Slashdot Mirror


IT Departments Fear Growing Expertise of Users

flatfilsoc recommends a long article in CIO magazine on users who know too much and the IT leaders who fear them. Dubbing the universe of consumer technology the "shadow IT department," the article highlights the extent to which the boundary between users' workplace and home have broken down. It notes the increasing clash — familiar to anyone who works in a company with an IT department — between users' home-grown productivity boosters and IT's mandate to protect corporate data. The inherent tendency of the IT department to want to crack down and control technology that it doesn't supply should be resisted at all costs, according to CIO. The article outlines strategies for co-existence. It just might persuade some desperate CIO somewhere not to embark on a career-limiting path of decreeing against gmail and IM.

82 of 499 comments (clear)

  1. Yeah, what he said.... by zappepcs · · Score: 5, Insightful

    and there are always groups of individuals in every company that DO NOT fit the one-size-fits-all software/security model.

    Some people/groups really need a sandbox to work in, without interference from good intentioned IT departments.

    A virus spread wildly throughout my company recently because IT had thought to conveniently map some not so useful drives for everyone... guess how that virus spread?

    IT needs to learn to provide and protect without being so intrusive as to hinder real work being done.

    Sighhh

    1. Re:Yeah, what he said.... by bigtomrodney · · Score: 5, Insightful

      That is certainly true to a large degree, but let's not overshadow the need for tighter security. Ultimately users need to bear in mind that their PC is for working, and really should only provide for their working environment. It's best to put aside the 'it's my computer' attitude and push the 'it's a company tool' attitude. Speaking as someone who has worked for years in IT, I would be more of the opinion that most staff in the IT department fear user knowledge because their own knowledge is lacking. From experience of a few different departments it's usually only one or two who have the knowledge to begin with and another five or six who are all talk. That's more what causes the friction between users and IT staff. No one minds a straight no if it is qualified, but I don't think anyone will tolerate a grunt of 'no' from someone who's not even sure why in the first place.

      --
      I never get used to these constant resurrections
    2. Re:Yeah, what he said.... by Jhon · · Score: 5, Insightful

      Ultimately users need to bear in mind that their PC is for working, and really should only provide for their working environment.
      Agreed. What need does a biller have in hooking up their IPOD to their work PC? Why would a clientservices-phone jockey need to hook up their USB memory stick? Why would a transcriptionist need access msn/hotmail/yahoomail?

      Then again, if it's a small shop and you're not really dealing with protected information on the network (say, medical records for example), then you may be fairly lax as to what users can/can't do at the workstation.

      *IF* however, you have federal and or state guidelines you MUST follow with regards to protecting identity and health information, then sorry pals, your workstation is locked down. Nope -- no unauthorized memory sticks. Nope, no internet access -- other than white listed work related sites. Nope, no access to install software.

      I've had users ask me for permission to install some "app" they like to use. The simple answer is "no" and I don't want to waste my breath re-hashing the same reasons. So I say "No. Check your employee handbook, page 12 for why" and walk away. I'm not going to have anyone of my guys jump through paperwork hoops to keep CAP or CLIA or MediCal happy so someone can have their computer go "ding" at a certain time using their favorite software.
    3. Re:Yeah, what he said.... by markov_chain · · Score: 4, Insightful

      What need does a biller have in hooking up their IPOD to their work PC? Why would a clientservices-phone jockey need to hook up their USB memory stick? Why would a transcriptionist need access msn/hotmail/yahoomail?

      Morale.

      This is a tricky thing and different for different types of work. A long time ago when I worked at a research lab, they tolerated my Linux boxes going onto their corporate network, which was a mix of Solaris and Windows. I even managed to interfere with their routing infrastructure by doing experiments with gated. They might have been upset about it, but in the end good work got done and the creative people were happy. If their policy had been draconian, the said good work would have been done at a competitor.

      --
      Tsunami -- You can't bring a good wave down!
    4. Re:Yeah, what he said.... by Jhon · · Score: 4, Insightful

      Morale.


      And how would their morale hold up when their employer is either shut down, fined in to oblivian or loses their ability to bill medical or some critical private insurance (essentially, you go out of business) for not providing necessary safegards for indentity/medical history? I don't think that their morale will be that high when they get their last check...

      A radio is fine. A tape deck. Even a CD player. Hell... even an MP3 player is fine so long as it's not hooked up (and unable to hook up) to a workstation.
    5. Re:Yeah, what he said.... by Theaetetus · · Score: 3, Insightful

      And how would their morale hold up when their employer is either shut down, fined in to oblivian or loses their ability to bill medical or some critical private insurance (essentially, you go out of business) for not providing necessary safegards for indentity/medical history? I don't think that their morale will be that high when they get their last check...

      Why is data so unsecured that the receptionist who plugs in her iPod can somehow get access to identity/medical histories? That's not the fault of the iPod or the receptionist.

    6. Re:Yeah, what he said.... by ElleyKitten · · Score: 2, Insightful

      Why is data so unsecured that the receptionist who plugs in her iPod can somehow get access to identity/medical histories? That's not the fault of the iPod or the receptionist.
      An iPod could have a virus/keylogger/spyware/whatever, and whatever information the receptionist (or data entry minion, or whoever has an iPod) works with as a part of her job can then be comprimised. It's not that she'd suddenly gain access to things she shouldn't, but that things that she does have and need access to need to be secured.
      --
      "What is Internet Explorer 7? Are you saying we can't access the normal internet?" - I love tech support. Really.
    7. Re:Yeah, what he said.... by yuna49 · · Score: 4, Informative

      One of my clients is a community health center. We're looking into the Linux Terminal Server Project http://www.ltsp.org/ for precisely the reason that meeting HIPAA requirements for privacy and security is nearly impossible unless we can centrally control what's running on the workstations. In the next hardware tranche we're looking to go diskless with no CD writers and no USB support for mass-storage devices.

      Having only one, centrally managed, desktop image has a lot of appeal as well!

    8. Re:Yeah, what he said.... by dankney · · Score: 4, Insightful

      A good net admin is flexibile. If there's a good reason for it, any rule can be bent. I'm going to treat you like an adult and explain why your actions are potentially risky and are against policy -- I'll ask you to work with me to find a less risky way to accomplish the same goals.

      If you're doing network experimentation for a legitimate reason (work-related, not just being a dick), it's easy enough for me to vlan you off from the rest of the network. I'll even give you a gateway to the internet if you need it, but you'd better believe that your gateway is going to null route anything that's attempting to hit my servers or your co-worker's machines. My job may be to enable your research, but it's also my job to protect everyone else's data and productivity from your experiments should they go wildly wrong.

      I'll make sure you can do your work, but you may not be able to go about it in the way that you originally wanted to; my flexibility must be matched by yours. If you crash your own machine in the process, that's a risk you chose to take. I just have to make sure that everyone else on the network has the same choice and isn't subjected to yours.

    9. Re:Yeah, what he said.... by Jhon · · Score: 3, Informative

      Print Screen -> jpg -> IPOD HD.

      Cut/Paste from APP -> text File -> IPOD HD.

      Scan

      You've obviously never worked with state/federal payors who are cracking down on fraud. Not only from the entity making the claim for service, but forcing the entity making the claim to police their own CLIENTS for fraud. There are volumes of various types of regulations and procedures that CAP/CLIA/Medi require and we are regularly inspected for compliance.

      Sucks to be in IT in the medical field sometimes.

    10. Re:Yeah, what he said.... by corbettw · · Score: 2, Funny

      Why is data so unsecured that the receptionist who plugs in her iPod can somehow get access to identity/medical histories?

      Because it's an important plot device so the hero can save his family. Duh.

      --
      God invented whiskey so the Irish would not rule the world.
    11. Re:Yeah, what he said.... by SatanicPuppy · · Score: 4, Insightful

      It's always the sales guys. I actually saw a group of them complain so hard that they succeeded in getting access to streaming media sites, at a time when our bandwidth was just about at capacity. It started to affect the rest of the building, so we throttled their subnet.

      You've never heard so much screaming and whining. Goes all the way up to the top. CEO gets involved, wants to know the problem. We explain the problem, which was reasonably unsolvable at that point (no money for bigger pipe).

      Then we provided the logs. We were pretty pissed off, so we provided all the logs.

      Result? 3 people fired for what we'd consider "real" violations, and 11 people given warnings about the proper use of work equipment.

      To this day, we have the most viruses, the most spyware, and the most user-caused problems from that department. The people who work there are not tech savvy, they are not problem solvers. But each and every one of them believes that their position is by far the most important position in the company, above and beyond the people who actually produce the product.

      Now I understand that you want a certain type of person for sales, and I understand that by and large, the kind of person who works in sales needs to have certain character traits to be a good salesperson, and that that sort of person isn't usually over-supplied with introspection.

      But take this to heart: IT is there to keep things working. IT is there to introduce, after a period of testing, new software. IT is there to protect company data from malicious outsiders...and malicious insiders, and to maintain critical systems, and to fix technical problems.

      The purpose of IT is not to do whatever you want them to do; they have to take care of the whole organization, and the needs of the organization as a whole come first. It's not to bend the security guidelines for every program that one person thinks he needs. It's sure as hell not to mindlessly support every whim of every middle manager who is desperate for his department to have something to blame for his failure to meet sales goals.

      Some users we trust with elevated permissions. Some users we allow to install their own software. It may even be as high as 8 or 9 percent of our user base. Percentage in finance, for example, is like 60%. The percentage in the advertising department? Maybe 1 in 100. They are non-technical users who have a poor appreciation of security risks, and are incapable of not clicking on a pop-up if one pops up in front of them.

      --
      ad logicam Claiming a proposition is false because it was presented as the conclusion of a fallacious argument.
    12. Re:Yeah, what he said.... by Anonymous Coward · · Score: 2, Insightful

      "Print Screen -> jpg -> IPOD HD.

      Cut/Paste from APP -> text File -> IPOD HD.

      Scan"

      Pen -> paper -> pocket

      Pencil -> post-it note -> pocket

      Information that is valuable enough to protect should be valuable enough to teach employees at all levels how to protect.

      How about the IT guys start teaching safety instead of just bitching about how little the employees know about it.

    13. Re:Yeah, what he said.... by jp10558 · · Score: 3, Insightful

      I'm sorry, but making users responsible for their own machines is a nightmare in a largeish orginzation. How do you track patches? Licensing? Do you send them to the Geek Squad when some random conflict between the 500 freeware programs, 3 improperly licensed programs, 3 work programs, 5 OSS programs, 2 pirated programs and 1000 spyware traces comes up? Do you just reformat and reinstall? How long does that take you?

      And how the hell do you roll out new software packages? Cause you have no idea what state the individual machine is in, I'm guessing you don't have a mass deployment tool, so do you put it on a file share and say go for it in an e-mail?

      --
      Opera, Proxomitron-Grypen,GPG 0x0A1C6EE3
    14. Re:Yeah, what he said.... by RESPAWN · · Score: 2, Insightful

      I was going to compose my own post, but you pretty much summed up what I was going to state. Most of these people posting here have probably never worked in the Healthcare IT industry. With the HIPPA laws (or is it HIPAA? I forget.) there are extremely stringent guidelines describing what will happen to a company if they mistakenly allow data to be released without authorization. Merely not being in compliance with the regulations (and there are many, including a stipulation regarding removable media) can bring reprecussions for a company.

      I think the problem with /. is that a lot of people here are obviously smart, computer-centric, people and naturally chafe at the idea of having restrictions imposed on their use of technology. Additionally, these people can probably be trusted not to mistakenly introduce a vulnerability to their company's network. But if you spend enough time in IT -- especially in an environment populated with high school educated people with little computer experience (such as a healthcare billing office), many /.'ers will gain a newfound respect for why IT occasionally has to institute many of its policies.

      --

      If Murphy's Law can go wrong, it will.

    15. Re:Yeah, what he said.... by MobyDisk · · Score: 5, Insightful
      Everyone clap. You just met the IT guy you have all been loathing, and he posts on Slashdot. Thank you, take a bow.

      What need does a biller have in hooking up their IPOD to their work PC? Why would a clientservices-phone jockey need to hook up their USB memory stick? Because if you whitelist sites, then when the boss says "go to site XXX and tell me this..." they can't. And when the HR department says "go to www.friendlyHRpeople.com" to file a complaint they can't do it. But if you blacklist sites, then they can get to what they want anyway using some workaround. slashdot.com is blocked but engaget.com isn't. Or you can see it through someones blog, or redirection, or RSS feed, or a cache, or an anonymizer. This is a battle nobody can win.

      This is the type of attitude that gets us into the game of "If I rename the extension to .rar then I can send you this critical document you've been needing!" Then .rar files are blocked the next day. Then you zip the rar and it gets through again. The war escalates forever. Perhaps each employee should make a formal request to their boss, then to the IT department, then write a formal justification for why you need to visit each web site.

      Of course, it is probably all moot because you had to give everyone local administrator priviledges so they could run the ActiveX time-sheet application your IT department mandated.

      This is the mysterious "IT guy" who thinks he knows the fixed-length list of things that each and every person in the company needs to do their job. They create a blacklist of everything they think you could do on your computer that is bad, and use some 3rd-party product to scan everything you do and disable those actions. They already know better than you every tool needed for every position in the company. Really, this person could just do your job.

      I've had users ask me for permission to install some "app" they like to use. The simple answer is "no" and I don't want to waste my breath re-hashing the same reasons. Yes, you surely know every app they are going to need and have pre-installed it for them. And every application you haven't heard of is probably a virus. Of course, if you had setup their permissions properly then they couldn't install applications anyway. Instead of policing each application, set appropriate domain policies and work policies that make sense. Limit the size of email attachments. Put quotes on their accounts. Make sure the network drives have appropriate permissions.

      Trying to monitor every application used on every PC is a modern version of micro-management. Do you look at every tool that is on someone's desk? Do you approve each stapler? If you don't let people visit web sites, can they bring in books and newspapers? Do you blacklist/whitelist the phone numbers they can call and receive calls from?

      So I say "No. Check your employee handbook, page 12 for why" and walk away. Then you are a jerk.

      This will probably get modded as a troll. But I bet every person with mod points on this system has had to deal with the likes of you. I'm glad I got to find you and finally say it.
    16. Re:Yeah, what he said.... by gmack · · Score: 4, Insightful

      The problem most of the time isn't theft. The problem is users who THINK they know what they are doing but really don't. I have worked in several offices where everyone felt they could do whatever they felt like to their own computers and only called the admin when they were at a loss of how to fix it.

      Some noteable moments:
      • The user who decided he needed a better sound card so he switched his with a "less important" user. I get called in when both machines have screwed up drivers
      • The user who thought that his department should have his own file server but then didn't secure it properly. They had to shut the server down to block the resulting viral infection that took out half the office.
      • The constant complaints that our 10 meg fiber internet connection feeding an office of 30 people just wasn't fast enough thanks to some user thinking (s)he closed his/her file sharing app but only backgrounded it.
      • The screaming panicked call from my boss telling me our website was hacked because our web page now contained links to other websites.. Turned out the machine he was viewing it on had adware installed that came with his favorite file sharing service.
      • Why is our traffic so high and why are we getting spam complaints? Traced to a user with a non secured wireless gateway being hijacked by some spammer.
      • Spotty network connectivity traced by another admin to a wireless gateway plugged in BACKWARDS and was feeding DHCP packets onto the network that provided a network connection to nowhere.

      Show me a way in advance to know what users can be trusted and I'll consider letting users have more control. Until then I'll demand that users don't' mess with anything for no other reason that I end up with more work every time they mess up.

