Security By Antiquity?
|
I just stumbled across something interesting, perhaps not as big an issue as I think: NIST (the National Institute of Standards and Technology)'s Computer Security Resource Center web site, which is there to spread information on good IT security practice, runs on Netscape Enterprise Server 4.1. This product of course no longer exists. According to Wikipedia: The product has since been renamed Sun Java System Web Server, reflecting the product's acquisition by Sun Microsystems. Since version 6.0 was released in November of 2001 I can only assume that version 4.1 is quite old, and that updates are no longer being written for it. Would you run this on your web server? Let me know. |

Comments (1)
Would I run this on my web server? No. I'm not a believer in the philosophy that "just because something has not been hacked then it must be secure." This is a philosophy that many Mac fanatics used to use when they were Windows bashing.
I would call this case a perfect example of security by bureaucracy!
Posted by Steve Sommers | April 26, 2007 6:52 PM