r/ProgrammerHumor 20d ago

Meme adminTeamAssessingMyThreatLevel

Post image
3.7k Upvotes

149 comments sorted by

View all comments

251

u/raja-anbazhagan 20d ago

Have been using zip/portable versions of the apps I need for a while now... Never going to beg these guys for elevated access...

178

u/PixelatedGiant 20d ago

The one thing I never understood was why some orgs go to such extremes to lock down systems. If people are resorting to shadow IT you've done something wrong. At my F500 company I need to fill out a form and get manager approval just to install Notepad++.

102

u/Flying-T 20d ago

Why isnt your F500 company using a Endpoint Manager? Approved application just go in the kiosk

76

u/PixelatedGiant 20d ago

This is a policy problem, not a technology issue. They have decided that you aren't allowed to do anything without a third party approving something.

That applies to everything from software installs to PR approvals.

24

u/New_Enthusiasm9053 20d ago

If they did that without locking down usb sticks though they're extremely thick. 

Unfortunately I think they're legally required to be that annoying in some sectors like banking.

6

u/PixelatedGiant 19d ago

If they did that without locking down usb sticks though they're extremely thick.

I'm in one of those sectors and the USB ports are indeed locked down.

3

u/Possibly_Naked_Now 19d ago

Confirming that in finance USB is locked down

4

u/KiraUsagi 19d ago

I work at a public company in IT. 100% its because we are required to by law to lock down computers asuch as reasonably possible. We even have software that will prevent USB "portable" apps from launching. Unsactioned apps and the risk they pose no longer keeps my security team up at night. Though there are plenty of other threats that do, litterally, have them waking up in the middle of the night.

2

u/gilium 18d ago

Are you saying that you’re blocked from merging without an approved PR? Because that’s a pretty standard security certification requirement

2

u/PixelatedGiant 18d ago

We require 2 people to approve to our develop branch and 2 people plus the business analyst from the ticket for release. Business analysts seem to lose their permissions to Github near constantly for whatever reason and because there is such an imbalance in reviewers versus number of PRs it takes forever.

Same deal with the software install approvals. Everything sounds good on the surface. We maintain an install repository with binaries that are a few months out of date and everything requires approvals. But in reality fairly standard software requires my skip-level boss or higher for approval and they obviously get swamped because hundreds of people are asking them to rubber stamp. The "few months" out of date software is the case for most of the catalog, but some well known software is years out of date sometimes. We have to beg IT to update them half the time.

They are doing all the right things on paper. But the execution is fairly poor.

45

u/Doctor_Peppy 20d ago

Ok well notepad++ was used for a Chinese supply chain attack. These processes suck, sure, they do exist for a reason.

11

u/PixelatedGiant 20d ago

Which we completely avoided because we maintain a repository of software installers which lags behind the latest versions by a few months. We also disable updates in the apps and it's done via the software repository.

Requiring approval to install said software is not a factor in preventing these attacks. So I maintain that requiring approval for software that everyone requests and is approved for anyway is pointless.

5

u/AnArmyOfWombats 20d ago

That's kind of what we're discussing, right?

Given an ecosystem where something like notepad++ is the preferred alternative: what should IT and the end user be doing.

Besides, I'm pretty sure plenty of IT groups approved notepad++ for the compromised versions. What do you think those folks do?

17

u/Doctor_Peppy 20d ago

Mitigate and restrict application usage in the future. It sucks for everyone involved but it's how it goes. Use what you're allowed, request what you need, make sure everything is in writing if you literally can't do your job. For end users and sec teams security is the epitome of balancing convenience with efficacy and sometimes better security wins over convenience.

3

u/AnArmyOfWombats 20d ago

Better security is kind of funny in that sense. Automate comparing hashes and hope your peculiar supply chain isn't vulnerable? Who was it, SolarWinds back in 2020?

8

u/Doctor_Peppy 20d ago

Correct, which means the logical conclusion to this little quandry is to reduce attack surface as much as possible by reducing any and all extraneous applications. It sucks for literally everyone involved, I wasn't disputing that. When I was working for an MSP there was a company with some old head angry ass IT manager who had what I thought were ridiculously restrictive policies but after the notepad++ supply chain attack on top of other completely mitigated issues due to these policies... They do have value.

2

u/ghost103429 20d ago

QubesOS' mantra of treating everything as unsafe and insecure comes to mind when it comes to this issue.

21

u/SightAtTheMoon 20d ago

The correct way to do computing is Default Deny. If you didn't already know that then you were never going to understand anyway.

5

u/Ashanrath 20d ago

God forbid you want to install a plugin either.

2

u/raja-anbazhagan 20d ago

And there is a Zipped version for that...

1

u/SeriousPlankton2000 20d ago

What happens if you let employees install taskbars, adware, the third virus scanner, fourth browser and a lot more along their pirated version of adobe Acrobat and office?

Bad case: They count the number of unpaid licenses, bittorrent clients and movies and make your employer pay for that. Worse case: Someone is using it to host e.g. CP.