Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
"It's one of our fucking contractors that took one of our scripts (that they're supposed to have duplicate copies of) and forgot to change to their own credentials."
Please forgive me if I'm misunderstanding something here... but it sounds like you're saying that outside parties have access to scripts with hardcoded legit credentials in the scripts, and that these outside parties have access to these scripts in an internal production/testing environment rather than from a repository? -
Elyz78095y@MobiusDerp yes. They do. It's retarded but so many of the decisions made by management is that way.
-
@Elyz Has management been made aware that this arrangement violates every principle of computer security at the most basic and profoundly obvious level?
-
Elyz78095y@MobiusDerp I'm a student, nobody will take me 🙃 fortunately that also means none of this is my responsibility
Related Rants
I had security reopen our test-user last week. I could run the tests once, then they started failing with "blocked user due to too many attempts at logging in". Huh, that's weird. I go through everything, every script, every scheduled task, every nook and cranny of every drive on every machine I could reach, and make sure the password is updated everywhere. Reopen account. Same shit.
I email around to some people, they don't use it, one guy asks if I checked x, y and z, I did. Then he's sure we don't use it anywhere else.
It's one of our fucking contractors that took one of our scripts (that they're supposed to have duplicate copies of) and forgot to change to their own credentials. That's literally the agreement, take our scripts and change the user and run them on your machines.
Afhfjdkdhdjdbd stop locking me out of everything with your incompetence. I email them, some cunt gets back to me asking for the new password. NO. USE. YOUR. OWN. CREDENTIALS. I KNOW YOU HAVE THEM, THEY'RE HERE IN THE LIST AND BEING USED IN ALL OTHER SCRIPTS AAAAAAAAAHHH
rant
i want to quit
security issues
end me now
monday funday
incompetence