Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Most of the time a security patch doesn't break software. There are exceptions and disasters have of course happened but you're kind of conflating general updates, upgrades and security patching. You can even canary test patches against percentages of your userbase since it's really simple with a Windows environment. Patching windows itself is probably the easiest thing to patch in an enterprise environment. The real reason these companies/organizations don't patch Windows is because they don't prioritize it and/or they're lazy.


You speak in certainties about vagaries.

There are plenty of companies where "most of the time it's not broken" is a big problem. Possibly bigger than the cost of a security issue (I don't know, because this is both hypothetical and I'm an outsider to the issues at play).

To not acknowledge that others would value a different part of the risk curve lacks perspective.


I mean, in my line of work Windows Update suddenly running and rebooting means fire risks. I wish I could connect the computer to the network so I could monitor equipment remotely, but it's too much risk. I hope utilities take the same measures. Certainly some work computers are vulnerable to all mess of viruses from not having gotten updates in years.


> I mean, in my line of work Windows Update suddenly running and rebooting means fire risks.

With all due respect, if that's the case you should not be running Windows.


I agree in spirit, but there's always a balance. And to clarify, I meant "risk" in the "failure analysis" sense. I didn't intend to imply that such risks should go unmanaged. Disconnecting from the internet is part of that risk management, but of course it is multi-layered.

I can't buy an Emerson control system for a small reactor getting reconfigured every other week, and LabView on an un-networked Windows computer is perfectly fine.

I would not use a PC (with any OS) to control a 10 kg reactor though. At least directly. I think it'd be okay to use a PC to coordinate discrete controllers as long as they couldn't change state without a command (i.e. latching valves and the like) and as long as there was a backup safety that didn't have a computer in the loop.

Safeties that do things like shut off furnaces if temperature sensors break or valves that shut off flow if it becomes too high or detect a flame are common, analogous to a fuse on a circuit board. You sure hope not to use them, but they'll suffice for unexpected situations.

But there's definitely a risk that has to be managed, and connecting infrastructure and industrial equipment to the internet is not managing it very well!




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: