Hacker News new | ask | show | jobs
by mixmastamyk 4622 days ago
And some software has almost an order of magnitude more vulnerabilities while simultaneously being unnecessary for most folks.

Oracle has been issuing ~50 per quarter recently, an incredibly long time to wait for critical fixes. In security, less is more. Now that Windows has become safer, the big targets are Java and Flash. It continues to be good practice to avoid standing behind big targets.

1 comments

Firefox has had in the region of 30-40 advisories per quarter recently, hardly an order of magnitude more vulnerabilities than the ~50 you mentioned as the Java plug-in's recent record.

Also, as has been pointed out in numerous recent debates about Java, it might be unnecessary for most folks, but there are still many millions who use it routinely. Indeed, this is precisely why I think Mozilla's U-turn on this issue was a sensible move.