logoalt Hacker News

crabmusketlast Wednesday at 12:32 PM1 replyview on HN

FTA, "even make the queued releases available for intentional, explicitly volunteering beta testers to try out." Under the proposed system, you have to opt in to the insecure early releases. Rather than opting out of them. Which seems like a more secure default!


Replies

kibwenlast Wednesday at 6:05 PM

> insecure early releases

This is the wrong framing.

There's no free lunch here. Delays in publishing not only slow down attacks, they also slow down critical security patches. There's no one-size-fits-all policy here, you're at risk either way.