• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Automated Security Patch Updates?

Chuklr

Gawd
Joined
Nov 1, 2009
Messages
788
DistroWatch.com Has the following news items regarding the Debian Project considering automatic application of security updates as the default:

Keeping an operating system up to date with security patches is one of the key processes involved in preventing a computer from being compromised by an attacker. With many computers systems being set up and left to run for months or even years unattended, the idea of automated package updates is an attractive option. The [URL='http://distrowatch.com/debian']Debian[/url] project is currently considering whether security updates should be applied automatically by default and, if so, what are the benefits and potential drawbacks? "The Debian project is looking at possibly making automatic minor upgrades to installed packages the default for newly installed systems. While Debian has a reliable and stable package update system that has been an inspiration for multiple operating systems (the venerable APT), upgrades are, usually, a manual process on Debian for most users. The proposal was brought up during the Debian Cloud sprint in November by longtime Debian Developer Steve McIntyre. The rationale was to make sure that users installing Debian in the cloud have a 'secure' experience by default, by installing and configuring the unattended-upgrades package within the images." [URL='https://anarc.at/blog/2016-12-22-debian-considering-automated-upgrades/']This blog post[/url] talks about some of the benefits and problems which could result from automated updates.

It sounds to me like this change may move forward.
 
DistroWatch.com Has the following news items regarding the Debian Project considering automatic application of security updates as the default:



It sounds to me like this change may move forward.

Ubuntu has this already as option but it's a bit risky at least for servers. You don't want any automated updates in production machines, every update must be tested before committing them.
 
Back
Top