White hat social engineering: How to become an admin of a system
ramon.dev
ramon.dev
Take heed of this post, it's how the incompetent rise.
If people are actually going to make an effort to kick people out to cement their position, then it is better to restrict their access, before they do too much damage. Getting one person who services the need is not worth it if they kick out everyone else.
If the only reason is to cement their position then sure, but there are good reasons to limit the number of admins. The more admins, the more attack vectors for serious social engineering, the harder change control is, the longer meetings go for, the harder it is to make necessary change, etc. etc.
I think if somebody cares enough to become an admin and shows they care about the users then I don't mind them getting a power trip out of it. It's the "admins" that got there because they know the boss, or because they convinced somebody they should have access because their job-title entitles them to it that you need to look out for.
If you want sysadmin power, get DNS access or AWS admin or active directory admin or root on all servers.
Actually, the jira admin probably grants more "power" and visibility onto every manager who's got to come to you for tickets. So it makes sense for politics.
The AWS or Network owner may have the keys to the kingdom in terms of provisioning access, turning off routers, running arbitrary code on things, etc. but that also comes with great responsibility. If you fuck around and break something on accident, or shut down a router on purpose, there will be consequences. You may spend 150% of your day putting out fires and getting yelled at by senior leaders for application-killing lag or outages.
Meanwhile JIRA guy gets to shift blame and interface with leadership. He may not have any power, but depending on the org, he could have a bunch.
When I worked for an ISP -- a big one, chances are everyone here has heard of em -- one of the most powerful people in the PMO was essentially a secretary ("project coordinator") who had the ear of the head of the PMO, the VP of Engineering, and the CTO. She smoked a lot of cigs, so if you could make it to that smokers circle you could twist some powerful levers...
The admin panel also has more buttons and buttons are cool.
It's a petty form of power.
I'm waiting again for an issue being fixed by some admin from a jira system. I could just do that myself, i could do that better then the other person, but i don't have the permissions.
Sometimes its like 'do i pay someone else to paint my walls vs. do i do it myself'.
I'm a software engineere, it feels naturally to control my environment.
Care enough about making things better such that others view you as valuable.
I would equate this to an outdated model of Developer vs Sysadmin. The sysadmin controls everything about the production system. They don't want to change anything. The developer needs to release a new version, which needs a new library, or needs an update to the OS, etc. Or they don't even know what the production system looks like and the sysadmin won't help. So the dev wants root access to just fix it instead of going through excessive redtape.
It's literally an instruction manual for using indirect methods of communication and influence to get people to do what you want. It's practically adtech for the self.
Ignoring the dangers of having charismatic power over people, I don't know under what circumstances it is ethical to manipulate someone, and I certainly wouldn't brag openly about it.
If you try to remember people's names is that manipulative? If so, why do we apologize for forgetting people's names? If we write down the names of people we meet, is that manipulative or is it just being organized?
If you do it badly, yeah that's weird.
> Declare that there are too many admins and that there needs to be a stricter policy to define who can be an admin.
> Take it on yourself to define (or redefine) that policy and present it to the system owner in your organization. Make sure you fit the new definition and make sure that staple admins are also included.
> No one remembers why you’re admin, but you’re setting the rules now so no one can dispute it. Victory!
What are we even discussing here? This is such a indicator of bad character.
I really don't think this is ambiguous. It's very clearly meant to be funny rather than serious.
Taking individual sentences in isolation is one thing.
Taking them in the context of the entire post is another. In the context of the entire post, I see plenty of ambiguity in this sentence.
Edit: and I've just now remembered what a great laugh I had reading some of the language in "The Anarchist Cookbook" even though all those non-traditional fire recipes were certainly meant to be used for some kind of malicious act :)
But hey you never know, some sociopaths will totally write something like this.
It could be taken that way, but the problem is that the author deliberately puts it in terms that make that ambiguous.
A much less ambiguous way to put it would have been:
1. Help out an existing admin by fixing something they care about fixing but are too busy to fix themselves.
2. Repeat step 1. enough times that there is general recognition in the organization that you can fix problems and will do so responsibly.
3. Approach the powers that be and point to your track record established in steps 1. and 2. as evidence that (a) another admin is needed to help carry the load, and (b) you are the right person for that job.
4. Get appointed as an admin.
The author's process might be essentially the same as the above, but it might not; there are various signs in his writeup of the latter, that might be valid signs or might just be his whimsical way of speaking. And if his process isn't the same as the above, then he's doing more than just acting responsible and thereby earning positions of responsibility.
Where the real divergence comes is this:
"8. Make sure to keep helping out anyone who wants to fix problems with the system. If you become a roadblocker, you will allow someone else to do step #1 and you might lose your access when that person reaches step #6."
Notice that in my steps 1. through 4. above, no existing admins get punted. So there's no need for someone who reaches my step 4. to take steps to prevent others from starting at my step 1. and working their way through the process. And someone who was genuinely concerned for the well-being of the organization would be open to the possibility that, just as the admins who were there before him weren't able to take care of all the problems, there might come a time when the admins including him might not be able to either.
Step 1: Become admin
Step 2: Say there are too many admins now, redefine the requirements for admins to fit you
Step 3: Stay admin, while others don’t qualify
Huh? This is cool?
On the topic of taking jokes seriously :
About 10 years ago I came across Winning with the Bongcloud, a mock 36 page guide to a new killer chess opening (1. e4 e5 2. Ke2 - the worst move possible in that position) which was about the funniest thing I'd ever read, brilliant in every way. It uses the vague terms real opening books do, with every example game leaving you with a "winning" position which is actually lost by mate in 1.
http://i.4pcdn.org/tg/1401479151063.pdf
I wrote the author a gushing email, saying it was a brilliant work, thanking him for the valuable addition to opening theory etc – playing along with the joke. The author wrote back a puzzling message explaining that it was actually all a joke, that all the diagrams were losing, etc as if I'd taken it seriously. I can't imagine why he thought I'd thought it had any value, if I'd taken it seriously. (Maybe he was out-trolling me?! That didn't occur to me until just now.)
Anyway, pleasingly, the Bongcloud is nowadays very famous. Almost every online stream where grandmasters say they'll play openings suggested by users, someone suggests the Bongcloud, and without fail they know what it is, and I've seen it played several times. It gives joy like no serious opening could.