Hacker News new | ask | show | jobs
by mpldr 1202 days ago
This. So much this. It's fine to not use the latest version, but use a supported version. If the version is EOL, don't use it. Even if you have backports. Otherwise you will inevitably run into issues where the system is insecure by-design. I can't ssh into half the servers because I have to first enable insecure algorithms, the PHP version is almost old enough to drink, and the Debian mirrors don't even serve this version anymore.

Sure, the system is stable. Until somebody finds it, then it can be a threat to the entire network.