4 ms·
Not a computer security engineer here but reading the article feels like in most organisations there are no safeguards in place for modifying global highly priv
by rapht 5y ago
Not a computer security engineer here but reading the article feels like in most organisations there are no safeguards in place for modifying global highly privileged accounts (the article cites introducing a global Office 365 admin and then removing existing global admins, etc).
Are there not procedures like double/triple validation of sensitive changes (like "creating new global admin account") by accredited humans?
I mean, in my line of work (finance), this is something that is enforced in multiple sensitive contexts such as money transfers - at certain thresholds, even the highest privileged person in the organisation cannot single-handedly authorise the operation.
- laurent92 5y agoBut it’s annoying to program. You need the same records as an undo/redo system, except they’re only applied after approval. Finance does it because everyone knows finance is boring already, but I’m not sure it would be possible to retain a JS programmer in another sector if the 6-eye principle had to be applied for every modification. It’s already hard to motivate them for i18n…
- wiz21c 5y ago> It’s already hard to motivate them for i18n… don't even talk about rounding issues !
- Thorentis 5y agoMaybe stop hiring 19 year olds who just did a "become a Web developer in 6 weeks" bootcamp to code your core security features then. Pay peanuts, get monkeys.
- laurent92 5y agoI pay $120k. Still hard to motivate people.
- RL_Quine 5y agoThat's terrible for a security position. No wonder they aren't motivated.
- School-Cotton 5y agoThat depends entirely on where the job is located. $120k is probably only "terrible" in the coastal USA and maybe Switzerland.
- laurent92 5y agoIt’s in France, it’s just for Java + React not rocket science. Claiming $120k is a shit salary is really entitled, it’s among the top 20% of engineers in France and top 7% of an entire country. For Java and React. Glad I don’t have him among my employees.
- RL_Quine 5y agoYour security staff have access to literally everything in your company, visibility into all communication and trust with physical devices. If they're not the highest paid of your engineering staff you screwed up. Glad I don't have the misery of being your employee.
- NtGuy25 5y agoThis is one of the biggest issues people don't realize. A react dev doing fully frontend stuff is usually paid more than a security guy. Management views this as the developer making a product and giving money. But with insurance no longer covering hacks like they used to, and with the absolute amount of ways into organizations, security people can literally save a company from millions of losses and possible collapse.
- dboreham 5y ago> It’s in France Perhaps better not to post a US$ denominated salary for a non-US location?
- matwood 5y agoi18n? Slow down there. Let's get a11y done first.
- abrichr 5y agoIf we were people like us, how would we solve this problem? i.s. What does an MVP consist of?