Conversation

Charlotte lotteheartplural/Cinny cinny_heart_plural thetadelta ursaminor treblesand

so many words lost spent on mitigating a vuln that is already fixed and also mainly applicable to multi-tenant systems

update your systems, switch away from distros who haven’t patched it

1
0
4

genuinely by the time i first heard of the vuln all my systems were already using 7.0+

1
0
1

like you should absolutely patch it because it’s an incredibly useful stage 2

anyways my scalding sysadmin take is that if your infrastructure needs to survive a single server going down but can’t you built it wrong

2
0
1

also long uptimes are not a good sign. you want to stay up to date with security updates at the very least. my servers max out at about a week of uptime

1
0
1
@charlotte At my work the servers simply shut down every night at 3h00 in the morning. It's not an internationally-sold product and whomever is still awake at that hour just shouldn't realistically... and because these are windows servers it's far better to give them the regular eepies anyways
0
0
0

@charlotte this is one reason (among others) that we developed things like k8s, live migration of VMs, DB server clusters, cephfs, and more so, you can easily reboot one server without loosing access to anything business critical. And sure setting up that all in house can be difficult, but small companies should have regular windows they are closed anyway, and big companies should be able to afford a dedicated ops team. Anything none critical should be able to survive being offline for a few minutes anyway. (this is a long winded way to say I agree with your sysad take)

0
0
0