zlacker

[parent] [thread] 4 comments
1. lopken+(OP)[view] [source] 2025-01-05 14:14:25
What motivates this attitude? Software, like anything else, needs to be actively maintained. This is a positive sign of technology evolution and improvement over time. To expect to run some software for 20 years without needing to apply a single security patch is ridiculous, and probably exactly the attitude that caused the author to get himself in this situation.
replies(1): >>kibwen+l7
2. kibwen+l7[view] [source] 2025-01-05 15:16:14
>>lopken+(OP)
> To expect to run some software for 20 years without needing to apply a single security patch is ridiculous

The whole point of my comment is that it's only "ridiculous" because of path dependency and the choices that we have made. There's no inherent need for this to be true, and to think otherwise is just learned helplessness.

replies(2): >>ocdtre+4a >>oarsin+da
◧◩
3. ocdtre+4a[view] [source] [discussion] 2025-01-05 15:36:51
>>kibwen+l7
Better security design fixes this. Sandstorm fixed this for self-hosters ten years ago (Sandstorm is designed to run unmaintained or actively malicious apps relatively safely), but people are still choosing the quick and easy path over the secure one.
replies(1): >>ferfum+Xe
◧◩
4. oarsin+da[view] [source] [discussion] 2025-01-05 15:39:11
>>kibwen+l7
Has there ever been any production software ever written that didn’t suffer from some kind of bug or exploit?

I don’t think imperfection is a choice we’ve made. I think imperfection is part of our nature.

That said, the current state of software development is absolutely a choice, and a shockingly poor one in my opinion.

◧◩◪
5. ferfum+Xe[view] [source] [discussion] 2025-01-05 16:17:42
>>ocdtre+4a
This is so true.

Sandstorm has been part of my selfhosted stack since it was a start-up, and it has worked for a decade with virtually zero attention, and no exploits I am aware of.

If there are other hosted apps that want a really easy on-ramp for new users: packaging for sandstorm is an easy way to create one.

[go to top]