|
|
Log in / Subscribe / Register

Linux Kernel Security Done Right (Google Security Blog)

Linux Kernel Security Done Right (Google Security Blog)

Posted Aug 5, 2021 9:22 UTC (Thu) by ncm (guest, #165)
Parent article: Linux Kernel Security Done Right (Google Security Blog)

Most companies perceive software updates through the filter of (1) it still works, (2) it broke. Not updating guarantees (1). Updating risks (2), meaning some unknown fraction of updates produce (2), while the rest are (1) and seen as exactly as good as the previous version, not better.

In such an environment it is not hard to see why updates are considered nothing but trouble. Without a change in incentive structure, there is no reason to expect a change in behavior will even be possible in almost all organizations.


to post comments

Linux Kernel Security Done Right (Google Security Blog)

Posted Aug 5, 2021 13:31 UTC (Thu) by mathstuf (subscriber, #69389) [Link]

Unfortunately, this leaves the externalities of security breaches via holes that were fixed, but not deployed. Until that starts getting factored in (via fines or actually punitive damages…not piddling amounts like $7.5M [1]), updates are always going to be "more risky" because companies put blinders on to the risk associated with staying on the current version. We have safety standards for infrastructure such as bridges, buildings, roads, etc. I really don't see why we completely ignore it for the infrastructure we've layered underneath everything else (as a society).

[1] https://arstechnica.com/gadgets/2021/08/google-class-acti...


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds