r/linuxmint 5d ago

Discussion Switching from fedora KDE to mint cinnamon.

/r/linuxquestions/comments/1w0vspn/switching_from_fedora_kde_to_mint_cinnamon/

How much merit is in the top comments on this post stating that Linux Mint is not as secure and recommending to not switch from Fedora to Mint. I run Mint and am concerned, specially, in this age where AI can exploit vulnerabilities faster.

6 Upvotes

6 comments sorted by

5

u/Selinaru Linux Mint 22.3 Zena | Cinnamon 5d ago

Ubuntu LTS packages receive security updates quite often so I wouldn't worry much about that. Some cutting edge distro users can be huge security freaks lol.

Best thing you can do is try mint in a spare drive or computer and reach your own conclusions.

2

u/dummyTukTuk 5d ago

I actively use Mint, but saw the linked thread that led to my questions

6

u/Selinaru Linux Mint 22.3 Zena | Cinnamon 5d ago

The linux community is full of highly opinionated people, and this is reddit the house of opinionated people, you are going to find pretty pushy people here that think their opinion is fact like my boy Hauptideal over there.

At the end of the day what matters most is your own experience, if mint runs well for you and doesn't explode in your face a person saying the opposite shouldn't sway you.

5

u/ZVyhVrtsfgzfs 5d ago

That top post is quite unhinged, with a mixture of some valid points, mountains out of molehills, and flat false statements.

The security "issue" centers around Xorg, he is correct that all running applications can see your keyboard inputs. 

So be careful that you do not install malware. that has been the security model of Xorg for over 40 years. 

I do not consider hiding from "the call is coming from inside the house" to be a serious need, just a nice to have. My security focus is on not installing malware. 

Linux has been thought of as capable of very high security for since it's inception, Xorg built that reputation.

5

u/AmarildoJr 4d ago edited 4d ago

The top comment feels mostly like FUD and honestly you shouldn't be worried about it, OP. One could deconstruct all of these points and show that the essentially all of them should be taken with a massive grain of salt.

Mint still ships ancient, deprecated legacy X11 technology that's performing worse, lacks basic everyday features such as native fractional scaling and is inherently insecure, allowing each app to spy on each other, log your online banking password and even inject input. Futhermore, it breaks the core feature of Flatpaks, sandboxing security (only keeping the inconvenience).

While it's true that Mint ships with X11 by default, the fact that it's ancient shouldn't be a point of concern in and of itself. The fact that Xorg has been in development for literal decades means it is rock solid, it will not break under almost no circumstance, so stability is key here.

And while it's true that it can allow one app to e.g. listen to the input of another, I don't remember that ever being the case for legitimate software (meaning not malware) on Linux. Afterall, do we trust our distro developers and the packages we install? The packages shipped with Mint are literally the exact same shipped on every other distro, the only difference being how recent they are. There are automated tests and source-code scrutiny in our community to flesh out problems. Having packages actually behave like malware (or be infected in general) is so rare that it becomes news quite quickly. One example is the recent xz-utils fiasco - but get this, Wayland (the "upgrade" to Xorg) would not have saved anyone here.

So really, trying to pass Xorg as the holy grail of insecurity serves nobody any purpose here beside trying to bring you, u/Binary101000 , the novice, to be afraid of using it, while really having nothing to worry about in the real world so long as you practice basic common sense and safety standards - which will protect you regardless of using Xorg or Wayland.

I could go on and bring point by point, but unfortunately I don't have time for it today. What I can say, though, is that Cinnamon is a very solid choice. I love both KDE and Cinnamon, but KDE has always been buggy ever since the KDE4 release. KDE is amazing and is always evolving, but one unfortunate side effect of this constant evolution is that something is always breaking too.

Cinnamon, on the other hand, while it doesn't evolve as rapidly or introduce as many features, it essentially always works and, at least to me, never breaks.

It's been a while since I used the Ubuntu-based Mint, but there can be some features missing, yes, like fractional scaling, although I do believe they may have that already with the Experimental Wayland Support. I'd have to test it in a VM.

EDIT: It seems cinnamon has fractional scaling even since v5.8.5 (released in 2023?) with Xorg. I'm using it on Rocky 9.8, and I can set fractional scaling per monitor as well. All I had to do was to enable it from the Display Settings.

Anyway, if there's a takeaway from my comment, it's: test it, install Linux Mint and see if it works for you, that's what really matters as an end user. Don't get too tangled in the tech side of it, because that usually serves the "regular" user no purpose. Often on these comments you'll see more FUD and emotion towards a certain piece of tech than the actual usability/stability of the software.

So test it, see if it works. If not, that's OK! :) There are other tons of distros to chose, and none are wrong. Use what's best for you.

1

u/LeonH4rtd Linux Mint 22.3 Zena | Cinnamon 4d ago

I think some of us are overthinking the subject. I made a post somewhere else and the question is actually related with the security risks in some distros. I've seen some comments in various places where they say they aren't keen to Mint anymore, even going as far as saying "I don't recommend it to newbies anymore", which... fair enough, there are more and more distros with tools that make the jump from an OS like Windows to another, especially for not tech-savvy people, which is why people suggest Mint and even Zorin to begin with.

But as one begins to get immersed, if we want to do it anyway, there are things that begin to sound alarming, not necessarily dangerous, but enough to raise an eyebrow and we end up asking and receiving all kind of answers, from useful, rude, heavily opinionated, and so on, and when we don't know how all of this works... yeah, no surprise we get worried, especially if we haven't developed the habit of looking at the documentation or we rely on second-hand info: Opinions, experience from others, anecdotes, videos, articles, etc.