Well, this "oppinion" in that community might change, when companies and/or individuals start legal actions against the responsible web-server administrators that knowingly refused to secure their service, accepting the possible damage to other IT systems?
There is a reason why personal insurances added "cyberdamage" to the liabilities they would pay for, as long as you take all reasonable measures to ensure system safety...
"My Linux webserver is safe and I don't care about the damage to others" does not work in mist western countries, as far as I know.
|