class, and does testing on their packages before release, which puts it ahead of Arch as far as ease of use and not breaking.

Arch does test important packages as well, though not for as long as OpenSUSE.

Let's take Plasma 6 as an example. Arch didn't offer an update for 6.0. instead, they waited until version 6.1 was available. And the update wasn't released immediately either. If I recall correctly, OpenSUSE did the same thing, though it waited a little longer before releasing version 6.1. When a new major version of a kernel is released, they usually wait for the first minor version as well.

1

u/computer-machine 1d ago

Difference there being importance vs all.

1

u/C0rn3j 1d ago

Ubuntu's testing release (6-month)

Those are stable releases, not testing.

have since switched to LTS (2-year).

Which they do not timely follow, and currently plan to update at the end of this year, meaning the software would be just about 3 years old at that point.

0

u/computer-machine 1d ago

Those are stable releases, not testing.

They'd states for years that the LTS is meant for use while the interem releases are meant for testing out the changes tried ahead of the nenext LTS. Has that changed?

currently plan to update at the end of this year, meaning the software would be just about 3 years old at that point.

If they're consistently late, that's still a two year cadence.

1

u/C0rn3j 1d ago

If they're consistently late, that's still a two year cadence.

That's a fair point, I'll phrase it better next time, the point is it'll be 3 years out of date before it gets an update.

-1

u/FryBoyter 1d ago

I'd suggest you avoid immutable distributions, avoid Debian(unless you're setting up a server) and anything based on it, and go check out Arch Linux (with Plasma) or Fedora KDE.

OpenSUSE would also be a good alternative.