you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 1 week ago (1 child)

Yeah I got to this in the blog and stopped:

" I don't think that we're any safer than before. That's because finding vulnerabilities has never been the bottleneck in information security. The bottleneck isn't even verifying a vulnerability report and validating its severity, as time consuming as that is. The bottleneck isn't determining the fix, creating the patch, or publishing a new release. The bottleneck is still, as ever before, getting the goddamn packages updated. "

Dude thinks security through obscurity is valid and thinks running

sudo apt update && sudo apt upgrade -y

Is the really hard part.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 1 week ago

    running

    sudo apt update && sudo apt upgrade -y

    Is the really hard part.

    That's not the hard part to do, it's the hard part to get other people to do, particularly those who can't just run the package manager or let in-doze play patch roulette every Tuesday.

    Security through obscurity isn't going to cut it in the future, much less than it already didn't in the past.

    Security through air-gapping is still pretty good.

  • source
  • parent