Re: Auto-Updates for production servers



In article <uDMoW0nGIHA.4272@xxxxxxxxxxxxxxxxxxxx>,
anthony.spam@xxxxxxxxxxxxxx says...
I hope you won't mind advice that contradicts your presumed views.
When Microsoft or any software vendor discovers a flaw that can be
exploited, they need to fix it.
If you don't apply the fix, you are vulnerable from that time on because
everyone knows what the flaw is.
You can test the fix to see if it breaks anything, but you still need to
apply it even if it does.

No, Anthony, you don't.

You need to patch if the update provides a resolution to something that
you might be exposed to, but if your server is not exposed to xyz then
you don't need ot patch for it.

Not all production servers are fully exposed to the Internet, most are
behind a firewall and have little or no exposure to most of the threats
you read about.

Yes, it's "good practice" to update with all critical updates and
security patches, but the update should be based against the threat vs
stability.

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@xxxxxxxxxx (remove 999 for proper email address)
.



Relevant Pages

  • Re: MCNGP Constitution, According to Kat
    ... *Calling me with a stupid question - $30 ... *Asking me to walk over to your building to fix the problem - $25/step ... *Spilling coke on keyboard - $25 plus cost of keyboard ... *Dealing with tech support requests for obviously pirated software - ...
    (microsoft.public.cert.exam.mcse)
  • Re: Checking for null parameter
    ... it throw a checked exception? ... How can you fix what you can't detect? ... before calling a method? ... Isn't this the same thing as if a NPE was thrown? ...
    (comp.lang.java.programmer)
  • Re: IE7 and windows XP
    ... They are all fixable after calling the web master and getting the ... Under IE6 I was able to type the first letter, ... KNOW HOW TO FIX. ...
    (microsoft.public.windowsxp.general)
  • Re: [PATCH] integrity: fix IMA inode leak
    ... until the system runs out of memory. ... Fix that by calling it from destroy_inode. ... since it seems to fix a real issue. ... and I'd anyway prefer a few warnings to my boxes OOMing. ...
    (Linux-Kernel)
  • Re: IE7 and windows XP
    ... They are all fixable after calling the web master and getting the ... Under IE6 I was able to type the first letter, ... KNOW HOW TO FIX. ...
    (microsoft.public.windowsxp.general)

Loading