I regularly saw Fortune 100 firms having domain controllers with MS08-067 unpatched in 2013. I also saw other places with pressurized Ethernet runs. I'm guessing it's still spotty depending on where you're at.
Deloitte _sells_ security consulting and they had DCs on public internet as recently as a few years ago (around the time they were breached).
At least tell me they were RODC's?
Oh yeah, no doubt. I'm not trying to suggest that the overall state of security is "good" by any means. I think we all know it isn't. I was more just making the point that if security is not where it could be, it's not really because any of this is new. We've known computer security was an issue for a very long time. Now doing something about it, well, that's a different story...
What is a pressurized Ethernet run?
An Ethernet cable inside a pressurized tube. If pressure changes you know someone may be trying to tamper with your line.
Clever. Do people actually do this? (The pressurized part, not the tampering part.)