HN2new | past | comments | ask | show | jobs | submitlogin

I think the idea is that everyone would get the info at the exact same instant. It also allows everyone to be "at their computer" ready to implement the fix.

It would mitigate the possibility of it leaking and getting exploited by someone.



That's foolish, and doesn't take into account how software updates are actually rolled out in the real world.

Many vendors will not just simply compile a new version of a library from upstream source and just throw it on their machines. They depend on a tested release from their distribution maintainer, or something along those lines.

Also many vendors aren't prepared to do a simple upgrade: some may have customization they need to forward-port and test. Or perhaps they'd prefer to backport the fix to their older version.

So basically, your "everyone gets info at once" means that blackhats can get the information and exploit it almost immediately, while the good guys scramble to -- much more slowly -- patch their systems.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: