6 ms·
Unfortunately, it's been established for a long time now that users cannot be trusted to perform updates by themselves, no matter how naggy you get about it, ev
by Chabsff 3y ago
Unfortunately, it's been established for a long time now that users cannot be trusted to perform updates by themselves, no matter how naggy you get about it, even for the most critical of security fixes.
Automatic updates, again unfortunately, are critical to safety.
- Blackthorn 3y agoUsers often don't want to perform updates because the updated version is worse in some way. That it has a security impact is unfortunate, but that's how it is.
- harkinian 3y agoI had an extension update itself and partially stop working. There's no way to go back to a previous version unless you happen to back up the old files.
- jasonjayr 3y agoAnd these automatic updates are often abused to remove or change features, or generally "enshitify" things. Which breaks trust and we are back to square one.
- woliveirajr 3y agoCritical to the user safety? Well, that's not a problem. Critical to the safety of some site/other users? Then the problem is a bit deeper, as my computer/software shouldn't be able to affect someone else.
- TeMPOraL 3y agoFind a way to do security patches without restarting the application or interrupting user's work, and keep featuers/enshittification updates separate from security patches - and then people will not mind auto-updates. Hell, you could just apply them and not even ask anymore.
- ifyoubuildit 3y agoThis attitude is a large part of what I find so repulsive about tech today. You are a guest on my machine. No matter how much you think you know better than me (even if you're right!), you don't get to make decisions like that. You can ask nicely, and if you can convince me that something needs to be done, I will decide to do it.
- ssl-3 3y agoWhy, sure. And I'll bet you prefer to do your own vehicle maintenance, too. But automatic updates aren't for you or me, or any of the other geeks here. They're for everyone else.
- bakugo 3y agoMy device is mine, not everyone else's. It's not your decision to make regardless of whether or not you think it's best for the "greater good".
- ssl-3 3y agoYou're not wrong. Fortunately, you have choices. You can choose to avoid software and operating systems that feature automatic updates. You can even write it yourself, if you wish: You're absolutely empowered to be absolutely in control of your things. There's nothing stopping you.
- ifyoubuildit 3y agoPractically speaking, we have the choices that one monopoly or another offers us, and only so long as those choices are convenient for them. I do avoid corporate overreach where it's practical (I have a dumb TV/vehicle/appliances/etc), but there will come a day when it's impossible to participate in society without giving in.
- ssl-3 3y agoLife is whatever you want it to be. There's plenty of ways to get through life that don't involve computers or software or television. You can choose differently than you have.
- ptx 3y agoIt has also been established that vendors cannot be trusted to refrain from bundling unwanted feature changes (and sometimes straight-up malware) with their security updates, so it's no wonder that users might be reluctant to install such updates.
- ryandrake 3y agoYes, this is the reason I do not enable automatic updates (in general, not just browser addons), and that software updates are so frustrating. If there was a way to specify I only want security updates and bug fixes and I do not want new features, UI redesigns, and so on, I would always update and maybe even turn on automatic updates. Software companies have no excuse--we have sophisticated version control software that allows you to manage multiple branches easily. Every software should have a maintenance branch and a "new shit" branch, and should allow both kinds of updates.
- chatmasta 3y ago> I only want security updates and bug fixes Just FYI, for iOS updates, you can in fact opt into these release channels separately. Go to Settings > General > Software Update > Automatic Updates. You will see two separate toggles, one for "iOS Updates" and another for "Security Responses & System Files."
- harkinian 3y agoYeah, it's nice. Also, old major iOS versions still get security updates, so a very old iPhone is still practically usable.
- bakugo 3y ago> Unfortunately, it's been established for a long time now that users cannot be trusted to perform updates by themselves, no matter how naggy you get about it, even for the most critical of security fixes. So let them not update. It's not your device, it's theirs. Mind your own business.
- mtlmtlmtlmtl 3y agoProblem is every single update claims to be security fixes, like for Android. Now I realise almost any bugfix can be construed as a security fix, but I've never seen an Android update that doesn't claim to include security updates, and I've never seen one that goes into any kind of detail(in the pop up prompt that is) on what any of the updates entail. Probably some of those were critical, and some of them were completely unlikely to affect real world security. As a user, how do I know when to take it seriously and when not to? All I'm told by the UI is that every single update they push "improves security and performance".
- bossyTeacher 3y agoThis if the ToS problem. Tell me, of the many services you use and products you own, how many ToS have you read? 3%? 10%? Probably less than 2%. Changelogs and release notes have the same problem. They take time to create, edit and review and no one who matters reads them. Why would they spend their time on it?
- mtlmtlmtlmtl 3y agoI get your point, but changelogs can often be generated semi-automatically from VCS. And I realise I'm not the typical user, but I actually do read(skim) TOS just to see if there's any centipad like stuff. Most of it is just boilerplate and you get pretty quick at finding the substantive parts with some practice. Of course TOS/EULA are hard to read for most people by design. They don't actually want you to read it. If they did, they'd offer a summarised version without all the legalese boilerplate. I get the same feeling about changelogs. They probably have one internally if they know what they're doing. It may even be online somewhere if I go looking. I can only surmise that for whatever reason, they don't want me to read it, which doesn't inspire trust.
- deleted 3y ago[deleted]
- Karellen 3y agoThe trouble is, security fixes (generally) don't get backported to older branches. If older branches are even a thing. Say you're on Foo 1.4.7, and the jump to Foo 1.5 includes a feature re-org you don't want, and no security fixes. So you hold your version on 1.4.7. But then a security issue is found, and Foo 1.5.1 is released with a fix. Is the version you have vulnerable? Maybe, depending on where the bug is. Is there a 1.4.8 update to fix it? Maybe not. How would you even get it? Heck, if you've switched off automatic updates, have you even heard about the 1.5.1 release? Are you checking on the release announcements for Foo to find out if there have been any security updates, ever? OK, maybe you check those things. But do you think J. Random User who saw a post on Reddit that said 1.5 sux0rz and they should stay on 1.4.x is going to? And do you like having botnets? Because that's how you get botnets.
- harkinian 3y agoAre outdated Chrome extensions really attack vectors? They're very sandboxed. I'd be way more concerned about the update itself being malicious, especially for simple extensions that shouldn't really need updates.
- Chabsff 3y agoPedantically, outdated Chrome extensions make for a poor attack vector in the first place because the majority of users get automatic updates, including being disabled/removed by Google themselves if the dev is gone and a problem is found.
- harkinian 3y agoYeah, I meant if they weren't automatic. Or to make things less theoretical, how often do extension devs currently find and patch security flaws?