[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-security] SUN don't care about security update ?



At 01:58 AM 3/20/2002, you wrote:
Home to as many as 200 websites or a single, powerful dedicated server.
If you're a service provider, the Sun Cobalt RaQT server appliance is
the alternative to "big iron" servers. The Sun Cobalt RaQ server
appliance includes everything you need to begin hosting now.


A direct quote from Cobalts website. You see the last bit "everything
you need to begin hosting now".
Well read that as "everything you need provided you don't need it to be
secure and don't mind if it gets hacked within 24 hours"

I bought a RAQ4 it's the first server I ever bought, I new nothing about
Linux, servers, dns, nothing. I bought it to host websites for my small
business. Within one week of subscribing to this list, reading manuals,
researching on the web, I realised that it is totally insecure. I had
bought a car without breaks, a house without doors, I might as well have
left it lying in the street with a sign on it saying "nick me". Since
that time I have had to learn vary quickly all about the security issues
and thanks to many people on this list I think my server stays
reasonably secure.

My point is: had the advertising been honest, had it said on the box -
"looks good, nice spec but open door to hackers" I never would have
touched it.

And that is why they have marketing people to spin EVERTHING, and they count on people to not do research.



In English law a product must be fit to perform the purpose for which it
is sold. The RAQ4 out of the box is not fit to host websites.

You and I now know that, but we can not return the boxes can we... the best we can hope for is sell them off to someone else who does not know what we know for a loss.



__________________________________________
Simon




_______________________________________________
cobalt-security mailing list
cobalt-security@xxxxxxxxxxxxxxx
http://list.cobalt.com/mailman/listinfo/cobalt-security