234
you are viewing a single comment's thread
view the rest of the comments
[-] stoy@lemmy.zip 64 points 1 day ago

IT guy here, if we gave developers the option to exclude whatever the hell they wanted from AV scanning it would just mean that we would end up with computers where the entire C: drive would be excluded.

No, can't have that.

So what should a decent IT department do to give developers the access they need to do their job while maintaining a decent level of security?

Well, the least bad solution I have worked with was to have a non generic path that was excluded by policy.

Something like C:\Excluded

The directory was excluded from AV scan and allowed in policy, the user could put what they needed there and it would be fine.

[-] paks@feddit.uk 1 points 19 minutes ago

At our place it's the IT guys trying to tell us to exclude the entire Downloads folder. One of our devs had to put her foot down and say no, we'd do something more sensible/limited instead!

[-] wizardbeard@lemmy.dbzer0.com 5 points 20 hours ago

Your user base must be better than mine.

Some chucklefuck over a decade ago caved to the "need" for a public shared drive. I can see the argument for things like HR policy documents and such. But they didn't just give all users read access. Oh no, everyone got full read write. No fucking governance model, no process to check that PII wasn't being stored there by people too lazy to follow proper procedure.

Thankfully that horror has been thoroughly killed, and MS Teams makes it so easy for people to spin up collab spaces and file storage that there's no use case anymore.

[-] asdfasdfasdf@lemmy.world 23 points 1 day ago

So what should a decent IT department do to give developers the access they need to do their job while maintaining a decent level of security?

Give them a Linux machine?

[-] egonallanon@lemm.ee 11 points 1 day ago

This doesn't remove security and compliance requirements for the business though. For our Linux endpoints we still deploy an AV on them and limit the user's ability to add exclusions.

[-] Eyekaytee@aussie.zone -2 points 1 day ago

You ever worked in an average corporate job? You're missing out on so much

The IT guys barely know Windows, they've most likely never even heard of Ubuntu, could you imagine such a thing :|

[-] luciferofastora@lemmy.zip 2 points 7 hours ago

Huh, weird. The IT guys I work with don't just know Windows, when I joked about wanting a Linux instead they pointed out that we have software devs using Linux too. I'd need some reason to request it, but if I know the right people (and more particularly, what their favourite snacks are), I could probably get it approved.

(Doesn't actually help me, given I'm stuck using proprietary tools that I couldn't get to run with wine, but at least the option is there. And that's a big corp.)

[-] henfredemars@infosec.pub 20 points 1 day ago

I appreciate you trying to keep your developers productive. Deeply appreciate the concern.

this post was submitted on 08 Jan 2025
234 points (98.8% liked)

Programmer Humor

19910 readers
1838 users here now

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

founded 2 years ago
MODERATORS