Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • About Bonfire
Em :official_verified:
@Em0nM4stodon@infosec.exchange  ·  activity timestamp 6 days ago

I despise how security updates are
bundled with feature updates.

Now we have to choose between risking getting malware from random criminal gangs when refusing to update, or getting embedded malware from the tech company itself that comes with their update.

And honestly at this point, I'm not sure which is worse.

#Tech #Enshitification #NoAI

  • Copy link
  • Flag this post
  • Block
Jo - pièce de résistance
@JoBlakely@mastodon.social replied  ·  activity timestamp 4 days ago

@Em0nM4stodon same. It should be illegal.

  • Copy link
  • Flag this comment
  • Block
lord pthenq1
@pthenq1@mastodon.la replied  ·  activity timestamp 5 days ago

@Em0nM4stodon
Try Ubuntu or similar

  • Copy link
  • Flag this comment
  • Block
Mike A
@mcladams@fosstodon.org replied  ·  activity timestamp 6 days ago

@Em0nM4stodon
Dear Debian,
Thank you for being Debian.
Love, Your users.

  • Copy link
  • Flag this comment
  • Block
Hugs4friends ♾🇺🇦 🇵🇸😷
@Tooden@aus.social replied  ·  activity timestamp 6 days ago

@Em0nM4stodon Hubs did an update a couple of months ago, and it locked him out of two apps. He's also been pestered to use AI. I am not going to update.

  • Copy link
  • Flag this comment
  • Block
przemelek
@przemelek@pol.social replied  ·  activity timestamp 6 days ago

@Em0nM4stodon ok, but look on technical side, most of updates is in binary format, and assumes one state, and leads to other. Now if you would like to have 2 updates, one for security, one for features.... it is difficult (I would like to say impossible) in diff approach.
You don't have 1 "start" version but multiple... maybe user has prev security, but not features....
Even for single app it seems that you would need to produce multiple versions of the same update.... lets say, you would always keep only 10 back... so 10 back, user can go with full, or only security... so there are 2 10 back, 9 back... user may start from each of those and choose going with features, or with security.... what will be even more wired...
Even if it would be distributed on source level... nope... it would be backporting security changes, or sometimes writing several versions of those....

Or you have some idea how to do it? Maybe there is some doable way I simply don't see, hope you will share 🙂

  • Copy link
  • Flag this comment
  • Block
Licho
@licho@kolektiva.social replied  ·  activity timestamp 6 days ago

@Em0nM4stodon where are the Linux phones? There are barely any on the market. It's ridiculous. They should have been ready years ago.

Not to be paranoid but I'm pretty certain there is a conspiracy going on, that will be a public knowledge like the light bulb cartel is today.

  • Copy link
  • Flag this comment
  • Block
Glen, waiting for the pre-poll
@glent@aus.social replied  ·  activity timestamp 6 days ago

@Em0nM4stodon I have difficulty with the practice that feature and security updates exist in differing streams which can be cherry picked for release.

Some of the largest security release stuff-ups I've seen has been in security updates backported into older code.

But also, the idea that software has features leaves me cold. That says a vendor doesn't release a software version until the user has a compelling reason (a desired 'feature') to upgrade. It speaks to excessive friction for software updates (waves at Windows) and a business model which doesn't fit cost structure. It all sounds like the 1990s and buying CDs.

After decades of trying we know how to do software in the large, and a code base which is frequently releasable is the norm. That's where the security fix should go. And that software shouldn't be so different from the previous release that the user cares.

  • Copy link
  • Flag this comment
  • Block
Aurimas Liutikas :google:
@Aurimas@androiddev.social replied  ·  activity timestamp 6 days ago

@Em0nM4stodon what do you think is a reasonable and sustainable software update model? How many versions behind do you back port fixes to? For how many months/years?

  • Copy link
  • Flag this comment
  • Block
Em :official_verified:
@Em0nM4stodon@infosec.exchange replied  ·  activity timestamp 6 days ago

@Aurimas It really depends on each piece of software and the type of data it handles.

  • Copy link
  • Flag this comment
  • Block
Aurimas Liutikas :google:
@Aurimas@androiddev.social replied  ·  activity timestamp 6 days ago

@Em0nM4stodon I think it is really difficult to maintain and sustain more than just the latest version of a piece of software, which then in turn leads to fixes shipping together with features. Having had to back port security fixes to an old version of Android I really feel for picking the lowest cost way out.

  • Copy link
  • Flag this comment
  • Block
Wouter 🇳🇱🇧🇷🇧🇪
@AccordingtoWouter@mastodon.world replied  ·  activity timestamp 6 days ago

@Em0nM4stodon At least equally bad

  • Copy link
  • Flag this comment
  • Block
Human 3500
@human3500@ottawa.place replied  ·  activity timestamp 6 days ago

@Em0nM4stodon sometimes, the best option is to change software packages. Harder to do with the OS.

#Tech #Enshitification #NoAI

  • Copy link
  • Flag this comment
  • Block
Zuthal
@zuthal@floofy.tech replied  ·  activity timestamp 6 days ago

@Em0nM4stodon security and feature updates should be separate as far as is practical

except where a feature strictly depends on another feature every feature should be selectable separately

  • Copy link
  • Flag this comment
  • Block
Em :official_verified:
@Em0nM4stodon@infosec.exchange replied  ·  activity timestamp 6 days ago

@zuthal 1000

  • Copy link
  • Flag this comment
  • Block
Arthfach 🐻
@arthfach@social.arthfach.com replied  ·  activity timestamp 6 days ago

@Em0nM4stodon I'd honestly say the in-house malware is worse. At least when criminals are trying to penetrate, you have defense in depth that should be kicking in. If you bring it in-house, however...

  • Copy link
  • Flag this comment
  • Block
Mx. Eddie R
@silvermoon82@wandering.shop replied  ·  activity timestamp 6 days ago

@Em0nM4stodon
Exactly this. Preparatory to shipping iOS 26, my iPad no longer accepts updates, so it's no longer safe to use online.

I was forced to the new MacOS on my work machine, which is a (small, but still) factor in scheduling a job interview this week.

  • Copy link
  • Flag this comment
  • Block
MostlyTato
@MostlyTato@mstdn.social replied  ·  activity timestamp 6 days ago

@Em0nM4stodon
I remember when you had to protect your OS from malware instead of your OS actually being the malware you have to protect yourself from.

  • Copy link
  • Flag this comment
  • Block
Em :official_verified:
@Em0nM4stodon@infosec.exchange replied  ·  activity timestamp 6 days ago

@MostlyTato This👆

  • Copy link
  • Flag this comment
  • Block
Camaleon 🍉🇺🇦
@camaleon@mastodon.social replied  ·  activity timestamp 6 days ago

@Em0nM4stodon I prefer, since years, the random criminal... at least, in this case, the law is in our side, while with the os, the law will protect them.

  • Copy link
  • Flag this comment
  • Block
Log in

Bonfire Dinteg Labs

This is a bonfire demo instance for testing purposes. This is not a production site. There are no backups for now. Data, including profiles may be wiped without notice. No service or other guarantees expressed or implied.

Bonfire Dinteg Labs: About · Code of conduct · Privacy ·
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Code of Conduct
Home
Login