3 ms·
The post advocates simply staying reasonably up to date, then says that IIS 6 is unreasonably old. relevant bit: This is not necessarily a high-intensity exerc
by alsothings 14y ago
The post advocates simply staying reasonably up to date, then says that IIS 6 is unreasonably old. relevant bit:
This is not necessarily a high-intensity exercise, once every few years you simply make sure you haven’t fallen too far behind the eight ball. Certainly you don’t let key software components get 9 years old and nearly 5 versions out of date.
This is quite a bit less intensive then you describe and I think it's reasonable to expect that a website taking payments not be more the a couple years out of date.
- jiggy2011 14y agoIIS 6 is part of Windows 2003 Server, therefor it will be on "Extended Support" until 14/07/2015 http://support.microsoft.com/lifecycle/search/default.aspx?alpha=Windows+Server+2003+R2 http://support.microsoft.com/lifecycle/search/default.aspx?a... This means that if there is some security vulnerability discovered with it then Microsoft will provide a patch, therefor from a security point of view it isn't "out of date". The number of years and versions is fairly irrelevant, there will be plenty of very secure systems in use by banks and the military that will no doubt pre-date much of what tesco is using by several decades.
- troyhunt 14y agoThe relevance is that none of the additional protections added to the technologies are available. We're in a very different threat landscape today than what we were in 9 years ago and the technologies provide advances to better protect ourselves. If you're using them!