    17. Re:Yeah, what he said.... by mikkelm · · Score: 2, Interesting

      "Now, you'll have to set a new password once a month. You *cannot* write it down for security reasons, so make sure it's something you remember."

      Walk through the offices four months later, flip the keyboards, and you'll find post-it notes with the last four passwords they've used placed underneath. Typically "1, 2, , 4." Teaching doesn't work.

      Relying on unreliable things for security is a Bad Thing, and the user is always the most unreliable part of any security system.

    18. Re:Yeah, what he said.... by Jhon · · Score: 3, Funny

      Walk through the offices four months later, flip the keyboards, and you'll find post-it notes with the last four passwords they've used placed underneath. Typically "1, 2, , 4." Teaching doesn't work
      Funny story:

      During a routine maintenance job (clean workstations/mice/keyboards), one of my guys found a post-it under a plebs keyboard. It read: "Do you think I'm foolish enough to keep my password here? HAH! I use my birth date so I don't have to!"

      I found the note hillarious. It was a HS kid working as a data entry drone. Now she works for me while going to college earning twice as much.
    19. Re:Yeah, what he said.... by element-o.p. · · Score: 2, Interesting

      Where I work, our official policy is that the computers are for work purposes, and unauthorized software is verboten. Our unofficial policy, however, is that if you don't cause the IT department more work and if you aren't causing a problem, then we (IT) don't really care...within reason. But, if something you installed hoses the network, or if you are sucking up so much bandwidth that it becomes a problem, then expect the IT manager to pay your manager a visit.

      It's basically a tacit acknowledgment that it's impossible (or at least, not cost-effective) to micro-manage every users' use of their work computers. We won't get too uptight if you bend the rules a little, once in a while. But if you cause problems because you are goofing off at work, the rules are in place to allow IT, through management, to take action to keep the company productive.

      --
      MCSE? No, sir...I don't do Windows. Yes, I am an idealist. What's your point?
    20. Re:Yeah, what he said.... by don_bear_wilkinson · · Score: 2, Insightful

      It's not the IT department's job to teach [safety] security. That should come as a series of internal policies and training from HR and other departments - after the policy comes from 'on high'.

      IT bitches because most companies have a huge lack of understanding on all sides, next to zero real policy direction from the top (IT is not at the Board table), and thus are left to clean up the mess. With too little money, too few staff and no way to prevent the problem without making enemies. Of people like you.

      --
      In Nature, stupidity is a capital offense. In human society, too many get off with less than a warning.
    21. Re:Yeah, what he said.... by dave562 · · Score: 2
      The problem most of the time isn't theft. The problem is users who THINK they know what they are doing but really don't.

      I agree completely. The term that I've heard for it is, "Knowing just enough to be dangerous." It is especially prevalent in the Windows world where everything is so "easy" and "simple". There are those users who want to do it all themselves and they think they are the best thing since sliced bread, but as soon as their house of cards comes crashing down around them, it's "All IT's fault because..."

    22. Re:Yeah, what he said.... by markov_chain · · Score: 3, Informative

      It would be much easier to use a digital camera.

      --
      Tsunami -- You can't bring a good wave down!
    23. Re:Yeah, what he said.... by RMH101 · · Score: 3, Funny
      Add to this the tool who brought in an apple airport and hooked it up to the corporate network without any wireless security, so that he could sit by the window. I'd have given him a longer patch cable, if he'd asked.

      Also add to this the other tool who plugged in another WAP with the internal DHCP server turned on and serving addresses in the same address range as his office network.

      A little knowledge is a dangerous thing? Just look what a *lot* of it can do...

  2. My personal nemesis... by NerveGas · · Score: 5, Insightful


        Has always been the user who *thinks* he knows too much, and is out to prove it - usually causing problems, havoc, and destruction in so doing. You know, the kind of guy who gets pissed when you won't give them root/Administrator priveliges because he thinks he's a real big-shot. I've heard arguments as silly as "Well, I'm learning Linux on my own at home, so sooner or later, I'm going to know how to use it whether you give me root or not." Yeah, good for you.

        It seems that every company I've worked for has had one. Maybe it's a small part of my personal castigation for the things I've done wrong. Who can say...

    --
    Oh, you're not stuck, you're just unable to let go of the onion rings.
    1. Re:My personal nemesis... by russ1337 · · Score: 4, Interesting

      For a moment I thought you were talking about me....

      But seriously. My IT department guys were kind enough to give me admin privileges on my workstation and on my colleagues workstations in my department. I didn't ask for it, but they obviously trust me to some extent and i've built that trust over time. I'm not a sysadmin and have never been one.

      It could have something to do with the fact I'm overseeing a highly technical project involving setup of IT systems of sorts. This leads me to the same problem the article mentions. Our system must stay isolated from the world - physically and connectively (no inter-tubes for you!). The problem is its users 'think' they know better and think its ok to put in a CD, or plug in a USB drive to play MP3's or whatever because they can at home. (I don't think I need to tell /.'ers of the dangers of CD's after the Sony rootkit debacle). Of course we've removed all accessible means in - CDROMS/USB slots etc... and have some very harsh rules. But still, it's only a matter of time before I walk in and find some guy with his mp3 player hanging from a machine, or installing something unauthorized... because they thought they knew better.

    2. Re:My personal nemesis... by 0100010001010011 · · Score: 5, Insightful

      My personal nemesis is the layers of abstraction you have from someone that actually knows something and the mentality of those people.

      My laptop at work continuously reboots. I ran a memtest on it and narrowed it down to a bad memory chip. IT wants me to send in my laptop. I'm sorry. I don't have time to deal with that down time, so I just put up with it restarting.

      The most annoying one is when they redid a few dozen internal webservers. All of a sudden the redirect didn't work (If you went to an internal site and it had been X minutes it redirected you to Corporate Web Login).

      I did some research on my own and found that when they upgraded to the newest webserver someone forgot to bring along the configuration. All the redirect websites were being sent out as plain/text. Firefox correctly rendered it as... plain text. When I e-mailed IT about it I got a nice form letter about "Firefox isn't supported, we use IE, etc".

      I then copy and pasted curl -v logs of all the websites that were broken. I didn't just tell them what was broken, I told them HOW to fix it. I never got a reply back and everything magically worked within a week.

      Sometimes there ARE users out there who know what we're talking about. I'm not asking for admin rights or root access. But I do want to be able to do my job and when your fuckups impede that, it does tick me off. The IT people I know are the ones that seem to have the hardest time saying the two 3 word phrases that every engineer (in my opinion) must learn before leaving college: "I don't know." and "I was wrong."

      In the mean time I wrote a greasemonkey script that when it saw the redirect page it sent me to the correct website.

    3. Re:My personal nemesis... by jcgf · · Score: 2, Insightful

      Sometimes there ARE users out there who know what we're talking about.

      Maybe there are users like you, but for every one of them there are ten that think they're like you.

    4. Re:My personal nemesis... by Stamen · · Score: 3, Insightful

      I agree 100%, I don't understand this slave mentality we have these days. Employers treat their employees like children and, of course, people live up to expectations and act like children.

      My rules for employees are simple, do your job well, or I will fire you. The rest I don't care about. I'm not paying to have a pet around that only does what I say while attached to a leash. I'm hiring someone to do a job, a job they are agreeing to do.

      Employees are just vendors that are permanent (for a period of time) and exclusive. But they are vendors, vendors of work. If I don't like the work, I'll replace them with another vendor if a better one exists.

      This is how a free market works, it's sad that this basic concept of American life left so long ago. In 1900 most people owned their own business and had a stake in the community. Now-a-days, we are just a number of micro-communist-nations, I.E, large corporations. I just don't get it.

      If the management doesn't know if employees are doing their jobs then I'd find new managers.

      Unless you have special needs, like government mandated privacy laws, such as medical databases, what does it matter if employees spend all day on IM or EBay or Gmail. If they aren't doing their job, fire them, if they are, then let them continue; how they choose to do their job is up to them, they aren't children or pets.

