4 ms·
For any X, getting rooted is still often a matter of someone with 1000 botnet nodes to burn running a for loop against an IP range. At which point, your odds of
by cat9 12y ago
For any X, getting rooted is still often a matter of someone with 1000 botnet nodes to burn running a for loop against an IP range. At which point, your odds of getting rooted are the product of how desirable that target is to write for loops against and how long it has been since you last applied security updates.
The reason WordPress tends to be root city is that there are a great many installs out there, of which many have never had step one done to harden it, and were last given security updates ~ when they were installed.
I would still outsource WordPress, but that's mostly in the vein of "the cost of outsourcing is less than the cost of me having to think about it one hour a month, while 1 hr/mo is a reasonable floor for the time cost function, but the actual value will probably exceed that at least once in a given year."
A WPEngine subscription costs $30 to "I don't care, why are you wasting my time with numbers this small." Developer time costs between $75/hr and "everything is on fire and you can only put out one fire at a time." Ergo it makes economic sense to configure nginx / DNS once, then outsource further complications to paid external support.
- meowface 12y ago>For any X, getting rooted is still often a matter of someone with 1000 botnet nodes to burn running a for loop against an IP range. At which point, your odds of getting rooted are the product of how desirable that target is to write for loops against and how long it has been since you last applied security updates. If you're looking at all Internet-facing servers in aggregate, yes, but if you know what you're doing then the odds of getting owned by a random botnet are very slim. Assuming you have a good security posture, your risks are dedicated and intelligent attackers and 0-days, not botnets scanning for low hanging fruit.
- JoachimSchipper 12y agoCareful, there - it's easy to forget to patch one site out of some hundred-odd. Big organizations are hard. (But yes, a single competent admin who doesn't take holidays will usually have pretty decent security.)
- meowface 12y agoOh yes, once you have more than a few employees you become much more at risk of that. I was assuming a scenario of one sys admin managing a small set of servers.