4 ms·
> We were forbidden from running scans again by management. A scan detects a severe vulnerability and their reaction is to never run scans again...
by janpot 6y ago
> We were forbidden from running scans again by management.
A scan detects a severe vulnerability and their reaction is to never run scans again...
- dragonwriter 6y agoWell, the issue seems to be the scan not only detected but realized the risk from the vulnerability, which is exactly what is the point of scans to help you avoid.
- ethbro 6y agoIt's hard to detect what HTTP DELETE does without, well...
- chasd00 6y agodid they turn the scan loose on PROD without scanning a dev first? granted, I wouldn't blame anyone for assuming a scan is read-only
- mprovost 6y agoA what first?
- beckingz 6y agoWhat dev? Real software engineers ssh directly into PROD to write code.
- hnlmorg 6y agoIt was a different era. A lot of best practices we take for granted now as being common sense were stuff we (and I say this as myself also being an old time sysadmin) had to first learn...and often the hard way. Plus the web wasn't as important business stratergy back then as it obviously is now. I doubt Warner Brothers would have been willing to invest in replica dev infrastructure when "developers can write code on their desktops". I know dev infrastructure is for more than just developing code, but common concepts we take for granted like IaC, CI/CD, config management etc wasn't formalised or widely used back then and servers were pets that were held together with duct tape and sacred rituals. In many ways, that's what made being a sysadmin in that era fun. There wasn't any shame in hacking together a solution.
- chasd00 6y ago"In many ways, that's what made being a sysadmin in that era fun. There wasn't any shame in hacking together a solution." hah true, and management was absolutely amazed! In the late 90s/early 2000s i worked for an independent pharmacy chain. I wrote what was basically just a proxy sitting between our dispensing systems and the central clearing networks for rx drug pricing. All it did was double check the price on the prescription (our stores weren't applying price updates which was a manual process at the time) and reject prescriptions that were priced wrong with a message telling the pharmacist to apply their price update. The CEO invented an annual award to give to me for the "work" hah
- jacurtis 6y agoBack in 2000, it was the wildwest. You actually did run tests on production and editing production code was not as insane of an idea as it is today. I don't think anyone (at least no one I worked for at the time) ran staging or dev servers. It was always stupid, yes. But back then we didn't have the tools and testing suites that we have today. CI/CD setups didn't exist. Git wasn't even built until 2005. The only version control solution was SVN at the time, which was released in 2001. But it was clunky and immature. Back in 2000, launching a site update meant someone would log into the server via FTP, drag the files over, and try to "be careful" while they did it. Using passwords that were written on a sticky note, stuck to the CRT monitor's screen (password managers weren't a thing). It is easy to forget how immature and primitive the world of web development was at this time. Also, the internet was still so new, that every C-level executive had built their careers by running businesses in the 70s, 80s, and 90s. Back before you built websites or relied on them for any significant impact on your bottom line. So to tell an executive from that era that your website broke when you poked at it, their solution would be to stop poking at it. Security wasn't really a major concern like today, and having a website was still mostly a novelty in the eyes of most executives.
- danans 6y ago> Back in 2000, launching a site update meant someone would log into the server via FTP, drag the files over, and try to "be careful" while they did it. Heck, I remember just compiling Java classes on the server machine itself, copying them to a production directory, and restarting the app server (tomcat IIRC). Source control was the sysadmin running a nightly backup of source directories
- phamilton 6y ago> The only version control solution was SVN at the time Pre SVN there was CVS, and before that was RCS. Now these didn't work the way we think about git today, but they did allow you to roll back to a known good state with some futzing about.
- peterpost2 6y agoWebsite is still alive and kicking more then 20 year later, guess it worked. /s
- kinard 6y agoBit like testing for COVID-19, if you don't test for it how can you have it?
- sealthedeal 6y agono politics, but this is like the "if you stop testing numbers go down" lol