Bonum Certa Men Certa

The Linux Mint Security Controversy Taken Out of Proportions, Distracting From Real Controversies

Clement Lefebvre
Photo from linuxmint.com



Summary: A so-called accusation (made in a personal blog) causes a media storm which neither Clement Lefebvre nor Canonical seem to be happy about

ONE of the best GNU/Linux distros (distributions of GNU, Linux, and desktop environments, complete with general-purpose applications), based on relative measures of popularity at least, is Linux Mint. It is so popular that in DistroWatch it beats Ubuntu sometimes. Canonical, which is in the centre of several controversies (over trademarks, privacy, and request for 'licensing' of binary packages) must realise that alternatives like Linux Mint can outgrow Ubuntu. There is a screenshots tour of Linux Mint 16 [1] and the release is imminent (now in RC [2-5]).



"Neither side was particularly upset over the original remarks, so to frame it otherwise would be somewhat dishonest."Some people want us to believe that Canonical uses FUD to discourage exploration of Mint as an alternative to Ubuntu (which Mint is a derivative of). Those people, however, base their analysis on the words of just one developer [6] whose words are rebutted by the Mint founder [7] (he is also unhappy about the source of the drama, namely Muktware [8,9], which led to more such coverage [10,11,12]). In trying to judge this, the whole scenario was a demonstration of media gone somewhat rogue, hostile where opportunism lies.

We have been watching this controversy closely for a number of days and it seems like sensationalist authors did a disservice and created an unnecessary rift. Neither side was particularly upset over the original remarks, so to frame it otherwise would be somewhat dishonest. It is very different from what happened recently when it comes to trademarks. Canonical and Shuttleworth (personally) were at fault and the EFF points this out in some follow-ups [13,14,15]. It is important to keep a sober balance and only criticise Canonical (Ubuntu steward) where the company (as a matter of company-wise policy) does something unethical. Presumption of guilt only leads to noise and distraction from the real issues.

Related/contextual items from the news:



  1. Linux Mint 16 Petra Cinnamon Desktop screenshot preview
    Linux Mint 16, code-named Petra, will be the next stable edition of Linux Mint, a desktop distribution based on Ubuntu Desktop. It could be released sometime this month or early next month (December).

    This distribution’s release track record suggests that Linux Mint 16 will be released less than two weeks from today. And when that happens, it will be the first stable edition of Linux Mint with Cinnamon 2.0 desktop pre-installed.


  2. Linux Mint 16 release candidate available for download
    Today in Open Source: Download the release candidate of Linux Mint 16. Plus: Will preloads help Linux? And the top five Linux games


  3. Linux Mint 16 RC released
  4. Linux Mint 16 RC Is Out With Cinnamon, MATE Desktops
    The release candidate version is now out for Linux Mint 16 'Petra' with MATE and Cinnamon 2.0 desktop flavors.

    It's getting close to another six-month update for the Ubuntu-based Linux Mint and the big feature this time around is the Cinnamon 2.0 desktop.


  5. Linux Mint 16 RC Brings Cinnamon 2.0 and MATE 1.6
    Clement Lefebvre had the pleasure of announcing a few hours ago, November 15, 2013, that the Release Candidate version of both the Cinnamon and MATE editions of the upcoming Linux Mint 16 operating systems are now available for download, and testing, from mirrors worldwide.


  6. Ubuntu dev, media slammed over 'security' comment
    Among these outlets were the OMGUbuntu and Muktware sites, both of which only deal with Linux and FOSS stories. In that context, it was even more surprising that they carried such reports.

    Muktware editor Swapnil Bhartiya was asked whether reporter Monika Bhati, the person who filed the story quoting Grawert and contributing to the hysteria, was a Linux user and also whether she had taken a look at the Mint update utility before writing.

    His response: "She is a resident journalist and uses Windows/Linux. We got Robin Jacobs to dive into the git pages and comments in LM to see how updates are labelled."

    Jacobs also wrote a story which, in effect, contradicted Bhati's story - and both stories appeared within 4€½ hours of each other on November 18.

