

Looking at how bad our current system is, there’s clearly no need to prevent the videos from getting out because the officer can get away with it despite that.
And even if the officer doesn’t, the department can just scapegoat them and just keep doing the same things.
All the more reason to not waste a 0-day or risk the knowledge of a backdoor getting out.
I run Debian on most of my systems and run all of my services in docker (with rare exceptions for node_exporter or stable core tools). My base systems get automatic security upgrades, and then I’ll manually check in every few weeks whenever I feel like it.
My services in docker are version locked to a specific major version (when there’s a tag available) so I can usually re-pull to get minor version updates freely without breaking issues. My few more finnickey services get manual upgrades from me every 6 months or so only.
I usually stick to an OS version for as long as I can, and to that aim I stick to LTS versions with long support windows.
4 major versions in 12mo is…a lot. Especially if those include breaking changes for you. Yikes