Post B4Xl15TFDF02vIIZMm by rick@a.n0id.space
(DIR) More posts by rick@a.n0id.space
(DIR) Post #B4XjGOBrhBtzPtL2Aa by rick@a.n0id.space
0 likes, 0 repeats
What i really hate about Linux security in companiesMedia: "patch your systems nooooww" IT sec guy: "ahh wee need to patch cve10! ahh ahh" *runs around like chicken *Customers: "yeah we do wanna kinda patch, but pls pls pls don't reboot our systems"Ops ppl: "urgh do we really have to patch again?! We already had an emergency patch two weeks ago *they already have a high workload *"Other ops teams in my chats: "are we affected? Are we affected?" Me: *also already with high workload * "Calm the fuck down pls!! Vendor says it cve 7, well not good but not earth-shattering.. We should patch, but please calm down. Vendor didn't even provide patches for this.... :baa:" I know, security is important, i also like my systems up2date but i feel sometimes stuff gets hyped way to much, media be like "Well just update and reboot", but in some big companies with thousands of systems its not that easy. Well patch and reboot is easy, but not the other bureaucratic stuff around it. other problem is that most of us have already a high workload and this comes ontop everytime... And yeah containerisation and stuff helps with that, but most of customers of my work area still have many vms and big bare metal servers :akko_badday: Thanks for listening to my monday morning tech rant :laughing_cirno:
(DIR) Post #B4XjV0jBDAsczZtQsi by rick@a.n0id.space
0 likes, 0 repeats
And the biggest problem is, that its happen in a more shorter timeframe every year... :baa: currently it feels like its every three werks...RE: https://a.n0id.space/objects/85d7fce7-d84d-4d29-9257-b36f097a907f
(DIR) Post #B4Xjd95c0SI9F6GSoq by kura@hai.z0ne.social
0 likes, 0 repeats
@rick@a.n0id.space introduce kubernetes.
(DIR) Post #B4Xl15TFDF02vIIZMm by rick@a.n0id.space
0 likes, 0 repeats
@aetios @kura we have it for some customers, but not all want and can use it.And you see, i'm currently not in the Kubernetes team :laughing_cirno:
(DIR) Post #B4XmvA1Na3ijCuZBqK by lilly@chaos.social
0 likes, 0 repeats
@rick most of us have already a high workload and this comes ontop everytimeueff sorry to hear :(patching and maintaining should really be part of the normal workload. It fortunately is for me but I feel your pain qwq
(DIR) Post #B4XmvAFui1LXvzMnUu by rick@a.n0id.space
0 likes, 0 repeats
@lilly thanks :3
(DIR) Post #B4aeZjkBrpZrTAgCtE by darkphoenix@not.an.evilcyberhacker.net
1 likes, 0 repeats
@kura@hai.z0ne.social @rick@a.n0id.space okay but then suddenly you have to deal with a dozen OS level vulnerabilities popping up in your images constantly and have to bother potentially both your suppliers and outside projects to rebuild which they often don't do for agesif anything I find this to be more of an issue in Kubernetes, because you have dozens more copies of the same deps and you don't have an automated way (i.e., the equivalent of an apt autoupdate) to fix it at scale because fixed versions are baked in
(DIR) Post #B4aeaYKPnQGMM00qIK by darkphoenix@not.an.evilcyberhacker.net
1 likes, 0 repeats
@kura@hai.z0ne.social @rick@a.n0id.space ...and to even find out what's in your images you'll want something like Trivy which... oh no oh fuck just suffered a supply chain attack because in IT the sky is falling down every other Thursday