4 ms·
I'll tell you how this happens: Colleague #1: "What password shall we set?" Colleague #2: "Just leave it default for now as we're still testing, we will chang
by gnrlst 7y ago
I'll tell you how this happens:
Colleague #1: "What password shall we set?"
Colleague #2: "Just leave it default for now as we're still testing, we will change it later".
- bouncycastle 7y agoColleague #3: "Sounds good to me. We're behind the firewall and the NIC used for Dell iDRAC or HP iLO is on an isolated network unique to the physical datacenter. Remote access for our techs is managed through a secured bridge that requires all sorts of security hoops on our company intranet, and remote access for general internet traffic is not available due to the firewall restrictions. There's no way hackers will get through that in the first place."
- Legogris 7y agoColleague #4-20: Build various integrations to database, all with their own ways of storing credentials. Colleague #2: "It's really past due time to change the database password, but first we have to make sure all critical systems can still access the database."
- bloopernova 7y agoWhich is why forward planning and prompt action is worth so much. I know I'm stating the obvious, but I've seen some worrying attitudes of "just in time" that seem to go hand in hand with a misunderstanding of Scrum Sprints or Kanban. Where people concentrate on the tree and ignore the vast interconnected forest around them.
- dspillett 7y agoHence the old adage: days of work can save you hours of planning.
- elisharobinson 7y agomanager: why is it taking so long to deploy a simple cluster. back in my day we could code a whole ...
- notzuck 7y agoExcellent use of copy paste from another thread. Upvote!
- merhard 7y agonice meme
- peterkelly 7y agoSource: https://news.ycombinator.com/item?id=21312609 https://news.ycombinator.com/item?id=21312609
- avip 7y agoGood ol' "temporary permanent" solution. https://stackoverflow.com/a/778275 https://stackoverflow.com/a/778275
- Phillips126 7y agoThank you for that funny read, lots of great comments!
- nonconvergent 7y agoColleague #437: "So whoever first set this up has left, so I'll just follow the documentation they left to figure out what they did... Oh. ...eh, I got a deadline."
- rjkennedy98 7y agoYou would be shocked at how nonchalant and downright negligent people can be about security at even the largest companies in the US. I did consulting work at a large insurance company that had the contact information, ssn, and PHI of pretty much everyone in the America (and I mean everyone). I lost track of the number of times people checked in the production password into git. In fact our production cassandra instance still was using the default cert password 'changeit' when I left. Unsurprisingly, this company was filled with contract workers and H1B workers that were barely able (if at all) to get their work done.