Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I would think ideally, programmers wouldn't break things that are working. We know that ideal doesn't pan out.


"programmers wouldn't break things that are working"

So you want the world's best security experts to manually review every module of every program you use, as well as every piece of every operating system you want it to run on, to make sure there are 100% certainly no exploitable bugs that could require a fix down the line?

That's the same argument, but with reality applied.

Programmers don't "break things that are working", people find design flaws that could lead to remote exploitation. If you don't patch your stuff, enjoy being 0wned, not my problem. For the rest of the world, bleeding edge is the safest place to be.


Yes, yes I would love that. Though, as I noted, nobody expects that ideal to pan out.

Reality applied to many large organizations to the prospect that things may break on an upgrade translates to "don't upgrade."

And really, this isn't necessarily bad. So long as what isn't getting upgraded has been compartmentalized and does its job correctly. Consider, we don't even think about asking companies to upgrade processors on a yearly basis. Monitors? Good for years. Actually, pretty much all of the hardware.

Why do we think software should be different?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: