4 ms·
My point is that patching third party binaries is generally not something companies take responsibility for. They wait for vendors to patch the binaries and shi
by staticassertion 5y ago
My point is that patching third party binaries is generally not something companies take responsibility for. They wait for vendors to patch the binaries and ship them.
- jiggawatts 5y ago> generally not something companies take responsibility for I have some bad news for you: viruses and hackers don't care about your support contracts and the delays they cause. Actually, I tell a lie: the hackers love them.
- staticassertion 5y agoThat's not relevant? The original premise here is "compiled languages will make things worse because they're harder to patch" except: a) It's very rare to patch things manually b) It's very rare to develop patches yourself (for 3rd party software) I'm sure some companies out there with many decades old deployments have to do stupid shit like that, but it's hardly the standard.
- lazide 5y agoHaving been on the receiving end of waiting a long time to get a patch for a actively being exploited zero day - the point is, even if you want to fix it yourself (which I desperately did), you can’t. If it’s some important piece of software you also can’t stop or the business stops - well, you and everyone else is just going to take it in the pants. Many enterprises are in exactly this bind. And support contracts only get you so far.
- staticassertion 5y agoI'm losing your point. So, you wanted to patch it, and you couldn't, so how is it bad then that a compiled binary would make patching more difficult?
- lazide 5y agoIt was impossible to fix because it was a compiled binary with no available source. That’s the point.