5 ms·
I never even patch automatic updates to my OS either (e.g. OS bigSur). I'd rather not guinea pig the latest updates and they usually don't add all that much val
by Kagerjay 6y ago
I never even patch automatic updates to my OS either (e.g. OS bigSur). I'd rather not guinea pig the latest updates and they usually don't add all that much value for chrome extension releases either, so a way to turn off automatic updates in chrome is highly desirable for me.
Download and unpacking from github is a pita, I'd need to do this to each of my computers seperately
- smt88 6y agoThis is a terrible security practice. Switch to Chromium and use a package manager to stay up to date. Don't freeze updates, especially on your browser.
- sokoloff 6y agoI work in software. I know the dangers of a day 0 exploit. I also know the dangers of an x.0 release of software. Security is often in tension with convenience/usability (as in this case). Concretely: I don't update to the latest MacOS day of release. I do update after a few weeks of "no significant issues reported" (or I'll update manually faster if I learn of a serious exploit). I still haven't updated to BigSur as some of the software that I rely on doesn't work on BigSur yet, so I'm on the latest patch of Catalina.
- jrochkind1 6y agoI'm not going to update to a new MacOS "named" release until it's been out for a while and probably has a patch release or two, agreed. But I install MacOS patch releases as soon as they are offered. It has never caused me a problem I am aware of, and I don't want to miss out on security patches, or even just bugfixes and perf improvements. Heck, I actually just upgraded a MacBook that was still on 10.12, which was EOL'd. But I upgraded it because it was EOL'd, and wasn't getting patch releases for security fixes, and I want those patch releases as soon as they are released!
- smt88 6y agoYou should let clients and users know that you care more about convenience than security so that they can make an informed decision about whether to trust their data with you. I don't know what x.0 software updates you're talking about (Chrome or Mac), but my comment never mentioned any. You don't seem to know that browser vendors don't really do those like OS vendors do. Either way, you can still avoid those while gettong security updates. In my memory, there hasn't been a breaking auto-update in Chrome in years, but there have been hundreds of 0-days. The numbers don't really work out for the tradeoff you claim to be making.