|
|
Subscribe / Log in / New account

Bad default, but be careful if you stop anybody's pig from dancing

Bad default, but be careful if you stop anybody's pig from dancing

Posted Sep 5, 2017 14:04 UTC (Tue) by tialaramex (subscriber, #21167)
In reply to: The 4.13 kernel is out by ledow
Parent article: The 4.13 kernel is out

There is a balance here, because of Dancing Pigs a large proportion of people whose device ceases to work because of security will label that as "Your thing is broken" not "Hooray for protecting me". It makes no sense for Linux to deliberately put up a fence where the equivalent Windows systems just shrug "Eh, who needs security when you can have compatibility?". However it looks as though Microsoft is moving in the same direction, there's no need for us to be _worse_ than them about security holes they're responsible for.

There's a "First Mover" penalty which is why the Web Browser Vendors sometimes behave like a cabal - if they all make your pig stop dancing at roughly the same time, you might shake your fists and blame the cabal, but at least you won't switch to the least secure option just because it keeps your pig dancing. This avoids the Powers That Be looking at the situation and deciding by fiat that there won't be any more security fixes, all pigs must be permitted to continue dancing even if it hairlips the governor.

There's also "Last change gets the blame" at work. In many cases the reason an organisation (or home) needs SMB1 is some obsolete third party device they've become dependent on. But they bought that years ago, and humans have learned to blame the new thing, for completely rational reasons, so even though the _right_ fix might be to replace that 10 year old printer or WiFi router, the actual fix may be to return the shiny new secure Linux appliance and get the insecure alternative instead.


to post comments

Bad default, but be careful if you stop anybody's pig from dancing

Posted Sep 8, 2017 15:05 UTC (Fri) by NightMonkey (subscriber, #23051) [Link]

I think you and I might be supporting the same users? It's like you are writing entries in my diary. Especially the last paragraph.


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds