|
|
|
|
|
by dijit
409 days ago
|
|
I hear what you're saying and I agree, but it's perhaps too black and white. Let's take one of the most disastrous bugs in recent history: meltdown. Speculative execution attacks inside the CPU. This required (in Paul Turners words): putting a warehouse of trampolines around an overly energetic 7-year old. This, understandably took a lot of time, both for microcode and OS vendors.. it took even longer to fix it in silicone. Not everyone is running SaaS that can deploy silently, or runs a patch cadence that can be triggered in minutes. I work in AAA games and I'm biased, we have to pass special certifications to release patches, if your publisher has good relations, waiting for CERT by itself (after you have a validated fix) is 2 weeks. |
|
What actually should have happened there is a full recall of all affected hardware. Microcode fixes and payments for lost performance in the mean time, until the new hardware arrives.
Meltdown was a desaster, but not only because the bugs themselves were bad. But also especially because we let Intel and AMD get away scott free.