A turning point for CVE numbers
A turning point for CVE numbers
Posted Feb 20, 2024 13:42 UTC (Tue) by pizza (subscriber, #46)In reply to: A turning point for CVE numbers by gmgod
Parent article: A turning point for CVE numbers
What's the standard financial disclaimer... "past performance is no guarantee of future success"?
I once publicly called out someone (who _definitely_ should have known better) for professional incompetence after they went on a "systemd is responsble for everything wrong with society!!!111" rant after something went wrong on a Debian 9 (I think) upgrade on a critical system. A remote, (completely) headless critical system.
...Because you don't do _any_ updates on critical systems without some measure of testing first. Or, at minimum, some sort of reversion/recovery procedure. While even basic (end-user) smoke tests would have caught this particular failure [1] the fact that there wasn't any thought given to recovering from an update failure (not even "remote hands" capable of hooking up and looking at the local console) was inexcusable.
[1] Due to non-Debian-supplied software failing to start properly and systemd actually catching the failure instead of ignoring it.