    The editor of OMGUbuntu, which contributed to the same idea being spread, was asked similar questions to those put to Muktware.
  7. Answering controversy: Stability vs Security is something you configure
  8. Linux Mint falsely accused of being “insecure”


  9. Canonical developer criticizes Linux Mint’s security, called ‘a vulnerable system’
    Ubuntu developer Oliver Grawert does not prefer to do online banking with Linux Mint. The reason being its unsecure handling of packaging upgrades that could leave the system vulnerable to attacks.


  10. Canonical Developer Criticizes Linux Mint's Security


  11. Does Linux Mint need better security?
    There have been disturbing reports in the media about Linux Mint having security problems. Is this something to worry about or has it been wildly overblown by the press?


  12. Lead Ubuntu Developer Claims Linux Mint is an Unsecure Distro – Is It?


  13. EFF responds: Mark Shuttleworth is still wrong"
    Though Lee was not required, by the law, to remove the logo he removed it.


  14. Trademark Law Does Not Require Companies To Tirelessly Censor the Internet
    Over the past few days, EFF and one of our staff technologists, the talented Micah Lee, have had an illuminating back and forth with Canonical Ltd over the use of the Ubuntu mark. While we don’t believe that Canonical has acted with malice or intent to censor, its silly invocation of trademark law is disturbing. After all, not everyone has easy recourse to lawyers and the ability to push back.

    That matters, because Canonical’s actions reflect a much bigger problem: a pervasive and unfounded belief that if you don’t police every unauthorized use of a trademark you are in danger of losing it. We hope that some clarity on this point might help companies step back from wasteful and censorious trademark enforcement.

    First, some background. This particular story begins in 2012, when Canonical made the disappointing and widely criticized decision to integrate Amazon results into searches conducted through Ubuntu’s desktop dash (this meant that a user searching for one of her own files would receive results from Amazon). At the time, we argued that this default setting raised significant privacy concerns. A few weeks ago, Micah published a web site—at https://fixubuntu.com—that provided users with code to disable this privacy-invasive “feature.”


  15. Electronic Frontier Foundation Goes After Mark Shuttleworth and Canonical
    The Electronic Frontier Foundation, an organization devoted to the protection of freedom in the open source world, has criticized Canonical and Mark Shuttleworth.




Recent Techrights' Posts

Why We Support Richard Stallman and You Probably Should Too
It's not about being "Richard Stallman fan", it is about maintaining the right to hold positions (on technology) like his
Some Large German Media Covers Richard Stallman's Talks in Germany Earlier This Week
LLM-based chatbots are just "bullshit generators" (as he has long called them)
Trouble in Red Hat/IBM and a Retreat to Ponzi Economics in Search of Wall Street Market Heist
Would you invest your life savings in this kind of crap?
Who Asked Software in the Public Interest (SPI) for a Refund? ($100,000, Resulting in Losses of $267,201 in 12 Months, Highest-Ever Losses)
The IRS does not reveal who or what's tied to this refund (or the cause/reason)
 
