6 ms·
You're leaving your firm incredible vulnerable to the "checkyoursudo gets hit by a bus" scenario aren't you? At least let the rest of your firm know you have se
by RobAley 9y ago
You're leaving your firm incredible vulnerable to the "checkyoursudo gets hit by a bus" scenario aren't you? At least let the rest of your firm know you have servers and give some credentials (for another account with sudo permissions) to e.g. a managing partner or similar (with instructions to never use them unless you die).
- HenryBemis 9y agoMy though exactly! For the company of checkyoursudo, he's what is called a Key Person Risk. But in my examples, I never use the "hit-by-a-bus". Sysadmins tend to frown upon that comment. I use the "win-the-lottery-go-to-Fiji-and-never-look-back". It always makes them smile :)
- kozak 9y agoI use "go to a vacation" as a euphemism for that.
- AnIdiotOnTheNet 9y agoThe problem with the "win-the-lottery-go-to-Fiji-and-never-look-back" as an example is it doesn't quite get the point across because they'll have time to gracefully transfer knowledge and after that they're just somewhere else in the world so I can still theoretically fly over there and beat them with a wrench until I get what I need. Death is a real thing that really happens to people, and from an organizational perspective it is valuable to keep in mind that no one in your company is immune to that.
- wccrawford 9y agoYeah, it's not the same at all. I had an ex-employer that fired me multiple times, and came back to me to get forgotten passwords multiple times. After a little soul-searching, and deciding I didn't want to harbor anger, I helped him with the ones I remembered each time. Had I actually been hit by a bus, that wouldn't have been possible at all. I'm sure that if I'd hit the lottery and gone to Fiji, I'd have been even more likely to help him with those passwords. In the end, not-burning-that-bridge did help me earn more money as he hired me back several times, and I demanded more money each time until I was asking almost as much per hour as he was getting from his customers and he simply couldn't afford me.
- checkyoursudo 9y agoI actually basically had this happen to me before, too. With two different employers. Aside from one of them being super annoying, over and over again, helping them out was the right thing to do. It's not like it cost me anything other than a couple of minutes of time. If someone already screwed you over, then... But otherwise, why not
- pertymcpert 9y agoHow do you get fired by someone multiple times?
- frandroid 9y agoNot learning the lesson multiple times. :)
- dorgo 9y agoThe "hit-by-a-bus" scenario for me is expressed quite often where I work. I have no problem with it, if it is not repeaded a dozen times. Then it starts to sound like a threat..
- dragonwriter 9y ago“depart without notice and without looking back” can be just as much of a threat, though, especially if the person raising the scenario is a Key Person themselves.
- fapjacks 9y agoI'm curious if I could get a chuckle by saying "Hit by an Uber"...
- jethro_tell 9y agoI'm laughing. Might be too early but I am.
- makeset 9y agoNice, and apparently you're not the only one: https://en.wikipedia.org/wiki/Bus_factor https://en.wikipedia.org/wiki/Bus_factor "The bus factor is a measurement of the risk resulting from information and capabilities not being shared among team members, from the phrase 'in case they get hit by a bus'. It is also known as the lottery factor, ..."
- galdosdi 9y agoI guess I have worked with different types of sysadmins. A good sysadmin has, or at least expresses traits of in their work, pessimism and realism. We have to constantly viscerally feel and know that any component can fail at any time. Remembering your own mortality goes along well with that. Being easily disturbed by this is not a trait I would like to see in someone with these kinds of responsibilities.
- rthille 9y agoI never worry about being hit buy a bus, I assume it'll be quick :-)
- jlg23 9y agoOne can also assume that any competent replacement for the "checkyoursudo who was hit by a bus" is able to log into machine after a reboot. I rather rely on beginner level sysop skills than on management understanding the implications of "this is my access to your mail server, don't handle with care, don't handle at all unless I am run over by a bus".
- walshemj 9y agoOne way we did it at BT was all the root paswords where placed in an separate envelope per machine, and kept in the fire safe.
- tokenizerrr 9y agoReboot into single user mode, reset root password, and done.
- ilikepi 9y agoThe issue is the new admin has no way to know whether all the processes running before the reboot are configured to come up automatically, and no sense of what external dependencies the server has. Further, the admin is forced to deal with problems reactively at boot time, rather than having the opportunity to gain an understanding of the server setup in advance.
- arca_vorago 9y agoNot if grub is encrypted, better even behind FDE.
- justaj 9y agoHow does booting for remote login in such a setup work though? You'd have to be physically present in order to enter the passphrase.
- arca_vorago 9y agoFor that I do an ssh shim at initram (with portknocking) for key entry preboot
- amdavidson 9y agoI would love to read a tutorial on that if you know of one.
- rthille 9y agohttps://hamy.io/post/0005/remote-unlocking-of-luks-encrypted-root-in-ubuntu-debian/ https://hamy.io/post/0005/remote-unlocking-of-luks-encrypted...
- deleted 9y ago[deleted]