Hacker News new | past | comments | ask | show | jobs | submit login

These long term support distros are toxic to everyone except proprietary software vendors.



You are surely joking and you're not good at it.


Do you trust package maintainers at Redhat/Debian/etc to properly backport security fixes to ancient branches? They don't exactly have a clean track record.

Look at the terribly old / EOL software in RHEL4 that is on "extended support" until 2017:

  Java 1.4
  SVN 1.1
  Apache 2.0
  Stunnel 4.0.5
  Python 2.3
  Glibc 2.3.4
  Firefox 1.0
edit: I stumbled upon some ELSA advisories a few weeks ago where additional security updates needed to be released for Apache because the CVE for which they intended to backport a fix was not adequately patched.

That is terrifying. There's a reason why upstream doesn't release fixes for those old releases.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: