10 ms·
Perhaps these sites should never have been setup. If they were valuable, someone would have noticed they had been attacked and would do something about it.
by polymatter 13y ago
Perhaps these sites should never have been setup. If they were valuable, someone would have noticed they had been attacked and would do something about it.
- stuaxo 13y agoI don't know, there is a place for the low-value occasional use site.
- estebank 13y agoShouldn't those be static then? Not that Apache or nginx are safe to keep around for years without update...
- Angostura 13y agoThere are many useful projects which run for a fixed term and which have an associated Web site. The problem is that there isn't a formal plan for decommissioning the Web site - perhaps turning it into static HTML with an 'archived' banner at the top.
- chadwickthebold 13y agoThe problem with that is that you are then putting the onus on your users to act as your net-sec team. Basically, if your user base is unskilled to begin with (old or economically disadvantaged) and the sites that are targeted to them break, they typically don't know how to let someone know.
- weego 13y agoThis isn't entirely the same domain, but I used to work on a lot of sites for the Dept for Education and the major problem is that people have awesome ideas for "engagement" and spend months or even years gathering support for funding. But that funding will only be for a specific time period. It seems obvious to anyone working in tech that a site needs ongoing support, but it's not obvious to funding panels who sign off the 18 month funding plan.
- belorn 13y agoFrom a webhosting perspective, few people ever notice when their site has been attacked. To a degree, this is by intention of those doing the attacking. They would rather have the site up and running, while the spam, code injection and backdoor can sit there earning them money. It's not until the spam causes damage (or is visible enough) that someone calls someone who is in charge, who in turn might hire a web developer, who in turn calls the hosting company in order to figure out that a 5 year old WordPress site that someone else put together has not been updated. Then it can take even longer until the new web developers has negotiated a price to fix the situation.
- notahacker 13y agoPlus the less extreme examples were comment spam, which is present on the vast majority of commercial sites generating millions, simply because the cost of removing or effectively filtering the spam exceeds the damage done by the spam (especially spam in the form of polite comments about how lovely the website is). Members of the public would have to look pretty hard to find the majority of these issues: they generally don't view source code and and even if they searched kidwelly.gov.uk for viagra the spam pages aren't indexed.
- SixSigma 13y agoAccording to the blog below, the problem isn't that no-one considers them valuable it's that there is no-one actually responsible for their operation and control. http://shkspr.mobi/blog/2014/03/2000-nhs-security-vulnerabilities-disclosed/ http://shkspr.mobi/blog/2014/03/2000-nhs-security-vulnerabil...
- rahimnathwani 13y agoSurely someone is signing off the hosting bill (even if it's one line item among many)?