HN user

washingupliquid

95 karma
Posts3
Comments31
View on HN

One is security updates and bug fixes.

That's where you're wrong. They're not one and the same.

Debian stable often defers non-security bug fixes for up to two years by playing this game.

I'm not interested in new features unless they make things actually work.

Debian stable time and again favors broken over new. Broken kernels, broken packages. At least they're stable in their brokenness.

Hence my complaint.

What it's about is, newer versions change things. A newer version of OpenSSH disables GSSAPI by default when an older version had it enabled.

Debian patches defaults in OpenSSH code so it behaves differently than upstream.

They shouldn't legally be allowed to call it OpenSSH, let alone lecture people about it.

Let them call their fork DebSSH, like they have to do with "IceWeasel" and all the other nonsense they mire themselves into.

When you break software to the point you change how it behaves you shouldn't be allowed to use the same name.

Maybe this is the kick in the ass Debian needs to upgrade the embarrassingly ancient dnsmasq in "stable" because while I can't think of any new features, the latest versions contain many non-CVE bug fixes.

But I doubt it, they will lazily backport these patches to create some frankenstein one-off version and be done with it.

Before anyone says "tHaT's wHaT sTaBlE iS fOr": they have literally shipped straight-up broken packages before, because fixing it would somehow make it not "stable". They would rather ship useless, broken code than something too new. It's crazy.

This sort of worked when the opinionated manager was Steve Jobs.

Steve indirectly had a hand in this, by emphasizing the humanities. That, unfortunately, backfired as a sort of positive feedback loop.

Someone hired a few underemployed artists onto the team, and the artists invited all their friends and soon took over the department.

People that in an alternate timeline would be smoking weed whilst sculpting wood in a derelict loft somewhere are now the lead designers, using our software as the canvas of a perpetual avant-garde art piece.

They also need to look productive to justify their jobs, so the need to change things is constant.

That's why in 2026 you could have a PhD in CS and still need to watch a YouTube video to learn how to change the volume.

Can anyone name a single substantive UI improvement in the last 20 years? They're simply hiding or moving stuff around at this point while no one has even touched accessibility.

Too many developers nowadays don't know this.

Guess they've never been on the phone with an elderly relative in tears because she can't figure out basic tasks on an iPad anymore after years of learning how.

That's when you realize you, as a highly-skilled technical person, can't either, because they've moved, hidden, or otherwise obfuscated them.

Yesterday I learned there are two icons in the Files app called "..."

Yes, two.

Incidentally I was looking for how to delete a file, which is now deliberately missing from the object's context menu, and intentionally hidden under one of these.

A public key is useless without the private key. Which the attacker in this unlikely scenario doesn't have.

So you login the first time and they either match, or they don't. If they don't you start over. The end.

Ignore the fact that most people will probably use the box to host a poorly coded vulnerable service anyway.

Public keys go over untrusted channels. That's why they're public.

I'm not confident you understand how crypto works.

You do realize the entire threat model here is a house of cards perched atop someone else's software hosted on someone else's hardware all of which you implicitly trust and discard in favor of some unlikely cloak and dagger interception scheme.

I'm supposed to believe MitM with the same exact keypair is somehow possible? Private keys are never exchanged. Did everybody forget how crypto works?

Yes you implicitly trust the public key on first login.... then just... immediately compare it with what's on your box?

Might as well seal your doors with duct tape to prevent ghosts from entering your home because this is equally effective.

I've stopped submitting quality reports to Apple Maps because they're all met with "while we couldn't make the change you suggested, we hope you continue to waste your time reporting these".

The issues are egregious too, like blatantly incorrect lane guidance that would send you in the wrong direction, or diverting me off a highway onto an unmarked, narrow country road that no one with any knowledge of the local roads would take ever.

Though I'm confident whatever BPO slaves they have processing reports 5000 miles away have a better understanding of the roads than I, as they are wholly incapable of even using Google Street View to confirm details (probably by policy) so they always demand I provide a photo or video a month after the fact. Because when you're lost in the middle of nowhere your first thought should be "Let's backtrack so I can grab some pictures for Apple".

It makes it sound even worse, cherry picking language like "not interested" as if the OpenBSD folks should shoulder blame for not being altruistic enough.

It reeks of trashing your benefactor, who gave you well-written free software, which you then made insecure with your own patches.

If you remove the roof of your car with a chainsaw and are inevitably injured later, is it the car manufacturer's fault they didn't offer that model as a convertible from the factory?

The better question is why are people still trying to assign blame all these years later? The IT world dodged a bullet but has moved on (and likely didn't learn from their mistakes as supply chain attacks are steadily increasing).

Why do Linux Distros modify OpenSSH?

The short answer is that they have to. OpenSSH is developed by the OpenBSD community, for the OpenBSD community, and they do not give a flying Fedora about Linux.

What complete horseshit. I stopped reading there.

The OpenSSH Portable branch is maintained by OpenBSD developers and SystemD is a completely optional add-on so why on earth would they make it a dependency? If they didn't care about the Linux community they wouldn't develop this software *for free* for them. They can go write their own GNU SSH then.

It certainly doesn't help that there are 165+ definitions of what constitutes a "complete GNU+Linux system" some of which use SystemD and some which vow never to.

It's not the OpenBSD developers' fault some Linux distros use overly complex plumbing and can't agree on one standard for their OS unlike every other OS out there, including Windows.

The xz backdoor was a Debian and Red Hat issue because they maintained patches to fix problems of their own creation. No one else was affected. Why should the OpenBSD people care? It's not their problem.

this is the exact kind of misinformation that prevents progress.

lol

Brazil does not "fuel" cars on sugarcane any more than the US fuels its cars with corn.

Brazil has been building cars which can run on 100% ethanol since the 1970s.

These are not obscure facts; this is common knowledge the US teaches to schoolchildren.

In the US gasoline is a 10% ethanol blend, sometimes 15%. E85 is available only in some midwestern states (I've NEVER seen it for sale anywhere on the west coast) and it's only good for flex-fuel vehicles, which most manufacturers stopped building ~ 10 years ago when the free money from the government shifted towards EV incentives.

This is reminiscent of the CHAZ takeover in Seattle when the protesters planted like 4 potatoes in a urine-soaked park and called it "the People's Garden" or whatever.

Spirit was an objectively terrible airline. Their business model failed. They folded. The end. This is why you can't fly Braniff or Southern Airways anymore in 2026. Failed businesses go under, they don't live on in perpetuity.

The fix for your repeated at-fault accidents is not more mandatory technology in cars.

The fix is you should be taking MUNI more often and a defensive driving course. Maybe be forced to drive a manual transmission car through Pac Heights until you can't. Your insurance premiums must be crazy.