4 ms·
I used to work on a place that everything was open by default and in comparison with closed by the default was a blissful experience. I never got the point why
by braza 3y ago
I used to work on a place that everything was open by default and in comparison with closed by the default was a blissful experience.
I never got the point why with 3 months of work I had access to the AWS account, all repos and passwords.
After some point in time I tried to understand with the IT director and he told me that he prefers to have a tougher hiring process and huge onboarding process and have that instead to ensure security first approach.
He told me that in some previous experiences he lost productivity with closed by default plus he used to have the same security issues.
I am keen to imagine that this is impossible in a big company.
- cratermoon 3y agoI've been involved in identity and access control work for a long time. The problems with open by default include: 1. People are fallible. I'm fallible. Someone fat fingers rm -rf / home/user and boom. At best you have a lot of very expensive engineers now doing firefighting instead of work that makes the company money. See for example Toy Story 2[a]. At worst, the company goes out of business. I don't like to have more access than I need, because if I screw up, and I do, there's no guardrails. If there is some unknowable list of people who have access because everything is open, glitches become that much harder to diagnose. No hiring process or onboarding system can fix human nature. 2. Firing someone. Everything's open, right? If that person is malicious and you leave even a sliver of access for them, they're in. They can kill the golden goose. It's happened. 3. One hack is all it takes. If a malicious party finds the keys to the castle gate, they also get into the treasury, the queen's bedroom, the armory, the food stores, everything. > he lost productivity with closed by default He's been lucky. The productivity lost is peanuts compared to the business itself. I used to say things about "the reputation of the company", but major breaches and IT failures don't seem to make a dent in any company's reputation any more. a. https://www.independent.co.uk/arts-entertainment/films/news/lightyear-toy-story-2-deleted-b2017238.html https://www.independent.co.uk/arts-entertainment/films/news/...