| ▲ | hn_throwaway_99 4 hours ago | |
How do posts like this make it to the top of HN? Nearly all the comments here are saying the same thing I thought: 1. Security researchers and companies are incentivized to install packages early. 2. Even without security patches, people and teams can still set the cooldown period that is appropriate to their risk tolerance. Even if someone in the wild does "get bit", it's better that a smaller number of people get bit than everyone getting bit at the same time. That's not "security theater", that's limiting the blast radius. I'd also add that adding in cooldown periods lowers the incentives for bad guys to try to compromise a package in the first place because there is a much greater chance all their work will be for naught. So I started reading this post with interest, thinking it would have some reason I hadn't thought of, but it just boils down to the faulty premise that "Godot is not coming". Bullshit, at the very least I now have agency over where I am in the download timeline. I just don't understand how such bad posts built on the flimsiest of assumptions make it to the top of HN. | ||
| ▲ | some_random 4 hours ago | parent | next [-] | |
It has a pessimistic title and just like redditors most HN voters don't read the articles they vote on. | ||
| ▲ | pixl97 4 hours ago | parent | prev [-] | |
I have no idea either. Every argument I hear about why wait times won't work are just factually wrong and using terrible assumptions they have zero insight into. And, the complainers are free to set the wait timer to 0 and go back to the way it was. I'll be glad to let them be the first penguin to jump in the water. | ||