|
|
|
|
|
by Hujiuu
1862 days ago
|
|
I'm not logging in as root directly. But non the less with 5 people what audit system would be even available in which only one person has access. All smart concepts cost either a lot of money or just don't work if you don't have enough people. Should the only techlead have access to the audit system? Probably. Should the only techlead have access to VMs? Probably yes. I made sure my systems are encrypted, 2fa wherever possible, no external systems besides the services. |
|
I know this sounds mean but software developers are really embarrassingly bad at security, because security is inconvenient by design and developers strive for convenience.