frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: How locked down are your work machines?

10•donatj•4h ago
I've been working as a Software Engineer for 20+ years.

Places I worked in the early years barely had an IT department at all. As a developer you were expected to be able to maintain your machine. We'd install whatever we want, experiment with different operating systems, etc. Total free rein, box was our tool to get work done with, they didn't care how you did it.

That went away a long time ago. Basic corporate spyware and rules came pretty early but still free rein over our tools.

I've worked with the same company for close to a decade now, and they have been tightening and tightening the noose slowly but surely. We're purportedly a software company, but we lost admin rights, installable software went from a blocklist to an allowlist. Everything we install needs to get approved by IT, and that approval takes weeks.

Today they took our Chrome extensions away. They've got an allowlist of about 15 extensions we can install. Everything I submitted for approval got rejected.

I'm frustrated with this arrangement and am wondering how standard this is these days in this industry?

So I'm genuinely curious, Hacker News: How big of a company do you work for, what industry, and how locked down is your machine?

Comments

throwawaysleep•4h ago
Never worked for a place that locked down and one of my jobs is in healthcare tech.

Enjoy being crippled and use the time to be mediocre and just collect checks.

p_ing•4h ago
This is standard, especially when the size of the company grows. Actually, Microsoft might be a rare exception.

Extensions are full of malware of various sorts, so it makes sense that they take them away. Allow list vs. block list makes sense as a block list is impractical to maintain.

Only thing you can do is complain to management and prove with real #s how this is impacting productivity.

But if you're a webdev, it's super unlikely today that you need local admin and cannot work within an allow list of applications. If you're a driver dev, sure I can see how it might be a blocker.

comprev•2h ago
At $DAY_JOB our Windows laptops are locked down and supported.

Linux & macOS people have zero support (outside hardware, corp VPN) and the password to the local admin account (thankfully Jamf does not reset sudoers file)

As more developers/operators opt for Linux or macOS I'm surprised support hasn't been expanded.

donatj•1h ago
Exactly how we started down this path.

We were an open macOS shop acquired by major locked down Windows using corporation. Started with nothing, slowly Jamf -> Intune -> Intense Corporate MDM Controls.

comprev•1h ago
Out of habit (and corporate experience) I default to ~/.local/ where possible in case lockdown happens at some point in the future.
apothegm•1h ago
This is basically a requirement for certain types of security certifications and for liability CYA reasons in the context of evolving laws about stuff like data breaches.
hannahstrawbrry•1h ago
Sounds like it's time for some malicious compliance. I have been enjoying the freedom I get on my machines ever since I left Fortune 500 but even there I had enough permissions to install the software required to do my job. You might not get some conveniences back but I hope that after a few days of "I'm waiting for IT to let me do my job" standup reports they'll reassess.
AuthAuth•26m ago
Devices are completely locked down users do not have admin rights and must make a request for anything to be installed or executed. They cant even use a USB without getting approval. Software must come from our internal software repo and we run updates so often that known mac haters beg for macs to escape the win11 hell we've created. Its awful and I feel gross helping manage such a user hostile environment. Yesterday our update tool shutdown someones computer in the middle of a important action. It prompted him 3 times with 15min intervals then shut down his pc. He was going berserk as he lost a lot of progress.

Most of this is because of the strict compliance requirements our security team enforces on us. But some of it is done because we dont know how to implement the stuff in a way that is strict but lenient. Mac is way better because we dont have as much invasive tooling that supports it.

tacostakohashi•25m ago
Totally standard / "normal" at BigCo (fortune 500, banks, etc.).

At MegaCorp, there is a never ending arms race between security/compliance teams locking things down, adding approval and surveillance checks, and everyone else just trying to do their job.

Usually there are workarounds and backdoors available to people in the know. If you kick up a fuss, you'll be seen as "difficult". A key part of the job is finding tricks to get things done _despite_ all of the rules / checks in place trying to protect you from yourself.

abrookewood•22m ago
It is hard for IT departments to continue to allow that freedom as the company grows and compliance requirements creep in. I am in the weird position of being responsible for Risk & Compliance while also directing the IT policy for personal machines. I've managed to hold on and grant everyone local admin access, but I get a LOT of push back every year from auditors and customers running their own audits. I'm hoping that continues, but it's probably 50/50.

Tell HN: 2 years building a kids audio app as a solo dev – lessons learned

24•oliverjanssen•10h ago•19 comments

Ask HN: Does "Zapier for payment automation" exist?

4•PL_Venard•9h ago•7 comments

Ask HN: How are you automating your coding work?

48•manthangupta109•4h ago•55 comments

Ask HN: When does changing pricing models break user trust?

5•skicoachapp•2h ago•7 comments

Tell HN: Claude session limits getting small

5•pragmaticalien8•6h ago•4 comments

Ask HN: How locked down are your work machines?

10•donatj•4h ago•10 comments

Ask HN: Do you have any evidence that agentic coding works?

397•terabytest•1d ago•408 comments

Tell HN: Amazon has deactivated my seller account

67•hacky_engineer•5h ago•69 comments

Tell HN: ChatGPT needs a persistent workspace layer

5•LostBeacon•2h ago•1 comments

Tell HN: The FAA is pushing to decimate small flight schools

4•salusinarduis•9h ago•2 comments

Ask HN: What's your biggest challenge with context engineering for AI agents?

3•karpathunter•7h ago•0 comments

How do you keep AI-generated applications consistent as they evolve over time?

3•RobertSerber•6h ago•0 comments

Ask HN: Is OBD-II telematics data more private than mobile app tracking?

3•insuranceguru•4h ago•1 comments

Tell HN: Claude helped me maintain my old open source project

6•nergal•3h ago•1 comments

Ask HN: What are good resources to get familiar with AI code editors?

3•northfield27•9h ago•1 comments

Ask HN: What single AI tool/technique 10x'd your productivity last year?

3•laxmena•7h ago•4 comments

Ask HN: Are you going to meetups/conferences?

3•carimura•8h ago•3 comments

Ask HN: Can someone make a CAS just checking last bit on x86/ARM please?

3•goofy_lemur•13h ago•3 comments

Tell HN: Avoid Cerebras if you are a founder

25•remusomega•7h ago•12 comments

Ask HN: Why does SOC 2 feel so hard for early-stage startups?

4•asdxrfx•9h ago•0 comments

Ask HN: What should I write about next? (CS student learning by writing)

3•Aditya_kachhawa•9h ago•2 comments

Tell HN: Bending Spoons laid off almost everybody at Vimeo yesterday

345•Daemon404•7h ago•320 comments

Ask HN: Revive a mostly dead Discord server

18•movedx•1d ago•28 comments

Ask HN: COBOL devs, how are AI coding affecting your work?

167•zkid18•2d ago•183 comments

Code review your plans and your implementation

3•mayassin•11h ago•0 comments

Ask HN: Which Matrix and Mastodon servers are you using and why?

5•fsflover•3h ago•2 comments

Ask HN: Which common map projections make Greenland look smaller?

17•jimnotgym•1d ago•17 comments

Ask HN: How do you keep system context from rotting over time?

15•kennethops•1d ago•21 comments

Ask HN: Is retreq / retspec a thing?

3•foobarbecue•11h ago•0 comments

Ask HN: How to introduce Claude Code to a team?

11•9dev•1d ago•4 comments