It's Wrong Not To Have An Update Up-To-Date Image On The Download Server

Started by abcuser2021, March 26, 2021, 07:37:35 AM

Previous topic - Next topic
Quote from: abcuser2021 on March 28, 2021, 07:45:02 PM
Quote from: franco on March 28, 2021, 01:49:21 PM
Yawn, it's just continuous riffing on the same buzz words, but still nothing specific. ¯\_(ツ)_/¯


Cheers,
Franco

So... by pointing out - installing an outdated image that filled with security vulnerabilities and took more than an hour to update is a security risk - is not specific enough?

ok then you can close this thread now.

No, no, no. We want to know more. How was your raspi compromised? All the forensics. Show some logs, anything supporting the claims. Highly interested!
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

What I would like to know, Who in IT and / or security would place equipment as their primary connection ( in this case their FW) exposed to their Internet connection without updating it first.  When you get new equipment, I have not seen, heard, nor placed any unconfigured equipment exposed to the Internet. 

Even with new equipment, you place it inside your network (still using your old FW / router / whatever) download the needed updates, TEST, then install and switch over. 

Why would someone place a newly unconfigured piece of equipment for use without configuring / setting it up as needed before allowing users access?

Case in point, when new computers are received by shipping, does IT start assigning and installing at a users location; or does it start placing them aside in a restricted network, download updates, configure AD, all the setup first?