2 ms·
The high expense is caused in part by the current high volume of vulnerabilities. Vulnerabilities and updates are inevitable, but the current volume of them is
by thingification 9y ago
The high expense is caused in part by the current high volume of vulnerabilities.
Vulnerabilities and updates are inevitable, but the current volume of them is not, by orders of magnitude.
The volume of serious exploits could be reduced dramatically if we started to more seriously apply the principle of least authority (and an important technique and way of thinking about that is capability security -- in fact an important technique to make 'brickless updates' easier to achieve too, I suspect).
I think how to kick-start the industry to actually do that is a difficult problem.