Security Updates Debate

The cluster discusses the pros and cons of software security updates, including risks of new vulnerabilities from updates, the necessity of timely patching to avoid exploits, and debates on update frequency and manual vs. automatic application.

📉 Falling 0.4x Security
5,099
Comments
20
Years Active
5
Top Authors
#3891
Topic ID

Activity Over Time

2007
2
2008
8
2009
36
2010
56
2011
92
2012
72
2013
180
2014
213
2015
246
2016
349
2017
448
2018
306
2019
373
2020
352
2021
510
2022
481
2023
481
2024
473
2025
401
2026
22

Keywords

IT RHEL EOL AWS SLES ASAP OS SOUP CVE updates security security updates fixes update updating patches flaws vulnerabilities upgrade

Sample Comments

rightbyte Oct 7, 2021 View on HN

Security patches and general updates are not distinct anymore. You might aswell end up with more bugs by updating.

linsomniac Jan 20, 2017 View on HN

... then isn't it not a big deal to commit to security updates?

bromuro Sep 26, 2022 View on HN

Updates may be a security threat too… didn’t log4j become a security treat _because_ it had been updated?

renewiltord Dec 18, 2025 View on HN

"Don't give me security updates every time there's a security issue. Instead do it occasionally because I like my vulnerabilities to be a surprise"

mesozoic Jul 21, 2018 View on HN

Not until theres a critical security vulnerability where you must upgrade.

jjeaff Dec 27, 2024 View on HN

the alternative is leaving software eternally insecure as people will not update them. and of those that will, 99.99% (probably not an exaggeration) will not have the interest, time, or ability to review code changes before updating.

allerratio Dec 11, 2012 View on HN

Not updating a package is the best way preventing security flaws to get fixed

vbezhenar Feb 25, 2023 View on HN

Not everyone cares about security updates.

fragmede Sep 6, 2023 View on HN

That depends on updates never introducing new vulnerabilities.

goldbrick Mar 28, 2016 View on HN

Fine, you're okay with old bugs. You're pretending that that's the main issue though. What's your excuse for punting on security updates?