Slashdot Mirror


Ask Slashdot: Should Hosting Companies Have Change Freezes?

AngryDad writes "Today I received a baffling email from my hosting provider that said, 'We have a company-wide patching freeze and we will not be releasing patches to our customers who utilize the patching portal for the months of November and December.' This means that myself and all other customers of theirs who run Windows servers will have to live with several critical holes for at least two months. Is this common practice with mid-tier hosting providers? If so, may I ask Eastern-EU folks to please refrain from hacking my servers during the holiday season?"

25 of 138 comments (clear)

  1. Green light by michaelmalak · · Score: 4, Funny

    If so, may I ask Eastern-EU folks to please refrain from hacking my servers during the holiday season?

    At least 10 countries have just been given the green light for hacking.

  2. windows? what were you thinking? by Anonymous Coward · · Score: 5, Insightful

    Using windows to provide an internet facing service was the first mistake.

    1. Re:windows? what were you thinking? by gavron · · Score: 4, Insightful

      What he said.

      I'm sorry the Windows-mods modded it down. It's instructional and it's informational. NOBODY should EVER use windows servers as Internet-facing devices.

      Sorry, mods. Reality suggests the 0 is your score for having a clue.

      E

    2. Re:windows? what were you thinking? by Anonymous Coward · · Score: 3, Funny

      Exchange

    3. Re:windows? what were you thinking? by MightyMartian · · Score: 4, Interesting

      Well, I do have OWA open to the world, mainly because of ActiveSync, but the actual SMTP server, no way. I've seen joe job and dictionary attacks bring an Exchange server running on damned heavy hardware brought to its knees. I run a Postfix server running postgrey, SpamAssassin and ClamAV that sits on port 25 and weeds out all the nasty bits and hands everything else off to Exchange. There's no way in hell I'd ever let Exchange's SMTP service feel the full force of what the nastier folks on the tubes can throw at it. If someone DDoSs Exchange's IIS daemon, oh well.

      --
      The world's burning. Moped Jesus spotted on I50. Details at 11.
    4. Re:windows? what were you thinking? by Penguinisto · · Score: 4, Informative

      No effing way. Only a complete and total newbie would even contemplate that, and I'd fire the first admin who tried to put such a thing in place.

      Exchange as an MTA sits behind firewalls and a spam filter (be it home-brewed atop a Linux machine, or an automated commercial appliance, e.g. Barracuda). OWA you put in its own DMZ, insulated on all ends by industrial-grade firewall/security devices. Even Microsoft anticipated that one, and allows you to rig it exactly like that (with the MTA and all other bits buried in your internal network).

      Back to TFA, I'm curious as to what's stopping the article submitter from sticking in a simple SCCM** box (or at least script something in Powershell that ties into Windows Update) and do his own %}$#@! patching? Relying on anyone other than the OEM to do patches is kinda, well, dumb.

      .
      ** I know, I know - SCCM blows goats. But it's not like it's completely impossible to set up, and besides - that's the price you pay for using so much Windows gear.

      --
      Quo usque tandem abutere, Nimbus, patientia nostra?
    5. Re:windows? what were you thinking? by dbIII · · Score: 4, Insightful

      Since in this case you can patch without reboots, the answer is just switching to linux (or anything else that can patch without reboots) CAN solve the problem.
      Of course it doesn't solve every server problem, but nobody above said it would, just you dishonestly shifting the goalposts and pretending it's no good unless it fixes problems that were not even being discussed here. That's a bit of a slimy little tactic IMHO so you must feel very strongly if you are prepared to lower yourself to that level, but let's keep all the mindless emotive fanboy bullshit out of it since it just makes you look like more of an idiot than you actually are.

    6. Re:windows? what were you thinking? by TheRaven64 · · Score: 3, Funny

      What would you suggest if someone wants to run ASP.NET code on their website?

      Therapy.

      --
      I am TheRaven on Soylent News
  3. Sure by Capt.DrumkenBum · · Score: 4, Funny

    may I ask Eastern-EU folks to please refrain from hacking my servers during the holiday season?

    Just reply to this message with the IP addresses of any servers you want to make sure will not be hacked and I will make sure the list gets to the right people.

    Happy to help.

    --
    If I were God, wouldn't I protect my churches from acts of me?
  4. change freeze by Anonymous Coward · · Score: 5, Informative

    I work for a company with 1200+ VMs and the change freeze concept is nothing new. For us, it's only 1 month around new years and mainly due to staffing issues if something goes wrong.

  5. It's not that bad by bigtrike · · Score: 5, Funny

    The server will be spending 50% of its life rebooting to apply minor updates and install software, reducing the risk of a security breach.

  6. Better safe than sorry. by Anonymous Coward · · Score: 3, Insightful

    This is for automated patching, you may certainly request to be patched by the support teams. Typically these two months are the busiest for online shopping sites and a botched patch could cost the business tons of money. Since you know your business the best, you make the call. Better safe than sorry in my opinion.

  7. Exercise that redeployment plan by RichMan · · Score: 3

    As company using a hosted service you do have a redeployment plan should movement to another hosting service be required, don't you ?

    Now would be a good time to exercise that plan.

  8. This is common, but.... by Anonymous Coward · · Score: 4, Interesting

    This ("change moratoriums") is a common practice around the holiday season. A number of the datacenters and other vendors I work with implement similar policies starting right before "black friday" and ending a week after new years. The logic is that changes could have undesirable consequences and the volume of e-commerce around this time would result in a potentially detrimental impact on operations. However, I have never heard of a company that holds out on security updates and other critical fixes due to such a moratorium.

