4 ms·
2 weeks ago new junior developer joined our company. He was really pissed that our company does not give out admin access to developers. And raised this proble
by sccxy 2y ago
2 weeks ago new junior developer joined our company.
He was really pissed that our company does not give out admin access to developers. And raised this problem in big company wide meeting and called our IT team ridiculous and told developers know how to handle computers.
Week later IT team did company wide phishing test. Same new junior failed this test.
Yes, even if rules are ridiculous. These rules help.
- spacecadet 2y agodont be this kid
- IshKebab 2y agoYeah but only because you shouldn't call it dumb in a company wide meeting just after you join. It is dumb, and thankfully I've never worked anywhere that denied admin access to engineers. Fine for HR or whatever.
- sccxy 2y agoActually there is special admin account, but you have to enter credentials manually. He wanted 100% admin account all the time.
- spacecadet 2y agoIn a really good org, Engineers THINK they have admin. lol.
- spacecadet 2y agoOK before you black and white nerds lose your minds, in some settings, like a startup, engineers are admins... but in general: Engineers should definitely not have "admin" access. They should have least privs for the systems and services they need access to... Dont be this either. It will end badly when you, in a stressed late night stupor, blow up your "admin" access... be smart- you honestly want least privs for your own protection!
- spacecadet 2y agoIf you truly understand this concept, then you know. When configured correctly, its damn near "admin"... but not "god clearance"...
- IshKebab 2y agoWe're talking about admin access to your own machine. Local admin. Not root access to servers. I can't say I have ever "blown up my admin access", whatever that means. Especially not late at night because I am in bed. And even if I did, so what? I have backups. Just means I lose half a day restoring my laptop.
- taneq 2y agoSounds like there are multiple reasons to not be this kid.
- halfmatthalfcat 2y agoI can see how it’s annoying to have to submit some kind of IT request every time you, as a developer, need sudo to install something. It may “help” but there is a non negligible cost to the company to source all those requests. The risk/reward in productivity vs falling for an actual, successful phishing attempt is probably a no brainer for most companies.
- rileymat2 2y agoDid they steal his credentials in the phishing test? Or was failure simply clicking the link? These are very different scenarios.
- sccxy 2y agoYes, he entered his password to phishing site. He demanded Spotify install at 100 ppl meeting... Just use web app and shut up next time :)
- firesteelrain 2y agoYouTube doesn’t work? They still make CDs too
- gonzo41 2y agoWas it a serious phishing test trying to trick people into using a fake auth portal? Or just don't click on this link test? Because those second ones where an email tricks you into clicking a link are a bad because they do two things. Firstly, they propagate the idea that you can click a link and the world ends. which rarely happens these days. Your corporate IT dept should have some network level controls on malware attachments and embedded scripts in HTML emails. And secondly, it breeds distrust from anyone with critical thinking in the motivations of the IT department.
- sccxy 2y agoYes, he entered his password to phishing site. He demanded Spotify install at 100 ppl meeting...
- DaiPlusPlus 2y ago> He was really pissed that our company does not give out admin access to developers I’d be annoyed too (I often work on Windows and services); fortunately it is possible to grant people local admin access scope to their own machines and treat their OS install as fungible cattle (e.g. Boot-from-VHD derived from a common image with preinstalled software, so if anything goes wrong they can be back-to-normal in under 60 seconds; and give people (non-admin) access to VDI for reliable access to Office/Email/SharePoint, especially if devs use Linux as a daily-driver but the rest of your org runs Windows). At the very least, people can just install a VM with admin rights in there - and what’s the difference between that and a physical machine?
- sccxy 2y agoActually there is special admin account, but you have to enter credentials manually after you click "use admin access" or whatever it is called in windows. He wanted 100% admin account all the time. If you complain 100 ppl meeting that it is annoying to install Spotify and you fail most obvious phishing test then I would not give him that local admin access.
- firesteelrain 2y agoThe problem isn’t admin. The problem is the IT team’s inability to provide self service. Getting admin isn’t the real problem
- eviks 2y agoNot giving him the computer - another ridiculous rule - would also help. So you example is a very poor defence of corporate ridiculousness I see some comments saying you can perfectly allow local installs of Spotify with the same security. What's your example that defends the original ridiculous policy vs this better one with less inconvenience to the users?