Hacker News new | ask | show | jobs
by cookiecaper 3671 days ago
>"keeping your system patched is a prerequisite to remaining secure" Completely false. This will 100% NEVER be a sane security model. The one true way is to have verified secure software installed in the first place. That is not impossible. It is just more expensive than releasing patches as flaws are exposed. Do not be fooled by the general flow indicating correctness.

While theoretically possible, it is not currently reasonable to employ this model for modern general-purpose operating systems. We're going to have to live with requisite patching and updates for a long time yet.