Ian Brown @igb
There is, frustratingly, no footnote or reference in @dotMudge's report to explain why he is making this particular claim.
View on Twitter ↗
0 30

Replies

Most of his other anecdotes or assertions have a footnote with more context and/or detail. It is weird that this one doesn't.
Also, the disjunction of "kernels" or "operating systems" and the use of a single aggregate percentage is pretty hand-wavy.
Given the different mechanics & constraints of OS vs. kernel upgrades at Twitter, there should be two different numbers here.
And since Twitter's OS upgrades and patches were mostly automated, OS non-compliance %s are usually extremely low.
Even going out on a limb to assume that he means only kernel version/patch compliance, the 50% number seems improbably high.
Furthermore, I assume that by "compliance" Mudge is referring to the compliance policies set prior to Mudge's tenure by KaOS & InfoSec?
Finally(?) "many unable to support encryption at rest" is vague AF. Does he mean unable to support a specific implementation of EaR?
As I have mentioned elsewhere, during my tenure Mudge's engagement in this area was a) minimal, and b) not constructive/helpful.