<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>olivetalks &#187; IT</title>
	<atom:link href="http://www.olivetalks.com/tag/it/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.olivetalks.com</link>
	<description>The Olive has arrived and it has things to say…</description>
	<lastBuildDate>Tue, 16 Nov 2010 19:25:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Is your colleague spying on you?</title>
		<link>http://www.olivetalks.com/2008/06/19/is-your-colleague-spying-on-you/</link>
		<comments>http://www.olivetalks.com/2008/06/19/is-your-colleague-spying-on-you/#comments</comments>
		<pubDate>Thu, 19 Jun 2008 19:36:42 +0000</pubDate>
		<dc:creator>ZoltarStark</dc:creator>
				<category><![CDATA[Stuffings]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[workplace]]></category>

		<guid isPermaLink="false">http://www.olivetalks.com/2008/06/19/is-your-colleague-spying-on-you/</guid>
		<description><![CDATA[One third of IT staff is snooping on their co-workers. They can access confidential information such as your salary details or personal emails.]]></description>
			<content:encoded><![CDATA[<p>Since I&#8217;m not a statistician I&#8217;m not really sure how reliable are the results of this <a href="http://www.cyber-ark.com/news-events/pr_20070530.asp">survey</a> but supposedly most people are being spied upon at work. According to this research one third of IT &#8220;professionals&#8221; secretly monitor their co-workers (quotes around the word professionals for the obvious reasons). As each of the miscreants snoops on at least a few people the chance of being under this illegal supervision is rather high.</p>
<p>That&#8217;s rather shocking to me. I know that as a sysadmin you have access to passwords and privileged accounts but you&#8217;re given them for a very specific purpose not just for your amusement. It&#8217;s like your GP telling everybody about your sickness.</p>
<p>Since it looks like avoiding the <a href="/2008/02/11/rules-for-system-administrators/">bad sysadmins</a> is going to be difficult, you have to defend yourself. The only sure defense in this case is not to use the computer at work for anything you&#8217;d prefer to remain private. You just can&#8217;t be sure otherwise. In many organizations IT staff who left may still have access to the company&#8217;s network. This increases your exposure even more. Like for example in this <a href="http://forums.hostgator.com/showthread.php?t=33170">organization</a>.</p>
<p>By the way, the research is already over a year old but it looks like it just got picked up by <a href="http://www.msnbc.msn.com/id/25263009/">MSNBC</a> and the <a href="http://helenaspopkin.newsvine.com/_news/2008/06/19/1591008-one-in-three-it-staff-snoops-on-colleagues">blogosphere</a>.</p>
<h3>Related post(s)</h3><ul class="related_post"><li><a href="http://www.olivetalks.com/2008/02/11/rules-for-system-administrators/" title="Bad system administrators">Bad system administrators (1)</a></li><li><a href="http://www.olivetalks.com/2009/06/07/naked-folders-in-wordpress/" title="Security problem with WordPress">Security problem with WordPress (2)</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.olivetalks.com/2008/06/19/is-your-colleague-spying-on-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bad system administrators</title>
		<link>http://www.olivetalks.com/2008/02/11/rules-for-system-administrators/</link>
		<comments>http://www.olivetalks.com/2008/02/11/rules-for-system-administrators/#comments</comments>
		<pubDate>Mon, 11 Feb 2008 20:42:57 +0000</pubDate>
		<dc:creator>ZoltarStark</dc:creator>
				<category><![CDATA[Stuffings]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[workplace]]></category>

		<guid isPermaLink="false">http://www.olivetalks.com/2008/02/11/rules-for-system-administrators/</guid>
		<description><![CDATA[Some system administrators like to invent their own "Best practices". See how crazy these people can get...]]></description>
			<content:encoded><![CDATA[<p>Here are some rules to make the job of a system administrator easier and more rewarding.</p>
<p><strong>1. Always change your systems without any plan.</strong></p>
<p>This way you can assure that you spend more time than was really required to do the job, redoing and undoing what you did last week or the previous month. You will look very busy, probably even doing lots of overtime. This is guaranteed to look very good on your next salary review.</p>
<p><strong>2. Do all new installations and updates directly on the production system.</strong></p>
<p>It will give you an extra adrenaline rush when you scramble looking for a backup copy of very important file you&#8217;ve just deleted. Especially if your maintenance window is just closing. And it will give you bragging rights to other sysadmins. You will even look better to the management. After all you saved time by not testing the patches and configuration changes on a test machine and since you don&#8217;t have a test machine you obviously didn&#8217;t spend any money on it.</p>
<p><strong>3. After connecting the servers to UPS batteries forget totally about installing any UPS monitoring software.</strong></p>
<p>Who needs any monitoring software? You can always log on to the servers and shut them down when there&#8217;s no power. Excellent job security, now they can&#8217;t fire you. And if power does go down you can claim overtime.</p>
<p><strong>4. Backup only some files.</strong></p>
<p>You know very well which files should be backed up and which not. You&#8217;ll be saving space on the very expensive backup media. In case of a total server crash you won&#8217;t have everything to recover the pre-crash setup and you&#8217;ll spend extra hours setting it up to the same configuration. Or at least as close to it as you remember. For sure this will be a better configuration, after all the previous one did crash. Oh, and did I mention the overtime already?</p>
<p><strong>5. Keep all the documentation about the set-up of your systems in your head.</strong></p>
<p>And nowhere else. This way you can be sure nobody will be able to use your secret sysadmin password for some nefarious activity. And you&#8217;ll have more work, again making you look very busy. Another benefit is job security. Too risky hiring someone to replace you if they wouldn&#8217;t be able to do anything with the system.</p>
<p><strong>6. Read your users emails.</strong></p>
<p>This is really serious. You need to check whether they&#8217;re not sending spam, viruses or any confidential information without authorization. Nobody else in the company has this capability so it&#8217;s all up to you. Management will be thankful when you warn them that one of sales guys is planning to quit and take the customer database with him.</p>
<p><strong>7. On your systems only install the applications you approve not what the users want.</strong></p>
<p>Users don&#8217;t know what they really need, they just spend half a day sending emails and the rest chatting. If you let them decide what kind of programs are running on your systems you could as well give them full administrator access and just watch the systems fall apart. Soon they will want 15 different web browsers, 12 email programs and 22 instant messengers. They should understand that you&#8217;re just trying to save money on licenses and save time on maintenance of those &#8220;additional&#8221; programs.</p>
<p><strong>8. Require each application to have a separate authentication scheme.</strong></p>
<p>This way if some user&#8217;s account gets compromised (in spite of the strictly enforced rule that each password has to be at least 25 characters long, containing at least 10 non alpha numeric characters and not repeating any symbol) you can rest assured that it will affect only one account in one application. And when you&#8217;re at it make sure to talk to the company management to fire immediately any idiot writing down his super strong password on a post-it. Such weak brains definitely do not belong in your company. Management will definitely listen to your advice if you&#8217;ve been following the previous rules. They owe you.</p>
<p>Any system administrators out there would like to share some additional advice?</p>
<hr align="left" width="20%" /> <a href="/category/computers/feed" title="rss feed to post"><img src="/wp-content/uploads/2008/01/feed-icon-14x14.png" alt="rss feed to post" /></a> Subscribe to the Computers posts of olivetalks, if you found this article interesting, thank you!</p>
<h3>Related post(s)</h3><ul class="related_post"><li><a href="http://www.olivetalks.com/2008/06/19/is-your-colleague-spying-on-you/" title="Is your colleague spying on you?">Is your colleague spying on you? (0)</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.olivetalks.com/2008/02/11/rules-for-system-administrators/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

