3 ms·
I have been researching this space recently, what turned me off was them scanning ports and then reporting to ISPs, supposedly because people were running vulne
by RaleyField 9y ago
I have been researching this space recently, what turned me off was them scanning ports and then reporting to ISPs, supposedly because people were running vulnerable versions, but reporting could make problems for users because some ISPs don't allow servers on home connections.
And here's the money quote: "The effort has been quite successful. Of the tens of thousands server owners who were informed, over 5% had upgraded already in the first ten days."[1] In other words 95% were left vulnerable and they were responsible for it. Does not inspire trust.
[1] https://nextcloud.com/blog/nextcloud-releases-security-scanner-to-help-protect-private-clouds/ https://nextcloud.com/blog/nextcloud-releases-security-scann...