      Oh, how did we get along for 100s of years without employers monitoring everything an employee does. The founding fathers and mothers wouldn't be happy with how we turned out, we became what they fought so hard against.

      Wow, I feel better now, thanks for listening.

  3. IT title does not an expert make by yagu · · Score: 5, Insightful

    I've met uncountable numbers of idiots when it comes to understanding technology. Guess what... many of them were peers in IT. In retrospect, it makes sense. I'd anticipated my move from college to a "real" job as a release from the world of idiots in the CS curricula. Finally, I'd get a chance to work shoulder to shoulder with people who knew.

    Not so much.

    I'd never considered where the rest of my university peers had to go -- into the same work force I entered -- duh.

    In the non-IT universe I discovered many were also clueless around technology, as I'd expected. What I hadn't expected was there were many non-IT people who got it, who understood technology, and worked with it adeptly. Many "got it" more than my peers. Some of the most profound ideas and innovation I've seen in IT have come from nontraditional non-IT people.

    I agree (without reading the entire article) with the summary and gist of the article -- IT does itself no favors ruling by fiat and instead should collaborate with users.

    This doesn't dismiss bad things happening and messes created by users left behind for IT to clean up. People who mess up should help clean up, but my experience has been many IT people are equally inept and likely to make messes.

    A degree and title in IT and CS means only that one has a degree in IT and CS, nothing more. It doesn't mean they're anointed and it doesn't mean they know more about technology than users.

    1. Re:IT title does not an expert make by fitten · · Score: 2, Interesting

      Yup. Back when I was entering college, it was... interesting (back in the 80s). That was when programming was starting to be seen as a viable job opportunity and many people were signing up for CS simply because of the opportunities that were thought to go along with it. I met a number of people in my first CS classes that had only seen computers on TV and maybe in stores. I met a few that had never even seen them in real life (only on TV). Most of those folks bailed out early but some stuck to it because of the expectations of the pots-o-gold that would be showered on you once you got your degree.

      This was mind-boggling to me as, even at that time, my friends and I had been learning about computers on our own for a number of years (yes, we were the ones in highschool who were 'assistants' to the teacher in computer classes... mostly because our teacher was smart enough to know that we probably knew more than he did so he asked for our help rather than try to prove that he knew more than we did).

      This carried over into work where many of the people who were actual programmers at the time were amazed at this group of people coming in who actually had computers at home and actually did things with them at home. Seeing us basically live-and-breathe computers frightened them because we kept up with (and devoured) any and all tech releases, both hardware and software, because we *love* it, not because we were required to do so for our job. For us, computers were a huge part of our life because we enjoyed them, not because we had to work with them. I know of several of those programmers who actually left the field to go do other things (or simply retire) because they were afraid they couldn't compete with us (more than one actually told me this personally).

      The trend of people thinking themselves computer experts because they could send/receive email and surf the web has only increased as computers became more popular and more and more people had contact with them. Heck, these days, I've seen people who have problems sending email try to diagnose and 'fix' computer problems for others who know even less than they do.

      It's actually fairly interesting... as OSs get more and more stable and more like set-top boxes, the more users will become strictly users (and rightly so) and less prone to doing more than installing software or maybe something as complicated as a new DVD, HDD, or more RAM. This means that less people will really be able to dig around inside a box and figure out what's wrong but it also means there *should* be less reason to do so (barring a hardware failure, they shouldn't have to do more than install/remove software and maybe click a button to allow OS updates to happen). I can easily see IT getting more hardware oriented and less software oriented over time because of this.

    2. Re:IT title does not an expert make by PitaBred · · Score: 2, Insightful

      I think that CS people should get more experience in IT. I've seen so many people with CS degrees just toss all kinds of stuff on the stack and not know why it slows down, they don't understand the connection between the software and the hardware resources. But that's completely off-topic :)

  4. dont think so... by justice7 · · Score: 2, Funny

    It takes a lot more than "I know how to build a computer .. and i play WOW all the time so i'm leet" to run an IT department. I welcome the smarter users; as long as they arent all wearing my tinfoil hat.

  5. Scare them! It's fun! by extremescholar · · Score: 2, Funny

    I don't work in the IT dept at my current employer, but I spent a number of years in the trenches before working here. Just today, I was causing fear, loathing, angst, and gnashing of teeth to one of our local IT folk. I told a young lady that I was going to ghost the hard drive from a little used computer onto a USB stick. Then take the hard drive and add it to my PC since I needed more space for my music collection. She was very nervous and thought I might actually do it. I was just giving her crap, but then again; if I need space I might...

    --
    Using the Freedom of Speech while I still have it.
  6. All in one page by Hokie06 · · Score: 2, Informative
    --
    Kilroy was here.
  7. IT Isn't Master of All by Anonymous Coward · · Score: 5, Funny

    I'm sick and tired of IT departments that try to control everything I do when I know perfectly well that WeatherBug and WinFixer are the right tools for the job. I am a smart and knowledgeable IT consumer, and I've been using these fine products at home for some time now. Why not at work too?

  8. I experience this every day... by doormat · · Score: 4, Interesting

    As a software developer outside of the IT department (I'm under direction of the Engineering group), I get this all the time. I get the run around, exclusion from important meetings, no say in things I have a large stake in, put at the bottom of the priority queue, and sometimes even people working to throw roadblocks in my way.

    I've always been a fan of decentralized IT - a core group working to "keep the lights on" and seperate groups providing services embedded in the groups they're providing services to, responsible to the managers of the groups who use the tools. Meetings still happen with the needed staff, but someone is a few cubes down the hall or at least on the same floor to answer questions and get feedback.

    --
    The Doormat

    If you're not outraged, then you're not paying attention.
  9. And why not? by Realistic_Dragon · · Score: 5, Interesting

    I would be 7 kinds of mad if anyone was using gmail and IM in my office.

    We work with NATO restricted data. *Everything* requires appropriate handling. E-mail is carefully fenced and the IM service is encrypted.

    But even if you aren't a company with such a strong need for data protection... well actually there is no such thing. At the very least you have financial data and client information on your systems. Losing some of that stuff is considerably more harmful than restricting people to company provided communication tools.

    Anyone placing data that hasn't been cleared for release (even by the very informal process of being sent out on purpose) onto services run by people with whom you have no contract and no reasonable expectation of integrity is, frankly, no better than the idiots who don't back up their data and are then surprised to find out that MTBF is not a guarantee. After all if your employees are using gmail et al you don't even know what data you *have* let alone what steps you need to take to protect it.

    --
    Beep beep.
  10. Most users are experts at being idiots by Fatchap · · Score: 2, Insightful
    Quote from the article:

    According to Pew, 42 percent of Internet users download programs, 37 percent use instant messaging, 27 percent have used the Internet to share files, and 25 percent access the Internet through a wireless device. (And these numbers are all one or two years old. Rainie "would bet the ranch" that the current numbers are higher.) Quote from Vin Cerf:

    ...approximately 600 million computers are connected to the Internet, and that 150 million of them might be participants in a botnet--nearly all of them unwilling victims. (http://arstechnica.com/news.ars/post/20070125-870 7.html) Yep as a CIO / CSO I would really be an idiot not to let my users do exactly what they do at home would n't I!!

    The simple fact is most users think they know what they are doing, but the lack the skills to adequately assess the risks of their actions. That is why they need to have rules around acceptable use and security policies to protect them from their own idiocy.
    --
    The only reason some people get lost in thought is because it's unfamiliar territory.
    1. Re:Most users are experts at being idiots by 99BottlesOfBeerInMyF · · Score: 2, Interesting

      The simple fact is most users think they know what they are doing, but the lack the skills to adequately assess the risks of their actions. That is why they need to have rules around acceptable use and security policies to protect them from their own idiocy.