Slopwatch: Google News and Slopfarms That Relay Nonsense From LLMs
Google News, which once prioritised or used to care about provenance and quality, is feeding slopfarms
Links 23/10/2025: More Health Concerns Over Dumb Chatbots (LLMs) and "Talking Cars" as Latest Buzz
Links for the day
Gemini Links 23/10/2025: Daylight Savings Time and Duration Shorthand
Links for the day
Links 23/10/2025: LLM 'Hallucinations' (Defects) in Practical Code 'Generation', China Becomes More Economically and Technologically Independent
Links for the day
Linux Foundation Uses LLM Slop to Promote Microsoft in Linux.com (Again), Rendering It a Linux-Hostile Slopfarm
Openwashing with slop by "Linux.com Editorial Staff", which basically seems to be a bot
Links 23/10/2025: Windows TCO Galore and "The Internet Is Going to Break Again"
Links for the day
Social engineering attack: Debian voted to trick you on binary blobs
Reprinted with permission from Daniel Pocock
Techrights Will Always Stand for Women's Rights
We even invest money - personal savings that it - in our principles
Certified Lawyers Should Know Better (Than to Intimidate Us With Man Who Drives on Motorcycle Through a Really Bad Storm Between Distant Cities, Then Collects Photos of Our Home)
Mentioning someone was in prison for bad things isn't a crime, it's a public service
The "AI" (Slop) Bubble is Already Imploding
"ChatGPT Usage Has Peaked and Is Now Declining, New Data Finds"
The So-called "Sexy" Buckets (AI, Quantum) Cannot Save IBM From Reality, Shares Tank
"No matter how much financial hocus-pocus they use to reclassify revenues to land in the "sexy" buckets (AI, Quantum), it still smells old and musty - just like this company."
Paul Krugman is Wrong About the Scope of Mass Layoffs in the United States
A few years ago society was accelerating its journey towards feudalism, boosted by COVID-19
Links 23/10/2025: Proprietary Blunders and CISA's Latest Disclosure of Holes
Links for the day
Gemini Links 23/10/2025: Fast Past (F1), 99.9% Uptime
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, October 22, 2025
IRC logs for Wednesday, October 22, 2025
Slopwatch: Google News is Promoting Fake 'Articles' About Fake Xubuntu, Fake Articles About Replacing Windows With GNU/Linux
The quality of the Web deteriorates and unless someone cleans up the mess, real sites will lose an incentive to produce anything
When "AI Layoffs" Mean Layoffs Due to the "AI" Bubble Popping
many people that are laid off by Microsoft claim to be specialists in "AI"
Mysterious grant forfeited, $100,000 from Software in the Public Interest accounts 2023
Reprinted with permission from Daniel Pocock
Evidence: bullying, student union behaviour: Armijn Hemel's FSFE resignation
Reprinted with permission from Daniel Pocock
Evidence: psychological abuse, stalking, Galia Mancheva, Susanne Eiswirt ignored by FSFE judgment for Matthias Kirschner
Reprinted with permission from Daniel Pocock
Helping FSFE scam victims and conference organisers
Reprinted with permission from Daniel Pocock
Nigerian fraud in FSFE constitution
Reprinted with permission from Daniel Pocock
Worrying and Amusing Stories of "Clown Computing" Gone Awry
Many of these disasters could be avoided
Links 22/10/2025: Amazon Plans to Replace Workers With Robotics, AWS and Clown Computing in General Ridiculed
Links for the day
Gemini Links 22/10/2025: Niri Completely Changes Multitasking and Overview of Diff-ers
Links for the day
Links 22/10/2025: Study on Misinformation by Slop and Heavily Debt-Sabbled Microsoft OpenAI (ClosedSlop) Uses "Browser" as Gimmick/Distraction
Links for the day
They've Already Spent Close to a Million Dollars on Lawyers and Sent Us About 50 KG of Legal Papers (Sponsored by Mysterious Third Party) to Try to Censor Techrights, Without Success
They try to overcompensate with sheer volume for a lack of solid, clear arguments (we are the victims here)
12 Months Ago the 'Hulk Hogan of UEFI' Officially Went 'Tag-Team'
We're actually sort of flattered or proud that such despicable people are so desperate to censor us
"Cloud Computing" Was Always a Joke, But This Week Was the Punchline
Maybe stop following tech trends and fashions
"Cloud Computing" Does Not Mean Safety
Fault tolerance is related to the notion of software freedom
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, October 21, 2025
IRC logs for Tuesday, October 21, 2025
The Fall of Windows: From Something to Nothing
