Say goodbye to Windows Server 2008 and hello to Azure? | Knowledge of the data center
Windows Server 2008 and several other popular platforms will be retired on January 14, and Microsoft is encouraging users to migrate to its Azure cloud by offering free extended support.
Windows Server 2008, despite its age, is still one of the most popular server platforms in use today. Recent market share figures are not available, but a Microsoft executive said this summer that the operating system version still accounts for 60% of the company’s server install base.
Data centers still using this operating system can upgrade, mitigate, or migrate to the cloud.
Updating to a newer operating system is always a good idea, as there are usually significant cybersecurity benefits to being on the latest version. But not everyone is able to do that.
The other option is mitigation, like adding extra layers of security around older machines and paying for extended security updates. The ESU will cost a flat fee, however – around 75% of the cost of the annual license itself.
But Microsoft also offers a third option: keep Windows Server 2008 but run it in Azure and get three years of ESU for free.
The risk of staying put
“Unfortunately, many commercial applications will not work on new server and desktop editions,” said Morey Haber, CTO at BeyondTrust, a Phoenix-based cybersecurity vendor. And it’s not just software, he added. There may also be hardware compatibility issues, such as drivers not being available for newer platforms.
But if these servers face the public Internet, they will pose a significant danger to data centers. “The next major vulnerability discovered that is potentially remotely exploitable will leave these devices vulnerable to a wormable exploit with no remediation strategy,” Haber said.
That’s what happened with the WannaCry and NotPetya attacks, he said. “Organizations will have very few mitigation strategies to work with.”
Another security issue is that older systems won’t be able to support new security standards for authentication and certificates, he said, and can also put a data center in breach of regulatory requirements.
Given the scale of the Windows Server 2008 deployment, the stakes are high, said Satya Gupta, founder and CTO of Virsec Systems, a San Jose-based cybersecurity vendor.
“Inevitably, many of these servers will remain online, many of which will protect aging infrastructure and healthcare systems,” he said. “Unfortunately, it will likely take another global security crisis, like WannaCry or NotPetya, before many of these laggards catch up.”
Why upgrading isn’t always as easy as it seems
Some data centers might not have a choice whether or not to upgrade, said Marty Puranik, CEO of Atlantic.Net, a Florida-based data center and cloud provider.
Atlantic.Net isn’t one of those data centers, he added, because it’s blessed with no legacy applications.
The problem with upgrading the operating system is that sometimes an upgrade can break a critical application, he said. Also, if a system is running, stable, and working, there is no obvious incentive to upgrade, especially when there are many other more pressing tasks that those responsible for data centers need to care.
In fact, a Windows Server 2008 system can perform better than newer machines because there’s less demand for those resources, he added. “These servers are lightly loaded because everything that can be moved has already been moved,” he said.
Other times, the data center itself may not have control over the operating systems used on the servers, because those servers are owned by external customers or other business units of the company.
Now, those outdated servers could pose a potential security risk to the entire data center, Puranik said.
Colocation providers, who typically only sell space and power, and whose customers configure their own network connectivity, have less to worry about, he added.
“But if you’re also providing internet, that could become a problem,” he said.
There should already be firewalls in place, he said, but now is a good time to check that all systems are properly isolated.
And if there are computers that are past the end-of-life date, there should be another machine between them and the public internet, one that’s patched and updated.
“People will scan the whole internet for these servers,” he said. “Just cutting off direct access or making it more difficult should provide some level of protection.”
End-of-life servers can be opportunities for hackers to find and exploit vulnerabilities, said James McQuiggan, security awareness advocate at security vendor KnowBe4. This exposes the entire data center to the risk of ransomware, data exfiltration or other attacks, he said.
Then there is the cyber insurance angle, he added. “There are clauses related to updating systems.” If a data center experiences a breach and there are older operating systems in the environment, the insurance company will deny the claim.
If end-of-life servers are in an environment, data center managers need to add additional layers of protection to their networks. This includes increased network monitoring and endpoint protection and response, he said.
“And a change management program [is necessary] to track all changes to the systems,” he added.
Alternatively, data center managers could take the opportunity to expand their use of the cloud, Atlantic.Net’s Puranik said. “Ideally you already have your toes in the water with clouds,” he said. “But if not, that’s something you could start with.”
Comments are closed.