Running old Debian
Let's pretend it is summer 2023: Debian released first update to Bookworm, 12.1 with Linux kerner 6.1. LLM coding is gaining popularity, but it is by no means in the mainstream OpenSource software. How long we can live with it, how safe we will be?
Installing the system
Easy way to install specific version of the sytem is to download image for the offline installation. The only distributions that are readily available to download are iso-cd and iso-dvd, larger distributions will require torrents or jigdo. netinst image, as well as manual install with debootstrap is less convenient to start with, as they will use latest packages by default unless pointed to [debian repository snapshot] or a local mirror.
I'm avoiding snapshot repository as it is rarely mirrored, and I expect it to be less available than many of mirrors. One the other hand, benefit of using jigdo is that it falls back to a correct files in the snapshot after trying all the proposed sources.
For this reason, and to keep the offline copy of as much packages as I can, I opted for building a local mirror:
- Downloaded iso-dvd for installation
- Used it and nearby mirrors to build 16G USB flash from the template, for futher installations
- Finally, repeated the process of using previous image and nearby mirrors to build Dual Layer BluRay, that gave me about 90G of packages.
Any of the images can be used readily by mounting the directory locally or on your nearest web server in insecure mode:
# /etc/apt/sources.list.d/srvdebian.sources
Types: deb
Suites: bookworm
Components: main non-free-firmware
Architectures: amd64
Uris: file:/srv/debian
Allow-Insecure: yes
Trusted: yes
Security updates
Bookworm is already out of maintenance by Debian Security, as it reached EOL on summer 2026. It will be supported as LTS for the next two years.
I didn't really want to go this route, but it is possible to pin down [the upstream bookworm-security][bookworm-security] and selectively update packages from it. Choosing what packages to update mostly depends on personal threat model: e.g. tracking what could be triggered remotely. I'll elaborate on mine later.
# /etc/apt/sources.list.d/bookworm-security.sources
Types: deb
Suites: bookworm-security
Components: main non-free-firmware
Architectures: amd64
Uris: http://security.debian.org/debian-security
# /etc/apt/preferences.d/ignore-bookworm-security
# -1 means enabled only if apt install -t bookworm-security
Package: *
Pin: release n=bookworm-security
Pin-Priority: -1
Internet
Browser-wise, I opted for [Librewolf], as it at least gets security updates (as of September 2026). However, I also preventively disabled JavaScript, and actually need to track at least some security upgrades. I can't say how safe it is.