Dropbox/googledrive is a huge security hole that is definitely blocked at most companies I work at.
Dropbox/googledrive is a huge security hole that is definitely blocked at most companies I work at.
I really don't see how you can develop such software without having at least the ability to easily gain administrative permission on the machine.
The only exceptions are some parts of the C++ debugger and the driver development kit.
I'm not sure if your "almost ten years ago" is meant to be hyperbolic, or genuine... I can't even remember why, but I know the project I was on 6 years ago definitely needed visual studio to have admin access, and it was all standard C# app stuff (maybe WPF?)
A dose of humility might be in order.
Corporate IT can admin the box for corporate training PowerPoint gunk. You get another box to run what you have written, and maybe another to run the development environment. Those don't go on IT's network. You can run a private LAN around the office, not connected to the outside world, in which you break things as you please.
This solution is even good enough for people who are intentionally dealing with malware.
This stuff isn't that hard - but those of us doing it see the mad things that people do when they're given blanket, even time bound, admin access. They're the ones dealing with the support calls when then every SQL Server installation has been done differently with no details of what specifically was done. IaC works.
Now iterate that over 1000s of other instances and you see the financial reason why devs need admin.
Unless the VM is somehow sandboxed it's just another box on the same network. So the same reasons for me not being admin on the physical machine (e.g. to not be able to download and run untrusted software because it might spread something on the network) should apply to the VM?
An account inside a VM will only let you play in that VM.
Whereas your account on the host is available and automatically granted access to all machines, fileshares and services on the active directory network. If it got admin rights, then you've got admin pretty much everywhere.
Nonsense. You can have local admin rights that work only on one machine.
That being said, there are indeed restrictions that can and should be set on admin rights. Not that IT would know about it or that it would limit pivoting much.
Why not report your findings to Microsoft and get your bug bounty payout?
And if this is true, wouldn't they also just do that from inside the VM?
Let's assume for the sake of discussion that to do what I need to do I not only need to install the program that requires priveleges, I also need a few of my company network drives mapped, access to some company systems, internet access and so on.
In fact, several VMs.
There is absolutely middle ground if you have the time and resources to get it running smoothly.
It's not practical to sit around for a week or more while you wait for each piece of software to install. No dev will ever get any work done.
Also, lots of stuff simply cannot be installed as a regular user, especially stuff that needs unfettered access to network cards or memory.
Because most of the non-insignificant ones still CAN'T be, under Windows, to this day. So special people get a completely separate account with pseudo-admin rights. I have to enter those credentials several times a day.
Then I spoke to a help desk guy, who said he had to enter his domain admin account password 40 TIMES a day.
What a waste.
IIS development - Visual Studio needs Admin to actively debug IIS.
Memory tools like dotMemory.
Dealing with Windows Services.
Shit... dealing with Windows.