Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Slackware is OK if you want to play around with Linux on a non-public-facing system, but it's bad advice if you want to run a secure public-facing server. It's too difficult to do automatic package updates on Slackware. Since so little software is packaged, you end up having to install most software manually, which means you become responsible for monitoring that software for security advisories and upgrading it in a timely manner when there's an advisory.

Here's my advice for a secure public-facing server: use Debian Stable, set up automatic upgrades every night, install as much as possible from the official Debian repository, and be sure to upgrade to the next Debian release before your current release loses security support. This way, the Debian Security Team is responsible for monitoring security advisories and rebuilding packages instead of you having to do it yourself.

Source: I just finished transitioning to Debian after 10 years of Slackware use, in large part because I found it too difficult to keep my Slackware installations secure.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: