Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

A big driver of automatic updates in the late 00s and early 10s were people who never updated their OS or browser and were getting compromised left and right. As I recall, one of the earliest widespread users automatic updates was Google with Chrome, which they did because otherwise there was no way to respond to severe 0days and such before huge swathes of users got hit.

So I think there's a place for automatic updates, but the feature should be restricted to security fixes only. Using it to foist ill-conceived changes on users is just abuse.



Agree. Security fixes are the killer app for automatic updates. I would argue there are other kinds of fixes that should make the cut: crash bugs, data loss bugs. Maybe even broken features, interaction annoyances, etc. Then it becomes a slippery slope, and the risk/benefit trade-offs are harder to arbitrate.

I don't think "ill-conceived" is giving enough credit. It has been clear to me for a long time that "security" is the justification for pushing the user to update, but the updates themselves are frequently leveraged as a vector for other, less user-friendly, practices.


Yeah people never wanted to update Windows since they had been burned in previous upgrades and their current setup just worked. Not only were upgrades difficult to do and took a long time, many times the new version was just worse or requires relearning lots of things. For what, asked the normal user?! But MSFT tied IE browser updates to OS updates just to make things so much worse for those people since now their choice was to either upgrade and have to deal with the distress of your UI changing, or be vulnerable to widely known exploits in your outdated browser.

My late dad preferred to not upgrade at any cost to the end!


That holds for major upgrades (e.g XP → Vista), but those didn’t used to just happen on their own. In the time frame my previous post was speaking of, one still had to buy major upgrades, and updates within the same version rarely brought significant UI changes. So in reality, there wasn’t much valid reason for there to be for example XP and 7 machines still running initial releases or early service packs for years on end (which was shockingly common). Most of the reason people had for avoiding minor updates is that they just found them annoying.

Now today of course things are quite different and it’s not unusual for a routine Windows update to turn things upside down. Users are more justified in update-averseness than they were 15-20 years ago, except of course now that brings much greater risk of getting pwned than it did back then.


> A big driver of automatic updates in the late 00s and early 10s were people who never updated their OS or browser and were getting compromised left and right.

I think we would be better off if people worked harder to prevent vulnerabilities before releasing the software.


I won't argue with that, but with how complex web browsers have become, holes are unavoidable regardless of the level of effort put forth to prevent them.


> I think we would be better off if people worked harder to prevent vulnerabilities before releasing the software.

Pawn Stars meme: "Best I can do is people using glorified chatbots to generate mediocre code an order of magnitude faster"

That said, the vast majority of the exploits that led to the widespread adoption of automatic update mechanisms were based around memory safety bugs which we do in fact have solutions to entirely prevent in most newly developed software these days.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: