Give the man a break. The blame simply is on not practicing proper isolation and keeping work to a secure and controlled environment.
Give the man a break. The blame simply is on not practicing proper isolation and keeping work to a secure and controlled environment.
Maybe don't install crap on your dev machine if you're not going to keep it updated.
Blame a normal person? Nah. A senior engineer with keys to the castle? They should really know better.
> The blame simply is on not practicing proper isolation and keeping work to a secure and controlled environment.
Who is responsible for setting this up?
I'm only arguing against not blaiming "the act of missing an update on a personal device". That's nigh impossible to achieve across the board for all software we use.
I'm not arguing he's blameless. I agree that Plex is blameless. I also agree that LastPass needed a better threat model for privellage escalation/insiders attacks.
That's why you chuck Plex on a NAS, an old workstation, at least wrap it up inside a virtual machine.
... at LEAST least run it as it's own user.
Not your dev machine for a security company!
I promise I don't usually buy into a scapegoat. This is a unique situation. Almost any other company and it's a forgivable mistake. Any other role it's a forgivable mistake. Hell, any other seniority and it's a forgivable mistake.
Bro you are responsible for all my passwords, could you give half a fuck about basic security?
If only there was some way lastpass could ensure that crap wasn't installed on corporate network connected dev machines...