4 ms·
There are typically a lot of controls that are about generally protecting you and the firm through enforcing things that I'm sure most people on here do anyway
by hnbear 2y ago
There are typically a lot of controls that are about generally protecting you and the firm through enforcing things that I'm sure most people on here do anyway as best practice.
For example - full disk encryption, enforced password access, and screen locking - if you lose it and it's not encrypted, doesn't have strong login creds required, lock screens, etc then all the data on it is out in the world. That can include customer data, access to your production systems, your companies code and ability to check it in and introduce other bad behavior in the product, etc.
Some of the other controls will be able access to internal systems. eg. VPNs, or cert-base auth controls other make sure that only employees can access those systems to protect them. If you're on an uncontrolled machine you lose the ability to guard who and what is connecting. I would expect there's more to your job than just Github - eg. where is your documentation, monitoring, infrastructure, etc. It's also possible in Github to setup cert-based and IP based access restrictions so your MacBook might not just work.
Some of the controls protect employees themselves. MDM on your laptop allows IT to reset your machine password and/or fix your machine in other ways. Similarly, enforcing patching for vulns, etc.
Contrary to popular belief some IT teams actually manage their fleets of machines to make it easier for employees to work.
You don't actually specify what the problem is with your work machine that means you don't want to use it for work.