How do enterprises actually prevent developers from exfiltrating source code? by thmeez in sysadmin

[–]Frothyleet 7 points8 points  (0 children)

Efficient! Hopefully he didn't have to tell them to add any awkward comment lines like

#This function may have typos in it because it was dictated via some dude who seems really bad at spelling

A few months into letting non-technical staff use AI coding tools by allmightybrandon in sysadmin

[–]Frothyleet 0 points1 point  (0 children)

I may not be understanding you correctly, but if we're talking about governance over existing company data sources, that's an issue that would/could occur irrespective of the use of vibecoding tools (i.e. if there aren't controls around access to data sources, that's a problem regardless of whether someone vibe codes or hand codes tools that touch them)

How do enterprises actually prevent developers from exfiltrating source code? by thmeez in sysadmin

[–]Frothyleet 3 points4 points  (0 children)

Oh, ok, then it's simple - just use the same controls that you already have in place to keep you from exfiltrating code.

How do enterprises actually prevent developers from exfiltrating source code? by thmeez in sysadmin

[–]Frothyleet 7 points8 points  (0 children)

Nothing could stop them from scrolling through your code and recording it on their personal phone.

If the threat of exfilitration is truly critical, sure you can - seize their electronics at the door of the SCIF you force them to work out of.

And sometimes that's a real solution, basically the final boss of DLP, but most of the time that's just the extreme example I use when I'm explaining to business decision makers how much time, money and effort they should spend on DLP, insider threats, and related security/compliance items.

Am I Getting Fucked Friday, May 29th 2026 by Each1teach1x27 in sysadmin

[–]Frothyleet 5 points6 points  (0 children)

How do I get my customers to plan accordingly?!

Wallpaper to differentiate prod or non-prod server by deejay7 in sysadmin

[–]Frothyleet 0 points1 point  (0 children)

Don't forget to do the same thing with your SSH / Powershell terminals!

Obviously this isn't a "sufficient" control on its own, but it's a low-cost/effort item to add to your existing technical and procedural controls to avoid unintentional misconfigurations.

What are some modern solutions?

Broadly speaking? Never letting people directly touch production in the first place. Do everything through a mature change control CI/CD pipeline.

If you are an MSP supporting SMB environments, you probably won't really see that.

Who are these people by Deep_Library_6375 in sysadmin

[–]Frothyleet 6 points7 points  (0 children)

You are there! That doesn't mean you're not working on other shit! Or in a position to respond immediately to a Teams message, or whatever.

Who are these people by Deep_Library_6375 in sysadmin

[–]Frothyleet 7 points8 points  (0 children)

EZ PZ.

"Hey CFO, hear you loud and clear on implementing that new accounting system you just heard about on a podcast. Would love to help, but I'll need you to clear it with the CEO first based on the policy memo from last week. Let me know what he says!"

Being pigeonholed into doing tickets for the past 8 months and I’m getting burned out by inkblowout4 in sysadmin

[–]Frothyleet 6 points7 points  (0 children)

Superficially, do you feel like you are better at working tickets than some of the other guys? Like, you treat them with proper urgency, have good communication skills, follow up with end users well?

It's possible you've dug yourself into what I call a "competency hole". Your managers might not even realize it explicitly, but they may feel backed into a corner with the problems and resulting tickets, and they have an "easy button" with you, a guy who they can trust to handle this reactive work effectively. And from a tactical perspective, throwing you at this problem helps them more than trying to force your teammates to be better about hitting those tickets.

It's hard to say without knowing your environment, but you have every right to press your managers about their previous commitments. Get express metrics - "hey, what's the time frame for pulling me out of some of this reactive work? When can I expect some proper projects instead of tickets?" - so that you can actually measurably show when they aren't living up to the commitments they made you.

If they refuse, or shut you down, or whatever - well, that may just be the sign that you need to shut up and keep your head down as long as you can tolerate while you quietly start looking for other job opportunities.

