Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Obviously it can be bypassed in the sense that somebody has full administrator database access.

The point about schemes like this is that instead of having to give 1000 support reps full access, you only give a few sysadmins full access. The likelihood of something going wrong with the data (through mistakes, willful abuse, extortion, whatever) goes drastically down.

In fact, once you got such a permission system in place, it becomes very attractive for the organization to use it. I mean, customers love it, they spontaneously write comments about it on Hacker News.

Even if you begin adopting it only for security theater (i.e. everybody still actually has full access), eventually some principled engineer brings up the idea to maybe remove full access for everybody cause now they have the access-granting system anyway, and this time they'll make a convincing case because the "move fast and break things" people have way fewer practical objections.



That's a very 90s view. The modern view is that only robots are sysadmins, and those robots are indirectly controlled. Some humans have superpowers in some systems, but not in the whole system.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: