Ask Slashdot: Should Hosting Companies Have Change Freezes? 138
AngryDad writes "Today I received a baffling email from my hosting provider that said, 'We have a company-wide patching freeze and we will not be releasing patches to our customers who utilize the patching portal for the months of November and December.' This means that myself and all other customers of theirs who run Windows servers will have to live with several critical holes for at least two months. Is this common practice with mid-tier hosting providers? If so, may I ask Eastern-EU folks to please refrain from hacking my servers during the holiday season?"
Green light (Score:5, Funny)
If so, may I ask Eastern-EU folks to please refrain from hacking my servers during the holiday season?
At least 10 countries [answers.com] have just been given the green light for hacking.
What Ever You Have to Say About Hostess Company (Score:2, Funny)
It's just too late. No more Twinkies.
And if you are concerned about freezing them, as the article seems to state? Don't bother. The shelf-life is astronomical!
Re: (Score:2)
Re: (Score:1)
Re: (Score:3)
No, that list includes 18 countries. The 10 that are eastern are:
Serbia
Montenegro
Croatia
Bosnia-Herzegovina
Macedonia (Former Yugoslav Republic of)
Albania
Belarus
Moldova
Russia
Ukraine
(The first few would often be called southeastern.)
windows? what were you thinking? (Score:5, Insightful)
Using windows to provide an internet facing service was the first mistake.
It's not that bad (Score:5, Funny)
The server will be spending 50% of its life rebooting to apply minor updates and install software, reducing the risk of a security breach.
Re:windows? what were you thinking? (Score:4, Insightful)
What he said.
I'm sorry the Windows-mods modded it down. It's instructional and it's informational. NOBODY should EVER use windows servers as Internet-facing devices.
Sorry, mods. Reality suggests the 0 is your score for having a clue.
E
Re: (Score:3)
Seriously. Even Windows-only people should know this. If they aren't placing protective devices in front of their Windows boxes to control access and limit the damage of attacks, they just aren't in touch with reality.
The funny thing is that most of these security appliances are running... what?
Re: (Score:3, Funny)
Exchange
Re:windows? what were you thinking? (Score:5, Interesting)
Well, I do have OWA open to the world, mainly because of ActiveSync, but the actual SMTP server, no way. I've seen joe job and dictionary attacks bring an Exchange server running on damned heavy hardware brought to its knees. I run a Postfix server running postgrey, SpamAssassin and ClamAV that sits on port 25 and weeds out all the nasty bits and hands everything else off to Exchange. There's no way in hell I'd ever let Exchange's SMTP service feel the full force of what the nastier folks on the tubes can throw at it. If someone DDoSs Exchange's IIS daemon, oh well.
Re:windows? what were you thinking? (Score:5, Informative)
No effing way. Only a complete and total newbie would even contemplate that, and I'd fire the first admin who tried to put such a thing in place.
Exchange as an MTA sits behind firewalls and a spam filter (be it home-brewed atop a Linux machine, or an automated commercial appliance, e.g. Barracuda). OWA you put in its own DMZ, insulated on all ends by industrial-grade firewall/security devices. Even Microsoft anticipated that one, and allows you to rig it exactly like that (with the MTA and all other bits buried in your internal network).
Back to TFA, I'm curious as to what's stopping the article submitter from sticking in a simple SCCM** box (or at least script something in Powershell that ties into Windows Update) and do his own %}$#@! patching? Relying on anyone other than the OEM to do patches is kinda, well, dumb.
.
** I know, I know - SCCM blows goats. But it's not like it's completely impossible to set up, and besides - that's the price you pay for using so much Windows gear.
Re: (Score:2)
Back to TFA, I'm curious as to what's stopping the article submitter from sticking in a simple SCCM** box (or at least script something in Powershell that ties into Windows Update) and do his own %}$#@! patching? Relying on anyone other than the OEM to do patches is kinda, well, dumb.
.
** I know, I know - SCCM blows goats. But it's not like it's completely impossible to set up, and besides - that's the price you pay for using so much Windows gear.
Shared hosting? Not sure if windows can do that, but that would explain why patching might be terminated. I recall a few PHP upgrades that broke a lot of things on LAMP stacks.
