4 ms·
There are strict security in place to prevent any "leaks" of software which means all USB ports are disabled in company devices, the company network has disable
by AussieOdyssey 10y ago
There are strict security in place to prevent any "leaks" of software which means all USB ports are disabled in company devices, the company network has disable git/github/bitbucket and our security manual explicitly states that the code cannot leave the intranet.
The consultant bypasses this by running wireless hotspots
- viraptor 10y agoTalk to a lawyer. Especially because you're asking about Oz advice on a primarily us site, so common understanding of the law may be different. And whatever you do, consider if you can afford getting both fired and sued right now - even if people tell you you're right. Also I'm assuming that's 100% the public GitHub service and not an on-site, or specially negotiated GitHub enterprise system?
- AussieOdyssey 10y ago100% public github because they want to give access to new employees who do not have access to enterprise system.
- thehardsphere 10y agoSounds like they want to give access to everyone on Earth!
- contravariant 10y agoPlease tell me you're not saying they're using a public repository (one reachable to anyone, even people not logged in to GitHub).
- grspencer 10y agocould be the repos at https://github.com/WestpacCXTeam https://github.com/WestpacCXTeam
- i336_ 10y agoI vouched for this because it's a fair point to make, and also because it can be 200% debunked: 1. That repo links to a publicly-viewable website, I'm seeing files in the list from 9 months ago (way long enough), and GitHub has a very clear, very well-oiled DMCA process. This is up because it's okay. 2. From https://news.ycombinator.com/item?id=13682657 https://news.ycombinator.com/item?id=13682657 (nearby this thread): > If you go to the company's public github & bitbucket profile you cannot see the project but you can see all the devs and all these devs have access to the code. IOW, it's a private repo hosted on GitHub. «The code is safe from the public» but the contractor's actions still squarely violate the security guidelines for the project such as no USB drive access (!) (https://news.ycombinator.com/item?id=13679303 https://news.ycombinator.com/item?id=13679303). The OP qualified this fairly explicitly here: https://news.ycombinator.com/item?id=13682501 https://news.ycombinator.com/item?id=13682501
- g00gler 10y agolol
- AussieOdyssey 10y agoSorry, that's not what I meant. I mean *.github.com and NOT an enterprise level private repository. If you go to the company's public github & bitbucket profile you cannot see the project but you can see all the devs and all these devs have access to the code. The logic is: All the employees are able to work with minimal delay (caused by background checks)
- contravariant 10y agoThanks for clarifying. It appears some other people in this thread ran to conclusions. Although the situation is still bad, just not immediately disastrous.