Hacker News new | ask | show | jobs
by ok123456 296 days ago
CVE inflation is real. Most CVEs are of very low quality.

Anyway, security updates should be decoupled from feature updates, so that people aren't hesitant to update. Otherwise, you get people who hold out because they're worried the new release is going to break all their settings and "opt-in" into all kinds of new telemetry.