Both you and other poster have spoken about keeping Pi out of reach of internet. Even if ports are not open, fetching external content on a distro with no security updates and insecure libs is putting your box in the reach of the internet, and many (probably most) OSMC installations are doing that.
No, I said it shouldnât be exposed to Internet not connected to the internet. There is a huge difference.
It seems like you are trying to insist on a distinction that is no longer valid once Bullseye has reached EOL. Once the libs fetching and parsing content no longer receive security updates, the box is vulnerable even if it is responsibly placed behind a firewall.
You are selling a commercial product that, in the way it is reasonably used, is running outdated and unpatched software. This is a practice that is heavily criticized in the tech community. There should have been no gap between Debian releases, and with this and all the complaints recently about orders, one can reasonably worry whether this (one-man?) shop is unable to keep up. I donât intend to post further on this, but I think the discussion can now be moved to somewhere like HN.
The problem is that you seem to be inventing fallacy after fallacy in each response. You keep saying âreasonably usedâ or how most people use the device but Iâve no idea how you would be so educated about peopleâs use cases for their device.
Trixie is coming in days, it can be migrated to now.
For OSMC shipped packages and their dependencies we always ship security updates and have long term support commitments.
The biggest attack surface to an OSMC device would be installing a dodgy add-on. Security updates will not mitigate that.
Playing videos will not cause problems. We even maintain some libraries downstream of Debian to improve security and performance.
My understanding is that you donât have any of our commercial products and are using a Raspberry Pi. I think with the energy youâve expended it may have been easier for you to use something different.
Shipping a new version of Debian on day one isnât feasible nor a good idea. As for orders, Iâm not sure what that has to do with the issue discussed here, but for what itâs worth we are on top of orders. We are navigating memory and chip shortages like everyone else however.
Hi Sam -
I think you shouldnât be so dismissive of CRCulverâs comments. I suspect the vast majority of your potential customers have no idea as to keep their OSMC device secure. Please assume that they plug it directly into their router, just as they would their Smart TV. This is even more likely if they have a Vero device, where the natural assumption for a customer will be that doing this is âsafeâ.
I, for one, always assumed that my VeroV device had a firewall enabled that would keep my VeroV reasonably secure. I now doubt this is the case, yet the Wiki does not contain the words âfirewallâ or âiptablesâ at all, which leads me to wonder how, as a customer, I should know or figure out what the default security configuration is.
Plugging the device in to a router is not an issue.
I actively discourage port forwarding however.
Iâve made a post here:
- Security updates are now shipping again
- OSMC is now maintaining Debian Bullseye security updates until the move to Trixie
Thanks for your patience and understanding
Sam
I donât have âMy OSMCâ anywhere. How do I find it?
Itâs under Settings, but it may vary depending on the skin youâre using,
Confluence.
It will be under settings
System settings?
Under System Settings I have:
Player, Media, Games, PVR & Live TV, Add-ons, Services, Interface, System
I canât find âMy OSMCâ in any of those.
@k_h1 With skin Confluence I found it at
GUI -> System -> Settings -> Add-ons -> My add-ons -> Program add-ons -> My OSMC -> Run
Hello Sam,
Iâm also having a problem with the updateâŚ
It crashes during the downloadâŚ
Iâve tried the hotfix âupdates2026fixâ and it doesnât workâŚ
Hereâs my log
Thanks in advance for your help.
The fix hasnât been applied.
Try again just enter updates2026fix and nothing else no space
Wow. OK, thanks.