" I don’t think that we’re any safer than before. That’s because finding vulnerabilities has never been the bottleneck in information security. The bottleneck isn’t even verifying a vulnerability report and validating its severity, as time consuming as that is. The bottleneck isn’t determining the fix, creating the patch, or publishing a new release. The bottleneck is still, as ever before, getting the goddamn packages updated. "
Dude thinks security through obscurity is valid and thinks running
That’s not the hard part to do, it’s the hard part to get other people to do, particularly those who can’t just run the package manager or let in-doze play patch roulette every Tuesday.
Security through obscurity isn’t going to cut it in the future, much less than it already didn’t in the past.
Security through air-gapping is still pretty good.
Yeah I got to this in the blog and stopped:
" I don’t think that we’re any safer than before. That’s because finding vulnerabilities has never been the bottleneck in information security. The bottleneck isn’t even verifying a vulnerability report and validating its severity, as time consuming as that is. The bottleneck isn’t determining the fix, creating the patch, or publishing a new release. The bottleneck is still, as ever before, getting the goddamn packages updated. "
Dude thinks security through obscurity is valid and thinks running
sudo apt update && sudo apt upgrade -y
Is the really hard part.
That’s not the hard part to do, it’s the hard part to get other people to do, particularly those who can’t just run the package manager or let in-doze play patch roulette every Tuesday.
Security through obscurity isn’t going to cut it in the future, much less than it already didn’t in the past.
Security through air-gapping is still pretty good.