Ask HN: Does CopyFail make a stronger case for rolling releases such as Arch?
1•fullstacking•1h ago
title really says it all.
Comments
davydm•1h ago
Good distros should backport updates like this - the patch has been merged into several downstreams. Whilst I prefer a rolling release, this isn't the reason to do it. You could even be on a rolling release that is behind (like arch - my Gentoo box was patched for this vuln before I even understood what it was, and I could run the exploit on my arch machine days laterz until eventually the update came). Speed of response by the upstream here is more important than anything else.
fullstacking•34m ago
I meant from a software architecture / maintenance standpoint. I assume its that much more work to backport vs just pushing the next change, I also assume this type of issue is only going to happen more thus more backporting / hotpatches ect.
davydm•1h ago
fullstacking•34m ago