4 ms·
We use OpsGenie at work. I've used their support a couple of times. Every time they needed to look at our company's account settings I've had to approve it (usi
by peledyu 6y ago
We use OpsGenie at work. I've used their support a couple of times. Every time they needed to look at our company's account settings I've had to approve it (using some sort of OpsGenie internal tool).
I was pleasantly surprised.
It's impossible to tell as a customer how hard it is to access my data without that internal authorization system, but it at least looks better than nothing.
- manquer 6y agoThere is no guarantee though, i.e. the system could be well intentioned but if could be bypassed , it does not really protect. The only way to get some assurance is run vendor app in your environment in a secure network without the ability to phone home.
- skrebbel 6y agoObviously it can be bypassed in the sense that somebody has full administrator database access. The point about schemes like this is that instead of having to give 1000 support reps full access, you only give a few sysadmins full access. The likelihood of something going wrong with the data (through mistakes, willful abuse, extortion, whatever) goes drastically down. In fact, once you got such a permission system in place, it becomes very attractive for the organization to use it. I mean, customers love it, they spontaneously write comments about it on Hacker News. Even if you begin adopting it only for security theater (i.e. everybody still actually has full access), eventually some principled engineer brings up the idea to maybe remove full access for everybody cause now they have the access-granting system anyway, and this time they'll make a convincing case because the "move fast and break things" people have way fewer practical objections.
- gowld 6y agoThat's a very 90s view. The modern view is that only robots are sysadmins, and those robots are indirectly controlled. Some humans have superpowers in some systems, but not in the whole system.