Live data from Hacker News

IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

openera.com

31–40 of 53 posts

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#31
post #23

The described IT painfully reminds me of Soviet-style planned economy. It tries to be the only economy in tow", but as it falls behind due to inefficiency, it tries hard to suppress any other economies that try to arise. And of course it is done in the name of security! Obviously everyone is trying to steal your secrets and that's why you have to live in outdated and broken environment.

A lot of different aspects of companies remind me of this. Usually dictatorial control, rigid hierarchies, policies made with no input from those who will follow them, etc. It's wonderfully ironic that the iconic capitalist organization is often so communist internally.

> It's wonderfully ironic that the iconic capitalist organization is often so communist internally.

I'm not an advocate of communism by any means, but I think the word you're looking for is "authoritarian"; maybe "dictatorial".

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#32
The "cloud" is a huge problem in the finance, legal, healthcare, and educational fields. Confidential client/patient/student data leaking out all over the place is a disaster waiting to happen, not to mention often outright illegal.

Let me give you an example: I recently bought a Livescribe Skypen, the new one with Wifi. It automatically syncs with Evernote, and works like a charm. But I can't use it for purpose, taking notes at work, because I can't have attorney work product for a client floating around on Evernote's cloud. That's just a no-go. My father in law encountered a similar problem. He's an IT director at a school district, and he has been trying to get teachers/staff to stop sending student information through GMail/Google Docs. It's almost certainly a violation of student privacy laws to expose that information to third parties without student consent.

I think there is some disruption to be had in this space. People want to use their iPads/tablets/etc and other cloud-reliant devices in their work flow, but at the same time that information has be stored in a way that adheres to security protocols and privacy policies. Google could over a "local Google Drive" service where a company could let its employees use Google Docs, but have that data stored in the company's internal network, with assurances that Google can't troll through the information to target ads or any similar privacy breaching and potentially illegal activity.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#34

I really do hate reading articles that praise rogue employees using cloud services. It's wrong for an infinite string of Data Loss reasons, uncontrolled access to cloud services is no different than leaving a laptop filled with confidential information lying in the front seat of your car. It doesn't matter how secure the user thinks it is, nobody in Security or Risk Management has qualified or quantified the risk. To…

Security in IT can be a way to reduce cost (via risk mitigation), but all too often it's just a form of authoritarian power play by petty tyrants.

In my experience, executives will get "dust in their eyes" if you bend a few rules to get things done in a bureaucratic environment. Plausible deniability, effectively. They want productivity without having to pay for it.

Dropbox, for example, is mostly free (up front), but with a level of risk cost associated with it. An enterprise on-premise Dropbox alternative is not free (up front) and may or may not have less risk than Dropbox. What's the better one? It's hard to measure. What's the ROI of sharing files? Depends on if your management likes fancy numbers games or just approves projects based on personal preference with numbers to make it look like they're doing some due diligence.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#35
post #11

The idea there is something wrong with the resourceful workers instead of the lagging IT is perposterous. IT right now in many companies is living in 2004 still. SO MUCH has changed in the intervening 8 years, it's no surprise that people are going with consumer grade products when corporate IT doesn't deliver modern resources.

> it's no surprise that people are going with consumer grade products

Indeed not. IT lags because it's hellaciously expensive to have it any other way. They're more than aware of what's happened over the last 8 years. At my day job, a profitable software shop doing some fairly cutting-edge stuff, we run everything on Lotus Notes. My desktop PC has 2GB RAM and runs Windows XP: a decade-old operating system. We just migrated our source control system from Visual SourceSafe to - wait for it - SVN. It's a gigantic leap forward!

IT recognize that they're not in a position to dictate radical, wholesale tool-and-process change. So they turn a blind eye to private initiatives which help employees stay productive, while gradually and systematically replacing broken pieces of infrastructure.

I use my own personal MacBook Pro for most of my work, relegating the XP clunker to a Notes terminal (a job at which it struggles.) I use Dropbox for syncing my own work and for sharing gigantic virtual machine images with my staff. I run three agile development teams using various cloud-based apps to manage workflow, dropping back to Lotus for necessary book-keeping tasks and ticket assignment. I run a backlog database in Evernote, and we have an internal wiki for mockups and collaborative story editing. In other words, my own personal mix of bleeding-edge and relatively mature.

That's what most businesses are like: a compromise, a heterogenous mix of solutions and processes which evolve over time. There's no shining uplands where every employee exclusively uses the latest tools, while very few workplaces are stuck with uniformly last-era tech.

