7 ms·
White hat social engineering: How to become an admin of a system
- runawaybottle 6y agoYou’re bragging about being manipulative?
- deleted 6y ago[deleted]
- bgutierrez 6y agoNo, he's explaining that acting responsible puts him in positions of responsibility.
- runawaybottle 6y agoReally? Because I think he broke it down into steps: Step 1: Become admin Step 2: Say there are too many admins now, redefine the requirements for admins to fit you Step 3: Stay admin, while others don’t qualify Huh? This is cool?
- pdonis 6y ago> he's explaining that acting responsible puts him in positions of responsibility It could be taken that way, but the problem is that the author deliberately puts it in terms that make that ambiguous. A much less ambiguous way to put it would have been: 1. Help out an existing admin by fixing something they care about fixing but are too busy to fix themselves. 2. Repeat step 1. enough times that there is general recognition in the organization that you can fix problems and will do so responsibly. 3. Approach the powers that be and point to your track record established in steps 1. and 2. as evidence that (a) another admin is needed to help carry the load, and (b) you are the right person for that job. 4. Get appointed as an admin. The author's process might be essentially the same as the above, but it might not; there are various signs in his writeup of the latter, that might be valid signs or might just be his whimsical way of speaking. And if his process isn't the same as the above, then he's doing more than just acting responsible and thereby earning positions of responsibility. Where the real divergence comes is this: "8. Make sure to keep helping out anyone who wants to fix problems with the system. If you become a roadblocker, you will allow someone else to do step #1 and you might lose your access when that person reaches step #6." Notice that in my steps 1. through 4. above, no existing admins get punted. So there's no need for someone who reaches my step 4. to take steps to prevent others from starting at my step 1. and working their way through the process. And someone who was genuinely concerned for the well-being of the organization would be open to the possibility that, just as the admins who were there before him weren't able to take care of all the problems, there might come a time when the admins including him might not be able to either.
- oneiftwo 6y agoI absolutely agree with this sentiment. It's why I had difficulty reading "how to win friends and influence people" despite how frequently and casually lauded it is. It's literally an instruction manual for using indirect methods of communication and influence to get people to do what you want. It's practically adtech for the self. Ignoring the dangers of having charismatic power over people, I don't know under what circumstances it is ethical to manipulate someone, and I certainly wouldn't brag openly about it.
- gowld 6y agoI don't see why people are intuitively manipulative deserve it more than people who study. Manipulation is a tool. How it is used it was matter.
- runawaybottle 6y agoSo let’s discuss how manipulation was used: > Declare that there are too many admins and that there needs to be a stricter policy to define who can be an admin. > Take it on yourself to define (or redefine) that policy and present it to the system owner in your organization. Make sure you fit the new definition and make sure that staple admins are also included. > No one remembers why you’re admin, but you’re setting the rules now so no one can dispute it. Victory! What are we even discussing here? This is such a indicator of bad character.
- mehrdadn 6y agoI think some of it was tongue-in-cheek...
- runawaybottle 6y agoAh ok, well now I feel like a dumbass. But hey you never know, some sociopaths will totally write something like this.
- pdonis 6y ago
- dfine 6y agoThis is an instructive article for how to get a lot done to improve systems as a "utility knife" developer in a growing startup, but how to do it responsibly.
- iandev 6y agoI think the article makes some good points, but I'm not sure that the gatekeeping step (step 6) is necessary. I think if you look at all the other steps, it fundamentally comes down to one thing: Care enough about making things better such that others view you as valuable.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- RcouF1uZ4gsC 6y agoFor my part, of can’t understand why someone would want to be admin. It seems like a thankless job with a lot of stress and you are often the first in line for blame if something bad happens whether or not it was your fault. But, I am glad that there are people who really like being admin enough to go to a lot of effort to become one.
- TheOperator 6y agoIt causes me way more stress to see bad admins fuck up so badly it causes an impact to other employees yourself included in the department while you sit passively by, than it is to put your hand on the wheel. The admin panel also has more buttons and buttons are cool. It's a petty form of power.
- sumfoni 6y agoIts often enough easier to control the system directly, which you care for, then to wait for others doing what you can do by yourself. I'm waiting again for an issue being fixed by some admin from a jira system. I could just do that myself, i could do that better then the other person, but i don't have the permissions. Sometimes its like 'do i pay someone else to paint my walls vs. do i do it myself'. I'm a software engineere, it feels naturally to control my environment.
