Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I fundamentally disagree with your point of 'a patch should be released as soon a possible'.

A patch releases the fix, but by necessity also puts a bright target on the vulnerability it fixes by providing the information on potential exploitable vulnerabilities in the system being patched. From that moment on it is a race between reverse engineering exploit writers and system maintainers to get their work done first.

Having coordination and predictable planning where possible allows companies to include security maintenance into the workload, rather than to have to constantly scramble and react to unforeseen and unpredictable wildfires.

It is not about 'convenience', it is a component of a mature security process.



Security by obscurity. Surely the information on the vulnerability is already out there by the time the patch is released?


No, not necessarily. That's the point of those disclosure timelines.


Security by obscurity can work just fine when it's a two week extension on a bug that has existed for years.


But it never ends at two weeks. Time and time again the vendors will put it off for years if you let them.


I'm defending monthly patches here, not giving vendors extra time.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: