by StressedDev on 12/13/2023, 3:30:04 AM
by I_Am_Nous on 12/13/2023, 2:49:17 AM
Apathy is definitely the issue. Sometimes you tell a vendor about an issue and they say their app doesn't use Log4J even though it's gobbling up the Log4J test script in the username field...they don't want to care, so you can't make them.
This does not surprise me. Updating software takes time, effort, and is risky. It's also not fun. The result is a lot of people ignore it even though it means their software can be easily hacked. Note I think people should keep their dependences update to date. Unfortunately, I also know human nature and that means I know many won't.
You see a similar problem with obsolete computers, operating systems, phones, routers, etc. People keep them connected to the Internet even though they have known vulnerabilities. People who do this will even claim they have not been hacked.