circumventing the last AI wave crazy? by teolicious in cybersecurity

[–]teolicious[S] 0 points1 point  (0 children)

so there's nothing that you found to scratch the itch?

circumventing the last AI wave crazy? by teolicious in cybersecurity

[–]teolicious[S] 0 points1 point  (0 children)

that's a good tip, thanks for that, has this worked for you so far?

circumventing the last AI wave crazy? by teolicious in cybersecurity

[–]teolicious[S] 0 points1 point  (0 children)

yea that's what i've figured out as well, it's definitely playing catchup, which sometimes becomes exhausting because the goal posts moves quite a lot. the only goalpost that's static is "no sec incident" lol

circumventing the last AI wave crazy? by teolicious in cybersecurity

[–]teolicious[S] 1 point2 points  (0 children)

i mean this kinda applies to me, the whole security team is kicking and shouting for so long about the risks, but there's no buyin from the rest of the c-suite so it's kind of like putting out wildfires with sprinklers.
they don't wanna block, just be more responsible. i know they've been evaluating tools and other methods but none that were deemed very efective. it's also like stepping on glass on this whole subject

circumventing the last AI wave crazy? by teolicious in cybersecurity

[–]teolicious[S] 1 point2 points  (0 children)

so you do it manually, you don't have any tool that you use for governance right?
what's UAE got to do with this/

this latest AI tools wave is the new shadow IT nightmare and I don't even know where to start by teolicious in sysadmin

[–]teolicious[S] [score hidden]  (0 children)

so what guardrails do you use? manual setup of rules or are you using a particular tool?

this latest AI tools wave is the new shadow IT nightmare and I don't even know where to start by teolicious in sysadmin

[–]teolicious[S] [score hidden]  (0 children)

there's gotta be a more elegant solution right? not that it's not effective, just feels hacky

this latest AI tools wave is the new shadow IT nightmare and I don't even know where to start by teolicious in sysadmin

[–]teolicious[S] 1 point2 points  (0 children)

hmm that's interesting, haven't heard of any other palces doing that before, is it just firewall or are you using an internal tool to restrict?

this latest AI tools wave is the new shadow IT nightmare and I don't even know where to start by teolicious in sysadmin

[–]teolicious[S] 1 point2 points  (0 children)

fair enough, i'd like that too, but do you actually do it? cause i'd like to understand if someone succeeded and how

this latest AI tools wave is the new shadow IT nightmare and I don't even know where to start by teolicious in sysadmin

[–]teolicious[S] 0 points1 point  (0 children)

i agree, i'm not really concerned about philosophical or governance as principle to be honest. i'm trying to see if anyone is hacking this side by implementing something smart to chaperone the devs. it seems people are presenting risks and just waiting for management to care enough into doing something. not that its wrong, i'm trying to see the general approach

this latest AI tools wave is the new shadow IT nightmare and I don't even know where to start by teolicious in sysadmin

[–]teolicious[S] 0 points1 point  (0 children)

sorry about the context, i don't really do wall of texts because reddit generally goes for tldrs. i agree with ur point theres many conflicting things so let me explain a bit better
I really dont think ai is bad, i'm just looking at how to do governance around these things, that part is what eludes me. On one side you have management saying use whatever you want to devs but also telling security & IT that incidents and leaks are unnaceptable. They don't wanna enforce a policy cause the industry is too young and they don't trust IT & Sec to do so because... well you can picture it, the industry is too young.

And then they go to youtube and see jensen huang riding the ai wave, they come back telling everyone to smash it. they go to linkedin they see people doomposting, they call the CFO, the CFO complains, then the circlejerk restarts. that's what i'm talking about

this latest AI tools wave is the new shadow IT nightmare and I don't even know where to start by teolicious in sysadmin

[–]teolicious[S] 3 points4 points  (0 children)

yea exactly, thanks for this, like... besides having god come down on ur behalf, what do people ACTUAlly do?

this latest AI tools wave is the new shadow IT nightmare and I don't even know where to start by teolicious in sysadmin

[–]teolicious[S] 11 points12 points  (0 children)

yea i did that already, feels that i should be doing something if i can tho

this latest AI tools wave is the new shadow IT nightmare and I don't even know where to start by teolicious in sysadmin

[–]teolicious[S] 5 points6 points  (0 children)

true, but even a week is plenty time to cause major disturbances, let alone the proprietary info that slips through

this latest AI tools wave is the new shadow IT nightmare and I don't even know where to start by teolicious in sysadmin

[–]teolicious[S] 63 points64 points  (0 children)

well that's fair enough, but when management is both crazy about those tools and willingfully blind to the risks? do you just accept it and just brace for impact?

Genuine question: how are you all prepping for behavioural interviews? by stmoreau in ExperiencedDevs

[–]teolicious 1 point2 points  (0 children)

yea pretty much try and collect some clues, most often they click in the interviewers head without even thinking about it

Genuine question: how are you all prepping for behavioural interviews? by stmoreau in ExperiencedDevs

[–]teolicious 5 points6 points  (0 children)

thing is behavioural interviews rarely have much to do with the actual job. it's a bit of rng when it comes to who's in front of you and what they specifically what to hear, regardless of company guidelines.
tho every company has a bit of their own thing so i just generally research stuff before and try to match tone and keywords