TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Pro-security? Stay away from these hosters

16 pointsby dolfjealmost 10 years ago

5 comments

kijinalmost 10 years ago
Without knowing the OS and patch version number, whether or not a company uses PHP 5.3 is completely irrelevant to how secure they are.<p>Ubuntu 12.04 LTS ships with PHP 5.3.10, and has been backporting security fixes since the PHP project EOL&#x27;d it. This will continue until April 2017.<p>RHEL 6 and CentOS 6 both support PHP 5.3.3, and will continue to do so for the remainder of their impressively long support cycle, until November 2020.<p>There&#x27;s been a lot of FUD about outdated PHP versions going around in some circles, and I&#x27;m frankly very annoyed by it. Free and open-source software aren&#x27;t like Windows XP. The original developer(s) announced EOL, so what? I&#x27;m under no obligation to get my PHP interpreter from the original developer(s), I get it from Red Hat and&#x2F;or Canonical.<p>The whole point of having a stable Linux distribution is so that you can stop worrying about upstream EOL issues. Heck, RHEL&#x2F;CentOS have even been backporting security fixes for PHP 5.1.6, not that any sane person would want to use that dinosaur of a version.<p>Some of the hosts on that list, however, are indeed using dangerously outdated PHP versions. Feel free to name and shame them.
评论 #9967010 未加载
daenneyalmost 10 years ago
I wonder if anyone bothered to contact the hosters? If not I think this is in poor taste. As far as I&#x27;m concerned when you see issues like this the right thing to do is to reach out to said companies, detail the problem you found and give them some time to fix it before setting up a wall of shame.<p>Besides that, being up to date with software patches is hardly the only measurement of good security. The fact that some hosters don&#x27;t even provide 2FA for your account would have me equally if not more worried, as would their practices regarding storing data and credentials.
评论 #9967423 未加载
评论 #9967417 未加载
nojaalmost 10 years ago
&gt; sometimes see that their front page has outdated PHP, as in 5.3 old. EOL for 11 months. That really bothers me. How can I rely on their security when their frontpage isn’t even up-to-date.<p>Errr... are you determining that the software is vulnerable through the version number alone? That won&#x27;t work, some vendors backport security patches.
评论 #9966948 未加载
评论 #9966942 未加载
helbalmost 10 years ago
&quot;Error establishing a database connection&quot;, googlecache here: <a href="http:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache%3Ablog.patrolserver.com%2F2015%2F07%2F28%2Fthe-infamy-list-hosters-edition%2F&amp;oq=cache%3Ablog.patrolserver.com%2F2015%2F07%2F28%2Fthe-infamy-list-hosters-edition%2F" rel="nofollow">http:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache%3Ablog....</a>
评论 #9967111 未加载
omgtehlionalmost 10 years ago
Pro-security? Stay away from shared hosting.<p>VPS&#x2F;VDS are cheap nowadays
评论 #9967519 未加载
评论 #9967464 未加载