4 ms·
It truly is fascinating, the world of tools and ecosystems built up to sidestep inane security rules in organizations. Spoken from experience, this includes th
by fancyfish 6y ago
It truly is fascinating, the world of tools and ecosystems built up to sidestep inane security rules in organizations.
Spoken from experience, this includes things like Anaconda in orgs where devs can’t use just any Python packages, or scripts from the internet copied and pasted into files because the firewall blocks git cloning. One could even consider AWS as a platform for devs to get around InfoSec red tape and have some semblance of control. The goal as a dev here is to fight the fewest fights to make tools available, by getting access to the biggest “bundles” of tooling they can.
In such organizations, there is either no concept of cost/benefit of overly restrictive firewall rules, etc, or the culture is such that the security team has become entrenched and unquestionable.
- Aeolun 6y agoCan confirm. I’m able to spin up multiple sets of m5.24xlarge without anybody blinking twice, but I’m not trusted to spend money to buy a ballpoint, for which I’ll have to go through the whole PO process. The disconnect here is unreal. When the only tool you have is a hammer, everything by necessity becomes a nail.