Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't agree that it's absurd. I would say it reflects a proper understanding of their situation.

You've doubtless heard Tony Hoare's "There are two ways to write code: write code so simple there are obviously no bugs in it, or write code so complex that there are no obvious bugs in it.". Linux is definitely in the latter category, it's now such a sprawling system that determining whether a bug "really" has security implications is no long a reasonable task compared to just fixing the bug.

The other reason is that Linux is so widely used that almost no assumption made to simplify that above task is definitely correct.



That's fine, except that it is thus no longer meaningful to compare CVE count.


I like CVEs, I think Linux approach to CVEs is stupid, but also it was never meaningful to compare CVE count. But I guess it's hard to make people stop doing that, and that's the reason Linux does the thing it does out of spite.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: