Live data from Hacker News

IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

openera.com

41–50 of 53 posts

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#41
post #38

Earlier quoted context omitted.

> It's wonderfully ironic that the iconic capitalist organization is often so communist internally. I'm not an advocate of communism by any means, but I think the word you're looking for is "authoritarian"; maybe "dictatorial".

I don't think so. That certainly forms a part of it, but there are also the aspects of e.g. senseless policies, large sub-organizations doing nothing useful for no good reason, people engaged in turf wars instead of doing something productive, etc. Authoritarian or dictatorial regimes can be quite efficient if the dictator is good, and I don't really associate those features with authoritarianism, but they are defini…

The workers don't own the means of production in a firm. It's not communist; it's Soviet. Show trials; pointless dig-and-fill exercises; five year plans; Potemkin villages; lunatic dictates from unaccountable leaders; and shadow economies.

Wonderful read: http://blogs.valvesoftware.com/economics/why-valve-or-what-d...

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#42
This is certainly the case with schools too. At my high school, we are provided a username and password to access the school's computers, as well as our own personal storage space on the network. However, students (and teachers) want ways to work on files they have on the school network­ — it used to be that we would have to email the files to ourselves, but the network administrators have just recently unblocked access to Dropbox. People are realizing that there are websites like Google Drive that will let them access their work from anywhere and migrating away from the school-provided storage.

Last year, someone was able to find a vulnerability in the network in order to install Google Chrome and Firefox. Supposedly, the IT guys were furious — not just at being hacked, but that students were using software that wasn't approved by them. Students and teachers are wising up to what good software is for them, and those choices don't always align with what IT says we need.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#43
You're really fighting two mantras - 'if it's not broken, don't fix it' vs 'we must build against worst case everything'. The arguments generally come from IT support and legal, respectively.

Realistically things are in the middle. This isn't a surprise. IT shops have to balance current real risks, potential risks, future risks, etc. It's the overly used 'black swan' event in IT that causes problems. It costs $200k per potential problem, and we've got 40, but the business only provides $1M in budget. So the black swan will happen, the business will demand a solution, so now you've got 41 problems - because 2 surfaced while fixing the 1.

To take a step back, it's simply because consumer IT has innovated quicker than both enterprise IT and enterprise security to prevent the takeover. Trying to understand that is a more interesting question, which probably finds its roots in the blossoming technology adoption of a younger generation more willing to consume high tech goods. Eventually enterprises adopt consumer technology, or build really good walls.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#44
post #32

The "cloud" is a huge problem in the finance, legal, healthcare, and educational fields. Confidential client/patient/student data leaking out all over the place is a disaster waiting to happen, not to mention often outright illegal. Let me give you an example: I recently bought a Livescribe Skypen, the new one with Wifi. It automatically syncs with Evernote, and works like a charm. But I can't use it for purpose, tak…

I don't think Google would be too interested in providing that service, but I don't see why someone else couldn't do it. At some level though, a Google Docs that's restricted to the office or campus is strictly less useful than old-fashioned docs on your laptop's harddrive, edited by normal GUI editors. Would any user want to use that service? In general, I think you have start mistrusting employees more, though. If…

It doesn't have to be restricted geographically--iDevices support VPN just fine after all.

And I think there is a disconnect between what users can be trusted to do in person, and what they can be trusted to do with computers. I don't think most users have a good mental model of how the cloud works, how it exposes data to third parties, etc. I imagine most people don't even realize that Google reads your e-mails and documents.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#45
post #41
post #38

Earlier quoted context omitted.

I don't think so. That certainly forms a part of it, but there are also the aspects of e.g. senseless policies, large sub-organizations doing nothing useful for no good reason, people engaged in turf wars instead of doing something productive, etc. Authoritarian or dictatorial regimes can be quite efficient if the dictator is good, and I don't really associate those features with authoritarianism, but they are defini…

The workers don't own the means of production in a firm. It's not communist; it's Soviet. Show trials; pointless dig-and-fill exercises; five year plans; Potemkin villages; lunatic dictates from unaccountable leaders; and shadow economies. Wonderful read: http://blogs.valvesoftware.com/economics/why-valve-or-what-d...

Precisely. I'm using "communism" in the American stereotype of communism sense.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#46
post #44

Earlier quoted context omitted.

I don't think Google would be too interested in providing that service, but I don't see why someone else couldn't do it. At some level though, a Google Docs that's restricted to the office or campus is strictly less useful than old-fashioned docs on your laptop's harddrive, edited by normal GUI editors. Would any user want to use that service? In general, I think you have start mistrusting employees more, though. If…

It doesn't have to be restricted geographically--iDevices support VPN just fine after all. And I think there is a disconnect between what users can be trusted to do in person, and what they can be trusted to do with computers. I don't think most users have a good mental model of how the cloud works, how it exposes data to third parties, etc. I imagine most people don't even realize that Google reads your e-mails and…

Just to clarify: are you more concerned about the Googlebot reading your documents to sell you consumer products than you are about employees attaching business or customer data to email or shared docs?

Because I'm operating with a much different threat model. Email is not and never has been secure. It is sent in plaintext unsecured from one unauthenticated mail server to the next. The moment the user attaches data to an email the game is over and we have lost. Sensitive data must be kept in systems that are designed to store sensitive data, and which do not have a "forward to my gmail account" feature. That's how IT can be relevant: provide that system. You might prompt the business to reclassify some formerly sensitive data as rubbish they're allowed to play with, but then their fingerprints will be all over the corpse.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#47
post #26

Its fun to rail on internal IT. Most organizations inadvertently set the department up to fail and then find themselves shocked, shocked I tell you, to find that they have failed to deliver. The boys in the basement aren't a bunch of Luddites, before the upstairs staff has even heard of the new tech out there, they're already dependent on it in their personal life (or have demoed and tossed it to the curb). Spoilers:…

Hadn't really considered things from this angle - I'd be happy to see a win-win-win for the people, IT, and the company.

If you want to solve the problem you're discussing in this article, you seriously need to talk to some dejected netadmins.

Most corporate technology problems where a solution exists but isn't used aren't technology problems at all, they're office politics problems (for the sake of argument I also consider business requirements / SOPs to be under the office politics umbrella, if you've ever tried to change them you know this is true).

It's rare that more technology actually fixes the problem. Usually getting more/new technology is a catalyst to changing the underlying social problems, or is just a workaround.

For example, my alma mater wants to implement a new thing to make service better on campus (sorry about the vague-ness, its about privacy of the people involved, and I'm not even supposed to know this). If the project goes through as originally planned, they'll save money and greatly improve services. But, it will never be approved without letting the CIO win a turf war in the process, so the project will end up spending an extra >$500k on unnecessary tech to do it her way. Did I mention this is a public school that really can't afford to be paying that much just to feed egos?

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#48
post #42

This is certainly the case with schools too. At my high school, we are provided a username and password to access the school's computers, as well as our own personal storage space on the network. However, students (and teachers) want ways to work on files they have on the school network­ — it used to be that we would have to email the files to ourselves, but the network administrators have just recently unblocked acc…

It's not just about being hacked or using un-approved software.

For example, Google Chrome allows itself to be installed to a user account, bypassing administration requirements which may be that "vulnerability." The install is not particularly big, 50MB or so, so when Little Johnny Hacker does it it may not seem like a big deal. When 20,000 students install it that's almost 1TB, before we even consider them actually saving school work! (If you don't have 20,000 students in your school lets assume your IT resources and staff are appropriately scaled.)

You might ask, when you've got 20,000 people who want a piece of software why wouldn't you just make it available to them? So, let's say your school uses some web tools like Blackboard Learn and somewhere along the line--maybe in Chrome, maybe in BbLearn, maybe in Java, maybe somewhere else--there's a bug and students can't upload their homework to BbLearn with Chrome.

Now you've got 20,000 student freaking out and swarming the help desk trying to figure out what to do, teachers are upset they have to change their plans since it's not the students' fault, and IT is flustered because this is an emergency and not something they can research and test and find an appropriate solution for their environment.

And all this because, clearly, the students know "what good software is for them" and IT is just a bunch of old hacks who can't keep up.

When you work in any collaborative or networked environment some sacrifices will be made to fit everyone in. It's an IT department's job to figure out what technology will make the cut and what won't. Some of those decisions will be good, some will be bad, and some decisions won't actually be in the IT department's control. If you don't like a decision that was made (or wasn't made), you should talk to IT about it. They may tell you to bugger off, or they may make an exception for you or even launch an investigation to launch of complete solution.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#49
In banks, especially those with large capital market or investment banking arms, you WILL risk losing your job if you try to work around corporate IT. It is basically a guilty-until-proven-otherwise perspective. I have seen it happen multiple times to front desk personnel.

That is also assuming you can, since many banks have super strict policy implementations which would necessitate greater than average technical know-how or investment to work around them.

Of course, there is a cost to this type of infrastructure. Whether you can dilute this cost to make it more accessible to ordinary companies by technical means alone, is something I suspect is not possible.

Re: IT’s Dirty Little Secret: “We’re aware of ‘Shadow IT’, we just can’t stop it”

#50
post #44

Earlier quoted context omitted.

It doesn't have to be restricted geographically--iDevices support VPN just fine after all. And I think there is a disconnect between what users can be trusted to do in person, and what they can be trusted to do with computers. I don't think most users have a good mental model of how the cloud works, how it exposes data to third parties, etc. I imagine most people don't even realize that Google reads your e-mails and…

Just to clarify: are you more concerned about the Googlebot reading your documents to sell you consumer products than you are about employees attaching business or customer data to email or shared docs? Because I'm operating with a much different threat model. Email is not and never has been secure. It is sent in plaintext unsecured from one unauthenticated mail server to the next. The moment the user attaches data t…

Uploading patient/client data to the cloud where a Google bot can read it is a breach of that patient/student's privacy. Blackberry email and the like can make email within the organization secure, and most teachers/doctors have the sense not to email sensitive documents to people outside the organization. However, most don't realize that emailing something to your gmail or uploading it to google docs is a problem. The mental model is still "this is private" even though Google is reading every word.
Post reply on HN