Earlier quoted context omitted.
I would much rather a long-term-stable product with fewer security vulnerabilities that didn't need frequent updates.
False logic. Slow update does not mean you have secure version. You can get ESR if you want the so-called LTS version. Freqeunt update addresses multiple things quickly: (1) security vulnerability, (2) performance regression (3) new features For a software widely used like FF, it is important that they keep the software up-to-date, make the software as slim as possible, and make the software easy to use. If you want…
This was not my claim. When there are security vulnerabilities I'm happy for the updates to be as quick as possible and as frequent as necessary. The problem is:
> (3) new features
Adding new features has a high chance of new security flaws, when you're operating at the speed of firefox on such an error-prone technology stack.
Different users want to meet this trade-off differently. I want fewer features, in fact I'm ok not to be bleeding-edge compatible with the latest poorly-designed HTML draft spec if it means a more secure browser. It's a question of how and where Mozilla (or other browser teams) organize their effort.