top | item 34574833

(no title)

jessermeyer | 3 years ago

There is obviously a trade off here, but categorically speaking, new releases introduce new bugs and security exploits too.

discuss

order

palata|3 years ago

But they do patch the known security exploits that are likely to be actively used. I'm happier with a security exploit (almost) nobody knows than with a published one that appears in hacking tutorials from 10 years ago.

jessermeyer|3 years ago

There are two degrees of separation here though: The software vendors and then the linux distros.

If you sell software that requires your clients to upgrade their system-wide security stack, so they might not. If it is statically linked, no need for them to.