Hacker News new | ask | show | jobs
by kbenson 3725 days ago
It's not even always about finding how bad your security is. Sometimes you might know exactly how they got in, but that doesn't affect whether you've successfully cleaned them out at all. Once someone is on your system, being absolutely sure you've cleaned the systems out of security issues is something you'll never quite be sure of, without booting trusted third party media and comparing the disk to a known good backup. Most sysadmins I know don't bother, it's easier to just restore from a known good backup and selectively copy anything over that was changed more recently. Restoring a live system from backup and making sure it's fit for production duty is quite a bit more involved than changing a password, or patching a program. It's not a huge burden, but extend it across tens of servers, and costs start piling up quick.

If you find out that someone's been coming into your house when you're not there for a few weeks, but you're not entirely sure how, you don't just change your key, you also check all your windows, possibly fix the latch or replace the window on any that are broken, etc.