Hacker News new | ask | show | jobs
by arandomhuman 54 days ago
Aforementioned security vulnerabilities don’t strike as a potential reason to you?
1 comments

Friend, considering the supply chain attacks going on these days, automatically updating everything, immediately, probably isn't the perfect move either.
You need to automatically update from a trusted source. That source better audit and update constantly. Which is hard.
Stable distributions have security teams.
Ignoring the real benefits of security updates to prevent the unlikely event of supply chain attacks sounds like a weird tradeoff.
A weird tradeoff but an increasingly important tradeoff to keep in mind nonetheless. Like I said, updating immediately isn't a perfect answer. But neither is waiting. I hope you're having this discussion, at least.