  9. What does your contract say? by HaeMaker · · Score: 3, Insightful

    Two months is a looong time. 17% of the year not getting full fidelity on your contracted services seems excessive. Usually, changes freezes are a few hours in the middle of the night, once a week.

  10. Re:POS by viperidaenz · · Score: 4, Funny

    Are you referring to Point of Sale business or Piece of Shit business?

  11. Standard practice by Jethro · · Score: 4, Informative

    Having change freezes is standard practice. Most places I've worked have a short month-end freeze, and a couple of month year-end freeze.

    However, critical security vulnerabilities are exempt from these freezes. Those still get done using whatever emergency protocols are in place.

    --


    In the land of the blind, the one-eyed man is kinky.
  12. Re:Hardly baffling by nabsltd · · Score: 3, Informative

    Perhaps you should co-lo your own gear where you can run daily patches and reboots and only affect your own stuff.

    Unless the OP is sharing an actual Windows instance with other clients (which would mean he should be paying about $1/month in fees), rebooting his instance should only affect him.

    It's possible that he is paying for a Windows instance on top of Hyper-V, and the underlying OS isn't getting patched, but that really shouldn't be much of a security risk for the OP, as the hypervisor OS isn't visible to the outside world. Likewise, even if he is sharing access to back-end services like SQL server, it's unlikely that the API he is using to connect to those services is vulnerable in such a way that a patched client would be a problem for an unpatched server. It's far more likely that there are SQL injection or other issues on the clients than a non-administrator connection to an unpatched server causing a compromise.

  13. Not hosting by LordLucless · · Score: 3, Insightful

    You didn't get this email from your hosting company. You got it from the company managing your servers. The fact that it's the same company is largely irrelevant.

    If the server management company isn't flexible enough to meet your needs, do it yourself. You keep track of the patches, you decide when they're ready for release, you release them, you test them. If you don't have the skills for that, or the money to hire someone with the skills, then get another company to do it. If you're using a dedicated server, there's nothing stopping you giving someone else the access to manage and patch it.

    If you yourself don't have root/Administrator access, then you don't have a server; you have access to a server. Fork out a little bit extra, and get a dedicated box that you control.

    --
    Just because you're paranoid doesn't mean there isn't an invisible demon about to eat your face
  14. Re:POS by Dewin · · Score: 4, Funny

    In my experience, they are one and the same.

    --
    Of course nobody reads the FAQ! If people read the FAQ, the Questions wouldn't be so Frequently Asked.
  15. Words vs Actions by holophrastic · · Score: 3, Informative

    You can't put up a sign that says "only a few people allowed beyond this point". And you can't put up a sign that says "very little loitering accepted". So you put up signs that read "no access beyond this point" and "no loitering", and then you simply don't enforce it for the first few people.

    If this company has a reduced staff, or wants to ensure that large problems don't happen during sensitive times, then they might want the freeze. And saying that there will be a freeze is the way to do that. But calling them and saying "hey, I know there's a freeze, but I'd really appreciate this patch when it's convenient." won't likely be met with a solid "no, screw you, we're in a freeze".

    Ice is usually still a little wet. Not every molecule freezes at the same instant.

    Look at it as an opportunity for you to be nice. They said "we'd really like to ease the harsh environment of christmas IT", and you can optionally say "I'll help you out by not patching for a while". It's an opt-out instead of an opt-in scenario, but it's the same.

    You're complaining about the default, not the final. And you can override the default with a phone call. Don't sweat it.

  16. Re:Go dedicated or go home by GNUALMAFUERTE · · Score: 3, Informative

    I'm using server4you. Their support sucks if you have to call them (they speak german, and very very limited english). If you need support, this is not your company. But if you can manage your own boxes, their uptime is great, and so is the hardware and bandwidth. In the last year we had less than an hour of downtime, and it was after midnight.

    The interesting thing: The prices. $28 for an Athlon X2 with 4GB RAM, 2 SATA disks and unlimited bandwidth.

    Again, the support desk is impossible mostly due to the lack of English proficiency, and their billing department suffers the same problem if you ever have an issue, but they do offer web reboots (you click a button, your servers gets rebooted usually in under 5 minutes). I once requested a server re-imaging and it was processed in 20 minutes. Hardware issues are taken care of very fast too. So, if you know what you are doing, and need nothing but hard-reboots and re-imaging if something goes horribly wrong, it doesn't get any cheaper than that.

    --
    WTF am I doing replying to an AC at 5 A.M on a Friday night?
  17. 216.34.181.45 by kf6auf · · Score: 5, Funny

    Whatever you do, don't take down 216.34.181.45.

  18. Article is based on incorrect reading by phoebusQ · · Score: 3, Informative

    I know which host and to which announcement this refers. All this is is a suspension of fully automated patching during the holiday season. If you want patching performed anyway, jut contact your support team. They prefer to make patching opt-in during this period to avoid site outages due to patching miscommunications.

  19. Customer satisfaction is important to us. by Mr2cents · · Score: 3, Funny

    may I ask Eastern-EU folks to please refrain from hacking my servers during the holiday season?

    Sure, just provide me with your domain name, provider and root password and I'll add you to my do-not-hack list.

    --
    "It's too bad that stupidity isn't painful." - Anton LaVey