Re: (Score:2)
Not sure if windows can do that, but that would explain why patching might be terminated.
I think we'll have seen everything by that point. The only Windows servers I've seen are either VPS or dedicated machines.
I recall a few PHP upgrades that broke a lot of things on LAMP stacks.
Sounds like someone didn't do their unit tests. The same thing can happen with any software which hasn't been vetted. Most shared hosts support multiple versions of PHP.
Re: (Score:2)
How do you think services like AppHarbor and Azure work? You don't get one OS instance per website process, thats for sure.
I'm aware that Windows can host more than a single site. Azure runs on a VPS or a dedicated machine. Otherwise, how do users remotely login and manage their sites, remote desktop? I don't know of any setups where they operate that way.
Re: (Score:1)
You know, you could have just said that you are not qualified to administer a server. Would've been a lot shorter.
Re:windows? what were you thinking? (Score:5, Insightful)
Of course it doesn't solve every server problem, but nobody above said it would, just you dishonestly shifting the goalposts and pretending it's no good unless it fixes problems that were not even being discussed here. That's a bit of a slimy little tactic IMHO so you must feel very strongly if you are prepared to lower yourself to that level, but let's keep all the mindless emotive fanboy bullshit out of it since it just makes you look like more of an idiot than you actually are.
Re: (Score:1)
The hosting provider is most likely trying to deal with obstacles caused by the terrible windows infrastructure. I imagine they aren't freezing because they feel like being lazy, there is probably a large amount of overheard and cleanup when windows patches are rolled out (especially when they break things).
Re: (Score:2)
Re: (Score:2)
Using windows to provide an internet facing service was the first mistake.
What would you suggest if someone wants to run ASP.NET code on their website?
Re: (Score:3)
Using windows to provide an internet facing service was the first mistake.
What would you suggest if someone wants to run ASP.NET code on their website?
Reverse proxy.
Re: (Score:2)
Correction, it's the second.
I>That's the first.
DrrrrTISH!
Re:windows? what were you thinking? (Score:4, Funny)
What would you suggest if someone wants to run ASP.NET code on their website?
Therapy.
Re: (Score:3)
It was some kind of proxy that made it look as if the website was on Apache instead of IIS.
I'm not joking; it really seemed like a legit product, for money, that protected large banks etc. by making it appear as if they used Apache. So that attackers wouldn't bother trying to attack it.
To be honest,I have no experience with MS IIS, but to me that says
Re: (Score:1)
Actually, it really is a shame that you can't reliably host .Net applications out of Apache on Linux. I know mod_mono made some headway into this, but it'd be huge if this were possible in a real, production ready way.
http://www.mono-project.com/ASP.NET [mono-project.com]
Re: (Score:2)
I'm afraid you'll have to take that complaint up with Microsoft - they're the ones who lock it into Windows so tightly and refuse to work towards compatibility with other platforms, after all. *shrug*
Re: (Score:2)
They were actually tacitly supporting the Mono project at one point I believe, because - I think - they saw it was their way of getting Silverlight support on as many non-Windows platforms as possible. Only Silverlight seems to have fallen flat on its face ("and nothing of value was lost") and thus I suspect MS are no longer that interested in Mono.
The .NET framework actually has built-in support for running on non-Windows and non-x86/x64 systems: there are various internal enumerations which indicate runn
Re: (Score:1)
The .NET framework actually has built-in support for running on non-Windows and non-x86/x64 systems: there are various internal enumerations which indicate running on Windows, Mac, or Linux systems and there are also flags for indicating Big and Little Endian CPUs. It was *designed* to be cross platform; it's just MIcrosoft themselves have never bothered to take advantage of this.
Look into .NET Micro Framework, it is a completely open source implementation of .NET (by Microsoft!) running on a wide variety of platforms.
Netduinos are the easiest way to get started with .NETMF.
(To be fair, .NETMF is more of a platform in of itself, a cool little mini-runtime of sorts, very awesome and fun to play around with)
Re: (Score:2)
Ooh, that's interesting - I've not come across that at all. All my .NET development is for the desktop platform; I shall have to take a closer look at that. I feel the need to make all the fanboys howl with rage by seeing if you can use it in bare metal mode on a Rasperry Pi (looks like people have already been looking in to it).