Of course Microsoft will pretend everything is fine and "just trust the hey hi" (AI)
Sounds Like Fedora is Ready to Become Less of a Slave of Microsoft (GitHub)
This seems like a belated move in a positive direction
XBox is a Dead Microsoft Product in a Dying Industry
It's probable that another wave of XBox layoffs is just over the horizon (maybe even before month's end)
Progress on Techrights Site Search
Fun times
IBM's Bluewashing of Red Hat Means the Layoffs Are Silent, Barely Reported
Don't wait to hear about "Red Hat layoffs"
Gemini Links 21/10/2025: Happy Disconnection, AWS Falling Apart, Closing of Gemlog Blue
Links for the day
Full Audio of Today's Richard Stallman Talk in the Technical University of Munich
Free/Libre software and freedom in the digital society
Microsoft XBox is Just Vapourware (Promises of Hardware That Doesn't Exist), Real Products Perish
just as developers lose interest in developing for XBox Microsoft is increasing the costs imposed upon them
Slopwatch: Fake Articles (Slop) in "Linux" Clothing in Google News (Noise)
all about what Google does
Links 21/10/2025: Even "Inventor of Vibe Coding" Rejects Vibe Coding, USPTO Experiments With Slop in Examination
Links for the day
Richard Stallman Talk Now Available for Viewing (Archived Copy, Not Live-streamed)
This recording is over 2 hours old
Links 21/10/2025: AWS-Induced Chaos and Social Control Media Curbs
Links for the day
Gemini Links 21/10/2025: Programming, StarGrid, Brand-New Palm OS Strategy Game in 2025, and Chatbot as Addiction Mechanisms
Links for the day
The African Lion and the American Cowards
Safaris exist for people to watch and enjoy animals
Amazon Web Shenanigans Perfectly Timed for Today's Talk by Richard Stallman
Maybe listen to him instead of looking for excuses to ridicule the messenger
Mission:Libre Has Taken Off (Project by Carmen Maris)
there will be a lot more to report on next month (after the event)
Techrights to Publish More EPO Leaks Next Week
We're meanwhile also doing lots of work on search, whose interface now looks better
Links 21/10/2025: 'The Lost Art' of Neon Signs and Twitter (X) to Enable Identity Theft (or Handle Theft) as a Service
Links for the day
Plagiarism With LLM Slop: Hindustan Times (HT Digital Streams Limited) Has Become a Slop Factory/Hub
What a disgrace
A radical proposal to keep your personal data safe, by Richard Stallman
"The surveillance imposed on us today is worse than in the Soviet Union. We need laws to stop this data being collected in the first place"
Next Week We Launch Search at Techrights
We're planning to launch it some time next week. Maybe Tuesday, maybe Thursday.
Talk by Richard Stallman Will be Live-streamed in Less Than 10 Hours
Happy hacking
"No Kings" in the Software World (GAFAM Should Not Exist, Either)
"No Kings" is a good slogan. Let's start by ridding ourselves of masters, not only those who reside in DC or visit DC
Every Morning
Bugs/edge cases combined with automation can spell disaster
Insane, Deliberately Dishonest, or Just Another Bigot?
very intellectually-dishonest human being
A Lot of Techrights is Built on Perl
Perl also runs the sister site
The Register MS Selling Slop for Microsoft (Vapourware, Ponzi Scheme, False Claims)
What will be left of The Register MS if it keeps repeating falsehoods and looking to profit from Ponzi schemes?
analytics.usa.gov Says Less Than 14% of Web Requests (to Government Sites) Come From Vista 11
Vista 11 was released more than 4 years ago!
People Who Attempt to Take Down Correct Information Need a Doctor a Day
“Journalism is printing something that someone does not want printed. Everything else is public relations.” ― George Orwell
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, October 20, 2025
IRC logs for Monday, October 20, 2025
Vista 11 is Sinking While Microsoft is PIPing (Mass Layoffs But Silent Layoffs)
We're witnessing a shift in platform dominance
Richard Stallman is Having a Good Week Already (Stallman Was Right About 'Clown Computing')
That alone is worth bringing up in his talk
An Update About Soylent News, With Jan Rinok "Back in the Saddle"
Burnout or "near burnout" a possibility when having to curate abuse
When Prominent GNU/Linux Distros Are Run by Spies
What has Microsoft Canonical become?
More Publishers and Companies Nowadays Say "GNU/Linux", Not "Linux"
It's not to see InstallAware saying GNU/Linux this week