Comments on: QotW #29: Risks of giving developers admin rights to their own PCs http://security.blogoverflow.com/2012/06/qotw-29-risks-of-giving-developers-admin-rights-to-their-own-pcs/ The Security Stack Exchange Blog Sat, 06 Feb 2016 05:11:22 +0000 hourly 1 https://wordpress.org/?v=4.5.6 By: roryalsop http://security.blogoverflow.com/2012/06/qotw-29-risks-of-giving-developers-admin-rights-to-their-own-pcs/#comment-4975 Fri, 08 Jun 2012 13:03:47 +0000 http://security.blogoverflow.com/?p=705#comment-4975 This is an essential distinction: in an ideal world, developers could use specific machines in a Dev environment to do all the development ‘stuff’, and their office machines to do office ‘stuff’

I’m not sure how often that happens though, I know one of the big gripes is that developers just want to do their job without hindrances – I wonder if having to switch machines would be exactly that. I know in most enterprise organisations I know, the developers have their machine, and it does everything they need, both office and Dev. Some are ahead of the curve and just allow a terminal instance into a machine on the Dev environment, which seems better.

]]>
By: scottpack http://security.blogoverflow.com/2012/06/qotw-29-risks-of-giving-developers-admin-rights-to-their-own-pcs/#comment-4972 Fri, 08 Jun 2012 12:52:36 +0000 http://security.blogoverflow.com/?p=705#comment-4972 Good distinction to bring up. I read this assuming that the developers had entirely separate systems on which to do their development. I suspect Rory was in the same boat.

I’m of the opinion that the conversation is entirely different depending on which system is actually being discussed.

]]>
By: Iszi http://security.blogoverflow.com/2012/06/qotw-29-risks-of-giving-developers-admin-rights-to-their-own-pcs/#comment-4971 Fri, 08 Jun 2012 12:35:14 +0000 http://security.blogoverflow.com/?p=705#comment-4971 Good QotW post, but I still can’t say I agree with the conclusion.

Maybe I just don’t understand the work environment of software developers enough, but it would seem to me (as @wrb looks to have touched on in an answer) that Dev environments should be separated enough from Production that Devs don’t really need Admin rights on their “office” workstations.

Then again, it was never really clarified in the question whether the asker was inquiring about development workstations or office workstations – or if the two are even separate in their company’s environment.

]]>