      Where I work is probably not representative of the industry as a whole, but IT and their policies result in less security and functionality than letting the users run amok. We started out as an engineering organization, a start up. Think a couple of network engineering experts and a few security guys. Add in a hundred more coders and 100 more business people (selling security tools). The engineering half of the organization goes out of our way to bypass IT as much as possible because they were hired by business majors with no clue. They implement things like an exchange server, Windows desktops, and an intranet Web portal that cost a fortune but only works in IE (engineering desktops run OS X, Linux, or a BSD). We actually (with no official IT on our side) maintain our own mail and IM and Web and fileservers.

      Now if this were an isolated case I might be willing to say, yeah that never happens, but this is about the 3rd place I've worked where IT was a bunch of clueless people that knew how to set up Windows servers and basically nothing else. Within the security industry, IT is often the weakest link.

      Note, some IT people are versatile and brilliant hackers that can put together a secure server from spare parts and OSS and fix my weird networking issues. Hail to them! Would that they were the norm in my experience.

    2. Re:Most users are experts at being idiots by vux984 · · Score: 2

      The simple fact is most users think they know what they are doing, but the lack the skills to adequately assess the risks of their actions. That is why they need to have rules around acceptable use and security policies to protect them from their own idiocy.

      Its worse than that. Its not that they can't assess risks, its that they aren't even aware of what is at stake. Nor do they understand the priorities of corporate IT in terms of cost and maintainability.

      Examples:

      We frequently rotate units and staff around. If there's "extra" software on a unit it that shouldn't be there, it has to be cleaned up. (And that takes time and costs money.) Its not that we don't want you to know the weather in tokyo, its that its not required, and it ultimately costs money. (Sure that's just a ghost image, plus updates, plus anything else that has been changed since the image was last updated... but on an 'unabused' machine we don't have to do even that. IT rightly tends to prioritize maintainability over frivolous functionality.

      Another one would be a user who downloads software that is "shareware", or "free for personal use" because he likes it at home. Well, guess what, "free for personal use" does NOT usually mean its free to use in a commercial environment, and "shareware" isn't free at all beyond its trial period. Just because you can get away without paying and the software will still work doesn't mean its ok. WinZip is a classic example. There's a reason why IT is only using XP's built in compressed folder support, or 7-zip.

      Another one would be one of those 'massive computing screen savers'; running the cpu at 100% all night instead of 'standby' x 100 PCs makes a substantial difference to the electrical bill. Its not that we think computing merseinne primes is somehow a security risk, but it costs a fair chunk of money, and potentially shortens the pc lifespan too. Do it at home if you like.

      And gmail? You are provided a corporate email address for corporate email. If you want to check your personal mail, have it forwarded to your personal cellphone, and check it on your lunch break. There is no need or reason for it to be on your office desktop.

    3. Re:Most users are experts at being idiots by 99BottlesOfBeerInMyF · · Score: 2, Interesting

      You sound like you have an IT department that is run by the muppets (wrong 1)

      From what I've seen, this is about 85% of IT departments, who think Windows is all there is and wouldn't know real security if it bit them.

      Your team then go and implement IT solutions that are outside of your mandate and that do not follow corporate standards or processes (wrong 2)

      It's not so much that we go outside our mandate, we just keep using resources that were set up before we had an IT department because they work, unlike the servers set up by IT. We go through normal channels to purchase new servers and the like, the problem (or benefit) is when they need fixing we don't call IT, we see who is on IRC that happens to have an admin account on that server (usually whoever set it up and one or two other people).

      Have you and your guys introduced more risk to the business because of your actions?

      I'm not sure this is true. Does keeping a lot of engineering data only on our internal, well protected apache hosted wiki reachable only via a VPN tunnel mean the company has more or less risk than if we all used IE to connect to some god-awful active X filled publicly reachable Web portal?

      Possibly, however I doubt you can substantiate that without being part of a corporate risk assessment, which you cann't do when flying below the radar.

      I'm not sure much flies "beneath the radar." We sell really expensive network intrusion detection and prevention applications and we run them internally and everyone has an account. The last time a virus got into our network everyone got an e-mail notification it had been detected and isolated and we made fun of the sales engineer for a week. The last time I had a poorly configured e-mail account that was trying both encrypted and plaintext communication with a server, I got an e-mail about it within hours of my client "upgrade."

      Still if I was CIO / CSO I would fire your asses! :-)

      Firing the guys that make all the money would be pretty interesting, but it would not be the first time I was at a company where all the people that made our products were let go, while management stayed on for a while. The real point I was trying to make is a lot of IT people are "muppets" in your terminology while a lot of engineers are not. If IT is in conflict with users, that does not necessarily mean IT is doing the right thing and often it means they are doing the wrong thing and need to be fixed/fired/replaced/castigated/or something.

  11. Re:I don't see a problem by smooth+wombat · · Score: 5, Insightful
    IT lost this fight when the USB memory stick became popular.


    Lock down usb ports.

    Besides, no matter what they do, they can't stop me from creating a knoppix cluster from my coworkers pc's after they all leave for the day.

    They can fire you.

    See, not so hard.

    --
    We will bankrupt ourselves in the vain search for absolute security. -- Dwight D. Eisenhower
  12. The day this is a reality by Oriumpor · · Score: 4, Funny

    Is the day hundreds of callcenters close down their Level 1 support. I always thought it funny to have columns and rows of people that do nothing but open the documentation the users have and read it to them over the phone. Since the phones are still ringing, I think this announcement is still quite a bit premature.

  13. "Idiots" data that hasn't been cleared for release by Cr0w+T.+Trollbot · · Score: 3, Insightful

    Anyone placing data that hasn't been cleared for release (even by the very informal process of being sent out on purpose) onto services run by people with whom you have no contract and no reasonable expectation of integrity is, frankly, no better than the idiots who don't back up their data and are then surprised to find out that MTBF is not a guarantee.

    Be sure to let Jimbo Wales know he's an idiot for doing it that way.

    I'm not advocating Wiki methods for a nuclear missle silo, but I think a lot more companies can profit from a Wiki-type approach to (some) data than those that can beneift from an NSA "everything is top secret and must be locked down at all costs" approach.

    Crow T. Trollbot

  14. Re:IT dept's delay work. by aquatone282 · · Score: 5, Funny

    It makes you wonder if they spend more time reading my email and slashdot posts than actual IT work.

    Reading your email and your slashdot posts IS our actual work.

    Signed,

    Your IT Department

    P.S. You're fired.

    --
    What?
  15. Re:I'm one of those rogue users... by methangel · · Score: 2, Funny

    This is your network admin, please come to my office. I have something to discuss with you.

  16. Sometimes it "has to fit" by winkydink · · Score: 4, Informative

    whether you like it or not.

    In the US, Sarbanes-Oxley places some strict requirements on data retention for publicly-traded companies. Employees choosing to use IM and gmail, could cause those requirements to be circumvented.

    --

    "I'd rather be a lightning rod than a seismometer." -Ken Kesey

    1. Re:Sometimes it "has to fit" by LurkerXXX · · Score: 4, Informative

      This is why the clever IT guy who doesn't want to get blamed for limiting user, as in the blurb, should bring in the corporate lawyers to lay down the law. This way it isn't the good IT director who wants to supply any needed technology, but the lawyer cracking down on things that could get the company in hot soup.

    2. Re:Sometimes it "has to fit" by Chazmyrr · · Score: 2, Informative

      It's a legal requirement, not a security requirement. If a company falls under SOX and they allow their employees to communicate electronically at work without recording and storing those communications, the company is breaking the law.

      It's a whole lot easier and less expensive to just block access to external email or IM than it is to monitor and record them.

  17. For every rule, there are exceptions by bhmit1 · · Score: 5, Interesting

    I've been a user that is locked into crazy setups. The traveling consultant at client sites who's PC is setup to be managed from the corporate network. At one point, I got tired of the insanity, took a ghost image of the machine they gave me, and installed linux on the machine (and then restored the ghost image in a vmware session).

