Locking vital systems in face of AI dilemma

Hi all, this is my first post. :waving_hand:

After using Linux Mint for a few months last year and coming across a few bugs, I jumped to LMDE for better stability, and found it. I also implemented several tips from easy linux tips project for further stability. As novice, I see a dilemma in locking vital systems as per this link, section 3, as I see two conflicting interests regarding the kernel and use of AI. On the one hand, locking these vital systems protects from unforeseen developments with the kernel because of AI used in kernel development; on the other hand, as recently seen, use of AI has revealed security flaws in the code, with follow up patches as a result. When is the right time to lock vital systems for stability, while securing healthy privacy and security functions? Are we there yet?

I decided to lock it again now, after unlocking it in spring when there were fixes for the security flaws.

I will do the same if anything important for privacy/security is being patched again.

What’s your takes on this?

4 Likes

Your link is a good article.
We should all read it, even if we have no intention of locking parts of our system .

My own reaction was that locking parts of a system by putting selected apt packages on hold is complicated and risky.
If I wanted a locked system I would simply refuse all updates. I have done it. In the past I ran FreeBSD for years without updates. It survived. What gets you in the end is the browser getting out of date with html changes. My system was , of course, behind a NAT wall. A fully online system, like a server, might need updates more often.

3 Likes

@nevj Thanks for your thoughts on this! I do not lock the browsers, as per the article, only a few core systems. Or do you mean that up to date browsers at some point could become in conflict with an older kernel?

2 Likes

No, I did not mean that.
I meant that a very old browser will eventually be unable to cope with new versions of HTML.

You do have to watch compatability between kernels and apps, but it is an infrequent problem.
Fixed release distros like Debian stay with one major kernel series (eg 6.12.x) for that reason.

There is a school of thought that says that security is better if you change you OS frequently. That might mean frequent updates, or it might mean rotating between several different distros.
If your computer is never the same when an attacker returns then it should make attacks more difficult.

2 Likes

Thank you for the clarification!

It makes sense that distro hopping makes it more difficult for attackers. But it also makes sense (to me at least) to go for one stable distro, locking vital systems and go through checklists for further stability and privacy/security. At least this is the game I want to play for now, it might change as I learn more, though.

1 Like

Yeah, but it is a nuisance.
If someone could come up with a distro that countinually morphed itself while staying stable for the user, it would be a very difficult moving target for attackers.

Dont laugh. The kernel uses that strategy now in its memory management. You app never loads in the same location when you run it.

1 Like

That the best idea, but which one… Ask here and you get 57 different answers …

Imagine linux chose just one, would we end up at the same place as microsoft :upside_down_face:

Think the base (debian) needs to be the start then flavours added like mint. But retaining the security part.

Also browsers, chromium as a base built on by chrome etc.

Everyone will disagree with me I know.

1 Like

Why not choose several?
It makes you more adaptive
It confuses attackers
No single distro is perfect, you can have the best of several worlds
You can use distros like tabs in a browser … do each project in a separate distro … it keeps each distro simple.

1 Like

Nothing we have discussed is going to help with this sort of event

All systems are an open door to something that is clever enough.
We may have to shut down the internet.

2 Likes

I am in fact in the process of preparing for a world without internet, investing in useful encyclopedias mostly bought second hand or given away for free. A well edited encyclopedia from the 90’s is better than nothing, or at best, slop. Then there are digital options such as KiwiX, downloading parts of wikipedia for local storage and so.

2 Likes

I am hoping that something better will replace it.
Going back to old techmology has never worked in the past
History tells me we always move onto something else … for better or worse.
History also says , what happens next is always unanticipated.

3 Likes

Think most of us are old enough to remember that period, same. With time before email voip whatsapp mapping … its really strange think about going out to dinner in a nice resto and people talking to each other without phone interrupting. I can even remember a time before TV not just colour

2 Likes