Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I worked for a big company with an IT department that was forcing strict policies on everybody. E.g. installing Skype could get you fired. But the developers working on projects for that company basically ignored the rules, because it was the only way to get anything done.

Not saying that there aren't companies for which this is desirable. Such companies exist. What I am saying is that their reasoning is bullshit and has more to do with some people keeping their jobs, so it's job security instead of actual security.



I think we're talking about slightly different things.

I'm a proponent of proportional amounts of paranoia. Restricting everyone is disproportional. Preventing developers from installing software on their dev boxes probably does more harm than good.

On the other hand, putting tight controls on computers people use for admin access to servers is not a bad idea if your company is big enough that only the dev ops guys really need to be in there with real regularity, or if your company handles sensitive data. Then the practical layer of security might be worthwhile to make getting into the datacenter via a compromised engineer or dev box harder.

That's the scenario I'm familiar with: secure boot on a separate machine, and a tight lid on what software you can put on the system, in order to guarantee a baseline level of hygiene for any system that talks directly with the datacenter.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: