Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 20 May 2010 16:28:20 +0200
From:      Roger Vetterberg <roger@vetterberg.com>
To:        Dan Naumov <dan.naumov@gmail.com>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: How long do you go without upgrading FreeBSD to a newer release?
Message-ID:  <4BF54704.20909@vetterberg.com>
In-Reply-To: <AANLkTilslPj7GtFD_tbliyvm7_18qeJOYqDMEca_70fa@mail.gmail.com>
References:  <AANLkTilslPj7GtFD_tbliyvm7_18qeJOYqDMEca_70fa@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On 2010-05-16 17:42, Dan Naumov wrote:
> Hello folks
>
[snip]
>
> Do you liva by the "If it's not broken, don't fix it" mantra or do you
> religiously keep your OS installations up to date?
>
>
> - Sincerely,
> Dan Naumov

Depends on the installation requirements.

I know of two 2.2.8 installations on PII hardware still running like 
champs, not a glitch in god knows how many years of 24/7 operation. None 
of them are exposed externally so there are no security considerations. 
The customers that runs them are still more then happy with their 
servers so I'm actually a bit curious to see how long they will keep 
them running.

I have a few other servers that are highly exposed. My mantra there is 
to run _verified_ software. Not necessarily the latest, but software 
that has no known bugs and has been well tested.
To religiously update everytime there is a new version and blame it on 
security is stupid. How do you know that a brand new version of a 
software does not contain a big gaping security hole unless it has been 
tested in the wild yet?

--
R



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4BF54704.20909>