This is a discussion on Re: system auto security update over night within the mailing.openbsd.tech forums, part of the OpenBSD category; --> : openbsd team work with security in mind. : automagically-download-patch-install-upgrade is NOT security. if you : have 1/2 systems, ...
| |||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
| ||||
| : openbsd team work with security in mind. : automagically-download-patch-install-upgrade is NOT security. if you : have 1/2 systems, you do not need no automation. if you have a lot of, : you can waste a couple of minutes to install a build-my-binary patchbox. : this is insane, think about what will your boss do if your automagical : upgrade broke your mysql (like debian does). think about it a while. Think about what your boss will say if someone broke into some of your systems because of a leak in the daemon because he brake in a few hours after midnight. If your system had applied the patch at midnight (or so) the system would still run secure. And btw. You don't have to run such an update-tool/daemon on a production systems. But maybe on your firewall, on workstations, on servers not needed for production... If you apply a binary patch to a production system and your mysqld will go down after that, you will have the same problem too... -steffen |