Re: (Score:1, Interesting)
Why the hell would you want to code in asp in the first place?
Years ago (circa y2k) I worked for a hosting company as a sysadmin. We had some customers that demanded ASP support (less than 10%), and we tried a solution, I think it was called chilliasp, that was essentially a classic ASP implementation for Apache on Linux. It was able to run simple stuff, but complex sites failed. So my boss insisted on getting some windows servers. We ended up running 2 NT4 servers. Those 2 servers took more effort to admin
Re: (Score:2)
Why the hell would you want to code in asp in the first place?
I don't get why people would want to code in ASP, what does it have that Perl or PHP don't? I mean, besides expensive licenses, platform restrictions, and huge security issues.
"Classic" ASP sucks ass. It's basically Visual Basic for Servers.
ASP.NET, however, is actually a pretty good platform, since it lets you write your server-side code in C#. While PHP does give you the advantage of a free (in both senses) platform, it isn't nearly as well
Re: (Score:2)
It's fine for small projects and it can, with difficulty, be scaled up for large ones (there are real-world examples aplenty), but if you are designing a big project from the ground up, ASP.NET might be a reasonable choice.
While I know it wasn't all ASP.net are we talking London Stock Exchange big [computerworld.com]? There are some additional hidden costs when using a Microsoft tool chain such as SQL Server [microsoftstore.com] license(s) and Windows Server license(s). If you're designing a big project this is where Java shines (I'm not a Java guy either). At the end of the day they're tools to get the job done and infrastructure considerations are part of the project.
Re: (Score:2)
Why compare to PHP? Sure, PHP is for small projects (but it can be scaled without much problems, it's awfully designed and not very elegant, but it gets the job done. Anyway, if you are going to talk big projects compare Perl, or if you want something more modern Python. If we are talking truly big and complex, I'll take nothing over C++.
Anyway, why ASP when there are better solutions that don't depend on a particular vendor who is well known for being the dirtiest motherfucker around, second only to oracle
Re: (Score:2)
How the fuck would you know about anything related to "big projects" from your cum-stained computer in you mom's basement? I suppose you can dream, but really, why not get some help and join / rejoin society and the sun light outdoors? And by the way, you should stop wearing your mom's panties, that's kind of creepy.
Re: (Score:2)
You are so mature. When I grow up I want to be just like you.
Re: (Score:2)
At least I'm not some self-important moron who lives in a fantasy world. Dude, get help.
Re: (Score:2)
You mean you had problems last decade. There is no way a company in 10 years can improve their product. It is just impossible.
Post Bill Gates Microsoft - Less innovative but more reliable systems.
Re: (Score:1)
How can an OS be secure when they just let anyone look at the source code whenever they want?! Crazy talk!
Sometimes, you simply have to believe the empirical evidence that is available. *nix servers are seldom hacked, Windows servers are frequently hacked. No matter what you like or don't like, no matter what you understand or don't understand, a mountain of empirical evidence says that *nix operating systems are better for serving.
A large number of us also believe that *nix is a superior desktop and workstation OS, as well, but we lack the mountains of empirical evidence that we have for servers.
Are *nix ser
Re: (Score:2)
I haven't heard about major security problems in IIS for years. Today you are no more or less vulnerable with IIS ASP. and SQL Server as you are with a LAMP.
Back before Server 2003. You put yourself at risk, however the newer version have gotten far more secure and reliable.
Sure you get your security patches and upgrades but you get those for the LAMP systems too.
The biggest flaw isn't in your software choices but how well you coded you ASP.NET and your PHP and your SQL (My Sql or SQL Server) queries. Bei
Sure (Score:5, Funny)
Just reply to this message with the IP addresses of any servers you want to make sure will not be hacked and I will make sure the list gets to the right people.
Happy to help.
Re: (Score:2)
127.0.0.1 ::1
fe00::0
127.0.0.2
Re: (Score:3)
216.34.181.45 (Score:5, Funny)
Re: (Score:2)
Here it is: 127.0.0.1
Thanks! :)
change freeze (Score:5, Informative)
I work for a company with 1200+ VMs and the change freeze concept is nothing new. For us, it's only 1 month around new years and mainly due to staffing issues if something goes wrong.