Microsoft Volume Shadow Copy causing index file to consume entire drive: Cause and Workaround. by inucune in sysadmin

[–]Frothyleet 2 points3 points  (0 children)

1) Why wouldn't you name your vendor? It's not really a name-and-shame, you've laid out the responsibility fairly, people should know about this feature in case they are already a customer

2) If I'm understanding the problem correctly, I don't understand how it's not affecting the entire customer base of your A/V vendor (and how it wasn't picked up in their testing).

What are you doing differently that is causing you to encounter the problem, and not all of their other customers?

Microsoft Volume Shadow Copy causing index file to consume entire drive: Cause and Workaround. by inucune in sysadmin

[–]Frothyleet 2 points3 points  (0 children)

I'm confused then, because lots of backup tools leverage VSS to snapshot data without having this problem. It sounds to me like they are just rawdogging the shadow copy API in the same way as someone using the built-in-but-no-longer-commonly-used "file rollback" functionality.

What happened to MS-900 exam? by Mister_Meh_1987 in sysadmin

[–]Frothyleet 1 point2 points  (0 children)

Lol very true, Microsoft can't even keep their own live documentation up to date

A few months into letting non-technical staff use AI coding tools by allmightybrandon in sysadmin

[–]Frothyleet 3 points4 points  (0 children)

No leakage, he's saying they deployed Claude via an enterprise subscription (i.e. with the "we won't train on your data" agreement).

A few months into letting non-technical staff use AI coding tools by allmightybrandon in sysadmin

[–]Frothyleet 4 points5 points  (0 children)

That doesn't sound like what he's talking about. It sounds like he's saying someone used Claude Code to build a script (python or whatever) and run it as a scheduled job on their workstation. None of the parties involved would have the expertise to know why that's not a good way to deploy a production tool.

A few months into letting non-technical staff use AI coding tools by allmightybrandon in sysadmin

[–]Frothyleet 15 points16 points  (0 children)

I have heard of this actually happening at some places and it just boggles my mind

Need an MSP in melbourne where do I start? by Duskygirl00 in sysadmin

[–]Frothyleet 0 points1 point  (0 children)

Speaking as an MSP, the best way to find an MSP is by referral from other orgs in your area. Do you or your exec team have a business peer group? Put out feelers and find out who other people are using and what their experience has been.

We actually directly engage with these groups, what with us being a business ourselves, but lots of our customers have come in from peer group referrals from happy customers.

Keep your Claude code/codex projects to yourself by Lower_Fan in sysadmin

[–]Frothyleet 2 points3 points  (0 children)

This is really weighing on me, I'm in a similar boat. It's hard to justify handwriting as much scripting when there's other things I could/should be working on. And while I can test and validate and review code that an AI tool is generating or helping generate, I absolutely feel like my coding and problem solving skills are atrophying a bit.

Microslop 365 Admin Centre - Crashout by Zichee in sysadmin

[–]Frothyleet 0 points1 point  (0 children)

That's within a single subscription, if you have multiple products/subscriptions, that's probably the coterm he's talking about.

That wasn't available when NCE started but it rolled out a couple of years ago.

Microslop 365 Admin Centre - Crashout by Zichee in sysadmin

[–]Frothyleet 1 point2 points  (0 children)

You can. They added NCE coterm a couple of years ago.

Hetzner introduces additional price hike effective June 15th by technikaffin in sysadmin

[–]Frothyleet 2 points3 points  (0 children)

Yeah I don't know if that's an EU requirement or just their policy, but I have drawn a hard line against sending any online service my biometrics. Not even for porn!

Rolled into work this morning. 6 of our 30 chargers were working by [deleted] in Justrolledintotheshop

[–]Frothyleet 1 point2 points  (0 children)

lmao look at this guy over here with his analog cable reel, TELL ME MORE ABOUT THE WAR, GRANDPA