❦ Billy Blaze ❦ is a user on mastodon.social. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

@ckeen I'll say the same about Linux when the first vulnerability hits it. A vulnerability is NOT the reason to stop using something entirely.

@tdemin That entirely depends on your threat model. If your business secrets rely on not being discovered by espionage, then yes you need to stop using software X. Likewise if your life or your sources's is on the line. (Think of signal desktop here). Then by all means stop using the software.

@ckeen temporary workarounds are a good thing in such cases (like disabling the vulnerable service for a while). Persistent switches aren't.

@tdemin The software in question -- electron -- reimplements every security thread we have seen in browsers of the early 2000s. This is by design and I don't think this will be the last critical bug in there. Using this as your application platform is just asking for trouble.