Re: (Score:1)
Go dedicated or go home (Score:2, Insightful)
Re: (Score:3, Informative)
I'm using server4you. Their support sucks if you have to call them (they speak german, and very very limited english). If you need support, this is not your company. But if you can manage your own boxes, their uptime is great, and so is the hardware and bandwidth. In the last year we had less than an hour of downtime, and it was after midnight.
The interesting thing: The prices. $28 for an Athlon X2 with 4GB RAM, 2 SATA disks and unlimited bandwidth.
Again, the support desk is impossible mostly due to the lac
Re: (Score:2)
Have you ever considered learning German? Then, you could butcher their language as readily as they butcher yours! it's always an advantage when you can insult the sheistikopf in his native language!
Re: (Score:2)
English is my second language, I don't live in an english-speaking country, and considering nobody has treated it worse than Americans are British, I couldn't care less. I don't mind small errors, typos, etc., but when your grasp of a language is so bad that you make communication impossible, it does bother me. It bothers me more when native speakers do things such as mix up the possessives and contractions (their vs. they're, for example), and other similar mistakes that drive me go berserk.
And If I ever l
Better safe than sorry. (Score:3, Insightful)
This is for automated patching, you may certainly request to be patched by the support teams. Typically these two months are the busiest for online shopping sites and a botched patch could cost the business tons of money. Since you know your business the best, you make the call. Better safe than sorry in my opinion.
Translation (Score:3)
Translation: "Dear Slashdot, I'm looking for a good Windows host. Any suggestions?"
Re: (Score:1)
I've heard on the interwebs about this student, I think his name is Linus who created some OS called 'Linux'. It's like BSD (1-800-ITS-UNIX) but free as in freedom and beer.
Unless you're running some stupid server which requires ASP.NET, in that case go dedicated.
Re: (Score:2)
Yes, but ... (Score:2)
Wow, you must REALLY hate sys admins (Score:2)
What have you got against sys admins anyway that you go out of your way to make them cry like that?
Exercise that redeployment plan (Score:4)
As company using a hosted service you do have a redeployment plan should movement to another hosting service be required, don't you ?
Now would be a good time to exercise that plan.
This is what happens when you outsource (Score:1, Interesting)
While I think its rather unacceptable for this to be done, its not all that surprising and you kind of deserve the result.
When you outsource you sacrifice things. Why are you letting them patch for you anyway? Its not like they are going to do anything special. All the do is release patches from their own internal WSUS server (or whatever its called now) rather than you have to do it yourself or letting the machine auto-patch on its own.
Realistically, if you're going to have someone else auto-patch, you
Careful you don't hurt yourself (Score:3, Insightful)
When you fall off that high horse.
What is the reason for an anti-outsourcing rant in this thread? To me, it sounds like the guy has his own website and that's what he's talking about. Do you host your own website? By that I mean do you have your own server, on your own property? If not, then you are outsourcing it. Even if you do, you are still probably outsourcing your Internet access and power generation.
If you don't like outsourcing that's fine and there's plenty of arguments against it, but save it for
Re: (Score:1)
I outsourced my datacenter's power to a "green" facility that promised only to use hamsters running on their merry wheels. Little did I know those little fuckers only live for 1-2 years on average.
Re: (Score:2)
Yes, I have a server sitting on my property. I have a government regulated Internet connection and power connection with HARD SLAs regarding availability. You want to try that one again?
That is entirely besides the point. There is nothing wrong with outsourcing. I also host certain parts of my infrastructure in someone elses data center. What I do not do is depend on someone else to do the job of Windows update when they provide absolutely no advantages of turning on auto-updates and the provide obviou
Re: (Score:2)
You know, I outsource a server.
Yet, I choosed a provider that gave me the things I care about. I have a nice SLA to rely upon, and I don't outsource configuration, because that is just stupid.
Yet, there it is somebody outsourcing configuration, and complaining that the provider won't configure the machines exactly the way he wants. Duh. You can be sure that if they were configuring the machines the way he wants, somebody else would be here, complaining about it.
Re: (Score:2)
He's a victim like a guy who had the choice between a $3000 used car with seatbelts and a $100 heap with a garbage bag for a passenger-side window, and picked the latter.