- yesenadam 6y agoThat doesn't sound white hat at all. It sounds sociopathic. At least he on some level recognizes that it "sounds like an evil plan for world domination".
- runawaybottle 6y agoThat was my sense, but apparently this is a troll post.
- yesenadam 6y agoHmm yes, that makes more sense! Not far enough from what I've seen written seriously that that was apparent, though I'm no expert in the field. On the topic of taking jokes seriously : About 10 years ago I came across Winning with the Bongcloud, a mock 36 page guide to a new killer chess opening (1. e4 e5 2. Ke2 - the worst move possible in that position) which was about the funniest thing I'd ever read, brilliant in every way. It uses the vague terms real opening books do, with every example game leaving you with a "winning" position which is actually lost by mate in 1. http://i.4pcdn.org/tg/1401479151063.pdf http://i.4pcdn.org/tg/1401479151063.pdf I wrote the author a gushing email, saying it was a brilliant work, thanking him for the valuable addition to opening theory etc – playing along with the joke. The author wrote back a puzzling message explaining that it was actually all a joke, that all the diagrams were losing, etc as if I'd taken it seriously. I can't imagine why he thought I'd thought it had any value, if I'd taken it seriously. (Maybe he was out-trolling me?! That didn't occur to me until just now.) Anyway, pleasingly, the Bongcloud is nowadays very famous. Almost every online stream where grandmasters say they'll play openings suggested by users, someone suggests the Bongcloud, and without fail they know what it is, and I've seen it played several times. It gives joy like no serious opening could.
- empath75 6y agoThe most shocking thing about this is that there is someone who actually _wants_ to be a jira admin.
- varikin 6y agoIt's not that someone necessarily wants to be a Jira admin, but rather, they want to have access to make changes directly related to their job. If they managing a team in some way, either project manager or some other role, they need to change how tickets are managed in Jira at some point. Maybe create new release versions for tagging tickets, or adjusting the lifecycle rules for a ticket. The easiest solution is to be a Jira admin. Otherwise, you need to find some permission for this user and request it. Then the next change needs a new permission. I would equate this to an outdated model of Developer vs Sysadmin. The sysadmin controls everything about the production system. They don't want to change anything. The developer needs to release a new version, which needs a new library, or needs an update to the OS, etc. Or they don't even know what the production system looks like and the sysadmin won't help. So the dev wants root access to just fix it instead of going through excessive redtape.
- motohagiography 6y agoI see these people coming. They are motivated by power for its own sake, and their playbook is limited. Take heed of this post, it's how the incompetent rise.
- ueu33hyrdd 6y agoIt's also how the competent rise though, in #1 they not only service a need but they identify that need on their own and in #4 they're completing tickets that are chosen partially based on how popular their resolution will be. What's the alternative, choose admins at random and ignore the people who have shown the most promise for understanding and contributing to tasks related to being an admin?
- theamk 6y agoIf people are only competent, they would not do #5 and #6. If people are actually going to make an effort to kick people out to cement their position, then it is better to restrict their access, before they do too much damage. Getting one person who services the need is not worth it if they kick out everyone else.
- Thorentis 6y ago> If people are actually going to make an effort to kick people out to cement their position If the only reason is to cement their position then sure, but there are good reasons to limit the number of admins. The more admins, the more attack vectors for serious social engineering, the harder change control is, the longer meetings go for, the harder it is to make necessary change, etc. etc. I think if somebody cares enough to become an admin and shows they care about the users then I don't mind them getting a power trip out of it. It's the "admins" that got there because they know the boss, or because they convinced somebody they should have access because their job-title entitles them to it that you need to look out for.
- EdwardDiego 6y agoBeing a JIRA admin is a pretty lousy form of power. Right up there with being a Slack admin.
- trynewideas 6y agowow, a take so bad that I immediately went to all their social accounts and blocked them, just in case
- teddyh 6y agoI flagged your post, just in case.
- dbsmith83 6y agoSoooo you 'social engineered' yourself into a Jira admin role, but you have to do all the work that a Jira admin has to do anyway now, and responsibly? Not a win in my book.. It actually sounds dreadful.
- kitotik 6y agoAnother popular term for “white hat social engineering” is “office politics”.
- blaser-waffle 6y agoRight? Sounds like another "how to hack growth" article that's basically just business 101, but with buzzwords that pander to STEM types.
- draw_down 6y agoThis is madness. You’re talking about a ticketing system! You have devised and enacted an eight part plan to control it... the ticketing system. What is the point.