To give a few examples:
- Running all services under a single Linux account, then requiring vendors to support password encryption in the startup scripts (everyone can access our production passwords!), then proceeding to store the production password in plain text in GIT and Confluence where everyone could read it.
- Everyone (including contractors) had access to the production environment through the testing environments, including unrestricted access to the production database (without requiring as much as a password). This was not deemed nearly as important as the passwords in the point above.
- I received an official warning for disclosing to AWS/GCloud that we did not have CI/CD setup but would be interested in getting one up and running at some point. This was considered to be "sensitive" information.
- Ansible deployments taking 12 hours (on a 6 server environment) because as it turns out, some random "security" settings slowed down SSH, incompetent people not really understanding what they we're doing did the rest.
- Ansible being blocked because someone in the security department read that it only required HTTPs access, turned out that they were reading the documentation for the WebUI.
- Requiring manual deployment of PR's to test environments and manual testing, the "evidence" + logs of doing this was to be documented in a Word document and attached to the PR.
- Automation and DevOps was banned because "The law does not allow us to do this"
- No rsync due to security reasons, great fun when you had to sync 200k small files :)
- PRs were kept around for months, so "senior" developers could estimate the risk. This included fixes that were hotfixed in production so that it was guaranteed to break again at the next 12 hour deployment (thus giving the same developers even more reasons to be even more "cautious" with all future PRs)
- Three different database schema's, three different database technologies, microservices, a React frontend, 50 outsourced developers for an internal CRUD application with 2000 entities, to be used by 10-20 users
- All .exes not on a whitelist were banned, so in order to run your application you just had to rename it to word.exe :)
- At one point external developers were hired, we requested a desktop for them that would allow them to "write" code. They got a locked down VM with notepad installed and nothing else