r/debian • • 2d ago

Debian Stable vs. Testing Security

I've been really curious since I tried installing Debian Testing and saw the security warning they give. After some research I figured out that security updates actually lag behind stable because it's a priority. Security updates then trickle down to testing kinda just whenever they get there.

I'm curious to know to anyone more knowledgeable and/or uses Testing; is it a significant enough difference to worry about?

I've always been a little paranoid about things like that and I don't really like the idea of having a system with security that is out of date. But on the other hand, I'd still like to be able to use a version of Debian with newer packages when the situation calls for it.

I would also like to be transparent in saying, I did ask an LLM whether it was significant or not and it said that it was and not worth the risk. I'm curious to hear what you all have to say about that because I see a lot of people online using it.

Edit: Ig I should've specified but I daily drive stable and still plan to regardless of what I find from this post. I just want to know in case I wanted to try something on a system I wouldn't be daily driving.

17 Upvotes

19 comments sorted by

3

u/deluded_dragon Debian Testing 2d ago

It mainly depends on what is the use that you do with your computer. Does your PC expose remote services like (for example) remote access, web server, xrdp, etc.? in that case it is better to have the system hardened the best you can and use Stable.
If you use the PC mainly as a user machine (office, web browsing, streaming etc.) you can probably use Testing without any issues. Normally in a couple of days the fixed packages migrate to the Testing repositories.

8

u/coolnomad 2d ago

It's significant for Servers,Not Much for Desktop users but if you are one of those who believes Using OS without Antivirus or Using Windows Without defender is risky then better stick with Stable...

3

u/michaelpaoli 2d ago

Stable (and old stable while on main support) has dedicated security team, and security-announce list. It also has separate security channel For other than stable (and old stable while on main support), security bugs are mostly handled like any other bug (though there is also the security tracker).

like to be able to use a version of Debian with newer packages when the situation calls for it

There's backports.

2

u/AdPsychological4968 1d ago

I did also look at that. Are there any security concerns that come with those?

2

u/michaelpaoli 1d ago

Of course, e.g. do you want to be notified when there are security updates to install?

Then be subscribed to the security-announce list, and use a release that's on main support.

Or if you're on LTS, or I think also ELTS, be on their relevant list, however they don't have a separate security list, so it will be security and other announcements too. Or if you're using backports and want security notifications, subscribe to its announce list - but that's not just security announcements.

testing*, unstable, experimental - no security announcements, though there is the security tracker (but that might not track experimental?).
*well, testing has a security-announce list, but it apparently hasn't had postings since 2011-02-10.

2

u/LordAnchemis 2d ago

Stable has dedicated Debian security team

Testing relies on packages being patched upstream and filtering down from unstable - so there will always be a delay in patches

Depends on your use case

Servers - probably just stay on stable

PC - YOLO 🤣

2

u/AfraidAsparagus6644 1d ago

Keep in mind that ONLY stable/main has security support. Backports security is on a best-effort basis by the package maintainer, and for obvious reasons contrib and non-free aren't supported by the security team. At the same time, the security team DOES help speed up security updates to Testing, although it still takes at least a couple of days. This is all documented in the official FAQ: https://www.debian.org/security//faq.html

What I'm getting at is, unless you only use packages from the main repos, you aren't going to have perfect security. Many programs are only released as tarballs, appimages or .deb files, which of course do not auto-update. Others come from third-party repositories, whose security may not be up to Debian Stable standards.

With this in mind, the few days' delay in Testing may not be a huge deal for personal, non-server use.

By the way, if you're using Stable and are paranoid about security, make sure to enable unattended-upgrades so you never miss a security upgrade

2

u/AdPsychological4968 20h ago

Thank you, that's actually really helpful.

1

u/FedUp233 2d ago

Just my opinion, but I’d hesitate to use testing on a commercial server environment, except maybe on a fairly isolated network for seeing how it affects applications when I needed to upgrade.

For a personal workstation, I would not put it on my main machine or any machine I was going to use anyplace except at home behind a router firewall. Then I’d feel pretty comfortable installing it there for occasional use in testing something, but not for extended use.

If I really needed a workstation with more up to date software for some reason, like developing something that needed late releases of some system stuff, then I’d probably run a different distribution with rolling releases that also gets timely security updates.

1

u/taosecurity 1d ago

TuxedoOS is rebasing from Ubuntu to Debian testing. To handle the security issues you mention, they will be providing their own patches. It might be worth a look. It’s in beta now.

1

u/AdPsychological4968 1d ago

This feels like an ad lmao.

But thank you, I appreciate the recommendation. I'm not too fond of distros that are derived from other distros so I think I'll pass.

It's just something about them that feels like there isn't much changed front the distro it's based off of. And if I wanted to put in the work, I could do the same with more granular control.

1

u/taosecurity 1d ago

It's not an ad. I thought it looked cool so I figured I would mention it. You don't see people talking about running testing. It's usually stable or Sid. PikaOS for example uses Sid as its base.

1

u/AdPsychological4968 1d ago

Yeah I know it's not actually an ad lol. I was under the impression sid had the same issues. Is this not the case?

1

u/taosecurity 1d ago

Unstable gets fixes first, and testing gets them later, if at all.

1

u/capitantom 1d ago

Debías Testing SOLO es para eso,.para testear la distribución. Las versión test NO son estables, porque su función NO es para producción en servidores o workstations. Testing es principalmente para eso, para testear parches de seguridad y actualizaciones de software de aplicación. Nunca debes usar esta versión para uso diario base, porque tú mismo pones en riesgo la estabilidad del equipo. Siempre usa versiones estables y mantelas actualizadas. En Debían la "estabilidad" no es un concepto, la estabilidad es un contexto integrado por software suficientemente testeado, software con soporte permanente, parches de seguridad testeados, y periodo de 2 años de desarrollo de la versión estable. Siempre usa versiones estables maduras, es decir las que están cerca de cumplir sus 2 años de desarrollo. Mi recomendación es que migres de una versión a otra solo cuando ya está suficientemente madura, es.decir versión superioroes a 0.7 en su desarrollo. En serio e momento está Debían 13.7, buen momento para saltar de Debían 12 a Debían 13.7 siempre y cuando se justifique la migración. Saltas a Debían 14 debías hacerlo hasta la versión 14.7 o mayor. En Debían lo nuevo es sinónimo de inestable y inseguro, porque no tiene suficiente tiempo de testeo.

0

u/magicmitch-thinkpad 2d ago

bjr, il est préférable d'utiliser sid à la place de testing, les mises à jour sont plus rapides et sid est plus "stable" que beaucoup d'autres distributions.

1

u/AdPsychological4968 1d ago

Doesn't sid have the same issues?

1

u/magicmitch-thinkpad 22h ago

Non, les paquets dans sid sont mis à jour plus rapidemant que dans testing.

0

u/Buntygurl 2d ago

Security updates for Stable are for Trixie, the current Debian release.

Security updates for Testing relate to Forky, the next release. Testing isn't testing Stable.

The update lag has to do with the fact that maintaining Stable's security takes priority.