Upgrade policy/urgency
Posted: Mon Jul 10, 2017 12:11 pm
Hi,
All new sites we develop use the current 2.x version as you'd expect and we update these regularly.
However, we also have some old 1.x versions where the clients have indicated that they prefer not to update past the last 1.12 version, primarily down to cost. We have encouraged this but until more recently, the old 1.x series seemed fairly secure and so we haven't insisted, even where the sites used our servers.
Now it appears that there are some more serious security issues identified more recently, which changes our view on the old versions, even though they are all 1.12.2.
Is there anything can be done relatively easily to secure these older sites please, or is it time to update everything? A couple of them have some tweaks to older versions of FEU so could be some fun there!
Just interested to know what everyone else's policy is on the 1.x updates please. I know you should keep everything updated all the time ideally, but sometimes it doesn't happen, particularly where a client is reluctant to pay for support.
Thanks
Dave
All new sites we develop use the current 2.x version as you'd expect and we update these regularly.
However, we also have some old 1.x versions where the clients have indicated that they prefer not to update past the last 1.12 version, primarily down to cost. We have encouraged this but until more recently, the old 1.x series seemed fairly secure and so we haven't insisted, even where the sites used our servers.
Now it appears that there are some more serious security issues identified more recently, which changes our view on the old versions, even though they are all 1.12.2.
Is there anything can be done relatively easily to secure these older sites please, or is it time to update everything? A couple of them have some tweaks to older versions of FEU so could be some fun there!
Just interested to know what everyone else's policy is on the 1.x updates please. I know you should keep everything updated all the time ideally, but sometimes it doesn't happen, particularly where a client is reluctant to pay for support.
Thanks
Dave