Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> use a good software whitelisting program that tracks elevations & the reasons for them, instead of just blanket giving everyone local admin on their own PC

You can propose such a thing. If you're in charge at a company, you might get to implement it. But if you do, know that it's a huge black mark against your company. I've seen how these whitelists work in practice. They're massive wastes of time. They get in the way of actually doing one's job, as creative work can't be constrained and approved in advance by some committee with a ten-business-day turnaround on getting some damn file conversion utility to run.

The golden rule of "security product" culture is this: inconvenience is a feature, not a bug, since friction reminds people that the infosec group exists. When it comes to stuff like this, all the incentives are lined up to just inconvenience people, not protect them. We ought to protect data, not code.



> We ought to protect data, not code.

Code is more dangerous than data. Personally, I'd be most worried by someone getting a virus that hacks into other computers and encrypts them and/or wrecks the network. Both can be protected against, first by cold backups and second by resilient / disaster recovery network, but both would also severely affect the company for a few days, so I'd rather avoid them.


That's code destroying data.

Losing data is bad for the business. A random box had software crashing? Just replace the box.


even setting up a new box might take one day of a productive person's time... unless, of course, if you standardise the dev setup... again many devs will complain, probably more than if you just remove local admin :D




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: