RE: Anyone know why the Alpha market is so so quiet?



-----Original Message-----
From: Arne Vajhøj [mailto:arne@xxxxxxxxxx]
Sent: May 26, 2007 9:45 PM
To: Info-VAX@xxxxxxxxxxxx
Subject: Re: Anyone know why the Alpha market is so so quiet?

Main, Kerry wrote:
Mass producing cars using an assembly line also brought the prices
of cars downs.

Yeah, but how long would Toyota and Ford be in business if they gave
away cars for free and only sold $1000/year support licenses?

:-)

If the cars got build by enthusiasts which did it for fun, then
they would probably be in good shape.


And we ignore that enthusiasts have to eat and to eat they need to make money.

(we ignore the fact that cars require materials per copy,
because software does not)


Software requires time and skilled resources. Both are limited resources. As the old saying goes - "Linux is free as long as you value your time as free as well."



And as has been noted here in the past - if an OS platform has 5-20
security patches released each and every month, given the huge
QA/testing for App certifications required, can a company actually
afford that platform?

Apparently yes.


Actually, you can not fault the Operations folks for not keeping the hundreds of servers they maintain with 5-20 security patches per month. The sheer volume is over whelming in many cases.

Remember that proper IT processes require their apps to be tested before any new OS patches are released into production.

Since most companies can not keep up with this huge volume of
security patching, they tend to release patches with no testing or
simply let the patches pile up thinking their firewall is good so
they can get away with it.

Unfortunately, as most security analysts will tell you, approx 50-
60%
of all security incidents are internal related.

How many of those use holes that should have been patched ??


See above - in many cases, it is not the fault of Operations staff. They need to co-ordinate OS patches with application developers and Business Units for down time. The sheer volume is amazing.

I would be willing to bet that a large majority of IT shops today have only a small fraction of the applicable (after review) RH Linux security patches identified at the following RH site applied to all their Dev/QA/Test/Prod systems.

https://www.redhat.com/archives/enterprise-watch-list/
[click on thread for each month and add them up - 34 security patches so far in May 2007.. 34!!!]

Case in point - if you have RH Linux systems - have you reviewed the 34 security patches released this month to see if they apply to your environment?

At what point does someone wake up and say "we can not afford this platform!!"


Kerry Main
Senior Consultant
HP Services Canada
Voice: 613-592-4660
Fax: 613-591-4477
kerryDOTmainAThpDOTcom
(remove the DOT's and AT)

OpenVMS - the secure, multi-site OS that just works.



.



Relevant Pages