3 ms·
All of the jobs I've worked have not had any technical restrictions on what software engineers could install on their work laptops. Most (but not all) had some
by codys 4y ago
All of the jobs I've worked have not had any technical restrictions on what software engineers could install on their work laptops.
Most (but not all) had some sort of asset management tool and/or antivirus as standard on computers, but nearly all provided exceptions to having that functional/installed.
I, and I expect many developers, likely select companies with IT policies that avoid potentially harming individual productivity.
- TedDoesntTalk 4y agoIf you work in financial services (banks, brokerages, hedge funds, exchanges), heath insurance, or the defense industry… your device will be locked down.
- pclmulqdq 4y agoI worked at a highly regulated financial company and they gave me root in prod and permission to install anything I wanted (on any machine I wanted). However, it was clear that EVERYTHING was being tracked, including SSL MITM attacks and the most invasive OS-level logging you can imagine, for compliance reasons. Abuse of that trust was a fireable offense and someone did get fired for it.
- gpm 4y agoI did an internship at a bank. They locked down developers laptops to the point of being unusable. Except all the developers just got permission to install virtual box, and ran another OS inside virtual box that they could and did do whatever they wanted to. This didn't improve security past not locking down devices, it substantially hurt it, but it was also the only way anything got done.
- cameronh90 4y agoSadly this is often due to regulations and industry expectations. I work in finance and we get all these audits and questionnaires from regulators, insurers, intermediaries, clients, etc. and many of them are straight out of the 90s. For example, when we replaced the VPN with a zero trust system, we got a ton of pushback. It didn't matter that the ZT implementation provided stronger guarantees than the VPN ever did as well as doing everything the VPN did. What mattered is that it wasn't called a VPN and they were expecting me to write "Cisco VPN" or similar. Unfortunately, developers having admin access on their machines triggers so many red flags in these processes. Doesn't matter if you install a load of auditing and remote attestation stuff, admin access is instant ticket to bureaucratic hell.
- peteradio 4y agoI worked in health insurance for a stint and wasn't completely locked down. I was able to install brew and some libraries, BUT received a call from security to review what/why I was doing it and ultimately there were no problems.