this post was submitted on 21 Jun 2023
95 points (84.2% liked)

Memes

45730 readers
626 users here now

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

founded 5 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[โ€“] [email protected] 8 points 1 year ago* (last edited 1 year ago) (1 children)

@printerjammed Simply put, this is bad for so many reasons. Since you're likely going to reject any direct reasons why this is bad, I'll give you an analogy.

I'm going to take "and never update it" almost literally and assume you guys haven't installed security patches since you first installed it, or stopped at some point long ago.

You're essentially driving a 15 year old car that hasn't had an oil change, brakes changed, or tires changed. There are known MAJOR safety recalls on the seat belts, airbags, and seats. You have refused to take your car in for free servicing under the recall and basically said, "It's working fine now. It's not worth the hassle scheduling an appointment at the mechanic. I'll take my chances."

But hey, "The car still gets me around and fits in my garage" you smugly think to yourself. "Why should I do anything different? It's MY car and I'm only endangering myself here."

Nope. Your car is endangering everyone else on the road. Bad brakes and tires are major risks for everyone around you. You can easily lose control and hurt or kill others on the road.

Bad seats, seat belts, and airbags means that occupants of your vehicle (your companies clients) can be injured or killed if they fail. Even if only YOURS fails, well...you're the driver. Also, if you do crash and your seat belt fails, you're now a projectile in the car and can injure or kill other passengers. I've seen this happen too many times as a firefighter and an EMT. Unseatbelted occupants are an enormous hazard.

Suffice to say your company is a vector for major attacks and vulnerabilities that not only will affect you, but your clients and potentially countless others who have nothing to do with your company since your server could be part of a botnet for all you know.

"bUt We HaVe OtHeR sEcUrItY cOnTrOlS aNd PrOpEr PrOtOcOlS fOr...." I'm going to cut you off here and straight up say: No. You don't. The fact you still have Windows Server 2008 installed and refuse to even update it tells me enough about your entire IT department and policies.

@snixyz

[โ€“] [email protected] 2 points 1 year ago

business doesnt spend money on IT. i'd love a new car