this post was submitted on 17 Jun 2026
208 points (97.3% liked)
Fediverse
42516 readers
546 users here now
A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, Mbin, etc).
If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!
Rules
- Posts must be on topic.
- Be respectful of others.
- Cite the sources used for graphs and other statistics.
- Follow the general Lemmy.world rules.
Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Sadly, a reluctance to install patches isn't unique to Windows administration. I worked at a site with a well functioning Satellite infrastructure and support contracts with Red Hat. And we (InfoSec) were still chasing down admins to get their shit patched. Thankfully, we had NAC and authorization to disconnect systems that feel out of compliance. Most departments got with the program pretty quick when they ignored the "please patch all critical vulnerabilities in three days' email and ended up with a "you are out of compliance and have been disconnected" email.
And Docker had made the whole Linux situation even worse. So many devs love to spin up containers, basically disable any sort of firewall, don't bother with IP filtering. Oh and let's just use passwords for ssh. Also, who needs logs? It's a container, right. So, let's disable all logging and not forward those anywhere. Then they promptly forget about the container until we run a vuln scan and find it's got half a dozen RCE vulns and have to run them down and ask why the fuck it's still running.
Linux is a much better base to build on. But bad security hygiene is still rife and still really bad for security.