Re: (Score:2)
Re: (Score:2)
Do you use SSL to access your bank account?
Do you use strong passwords?
Do you use a firewall and patch whatever OS you are using regularly?
If so, why? Nobody will hack you, after all, hacking is illegal and nobody will blame you for having "password" as your password even if someone does hack your account (and steals your money) or hacks the company that you work for. It's all the fault of the hacker.
Locking your car and house is stupid too - stealing is wrong so nobody would steal even if you left the door
This is common, but.... (Score:4, Interesting)
This ("change moratoriums") is a common practice around the holiday season. A number of the datacenters and other vendors I work with implement similar policies starting right before "black friday" and ending a week after new years. The logic is that changes could have undesirable consequences and the volume of e-commerce around this time would result in a potentially detrimental impact on operations. However, I have never heard of a company that holds out on security updates and other critical fixes due to such a moratorium.
Re: (Score:3)
It's a tough call, but it's worth keeping in mind that not all windows updates go smoothly.
What does your contract say? (Score:4, Insightful)
Two months is a looong time. 17% of the year not getting full fidelity on your contracted services seems excessive. Usually, changes freezes are a few hours in the middle of the night, once a week.
Re: (Score:2)
Re: (Score:2)
Oops, yea, you are right, but there are usually provisions for security related changes or emergency changes, and two months is still too long. Week before and after black friday, then two weeks leading up to Christmas should be plenty.
Re:POS (Score:5, Funny)
Re:POS (Score:5, Funny)
In my experience, they are one and the same.
Change freezes? (Score:1)
Is this something to do with global warming?
Hardly baffling (Score:2)
Real (TM) IT shops have change freezes all the time. It's called release management. Perhaps you should a) host on some more stable platform, or b) co-lo your own gear where you can run daily patches and reboots and only affect your own stuff.
Re:Hardly baffling (Score:4, Informative)
Perhaps you should co-lo your own gear where you can run daily patches and reboots and only affect your own stuff.
Unless the OP is sharing an actual Windows instance with other clients (which would mean he should be paying about $1/month in fees), rebooting his instance should only affect him.
It's possible that he is paying for a Windows instance on top of Hyper-V, and the underlying OS isn't getting patched, but that really shouldn't be much of a security risk for the OP, as the hypervisor OS isn't visible to the outside world. Likewise, even if he is sharing access to back-end services like SQL server, it's unlikely that the API he is using to connect to those services is vulnerable in such a way that a patched client would be a problem for an unpatched server. It's far more likely that there are SQL injection or other issues on the clients than a non-administrator connection to an unpatched server causing a compromise.
Re: (Score:2)
I certainly put freezes in place for a week or two surrounding major holidays like Christmas. But we're talking about a damned long freeze here.
Re: (Score:3)
"Your" servers? (Score:2, Insightful)
How are they "your" servers if you cannot patch them whenever you deem necessary?
Standard practice (Score:5, Informative)
Having change freezes is standard practice. Most places I've worked have a short month-end freeze, and a couple of month year-end freeze.
However, critical security vulnerabilities are exempt from these freezes. Those still get done using whatever emergency protocols are in place.
Re: (Score:2)
Having change freezes is standard practice. Most places I've worked have a short month-end freeze, and a couple of month year-end freeze.
However, critical security vulnerabilities are exempt from these freezes. Those still get done using whatever emergency protocols are in place.
Especially for systems hosted in The Northern Hemisphere.
It's winter, people should know enough to expect freezing this time of year.
Is this common practice for change freezes in Dec. (Score:2)
Yes! If your company does not have a change freeze in effect for at least some portion of December or November it should. Nearly all countries and religions observe significant national holidays during this time. It also tends to be a very significant or the most significant time of the year economically for many countries and companies. That said non-functional security patching and security related activities would be good exceptions to this rule. Large hosting providers, not wanting to single out custome
rackspace (Score:2, Informative)
If you read the email properly, they are not doing automatic patching of these releases, but nothing to stop you applying them yourself.. or getting them to apply them if you specifically ask for them.
Change Hosts (Score:2)
Time to change hosts.
Not hosting (Score:4, Insightful)
You didn't get this email from your hosting company. You got it from the company managing your servers. The fact that it's the same company is largely irrelevant.
