3 ms·
I'm not sure there's a difference in practice. Sure it's not that there are known problems, but security isn't a thing you have or don't have; it's a process.
by technomancy 11y ago
I'm not sure there's a difference in practice.
Sure it's not that there are known problems, but security isn't a thing you have or don't have; it's a process. If your process for identifying and fixing security flaws is broken, that's insecure.
- duskwuff 11y agoUpstream is patching security flaws just fine. The problem is that you can't get the security fixes alone; they only come along with version updates, which Debian stable doesn't want.
- technomancy 11y agoI understand this; I'm saying that a security process that ignores users who value stability over the latest hotness is broken for all use cases I actually care about.