2 ms·
The same reason I tell people to stop running PHP 5.6: If a security vulnerability is discovered, you always want to be on the latest version. If updating req
by CiPHPerCoder 7y ago
The same reason I tell people to stop running PHP 5.6:
If a security vulnerability is discovered, you always want to be on the latest version.
If updating requires a lot of effort and risks, the solution isn't "don't update". The solution is "fix those problems".
- Rochus 7y agoWell, maybe if you have implemented a server in Qt which is accessible to open internet, such as PHP in your example. 99% of the Qt applications I'm aware of are desktop or "embedded". I'm working with Qt since 20 years now and had never a security issue or a known vulnerability relevant to my projects.
- heeen2 7y agoThere is also qtwebkit, the wrappers around ssl which could have issues validating certificates, qml could have issues with untrusted content etc.
- Rochus 7y agoWebKit is a web client library. I'm not even sure why a Qt developer would use it. That's among the first things I delete before compiling the Qt 4.x framework. OpenSSL is yet another third party library which can easily be replaced if need be without affecting Qt. And of course each application is a security risk, but definitely a smaller one than the user in front of the screen.
- JohnFen 7y agoLibrary providers make this really, really hard though. They should do what used to be common practice -- separate security updates from feature updates, so that applications relying on the library don't have to be on the total upgrade treadmill.