Fast upgrades
Fast upgrades
Posted Apr 27, 2026 9:31 UTC (Mon) by farnz (subscriber, #17727)In reply to: Fast upgrades by roc
Parent article: Dependency-cooldown discussions warm up
There's a stochastic element, though. Some vulnerabilities are "wormable", and really do need patching immediately, because you'll be probed in the next few minutes. Others, however are not - if the botnet time to probe for the vulnerability in your site means that it's uneconomic to probe more than 1% of sites in a day, then you have days before you're above the "more likely to be exploited than not" line.
Now, this comes with the caveat that if you're a high-value target, you're likely to be in the first day's worth of probes, but for many people, a week's delay is an acceptable risk - there are more likely causes of issues than a 10% chance of having the vulnerability exploited.
And for consumer software, it goes further. You do not need to upgrade until you're next about to run it; I have an app on my phone that I use rarely (once a month or so), and which has thus spent more time being upgraded than being used. I would not suffer any harm if, instead of upgrading every week or so, when a new update comes out, I upgrade once a month (when I'm next going to use it). Sure, I'd have vulnerable versions on my phone for longer - but it's not running code, so can't be exploited.
The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:
Note: you can avoid this step in the future by logging into your LWN account.
