Slashdot Mirror


Balancing Bad Applications vs. Network Security?

Darlok asks: "One of our clients recently purchased a new financial software package from a major vendor for their industry. This is not a small mom-and-pop software house. The problem is, like a lot of industry-specific software, there are a considerable number of bugs. What's shocking is that to work around a problem preventing users from logging on, the manufacturer's recommended solution is to grant -Domain Administrator- privileges to all users, and they refuse (or are is unable) to explain that need further (it's bad enough that an increasing amount software seems to require local administrator privileges). Considering the enormous costs involved, how do you explain to Management that they shouldn't run this software until the problem is resolved -- which could be a long time, costing even more money? How do you balance productivity versus security when ANY productivity would give away the keys to the city? What can make an industry-specific software manufacturer pay attention to larger issues when they already have something of a captive audience?"

2 of 93 comments (clear)

  1. Sig by XanC · · Score: 0, Offtopic
    Okay, this is off-topic, but I'm confused. Not that I'm saying I disagree with you, but when somebody places his hand on the bible and swears an oath, he's attesting that he means it because he believes in justice in the afterlife.

    Basically, it means the Bible is more important than the Constitution.

    So how does pointing this out help your case?

    1. Re:Sig by Philip+K+Dickhead · · Score: 0, Offtopic

      Sometimes, a man's got to learn how to think.

      --
      "Speaking the Truth in times of universal deceit is a revolutionary act." -- George Orwell