Overall, this approach is better. When I started in engineering back in 2000, it was still a debate as to whether developers should have admin on their own machine.
Overall, this approach is better. When I started in engineering back in 2000, it was still a debate as to whether developers should have admin on their own machine.
I need to do development regularly for our workflow systems. That includes a NodeJS based process, so npm has to work, I backup code to gitlab, need to use Postman/Insomnia to test APIs, whatever.
I don't have admin rights on my windows machine, because that's obviously unsafe. All the software on my machines is outdated, as I need to open a ticket for each and every update of VS Code and whatever I'm using and answering those tickets can take some time. Also I feel dumb doing that.
After "securing" the systems even more, IT changed the proxy server. npm didn't work from one day to another. They had to debug it for a week and finally gave up and just whitelisted it and whatnot. Will probably only survive until the next update.
gitlab doesn't work anymore, as basic auth is not supported by the proxy server anymore. I don't have the time (nor the rights - ha!) to fiddle around with that all day to get it working, so there's no versioning happening and "backups" or collaboration are based on local file systems or sending mails with the code attached, too.
My local environment of our workflow server can't connect to the app store to update the integrated apps. Something with the proxy, I don't know. So I'm developing against outdated versions of everything...
Want to connect to external APIs? Need to create a ticket so something besides Outlook and the browsers can connect to the outside world. Sometimes it doesn't work, so... you guessed it... make a firewall/proxy exception. Just takes a day or two.
Also updates in core infrastructure like proxy and firewall are not communicated. So you come into the office monday morning and everything is burning and nothing works anymore. "Yeah, we changed the proxy on Saturday..." Fuck it.
Final thing: One of my biggest projects is to provide a public API to create an easier onboarding experience and one standardized way to place orders with us... IT wanted to do it with their software partner, no other ways possible. We already had something ready we could have bought, deployed and customized in 3 weeks time. Now it's half a year later and the test version is ready. Endpoint URL looks like hell and _every single user_ needs to have his IP whitelisted to connect to the API. Even for the testing endpoints. For security reasons obviously. I'm just done with it.
edit: Yeah, slightly off-topic but had to vent somewhere. Thanks for your patience.
To be fair: Most of the people don't really need much more than SAP, Excel and Word and that's... "uncomplicated" to run with some proxy and firewall config etc.
Treating a dev box as anything other than a permanently compromised piece of hardware is a recipe for disaster, and that applies to our machines where we have to run those tools.
I particularly like joining a new company and being expected to write and memorise several distinct, secure passwords before having the computing and network freedom to use a password manager. Having to tell my new manager I forgot my password is a riot.
I'll give you no AV/EDR/XDR/Mountain DewDR that'll use up your CPU if you'll grant me no external I/O ports at all on your computer. In fact, I'll throw you a bone -- no input devices on a fresh install and you can have all the output devices you want. And no input means no need to remember passwords!