Default action policy for "Security Updates" changed between 14.04 and 16.04

Bug #1700930 reported by Etienne Papegnies
22
This bug affects 4 people
Affects Status Importance Assigned to Milestone
unattended-upgrades (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

In Ubuntu 14.04.5, the default policy under the "Updates" tab for "Security Updates" is set to "Display Immediately".

In Ubuntu 16.04+, the default policy is now "Download and Install Immediately".

I think this occurred due to the fix rolled out for bug #1554099.

This has the following consequences:

- Users may be denied apt lock when trying to install software because unattended-upgrades is running in the background.

- If a shutdown is forced when the background update is running, users may be left with an unstable system

- In case the update server is compromised and made to deliver malware, the blow to the userbase will be massive

- From a PR standpoint, this moves away from the previous "your system won't ever do stuff without your permission" default policy.

I'm of the opinion that the "Display Immediately" default should be rolled back. Failing that at least an official policy change announcement should be published so that users are made aware of this new default.

Changed in software-properties (Ubuntu):
status: New → Opinion
description: updated
Changed in software-properties (Ubuntu):
status: Opinion → New
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in software-properties (Ubuntu):
status: New → Confirmed
Revision history for this message
Sebastien Bacher (seb128) wrote :

Reassigning to unattended-upgrades which is what has the configuration, software-properties is just a frontend allowing to edit it

affects: software-properties (Ubuntu) → unattended-upgrades (Ubuntu)
Revision history for this message
Sebastien Bacher (seb128) wrote :

you might want to write about that to the ubuntu-devel@ mailing list which is better discussed for such discussions

Revision history for this message
Sebastien Bacher (seb128) wrote :

bug #1690980 is about the lack of feedback when trying to shutdown or reboot

Revision history for this message
youthinkso (jlxb) wrote :

This issue affects me directly. I have been using 16.04.x for about 1.5 years and for most of that time updates (security and otherwise) have been carried out just as I have directed. However, not long ago I discovered that updates were being carried out in the background with disregard for the options I have chosen. Unattended Updates has been enabled and working in the background. I had never heard of it and could not find an interface to affect it.

I discovered it a few weeks ago when firefox 55.0.2 was pushed out. Some one hadn't done enough beta testing and introduced a pretty severe bug to a very large community of users. I quickly rolled it back only to find it reinstalled the next day. And, again the next. Some one decided that FF needed to be updated every day, without permission and without notification.

After some investigation I found that some in the Ubuntu community have openly supported this policy in order to "better serve" the community. Apparently, the sentiment is that the average user can not be trusted to keep their own computer updated and thereby exposing the community to risk. It is for the good of the community as a whole.

The FF issue is a perfect example of a continuous distributed denial of service imposed by policy. The people who turned "on" the unattended upgrade policy are not listening to the feedback. As of today, FF 55.0.2 is still severely broken (on my platform) and is still being pushed out on any automatic or manual update unless unattended upgrades are disabled completely or FF eliminated from apt upgrades manually.

Conclusion: I did not turn this tool on. In fact, I had selected to turn everything automatic "OFF". No one asked me for permission. No one notified me that a policy had been chosen for me that over rides MY CHOICE - did I say that loud enough?.

I installed 16.10.x on a new laptop a month ago and I see that unattended updates is installed and active - overriding my choices by default. In Software and Updates, I have all automatics turned off and yet every night that system downloads and updates my computer. Who the hell are you people?

Yes, of course there is a way to turn it off - before some one tries to tell me "all you have to do is...."

That is not the issue! You turned it on! I sincerely urge you to back off your holly-er than thou point of view and honer end user choices. NO more secret policy changes! And, no more unintended consequences resulting from those policies. Should we not be able to trust you?

Revision history for this message
youthinkso (jlxb) wrote :

I spelled Honor wrong. How embarrassing!

Revision history for this message
Garry Trethewey (garrytreth) wrote :
Revision history for this message
Adam Smith (adamsmith) wrote :

Unattended-upgrades is for server images and is not usually installed with a desktop. You should be moaning to Martin Wimpress about this.

Revision history for this message
Etienne Papegnies (etienne-papegnies) wrote :

@adamsmith: you're wrong, the package is installed in stock ubuntu.
This is an ubuntu problem.

Revision history for this message
Adam Smith (adamsmith) wrote :

Sorry, yes you are right. I've been working with lubuntu too much which doesn't. Ubuntu-mate didn't used to ship with it either, but that seems to have changed in recent versions.

Carry on.

Revision history for this message
Etienne Papegnies (etienne-papegnies) wrote :

So, errata. Turns out I was wrong too.

I met @kirkland Dustin Kirkland at ubuncon-europe last week end and we talked about this.

It turns out this change IS official policy and is advertised here:

https://insights.ubuntu.com/2016/12/08/ubuntu-16-04-lts-security-a-comprehensive-overview/
https://wiki.ubuntu.com/Security/Features

I still feel this was somewhat under reported and that the classic media sources that cover Ubuntu have dropped the ball big time but I can't fault Ubuntu for that so I'm closing this issue.

I'll just have to remember to turn this off on any new install or mention it to
the machine's owner and explain the possible consequences.

Changed in unattended-upgrades (Ubuntu):
status: Confirmed → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.