    But here's the thing, I don't ask for support from the IT department because I'm the odd guy. I know they can't support me. What annoys me (as the one who helps other IT departments manage lots of PC's) are the people that install various applications that cause our automated installs to fail. 90% of the machines are managed with little to no effort. It's the 10% that cause days of work while we try to figure out which of the 20 apps you installed is breaking our install tool.

    And for all those against IM and email lockdown, I've been to trading companies where that's the law. They get in trouble when they don't have logs of what people said on IM, email, phone calls, etc because that's how they catch insider trading. Of course for every sensible rule, I've seen 10 that make no sense at all. As has been said before, the USB key should force companies to reevaluate their policies.

  18. Interesting article... by Psmylie · · Score: 2, Informative
    But wrong on a few counts. There are so many reasons to keep things locked down. Data security is the main one. There is also support issues, regulatory issues, etc. For example... traders don't get to use IM where I work. Know why? Because the SEC wants to be able to pull records of all financial instructions, and our traders wanted to send trade instructions to each other via IM. We had no way at that time to record IM's, and no way to confirm that an IM was actually read by the person it was sent to in a timely manner.

    This is kind of interesting, from the article:

    "When you find that people have broken rules, the best thing to do is try to figure out why and to learn from it."

    Sorry, no. When you find out that people have broken the rules, you write them up or you fire them, depending on the severity of the situation. What if the rule that was broken was someone carting around an unencrypted "backup" of a customer database on a thumbdrive, which he lost? Where I work, that's three major rules broken right there. If that happened, that person would be fired immediately.

    Corporations aren't stupid. Hidebound, maybe, and slow to change, but if something is forbidden, there is usually a really good reason for it. Also, IT does not run the company, in most cases. Follow the chain of command up high enough, and you'll find IT's bosses. If you have a tool that you need or want, then petition for change. Don't do an end-run around the guys that are trying to keep you working, you're only going to hamstring yourself in the end.

    The major problem is, people are making their decisions based on commercials or salesmen that promise an easy, 100% reliable solution to an existing problem. Then they run to IT to complain when the product doesn't perform the way it was supposed to. This makes extra work for an IT department that is probably already overworked. You want to play with toys, play with them on your own gear, not the corporate gear.

    That said, a wise CIO is going to pay attention to what the employees say they need to find out:

    a): If they really need it

    b): If there isn't something better or already in-house that can fill that need

    c): Is it safe to use, and what are the support requirements.

    The important thing then is to tell the end user, No, you can't have that because of: ___, and give them an actual reason, instead of just telling them "against policy"

    --

    psmylie's dictionary: Godzillion (noun) Any number large enough to destroy Tokyo

  19. The power user vs the not so power user by onkelonkel · · Score: 5, Insightful

    1. "My hard drive is howling like a panther passing a kidney stone. Every time I run chkdsk I lose a few more sectors. I've backed up all my work to the network drive. When you get a chance can you come and fix my computer?"

    2. "My computer won't start. It's been making this squealy noise for about two weeks and then all of a sudden it just died. You have to come right now and fix it because all the annual budget files are on my desktop."

    Which call would you rather get?

    --
    None of them can see the clouds; The polished wings don't care.
    1. Re:The power user vs the not so power user by garcia · · Score: 4, Interesting

      I'm a fairly knowledgeable computer user with 10 years of Linux experience on top of the standard Windows use since 3.1. When I have an IT problem I play stupid, real stupid. You know why? Because the second they think that I'm self diagnosing a problem it becomes priority 0.

      When I called up to tell them that my co-workers computer was denying Groupwise proxy rights via a VBA Access module for a single proxy account and not any others, they ignored me for *four weeks*.

      When I call up and say, "my computer doesn't work" they show up in minutes and do whatever it is that they need to do.

    2. Re:The power user vs the not so power user by Heisman · · Score: 5, Funny

      Well, since user #1 is probably a typical /.er, and user #2 is probably the long leggy blond girl from accounting/payroll. I'm going to go hang out under #2's desk for a while. I'll see you guys later.

  20. But for the I-D-Ten-T by ShaggyIan · · Score: 2, Insightful

    Yes, most corporate users surf the web at home.

    Yes, most of their home machines are horribly infected with spyware, viruses, and other things I grow weary of cleaning up. I have friends who make their livings cleaning up home PC's. Most of them have "regulars".

    I have no problem helping my advanced, capable users be more productive through technology. I will even grant local admin when warranted.

    I have major problems letting my users chat with their friends on IM while surfing porn, watching last nights CSI on YouTube, and unwittingly sending out spam on behalf of a botnet (while trying to infect the rest of the network). Whenever we (and by we I mean management) loosen the reigns, this is what I find all over my network.

    Giving your users admin/root (i.e. ticket to ride) trying to make your life (or their life) easier only tends to make both of your lives harder later on.

    Top down corporate stragedy types really don't need to be worrying so much about individual users. Good IT staff with sufficient decision making authority renders this entire "concern" moot.

    --

    This sig was generated randomly by one million monkeys with Speak 'n Spells. . .
  21. Why fear when you can enlist their help. by thomasa · · Score: 2, Insightful

    When I come across someone who I find reasonably able to fix problems, I sometimes
    enlist their help on assisting their computer neighbors. I also find that people
    who think they know a lot quite often mess up their computer even more and consequently
    require my help more - That is okay, it keeps me employed. It is changing though
    with users losing admin rights. They really cannot do anything as a standard user.
    On UNIX computers, The users tend to be more technical (I find) but still require
    assistance sometimes. Especially when they do not have root.

  22. Re:"Cheap" support by Jhon · · Score: 2, Informative

    If a user screws up a machine, slap the standard install image back on and try try again.


    And if the "screwed up" machine was infected with a malware which keylogged and/or sent information (such as client personal information/transaction records/ssns/ccard numbers) or perhaps medical records to some PC in Denmark BEFORE you restored from that image?
  23. Re:I don't see a problem by Volante3192 · · Score: 2, Insightful

    If IT locks down USB ports, I'm sure they'd have gone over the possibility that they could be locking out legit reasons and have planned for it. No IT department worth its carbon would lock down something that close to the user without preparing for the eventual onslaught of calls asking "Why is my USB drive is broken?!" ...that or their admin is a sadistic bastard and goes on unreachable vacation the next two weeks...

  24. IT is there for the Users to use by Junior+J.+Junior+III · · Score: 3, Interesting

    We should love smart users. If they come up with their own solutions to problems, they're de facto developers. If the business is run well, good workers will succeed and advance while poor workers fail and leave the company. In time, we'll have evolved a class of competent users, even experts, and have application development in the hands of everyone, along with the skillset to actually make decent software. It's a long way off, and maybe a pipe dream, I know, but don't squash the dream. Please.

    --
    You see? You see? Your stupid minds! Stupid! Stupid!
    1. Re:IT is there for the Users to use by Peter+Trepan · · Score: 2, Insightful

      Perhaps more importantly, smart users should love you. IT departments suffer because they don't forge relationships outside their department. While everyone else has friends and advocates at budget time, IT workers are viewed as interchangeable, even redundant. If you snub or ignore technically smart users, you're alienating the one outside segment that's even capable of understanding why you're needed.

      --

      Step into a huge movement. Don't Tread In Me.

  25. Work tech. is for WORK by brendanoconnor · · Score: 2, Insightful

    Letting users do whatever they want on company computers is a great way to have a lot of things go wrong very quickly. When you are at work, you are there to be working, not playing around on the internet, talking to your buddies, exchanging ims and emails an whatever else you could possibly be doing that has absolutely nothing to do with your job.

    At my work, our computers are completely locked down and we cannot change anything, no matter how mundane. I personally thing this is great because I know that whenever I go to the computer, it will just work. If we could change things, I have no doubt a few of the employees would just have to screw with things and then when it didn't work, it would then screw up my job and cost the company a lot of money, not to mention cause my workers and I unneeded stress.

    All this comes from someone who has several computers running from home with various operating systems doing various tasks. I could probably improve things at my work in regards to how tech is handled, but it is not my job. If I want to play sysadmin, I can do it with my own gear, on my own time.

