3 ms·
> stupid I am not defending the totality of EFX's process by any means. I am just pointing out that "install every high severity patch right away" is not as ea
by wavegeek 9y ago
> stupid
I am not defending the totality of EFX's process by any means. I am just pointing out that "install every high severity patch right away" is not as easy as it looks.
Others have pointed out this patch was not available for all current versions, for example. So, to install the patch you need to upgrade. Oh, that breaks <dependency>. So we need to upgrade <other thing>. But that regresses a feature we use ....
The major issue with EFX was the fragility of their overall architecture. A single weakness should not be enough to lay the whole DBMS open.
- speedplane 9y agoThe tech industry has to move more towards declarative systems, rather than procedural ones. Docker, Kubernetes and similar tech can auto-update in the background without any downtime. It's impossible to maintain thousands of VMs without some sort of declarative system.
- qaq 9y agoEach thing you are listing increases complexity and attack surface.
- speedplane 9y agoIt actually decreases complexity. Updating 1000 VM servers using these technologies can be made automatic. True, it provides an additional attack surface, but the gains of having everything always patched are well worth it.
- qaq 9y agoEverything does not include your actual app, so yes it's convenient but doesn't really help that much
- speedplane 9y agoI'd argue that convenience is a security feature. The easier something is to do, the fewer mistakes you or your team will make. Stand by my initial post, declarative systems will become more and more popular and will improve security.
- thehardsphere 9y agoWhat is the non-tech industry supposed to do?
- georgebarnett 9y agoThere are great reasons for not installing patches right away. "There might be an outage" is not one of them.