|
|
|
|
|
by cycomanic
1798 days ago
|
|
If we take your argument further all engineers should be given the root password to all production servers and we should simply trust them (and keep logs) to not use the password? Access control is something so central to IT systems that I'm frankly dumbstruck that someone would argue against them on HN. |
|
If you do need it to do your job, you shouldn't have to run to your manager several times a day to make a request to do it. You should have root or whatever is necessary and it can be audited.
I'm not arguing against access control. I'm arguing for those with responsibility to work to be given the commensurate authority to do their work -- with auditing even.