  26. Re:I don't see a problem by 0racle · · Score: 4, Insightful

    If the company has decided that they are going to lock the use of unsanctioned peripherals, then the question becomes not, 'why doesn't my USB drive work,' but 'why are you bringing a USB drive in?'

    --
    "I use a Mac because I'm just better than you are."
  27. The good, the bad and the dumbass by e.coli · · Score: 3, Insightful

    As an IT tech, I have known users who knew their stuff, maybe 0.5% of the employees of any given company. And I have know techs who did not know their stuff, maybe 60%.

    But all in all there are reasons why computers are locked down and there are reasons why IT mandates that "thou shalt not". Too many times there have been licensing issues where a know-it-all user with the ability to install software on their local box has brought in a package from home to install because they could get their work done better/faster/more colorfully with it than they could with the software that the company licensed. And when the project/document/spreadsheet that they created in that software can't be read or modified by any of the licensed software, they instantly become indignant and blame IT for not finding a way to convert their information. Contrary to popular mis-belief, IT does not have experience in EVERY piece of software out there. And when some disgruntled soul left the company they would let the anti-piracy folks know about the illegal installs.

    And then there are the ones who download every bit of shareware/freeware/spyware in the known universe to their local box, turning their machine into a zombie or worse.

    IT is usually mandated to keep the network running smoothly, virus and spyware free, and within the licensing agreements of the software that they have purchased. To do that they have to lock down the network, the computers and the user rights because the know-it-alls don't care about security, safety or licensing. They just want to run Weatherbug because they are too lazy to check into the WeatherChannel.

    And then there are the users who listen to Internet radio (sucking down bandwidth), download illegal music and software (because it's faster than at home), and cruise the porn and game sites. Most users don't remember that the computer, network and internet connection still belong to the company that they work for and the aim of IT is to make sure that everyone can play and work together to the betterment of the company.

    Give me a user who will work within the guidelines, request the software that they need to do their job and, at the end of the day, tend to their personal internet needs from their home computers.

  28. IT Titles and IT BS by umbrellasd · · Score: 2, Interesting
    Worked for 3 years as a business analyst at a health insurance company. I came from 6 years of IT background and we developed IT solutions in the business group. This was a general trend of consolidation where there was more leverage to have a person that understands the business as well as technical side and cut down the overhead between the two groups.

    At the company, many of the users were technically savvy, and more importantly, the process associated with IT was prohibitively complicated. It would take too long to get an IT project approved, and so people would use readily available tools (Excel and Access were the big ones) to develop solutions that met the need.

    I'm sure everyone knows that in the health insurance industry, data privacy is extremely important, so yes, the IT department had some valid concerns about meeting government regulation, but to be fearful of an educated and motivated user that needs something and is willing to invest their time to get it...that's stupid.

    This type of alarmism is your typical FUD that arises when a bunch of established people get jittery about where their paycheck will come from when they feel that someone is threatening the usefulness of their job by doing the things that they used to do. I have one response to that.

    The model-T Ford.

    Yes, all those horse and buggy people were pissed. The smart ones just rolled with it and became mechanics and made fortunes in the automotive industry. And here, too, all that is really required is to say, "OK, what are the new services that we can provide now that we have successfully built tools easy enough that the end-user can use them productively for basic development and analytic tasks?" Guess, what? There will be many more jobs that grow out of millions of educated users all over the world learning to use Excel and Access, etc.

    At the health insurance company, what I could clearly see that our VP of IT could not, was that the efforts of our business people were doing an amazing job of forcing the IT process to become more efficient and less complacent. In other words, it demanded that IT actually earn their paycheck, and that IT explore the new responsiblities that they could take on with their considerable technical skills, in order to better serve a new and more educated customer (technically knowledgeable business users).

    Fear arises because people are God damn lazy. "But I like doing what I've always done. Doing new things is hard. I have to actually learn to do new things. Oh, I just can't possibly see what we will do now that users can do things with data. Oh, why! Why did we give them a power tool that empowers them to go to Home Depot and then rennovate their house themselves, oh why???" Well carpenters haven't gone out of business and neither will IT people...not the proactive ones at any rate.

    The tools will get better and the end user will be able to do more, which means there will be more new business requirements that need specialists to assist the business user, and so on. It's been this same process for generation after generation, and every there are a bunch of alarmists crying doom, and every time new opportunities arise from the changes and the economy experiences a net positive growth.

  29. One big logical flaw... by pla · · Score: 2, Interesting

    IT's mandate to protect corporate data

    Here we have the single point that makes this entire FP one big strawman...

    Yes, IT takes some measures to protect corporate data, both from inappropriate access, and from erroneous (or malicious) deletion.

    The bulk of this "clash", however, involves two points - Maintainability, and the difference between personal and corporate liability.


    Maintainability... Given a network of dozens, or even hundreds, of users, homogeneity means everything. If it takes an extra 15 minutes to solve a five minute problem because each user has their own bizarre configuration and preferred tools, you've wasted three quarters of my time vs just using the tools provided. And speaking of "provided", IT simply doesn't have the time to check each and every machine daily for pirated software. "Oh, but just fire anyone that has pirated software"... Yeah, sure, at up to 50k per violation and the need to replace a presumeably qualified (if careless) employee - Not an option as a default policy.

    And I haven't even mentioned that people expect support from IT on anything and everything they can find on their machines... Guess what? I don't know everything. I can fix and teach Outlook, ThunderBird, Netscape, Eudora, Calypso, Elm, Pine, and perhaps a few dozen clones thereof, but I still won't have a clue how to fix your problem with FooMail; and even if it works similarly enough to one I do know that I can walk right through it, I won't know that until you've already wasted the time it takes me to visit your office (times two, since presumeably neither of us will get anything else done in the meantime).


    As for liability, take the GMail example... In many companies (anything healthcare related, anything publically-traded, and just a good idea in most cases) you have legal minimum retention times for email; On top of that, since those emails count as a liability, you want to enforce that same period as a maximum retention time as well. GMail makes both impossible - You can't guarantee the legal minimum, and you can't automagically delete mail after that time. For that matter, you can't even guarantee that you'll ever again have access to a terminated-for-cause employee's email five minutes after security escorts them out.

    You also need to worry about the motivation for using third-party email... If a company provides its own email server with no unreasonable content or size filtering, why would employees use GMail for work-related material?

    The same applies to IM (though admittedly far fewer companies host their own IM than host their own email).



    I (and most IT workers) don't seriously give a rat's ass what you do on your office computer - Your productivity only matters to you and your manager. I really don't care if you want to play Solitaire all day long. So this has nothing to do with control. But when I get reprimanded (or worse) for letting a random user get the company fined tens of thousands of dollars or under criminal investigation for unknowingly hosting kiddie porn, yeah, you can bet the farm I'll choose "lock your machine down" every time.

  30. When they need your help by Twillerror · · Score: 3, Insightful

    It sounds all fine and dandy to allow the user to install all kinds of stuff on there machines. And without a company mandate with some teeth ( termination or write ups ) most people will install things on their own anyways. We have prevented people from having root access, but generally they figure out what the password is or someone in IT tells them.

    The only problem with these sorts of users is the support they require when it turns out they don't know what they are doing. Any boob can install iTunes, but even the smarter ones start having problems trying to figure out why there machine crashes afterwords. Then IT is called and blamed.

    I'm fine with having these users install whatever they want, just as long as they realize that when they have a problem of any kind of size ( word won't start ) I'm going to blast the machine. If they are smart enough to install all the extra software they are smart enough to put their data on the network or at least in one folder where I can copy it. If they say I lost all my MP3's I'm not going to have a problem telling them tough.

    These same people don't have to sign the invoices for their expensive laptops, I do. It is company property and companies should have every right to tell individuals what they can and can't install. At the same time they cannot be so stubborn as to not allow for newer software to get added, even if it does pose some sort of risk. Instant messenger and those types of programs can greatly increase productivity if used correctly. If the employee is chatting with his wife, I'd rather he do that then go in the hallway and call him on his cell...chances are he is actually doing something in between the chat lines.

