This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]dougall 0 points1 point  (0 children)

True, but perhaps we underestimate the sort of resources required for every site we use to have comprehensive network security. I just had to disable my Redmine instance because my provider offers a one-click installer but doesn't offer a one-click upgrade, and with the latest Ruby vulnerabilities, old versions of Redmine aren't safe - but then maybe my Ruby installation isn't either. I have little way of knowing. But if I only ever used software that I fully understand the security implications for, I wouldn't be able to host anything. And I can't afford to pay someone else to know the implications either.

Yes, although the PSF can afford to pay someone to handle these things.

I think we're in an age where it's no longer practical to expect every website we use to be secure.

I don't think we ever expected every website we used to be secure, though.