• Blue_Morpho@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 hours ago

    Yeah I got to this in the blog and stopped:

    " I don’t think that we’re any safer than before. That’s because finding vulnerabilities has never been the bottleneck in information security. The bottleneck isn’t even verifying a vulnerability report and validating its severity, as time consuming as that is. The bottleneck isn’t determining the fix, creating the patch, or publishing a new release. The bottleneck is still, as ever before, getting the goddamn packages updated. "

    Dude thinks security through obscurity is valid and thinks running

    sudo apt update && sudo apt upgrade -y

    Is the really hard part.

    • MangoCats@feddit.it
      link
      fedilink
      English
      arrow-up
      0
      ·
      4 hours ago

      running

      sudo apt update && sudo apt upgrade -y

      Is the really hard part.

      That’s not the hard part to do, it’s the hard part to get other people to do, particularly those who can’t just run the package manager or let in-doze play patch roulette every Tuesday.

      Security through obscurity isn’t going to cut it in the future, much less than it already didn’t in the past.

      Security through air-gapping is still pretty good.