Linux Kernel Security Done Right (Google Security Blog)
Linux Kernel Security Done Right (Google Security Blog)
Posted Aug 5, 2021 9:22 UTC (Thu) by ncm (guest, #165)Parent article: Linux Kernel Security Done Right (Google Security Blog)
Most companies perceive software updates through the filter of (1) it still works, (2) it broke. Not updating guarantees (1). Updating risks (2), meaning some unknown fraction of updates produce (2), while the rest are (1) and seen as exactly as good as the previous version, not better.
In such an environment it is not hard to see why updates are considered nothing but trouble. Without a change in incentive structure, there is no reason to expect a change in behavior will even be possible in almost all organizations.
