logoalt Hacker News

user43928 • today at 5:38 PM • 0 replies • view on HN

I don't think anyone criticized the timing of the patch.

But I find it egregious that they didn't roll it out as a security update at all, which is why it was not automatically installed in OP's case, even though the fix was already available.

I mean, what else requires a hotfix via security update if not a fatal flaw in your remote access authentication leading to full root access, that is actively being exploited in the wild?

Also, it's not really on the user to gate remote access behind an additional firewall and authentication layer. This is something that just has to work securely.

If it doesn't, that's understandable, but still hardly the user's fault.