Gordon Messmer
gordonmessmer@fosstodon.org
Posts
-
Post #3161656
I'm a little worried that a generation of admins has been conditioned to believe that a package manager is a substitute for a vulnerability scanner. No pending updates != No vulnerabilities
-
Post #2989190
After managing production networks for 30 years, I believe that LTS systems exist to prioritize compatibility with the ecosystem in which they operate, whereas more recent releases will typically have the smallest number of known security flaws. Apparently there are people who don't believe this?
-
Post #2989189
SeaGL is coming up and CfP is open. I don't see any talks in their last 10 years of archives that discuss the difference between LTS and regular release systems from a security point of view. I am finding that far more people than I expected believe that LTS systems offer better security. Do you think such a talk would be interesting or useful?
-
Post #2989188
One of the things I love about Free Software is the pervasive spirit of collaboration and respect. But at the same time, I think that we are failing our community by never discussing the trade-offs required for development processes like LTS distributions, because it sounds too much like criticism.
-
Post #2989187
It's much more accurate to see a free LTS release as the period during which you can participate, rather than the period during which your system gets support. Despite the name, free LTS systems come with no support, and you should not assume that the packages you use and care about will be maintained unless you participate in their maintenance.
-
Post #444507
Someday I hope to be able to describe technical concepts as clearly as this. Thank you @samwho https://samwho.dev/memory-allocation/