One chestnut from my history in lottery game development:

While our security staff was incredibly tight and did a generally good job, oftentimes levels of paranoia were off the charts.

Once they went around hot gluing shut all of the “unnecessary” USB ports in our PCs under the premise of mitigating data theft via thumb drive, while ignoring that we were all Internet-connected and VPNs are a thing, also that every machine had a RW optical drive.

  • TechyDad@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    2 years ago

    ZScaler. It’s supposedly a security tool meant to keep me from going to bad websites. The problem is that I’m a developer and the “bad website” definition is overly broad.

    For example, they’ve been threatening to block PHP.Net for being malicious in some way. (They refuse to say how.) Now, I know a lot of people like to joke about PHP, but if you need to develop with it, PHP.Net is a great resource to see what function does what. They’re planning on blocking the reference part as well as the software downloads.

    I’ve also been learning Spring Boot for development as it’s our standard tool. Except, I can’t build a new application. Why not? Doing so requires VSCode downloading some resources and - you guessed it - ZScaler blocks this!

    They’ve “increased security” so much that I can’t do my job unless ZScaler is temporarily disabled.