4 ms·
Developers often are a soft target, esp. in small/medium companies, but in my experience it's more of necessity by imposed expectations from management, than pe
by mickronome 8y ago
Developers often are a soft target, esp. in small/medium companies, but in my experience it's more of necessity by imposed expectations from management, than people actually wanting to have "root" everywhere. But I and many others dislikes getting yelled at by management, and no one has yet to accept any reasonable security precautions as a reason for delayed delivery without promptly ordering that precaution to be summarily removed, at least not in any of the companies I worked or consulted at the last couple pf decades.
If management understands that security costs time in feature development, fine. But with the role software development has these days in companies, if security and ops doesn't succeed in getting management on board, please don't hold the developers hostage! Work with them and try to find the least bad ways of working quickly enough. Many of them will support calls for better security practices as long as it doesn't imply more sleepless nights because goals haven't been changed, only the speed of which work can be done.
For any substantial deployment, I really don't want to have any access as a developer, but often I have to have root access to tons of machines simply to have any chance at actually doing my work.