On Thu, Mar 24, 2022 at 09:33:50AM +0100, Ulrich Windl wrote: > >>> Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx> schrieb am 24.03.2022 um 08:12 in > Nachricht <YjwZ56FP4Qgx3cMC@xxxxxxxxx>: > > On Wed, Mar 23, 2022 at 10:34:00PM +0000, Dave Howorth wrote: > >> FWIW, I think Greg was a bit too outspoken calling long maintenance > >> attempts 'crazy'; that may have intimidated some. I'm thinking of > >> moving distro to one that provides longer term maintenance than my > >> present one. Although CIP is a completely different ball game; I hope > >> they succeed. > > > > It is not "crazy" it is "well documented". As someone who has been > > doing this work for 20+ years now and sees all of the stable kernel > > patches flow by, it's obvious that a distro that does not keep up with > > them is insecure by design. > > If "newer is better" I'd agree. Sometimes "newer is actually worse". > Some new features intended to improve things sometimes actually make things worse. That's not the issue here. Do you want to run a kernel with known security problems, or one with "unknown potential problems." The latter is always the case, so please don't pick the known-insecure one, that's just foolish. greg k-h