This is exactly extremely common. In my company there is this constant battle about the devs having admin rights on their machines. We need admin rights to do our job. We have had dozens of meetings explaining the situation but IT can’t come up with a solution so the devs go around security because they have no alternative if they want to finish their work . Same with Dropbox. They block it but we have suppliers who…
I have my own PC strapped under my desk connected to public Wi-Fi. I use it to do all my work. My company pc is left turned on but disconnected, sitting on top of my desk to dissuade suspicion.
When Employees Use Software That IT Hasn’t Approved
291–300 of 326 posts
Re: When Employees Use Software That IT Hasn’t Approved
#292Security training focuses way to much on email phishing and not enough on this kind of stuff. Actually getting your work done, managing your own computer. Of course people can't be trusted if they havem't been trained. How to handle USB drives. What and from where you can download and run programs. What actually IS a program and what isn't. Many of us learned this the hard way by playing lots of cracked games in the…
It's tough, I give security awareness trainings myself and I completely agree with what you're saying. However, that's a lot of information to give to a group of new employees that can span any department and technical understanding. I actually was talking today with a customer during a logical assessment about if I talked about downloading malware in the training. I dedicate an entire section to downloading document…
So I change my DNS settings to use an 8.8.8.8 dns first, and my company dns second. Now I can access both archive.is and sites on the company network. Excellent. But in doing this I circumvented all the DNS filtering, not just for this site. The reasonable thing would have been a warning like a https-style warning "Are you sure you want to continue to this site"? Or a way of whitelisting, perhaps temporarily, a single address. Instead my options were to ask an administrator or disable the whole security feature entirely. (Or connect/disconnect the VPN temporarily every time I needed something blacklisted, but that didn't feel like a good solution).
Re: When Employees Use Software That IT Hasn’t Approved
#293Earlier quoted context omitted.
You're essentially suggesting "properly" going through the slow and inefficient bureaucracy machine, when the underlying issue is exactly that people tried to do what you suggested but ended up getting nowhere. You realize you need a kitchen sink, it turns out there are 2 other teams who already created their own semi functioning kitchen sink which they want you to adopt, but doesn't fit in your kitchen, and the CIO…
If your machine is slow and inefficient, it needs repair or resources. Fix the machine, don't build a smaller one propped against the side of the garage. A rising tide raises all boats, put your effort towards improving the company by rising the tide. You are adding redundancy and overhead elsewhere. Now you have 30 people at your company playing account admin, managing passwords and permissions to different platform…
As a dev, I will get my job done, and if that means breaking company policy, I'll do it. I've used SOCKS proxies to get around company firewalls because the whitelist time is measured in days, and I have minutes. I've used my phone as a hotspot when IT broke enough of the internet to be a bother. I've used SSH tunnels combined with Nginx reverse proxies to get around routing approval processes. I've even built a port forwarding service because IT took too long to approve and implement their own, and it has been in production for years (I don't think IT is aware of it, though I should probably get it all cleaned up at some point).
If management decides security is important, but not important enough to make efficient, employees will work around the limitations.
Re: When Employees Use Software That IT Hasn’t Approved
#294Earlier quoted context omitted.
I have seen IT being unaware of and unwilling to meet requirements of highly specialized technical teams, such as network engineering. You cannot have a TELNET client because the use of TELNET is prohibited by corporate policy, test TCP connections another way. You don't need vim when you have vi. You can't have admin rights but we don't support drivers for RS232 dongle so nope. Sometimes it's quite a challenge to ge…
Use netcat. Telnet is pretty hard to procure since it's not included by default since Windows 7.
Re: When Employees Use Software That IT Hasn’t Approved
#295Earlier quoted context omitted.
We attempt to address this by making IT's annual bonus tied in part to our dev's project completion. It's not perfect, but the heart is in the right place. A big problem with this is that when we're dealing with limited manpower, we'd rather throw it at the easy issues than the hard ones, and ultimately get more things done.
Maybe create a 'time wasted' ticket system to help quantify employee hours wasted by IT roadblocks? It smells like it could be gamed heavily, but it might work better.
Re: When Employees Use Software That IT Hasn’t Approved
#296Earlier quoted context omitted.
I'm heading down this path right now. How do I obtain my certs while also allowing enough freedom for the dev teams to operate. We have to deal with the fallout when they screw something up, there has to be a happy medium somewhere.
What's the issue specifically? Developers don't need admin rights for much of anything in this decade. No need to bother with that. Common software has to be made available in self-service, so developers can install development tools like notepad++ or visual studio. Deployment is usually the challenge because you have to store binaries somewhere, copy it to some random servers and finally execute it, each step causin…
Please defend this position.
My experience, mostly with Linux-like tools, is that those tools are built with the assumption they are being used by someone who knows what they are doing, and that they have the appropriate level of control of the machine -- they are tools for professionals to build tools.
If you don't have rights to install or execute them, you're done. You can't make any forward progress.
Re: When Employees Use Software That IT Hasn’t Approved
#297Earlier quoted context omitted.
That highlights a problem woven through the industry which is that the IT department isn’t always the sharpest team in the building, even on security matters.
It's worse than that. I haven't met an IT person yet that wasn't as smart as the developers they worked with, except in slightly different domain. But the incentive structures are aligned in a way that makes IT's real job to execute cover-your-ass directives which freeze work. Doing the right thing is literally the opposite of what IT is being paid for.
You are very, very fortunate.
The standard big-company IT person I see at client sites is not very bright or will-informed.
Re: When Employees Use Software That IT Hasn’t Approved
#298Earlier quoted context omitted.
> My guess is that outside the tech industry, new ideas are relatively rare so even very simple ideas feel incredibly valuable. Are they not rare even inside the tech industry?
Put it this way: if all our engineering design documents and presentations leaked, our competitors would get less value from their contents than they would have to spend on the reading.
Re: When Employees Use Software That IT Hasn’t Approved
#299Earlier quoted context omitted.
If your machine is slow and inefficient, it needs repair or resources. Fix the machine, don't build a smaller one propped against the side of the garage. A rising tide raises all boats, put your effort towards improving the company by rising the tide. You are adding redundancy and overhead elsewhere. Now you have 30 people at your company playing account admin, managing passwords and permissions to different platform…
And what happens when you don't have good management? You end up with kludgy solutions and IT constantly falls behind. As a dev, I will get my job done, and if that means breaking company policy, I'll do it. I've used SOCKS proxies to get around company firewalls because the whitelist time is measured in days, and I have minutes. I've used my phone as a hotspot when IT broke enough of the internet to be a bother. I'v…
Re: When Employees Use Software That IT Hasn’t Approved
#300Isn't IT something from the past? I would expect people knowing how to use a computer and what they need to do their job.
As a lowly help desk technician perusing this thread, you couldn't be any further from the truth. The software devs never open tickets, everyone else does and its for the most banal problems