Hacker News new | ask | show | jobs
by slt2021 1887 days ago
if your unpatched server is being used as a command&control server in an active offensive campaign, you can be liable for damages your server caused.

I hope that in the future there will be some fine for Server Neglect (leaving internet facing server unpatched and hosting web shells for 5 days after patch publication by vendor) and you will lose your server and all your data for such misdemeanor.

1 comments

> I hope that in the future there will be some fine for Server Neglect (leaving internet facing server unpatched and hosting web shells for 5 days after patch publication by vendor) and you will lose your server and all your data for such misdemeanor.

I can see it now: "Government stole decades of family photos and videos because my Linux/Plex server was available online."

good security practice, you don't patch your servers - turn it offline at least or government will nuke it