Even if IT suddenly decided to spend millions of dollars in a company-wide orgy of upgrading, the resulting chaos would bring our business down quicker than the spend would ruin us.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#36
I remember at an old job on a stock trader's last day he emailed himself (from corporate email to gmail) a spreadsheet that contained proprietary models, client holdings, etc. That's a serious breach, and luckily traders are dumb enough to use corporate email to do this because if he used something like dropbox it probably would never have been caught. I don't like being restricted ever, but you can see why a company might try to block these cloud storage services to protect itself and its clients.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#37
post #26

Its fun to rail on internal IT. Most organizations inadvertently set the department up to fail and then find themselves shocked, shocked I tell you, to find that they have failed to deliver. The boys in the basement aren't a bunch of Luddites, before the upstairs staff has even heard of the new tech out there, they're already dependent on it in their personal life (or have demoed and tossed it to the curb). Spoilers:…

I'm not anywhere near the firewall team, but my company seems to struggle with blocking these services quite a bit. In particular, google drive is very hard to block: they use HTTPS and they don't have a fixed set of addresses that the service is delivered from.

Their solution? Add a GPO to all our windows machines to force a '127.0.0.1 drive.google.com' entry into all the HOSTS files on our network.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#38
post #23

Earlier quoted context omitted.

A lot of different aspects of companies remind me of this. Usually dictatorial control, rigid hierarchies, policies made with no input from those who will follow them, etc. It's wonderfully ironic that the iconic capitalist organization is often so communist internally.

> It's wonderfully ironic that the iconic capitalist organization is often so communist internally. I'm not an advocate of communism by any means, but I think the word you're looking for is "authoritarian"; maybe "dictatorial".

I don't think so. That certainly forms a part of it, but there are also the aspects of e.g. senseless policies, large sub-organizations doing nothing useful for no good reason, people engaged in turf wars instead of doing something productive, etc. Authoritarian or dictatorial regimes can be quite efficient if the dictator is good, and I don't really associate those features with authoritarianism, but they are definitely stereotypical (if not necessarily real) communism.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#39
post #32

The "cloud" is a huge problem in the finance, legal, healthcare, and educational fields. Confidential client/patient/student data leaking out all over the place is a disaster waiting to happen, not to mention often outright illegal. Let me give you an example: I recently bought a Livescribe Skypen, the new one with Wifi. It automatically syncs with Evernote, and works like a charm. But I can't use it for purpose, tak…

I don't think Google would be too interested in providing that service, but I don't see why someone else couldn't do it. At some level though, a Google Docs that's restricted to the office or campus is strictly less useful than old-fashioned docs on your laptop's harddrive, edited by normal GUI editors. Would any user want to use that service?

In general, I think you have start mistrusting employees more, though. If an employee can't be trusted not to attach rightfully-secret data to email without heroic IT efforts to prevent that scenario, maybe that employee can't be entrusted with the data period. The old "firewall" method of implicitly trusting everyone on staff with pretty much everything is quite inappropriate for most business situations.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#40

I remember at an old job on a stock trader's last day he emailed himself (from corporate email to gmail) a spreadsheet that contained proprietary models, client holdings, etc. That's a serious breach, and luckily traders are dumb enough to use corporate email to do this because if he used something like dropbox it probably would never have been caught. I don't like being restricted ever, but you can see why a company…

TBH, client details really should belong to both the firm and the traders, since at the end of the day those clients most likely will continue to execute trades with that trader regardless of what firm they work at. Back when I worked in finance, many traders I knew were hired based on the clients with whom they had a solid professional relationship.

The value of a trader to a firm is essentially their professional relationships with clients combined with the efficiencies and information provided by the firm itself. The trader needs information from the firm and his co-workers to effectively monetize his client relationships, but those relationships really are his/hers at the end of the day. It's not like a trader can leave a firm and some other trader can pick up those relationships right where the other trader left them off. They can try of course, but the relationships are likely to move from firm to firm with that trader.

The spreadsheet is also dubious grey area. Yes, it may be proprietary information created by the trader while at that firm, but it is just as likely to have been created by that trader before he joined the firm that he brought with him when he joined. The only thing that changes when a trader joins a firm is that he ceases to use inputs from the economists and analysts at his previous firm and now begins using the figures from the economists and analysts at his new firm. Proprietary models often are created by a trader and intelligible to that trader and only that trader, unless they happen to have trained a junior trader to understand the ins and outs of their own model.

I was one of the analysts myself and every single model created by any senior analyst was reused by their junior analysts, but was often scrapped anytime a new senior analyst who joined the firm to replace the previous senior analyst. When you have your name and reputation on the model and the investment advice, the tendency is to do a big rewrite.

Post reply on HN