3 ms·
I have no evidence, but I imagine it's a solid "no" at any of the largest well-known companies. No way in hell is live production data available to every develo
by developer2 10y ago
I have no evidence, but I imagine it's a solid "no" at any of the largest well-known companies. No way in hell is live production data available to every developer. But it's certainly typical (rather, completely standard operating procedure) at most small and also mid-sized companies. It's even worse than "everyone has access to the production database" - it's "the production database is copied to staging and individual developers' VMs".
Smaller companies never invest the time to set up proper staging and developer environments that operate on purely fictional data. It always starts as a copy of production; and the majority of companies don't even take the most basic step of swapping out sensitive info. The numbers of times I've seen users' plaintext account passwords (another problem entirely) synced to every developer's machine is honestly astounding.
- existencebox 10y agoRealized I wrote an essay, TLDR version: Even with best intentions the real world is very messy, and I am more paranoid that most and thus would still advise limiting data exposure to bigCos. Having worked at multiple of the largest, I would say your statement is 'broadly true' (especially in terms of intent, there is certainly the mission to protect that data) but there are enough edge cases that one can logically worry; Imagine a scenario where some legacy property that is in the prod vnets and needs prod access but doesn't have all the oversight mechanisms new services do, and is now handed to a very junior engineer to maintain with all the power that entails. I'm staying very far away from making any statements about opinions on the actual enterprises goals/merits from data collection to distract my key statement, but regardless of that, there are enough of these "edge cases" that I as a consumer would reasonably want to limit as much as possible the footprint of data I allow to these companies. The "vulnerable surface" of data across all of these large companies is just too wide to protect 100%, especially given that you HAVE to trust some people as "good actors", and while this tradeoff is fine for many people, I fall on the line of not being a fan. I may be being paranoid about this, but I want to both disclose that I'm an MSFtie and none of these statements are specific or represent concrete information about any companies for which I am bound to an NDA on internal operations. They are just my learnings/intuitions as a paranoid dev/ops who has seen a wide range of operating environment and the various pitfalls within, and would have made an equivalent statement earlier in my career prior to my bigCo phase extrapolating from small/midCo patterns and trends.