===== Security shoot-out: LTS vs regular release systems ===== * **Speaker**: Gordon Messmer * **Room**: 332 * **Time**: Saturday, [[https://pretalx.seagl.org/2026/talk/RZGP8K.ics|Oct 24th 2:30 – 3:20pm]] * **Format**: Talk (50 minutes) * **Difficulty**: Intermediate to Advanced * **Track**: Security & Systems * **Additional Tags**: LTS, Regular Release, Security, GNU/Linux, Vulnerability Management, Fedora * **Experience**: Software developer and production network manager since 1997 with experience at Google; contributor to Fedora, dnf, rpm, and PackageKit, and author of a namespace tampering debugger used by Fedora. ==== Description: ==== The security characteristics of Long Term Support (LTS) versus regular release models have remained fundamentally similar for decades, but community sentiment and adversary capabilities have evolved. This session explores the unique challenges of maintaining security in LTS systems, particularly when they continue to ship code that is no longer maintained upstream. The talk will examine different interpretations of security, the distinction between stable and unmaintained software, and what patch frequency actually indicates about a system's security posture. Additionally, it will discuss how the rise of AI-driven tools for vulnerability discovery and exploit deployment may shift the balance between these two release models. **Target Audience:** * System administrators and DevOps engineers * Security researchers and auditors * Linux distribution maintainers and power users