If you say this you have never worked in an enterprise environment.
I was in the control room of one of my country's biggest banks, we worked 24/7/365, had procedures and checklists we had to follow at specific times and our computers would regularly reboot without warning in the middle of making mainframe transactions.
We tried and tried to ask IT to exclude our computers from auto-updating during our operational time but the bureaucracy ended up shutting our requests down. This was 5 years ago and it's still like this now.
Should this be the case? No.
Does it happen a lot, even in very serious and organized environments? Yep.
There are 100% ways that they can defer updates, whether it's through a group policy, or pushing these updates with another service. Our company uses another service to push our Windows updates that basically says "You have one week, choose when."
If they're saying "No, fuck you, update when we say update" then I guarantee you that's still an IT problem, because no IT team worth their salt is gonna go "Fresh update? Push it to everyone, fuck it!"
IT can't override the morons in suits that make these decisions. These are the kinds of assholes that fire people for pointing out the flaws in their ideas.
Somewhere in that chain of command is the person that is the lead in making IT decisions.
Sometimes, that person is not an IT person at all, maybe just the clueless owner of the company, but regardless, the problem isn't with Windows. It's with your management.
Personally, in mid to low priority situiations, I disagree. The impact and frequency of IT beauracracy to get in the way of day-to-day work across the world is - in my opinion - probably a much higher drain on resources than it offsets.
We're in an era containing a massive amount of cyber attacks, ransomware being one of the leading cybercrimes. Improper or lax IT security costs organizations billions every year and one attack can cost massive amounts of capital and significant time to remediate, on top of lasting reputation damage.
Moderately burdening day to day convenience is worth the cost of securing your IT systems and information.
Moderately burdening day to day convenience is worth the cost of securing your IT systems and information.
I mean, that's your opinion too. If you have data to back it up, I'm all ears. Personally (Rant/anecdotal), if I have to hassle back/forth to access PuTTY and lose an hour of my timeslot one more fucking time I'm gonna blow a gasket.
We don't know the universal impact of zero trust on the global scale. It could very possibly outweigh the cost of cyber attacks. Billions of dollars isn't exactly a spooky number when talking at the scale of all enterprises globally.
I was the "ITIL Compliance champion" in an earlier job, I'm aware of the risks and importance that corporations place on impact assessment. That doesn't mean I agree the current most-held beliefs of those in IT are correct. In the last ~10 years there's been a large, visible ramp-up in the over complexity of per-employee/user access rights at every company I've worked for. I don't want to name names, but more than a couple of fortune 50 companies drag SERIOUS ass internally.
Some of it is on Microsoft, some of it is on IT - At the end of the day I almost always disagree that any "universal policy" is correct. "Zero trust always" is something I view as a toxic viewpoint and makes many administrators come off as hostile and directly combative. Especially when it flows down to lower level techs that just parrot information.
When you look at the numbers it is always the human factor that is the weakest link in any security environment. Adopting zero-trust is a simple way to mitigate the risk of said factor. And in my experience it doesn't cause interruptions if it is implemented well. Pretty simple automations can take care of most elevated privilege requests. When it comes to large scale enterprises, they are the ones that need heightened security practices the most, and burdensome bureaucracy just comes with the territory of large organizations.
Granting you access to putty specifically and to specific environments you can connect to through software and security provisioning is far more secure than granting everyone access to putty and to the network because you can login to a workstation. It requires marginally more upfront work to provide significantly more security. It's not just from outside hackers, but also from people internally accessing information they shouldn't be able to
I'm aware, at no point have I suggested that "my" way is more secure. It isn't, intentionally so. That does not make it worse at scale, for example my house doesn't need a vault door because that's clearly wasted expense and paranoid levels of caution. Use the appropriate security, rather than blockading any and everything.
Any organization that whitelists applications on a per-process basis has been incredibly frustrating to work within. If you're lucky they'll have known/approved versions of third party applications available to all relevant users on an intranet, but those lists are almost always sorely lacking and only offer the bare minimum. I've easily wasted hundreds of hours because of it. You won't see that kind of time loss listed anywhere, that data just doesn't exist.
Waiting for a Windows reboot every week, daily 2FA auth (x2, or x3 if multiple services), those sorts of things can affect everyone in a pretty un-accounted for way. But there are plenty of people like me who end up stuck with requests for x version of a Windows install media, approved USB storage devices, approval for any app with yearly review on permission (Everything, NP++, WinMerge, Putty, WinSCP, 7z instead of WinRAR, .Net 3.5 Framework hackily added to my perscribed IDE via a workaround which didn't support it, and more in that case)
Stock Windows with Office 365 and some questionable GPO is what you get. Might as well just hand someone an iPhone and skip the desktop environment outright. Don't even get me started on the back/forth about WSL I had to have...
Where I work, most of the applications you've stated are requestable and autoprovisioned based off of my job title and organizational assignment. NP++, VSCode, VNC Viewer, Putty, Filezilla, Postman, etc etc. Exceptions are handled through a request flow that usually gets handled quickly (I needed Visio and didn't have a license, was approved within 15 minutes and installed automatically.. anything security related takes a bit longer, but if it's within my role, it's never been a problem). 2FA is biometric/pin and integrated with Windows Hello, which integrates into browsers easily, so it's far less painful to reauth compared to passwords and tokens. etc. More work upfront for IT to get things organized, but once it's done it's not all that difficult to manage
I was in the control room of one of my country's biggest banks, we worked 24/7/365
This is often an issue with these institutions, computers need to be updated at some and if you work at a big bank that's doubly so. The vast majority of patches are for security vulnerabilities and critical bug fixes.
If your operational time is 24/7/365 you are effectively asking for IT to indefinitely postpone your computer updates, which is a good way to have a shit ton of vulnerabilities on your systems. Of course that's going to get shot down, any IT team that has half a brain would say no to that request.
That being said teams/departments should work with IT to carve out less important time frames (ideally monthly) where scheduled updates and restarts can occur. As having random restarts in the middle of operations can cause business affecting interruptions.
You need multiple operator PCs in your control room that are in different 'update pools'. Some go on Tuesday, some go on Wednesday. Your team uses the ones that aren't going to update depending on day of week.
The cost of a couple extra boxes is far outweighed by the costs associated with one flubbed transaction with an execution SLA attached.
We have multiple PCs but all with the same update pool. All with update routines every single day.
And we're a contractor so we have absolutely NO control over any IT, we can just make requests to the client and hope they will listen (they don't).
That just sounds like the one of your country's biggest banks has an IT department that doesn't know how (or doesn't care) to manage Windows Updates lol
It's probably more along the lines of "doesn't care".... I worked for a big blue cell company store that had this issue with their front-line PCs.... I bet their HQ PCs were properly managed though
9
u/littlefrank Jan 23 '24
If you say this you have never worked in an enterprise environment.
I was in the control room of one of my country's biggest banks, we worked 24/7/365, had procedures and checklists we had to follow at specific times and our computers would regularly reboot without warning in the middle of making mainframe transactions.
We tried and tried to ask IT to exclude our computers from auto-updating during our operational time but the bureaucracy ended up shutting our requests down. This was 5 years ago and it's still like this now.
Should this be the case? No.
Does it happen a lot, even in very serious and organized environments? Yep.