5 ms·
> customer-controlled updates This is a huge one where I'm at. Our flagship product is not a SaaS, customers install it in their own cloud environments, and a
by Sohcahtoa82 16d ago
> customer-controlled updates
This is a huge one where I'm at.
Our flagship product is not a SaaS, customers install it in their own cloud environments, and as a result, they scan us with Wiz, Prisma, basically anything that supports agentless scanning, and then send us reports demanding answers and remediations.
Half the time, they're running versions that are over a year old. Sometimes, the version they're running is 3 years old and end-of-support. Then tell us they don't want to upgrade. It's the dog-wanting-the-frisbee meme, except it's "Patch CVEs? NO UPGRADE! ONLY PATCH CVEs!"
And every time there's a new CVE with its own web page, logo, and TikTok dance, we get dozens of tickets from customers asking if we're affected and what the workaround is. Like, yeah, I get that an easy-to-exploit LPE like DirtyFrag seems scary, but the system has SSH disabled on production deployments. If an attacker has shell, you've already lost.
Terrapin was especially infuriating. Customers were acting like it was an authentication bypass.