If the server management company isn't flexible enough to meet your needs, do it yourself. You keep track of the patches, you decide when they're ready for release, you release them, you test them. If you don't have the skills for that, or the money to hire someone with the skills, then get another company to do it. If you're using a dedicated server, there's nothing stopping you giving someone else the access to manage and patch it.
If you yourself don't have root/Administrator access, then you don't have a server; you have access to a server. Fork out a little bit extra, and get a dedicated box that you control.
Words vs Actions (Score:4, Informative)
You can't put up a sign that says "only a few people allowed beyond this point". And you can't put up a sign that says "very little loitering accepted". So you put up signs that read "no access beyond this point" and "no loitering", and then you simply don't enforce it for the first few people.
If this company has a reduced staff, or wants to ensure that large problems don't happen during sensitive times, then they might want the freeze. And saying that there will be a freeze is the way to do that. But calling them and saying "hey, I know there's a freeze, but I'd really appreciate this patch when it's convenient." won't likely be met with a solid "no, screw you, we're in a freeze".
Ice is usually still a little wet. Not every molecule freezes at the same instant.
Look at it as an opportunity for you to be nice. They said "we'd really like to ease the harsh environment of christmas IT", and you can optionally say "I'll help you out by not patching for a while". It's an opt-out instead of an opt-in scenario, but it's the same.
You're complaining about the default, not the final. And you can override the default with a phone call. Don't sweat it.
Utility companies (Score:2)
I spent 2 years working for a utility company in Australia where we had an annual change freeze to core systems during the bushfire season. We couldn't afford for systems to be down for non-essential changes when there was the possibility of a 'real world' emergency breaking out. This went doubly so for anything involved in the SCADA network.
Troll (Score:2)
If so, may I ask Eastern-EU folks to please refrain from hacking my servers
If so, may I ask the Slashdot editors to please refrain from letting people post trolls.
we have a year end freeze too (Score:2)
we lock down from about mid december to mid jan.. partially because of staffing, but mostly because our enviornment needs to be stable for year end processing (I work for a bank). no elective changes are allowed during this time.. only fixes if something breaks.
we don't run our shit in thrid party datacenters, so it's not exactly the same scenario, but it's understandable that no changes are allowed. what if your stuff breaks and you don't have staff due to the holidays? if we fuck up, we only fuck up our s
Article is based on incorrect reading (Score:4, Informative)
Customer satisfaction is important to us. (Score:4, Funny)
may I ask Eastern-EU folks to please refrain from hacking my servers during the holiday season?
Sure, just provide me with your domain name, provider and root password and I'll add you to my do-not-hack list.
Why still allow top hacking countries? (Score:3)
I'm sorry to say that OP seems to be nationalistic about his "hacker countries" conception, promoting negative stereotypes, not to mention that he confused EU with Europe.
Top hacking countries are very different from Eastern Europe countries: USA (yup, still number 1 spot), China (Eastern, but not European), Russia (not Europe, just Eastern), Brazil, Germany (Europe and EU, but not Eastern), UK (an island off Europe coast), India (totally away from Europe)...
With your attempt at "humour" you basically allowed all those people right to hack your servers over the next two months ;-)
Re: (Score:2)
Locate your customers... (Score:2)
And block everybody else at the firewall.
There's no reason to let any of China, Pacific Rim, Middle East, Former Soviet Bloc, Africa, etc. onto my servers.
So they don't get on, and nothing of value was lost.
Know what else? My log files don't fill up with useless shit anymore, and the numbers of automated attacks and form spams have dropped dramatically.
Last time I checked, you can download fixes for your servers. Just FTP them up or whatever and install them manually. Get a new web host over the l
they must have some big-time customers (Score:2)
major companies generally require a change standstill during holiday seasons, as well as certain accounting-rules critical times. so do outfits like the FAA, which for some ungodly reason doesn't want its comm channels flipping like fish at all hours of the day and night. some damn silliness about "life safety" or some other freakin nonsense.
I work for a telco, and this is very very old hat to us. "why are our lines down, we have 30 planes stacked up for landing?" "uh, backhoe party on the front lawn ri
Re: (Score:2)
As my grandad used to say: if you want it done right, do it yourself.