Ask Slashdot: Should Hosting Companies Have Change Freezes?
AngryDad writes "Today I received a baffling email from my hosting provider that said, 'We have a company-wide patching freeze and we will not be releasing patches to our customers who utilize the patching portal for the months of November and December.' This means that myself and all other customers of theirs who run Windows servers will have to live with several critical holes for at least two months. Is this common practice with mid-tier hosting providers? If so, may I ask Eastern-EU folks to please refrain from hacking my servers during the holiday season?"
Using windows to provide an internet facing service was the first mistake.
I work for a company with 1200+ VMs and the change freeze concept is nothing new. For us, it's only 1 month around new years and mainly due to staffing issues if something goes wrong.
The server will be spending 50% of its life rebooting to apply minor updates and install software, reducing the risk of a security breach.
Whatever you do, don't take down 216.34.181.45.