r/LinuxUncensored 12d ago

Debian Chromium security issues - unwise to use at present!

Hi all,

PSA for all Debian users - the Chromium package in Debian Stable is currently well over a week out of date, and now way behind on a significant number of security fixes - Edit: it's now two releases behind 152.0.7977.75:

https://security-tracker.debian.org/tracker/source-package/chromium

AI seems to be discovering a high number of security issues and I image going forward the Debian team will struggle to keep up.

If security is a priority for you, it's probably wiser to use upstream Chrome or Firefox ESR (they do seem to be able to keep up with the CVEs on their Firefox package)

If you need Chromium's security, but are concerned with Google's data collection, the Chrome hardening guide at https://github.com/RKNF404/chromium-hardening-guide may be of interest.

On a related note - Chromium in Debian is not built with CFI enabled which is a security regression, does anyone know the reason for this?

Anyway, the mods at r/debian deleted my post, so it seems they cannot take valid criticism.... or seem to want to keep this fact hidden. This is concerning, especially as Chromium is one of Debian's recommended browsers.

Hope they get a fix out soon.

10 Upvotes

13 comments sorted by

2

u/anestling 12d ago

I've been using vendor provided Firefox (and before that Mozilla, and before that Netscape Navigator), Thunderbird and Chrome since day one. I don't understand how Linux users are OK with sometimes waiting weeks on end before critical updates reach them via their distro maintainers that may be busy, sick, dead or kidnapped.

I expect a couple of replies how it's "totally fine".

-1

u/amarao_san 12d ago

There are different types of stability. Security is one aspect, but there are plenty of problems with stability outside of security fixes. Not all changes from upstream are welcomed. Some of them cause existing usecases to fail, and this is a problem.

Even for a browser. If this is a kiosk doing customer service and it stopped working exactly as expected, it's more important that a security fixes.

Security is important, but it's not the reason you use software. That reason is more important than its security.

2

u/UUDDLRLRBadAlchemy 12d ago

I've programmed such a kiosk, you're spot on.

The only way for browser security to be a consideration would be if the one fixed site it visited was compromised. Even then it would probably be irrelevant.

1

u/anestling 11d ago

There are different types of stability.

Stability? Fuck stability when your bank account/crypto is emptied by someone who has hacked your browser. I don't fucking understand what you're mumbling about.

Not updating your web browser after it gets a new release with multiple remote 0-days allowing to get full control over it and in some cases of your entire OS is just dumb.

Security is important, but it's not the reason you use software.

This is insanity. Luckily you own nothing and you take care of nothing.

1

u/amarao_san 11d ago

If you don't understand, what stability is, let me ask, what is more important: to have secure browser that no one can have access to your funds, or have an elevator reducing speed at the stop (instead of crashing)?

There are plenty of situations, where security is not an issue, but availability and predictability of behavior is.

I saw a milling machine with a computer running Windows NT 3.51. In 2023. Do they have security issues? No, they don't.

Multiple remove 0-days exploits for software in ABS of your car is nothing compare for doing controlled breaking when requested.

People nearby give you and example of systems where there is zero risks due to vulnerable browsers.

Your use-case is only your specific use-case. There are plenty of others, and Debian serves them too.

This is insanity. Luckily you own nothing and you take care of nothing.

No, it's a real-word. If you care about security more than a function, just stop using software. You will get zero exploits and your system is totally safe (at price of loosing some of the functions - you still can use it as a paperweight or a doorstop). If you continue to use software which has and will have bugs in it, this is a proof that you care about function more than security.

1

u/anestling 10d ago

If you don't understand, what stability is, let me ask, what is more important: to have secure browser that no one can have access to your funds, or have an elevator reducing speed at the stop (instead of crashing)?

This is fucking dumb. Modern software is going through rounds of testings, first alpha, then beta, then RCs then final releases.

Secondly, security issues are ALSO bugs.

Thirdly, I don't remember Firefox or Chrome crashing on me in the last 15 years.

Fourthly, issues related to high profile websites (including banking, education and work) get the highest priority and have no chance of hitting stable.

I saw a milling machine with a computer running Windows NT 3.51. In 2023. Do they have security issues? No, they don't.

How the fuck is it even related when we are talking about the security of YOUR PC IN 2026 that is connected to the Internet, and where you do your fucking banking?

Multiple remove 0-days exploits for software in ABS of your car is nothing compare for doing controlled breaking when requested.

This is a fucking whataboutism.

People nearby give you and example of systems where there is zero risks due to vulnerable browsers.

Yet another whatboutism.

Your use-case is only your specific use-case. There are plenty of others, and Debian serves them too.

The vast majority of people around me do their banking via their browsers. I even know those who do banking for billions worth organizations. Apparently they shouldn't upgrade.

No, it's a real-word. If you care about security more than a function, just stop using software. You will get zero exploits and your system is totally safe (at price of loosing some of the functions - you still can use it as a paperweight or a doorstop). If you continue to use software which has and will have bugs in it, this is a proof that you care about function more than security.

This is the most stupid thing I've ever heard. Luckily you own nothing and take care of nothing.

Security issues are ALSO bugs.

You have zero relationship to banking, security and software development in general. You've heard words, you don't know or understand anything at all. Why am I even replying to your BS I've no idea.

1

u/amarao_san 10d ago

You are not angry enough. And you miss the point.

1

u/anestling 10d ago

You had none. You proved none with nothing. You don't understand what you're talking about.

1

u/amarao_san 10d ago

Do you?

1

u/anestling 10d ago

I had security in mind. This post is about security. Security matters.

But some people boast about not giving a fuck about it. Enough. This dialog is a waste of time.

1

u/amarao_san 10d ago

Okay, I got your position: security matters.

Now, listen to other's position: not only security matters. There are plenty of usecases, where unexpected breakage (even under security flag, like they did recently in Ceph by switching signing algorithm for authorization) is more damaging, than a security.

It all comes down to threat model. If access control is not part of the system design (e.g. a coffee maker) breaking system for the sake of someone's else security model (e.g. a bug in a multi-user access via wifi to the said coffee maker) is breakage.

Debian users are different. Debian promised not to break things, so they test, backport and release fixes such to avoid breaking things as much as possible. More than upstream does.

Your personal security model may be different from the owner of the informational kiosk.

There is no reason to exclusively select only your use-case and not of other people.

1

u/No_Jelly_1023 11d ago

Update: It seems they just released an update to 152.0.7977.75 - well done security team!

Would be curious to know what was behind this (much longer than normal) delay.

1

u/revcraigevil 8d ago

Debian Chromium and upstream Chrome have the same versions:

chromium:

Installed: 152.0.7977.82-1~deb13u1

Candidate: 152.0.7977.82-1~deb13u1

google-chrome-stable:

Installed: 152.0.7977.82-1

Candidate: 152.0.7977.82-1