    That said the company still has the right to monitor the person for any traffic going over their network. If the guy gets in trouble and they find that he chatted with his wife all the time it should be admissable in determining his dismisal. Everyone out there knows when enough is enough, those that don't usually end up without a job.

  31. I'm more liberal than CostCo with my employees by Travoltus · · Score: 2, Insightful

    and I still say:

    1) It's my property (well, the owner of the company is my boss, but I manage this data center)

    2) On my property, it's my internet usage rules, as long as I'm fair about it.

    3) I bear the full responsibility for stuff going boom (physically, financially or legally), so I have the full right to monitor and control network usage.

    4) You can always go home and use IM and gmail if you want. I have no control over that (though one jackass company in Michigan certainly would want to).

    I support SOX, though I admit we're not a publicly traded company...

    --
    --- Grow a pair, liberals... stop letting the Republicans bully you!
  32. It's called "physical security". by khasim · · Score: 3, Insightful

    Why is data so unsecured that the receptionist who plugs in her iPod can somehow get access to identity/medical histories? That's not the fault of the iPod or the receptionist.

    Because without physical security there is no security.

    Locking down the PC so that the receptionist cannot move data to his/her iPod would also, logically, prevent the iPod from doing anything that s/he would want it to do.

    Unless you configured an iPod specific rule. And security is broken by "exceptions".
    1. Re:It's called "physical security". by rsborg · · Score: 3, Informative

      Locking down the PC so that the receptionist cannot move data to his/her iPod would also, logically, prevent the iPod from doing anything that s/he would want it to do.
      This is not true. The receptionist should be using his/her PC/Mac at HOME to load the iPod with *her* music. No interaction between the mp3 player and the workstation/laptop is necessary. The iPod still plays songs/video as it should, but without interacting with the work computer.
      --
      Make sure everyone's vote counts: Verified Voting
  33. It's not the technical users we fear... by gillrock · · Score: 2, Insightful

    This is not fear we have. I certainly don't fear the Software Developer that has good Unix or Windows knowledge. Hell, I'll try and learn a thing or two from those folks. However, we in IT have a job to do and we're trying to do that job with a couple of things in mind.

    1. Keep the Lowest Common Denominator employee productive and not constantly working on their system(s). If you're a hot shot techie at home, you have to realize that IT needs to make things work for the non-techie employees as well as you. Admin Assistants are a good example. They don't know about SysInternals or Slashdot or Linux and they don't care. They do care about office applications working then they need them for that presentation their boss (sometimes your boss) is about to give or whatever else is their important issue of the day.
    2. IT is not interested in how you do things at home and telling us that's how we should do it at the office. We're running a business, we're not running your little computing playground you have setup in your house. Hell, we have them too, but those solutions are not business solutions, they are home solutions and are different solutions that employ some of the same technology. It's an apple and an orange. IT is not really interested in how you have your computers at home on a certain switch or how you do backups or you telling IT how they should setup their network and what their problem is. Personally, I'm interested in talking to you about that for stuff and comparing it to what I do in my home, but not the business I work for.
    3. IT places restrictions for good of the business and so that IT can focus its energy on a limited number of products. If IT let everyone just run what they wanted on their systems, IT would be a nightmare and the company couldn't get good quality people to do the job well. Everyone has products they like and favor, even the IT people, I certainly wouldn't want to work for a company where I had to support every anti-virus software in existence or every Linux distribution because it was the whim of the person who's office the system was installed. I want to see a buisness reason for supporting multiple Linux distributions or anti-virus software. IT makes business choices based on best practices and industry leading technology products. Well, at least IT tries to do this, in most cases.

    On the flipside of the coin, the company where I work now has in it's IT policy that checking your personal email (Gmail, Yahooo Mail, hotmail, etc.) is not allowed. I don't get this, personally, but that's the policy and everyone scoffs at it. Also, IM is not allowed/supported, but there is a way around it that everyone uses.

    Policy and practice by IT is there for the wide abuser IMHO. For example, an employee who puts 8 different firewalls, 3 anti-virus programs, and a slew of other non-work applications on his company issued laptop that has the company anti-virus and firewall. This person has the balls to call the help desk and complain that his laptop is performing like crap. Genius, uninstall 7 firewalls and two anti-virus programs and I bet your laptop performs a whole lot better.

    I think everyone in any company should spend two weeks working in the company's IT group as part of orientation and I think seeing and hearing the issues first hand from that side of the fence will generate a different set of articles from this one.

    --
    "...the shortest distance between two points may be straight line, but it is by no means the most interesting."
  34. You're missing the point by KingSkippus · · Score: 3, Insightful

    The point of the article is not that you should or shouldn't try to lock things down. It is that that no matter how much you try to lock things down, your users will find ways to open it up to get their work done.

    If you're smart, you'll figure out ways that you can both get what you want: Your security and manageability, and their productivity and ease-of-use. Handing edicts from on high is a pretty stupid idea. The point of the article is that you're not shutting down what they call "Shadow IT," you're simply driving it underground where it's harder to see and deal with.

    But, you know, it's your property and your rules, so by all means, do with it what you will, and good luck with that.

  35. It's a question of misplaced priorities. by Kadin2048 · · Score: 2, Insightful

    If the receptionist is assumed to be untrustworthy, then they could just as easily install a real hardware keylogger in between the PC and the keyboard. (And that would be a lot easier to get than an iPod-disguised keylogger.)

    I'm not saying that there aren't situations where barring anything that could carry data away is appropriate. It's just that IT types seem to hone in on the "security breaches" that they can shore up, to the greatest inconvenience of users, while ignoring glaring holes elsewhere. If you're going to tell the secretary that she can't charge her iPod from the USB port because of the risk of keylogging, I hope that the keyboard's PS/2 connector is superglued in, or the entire chassis is encased in a locked steel container. Otherwise you're ignoring an obvious avenue of attack (like these), but going after a highly unlikely one, even though the treatment for the unlikely one annoys the user more.

    Most IT departments have so many security problems and vulnerabilities, it's hard to even know where to start. But rather than working through them in a rational way, they seem to begin with the premise that "anything that annoys the users in the name of security must be good." (Probably not their fault; it's probably an attempt to placate a PHB somewhere by making the security really obvious...)

    It's ultimately a glass-houses issue. Before overt, draconian security measures are put in place, everything else ought to be locked up already. Otherwise, it just makes the IT department look like they're power-tripping, regardless of the real motivation. And in the corporate world, it's not good to make everyone else hate you. Particularly the secretaries.

    --
    "Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
    1. Re:It's a question of misplaced priorities. by Jhon · · Score: 2, Insightful

      "anything that annoys the users in the name of security must be good."


      I think it's more the case that you are focused in on the restrictions that effect you rather than getting a view of the "big picture". The trees are blocking your view of the forest.
  36. Validation and Regulation by Mutatis+Mutandis · · Score: 4, Insightful

    This is a general observation that can be made regarding 'regulatory' departments that are concerned with security and legal compliance. Generally the rules are written down by someone senior, who uses common sense to reach what seems, at the time, a reasonable compromise and a practical approach. Next, they are handed down to a team of juniors, who enforce without understanding, because that is what they have been told to do. Through habituation, the regulations become Holy Writ and nobody is allowed to touch them --- a situation the original author(s) would probably have regarded as silly and dangerous. Finally, everybody formally adheres to the rules while circumventing them by any means possible, making a total nonsense of the original purpose.

    This is by no means limited to IT. It also applies to finance or health care, or for that matter the US Constitution. It seems to a general human phenomenon. But it just seems that IT departments are more prone than others to the extreme aberration that I would call IT fascism: The belief that the ideal organization is regimented, uniformed, homogeneous, goose-stepping, controlled, and obedient; and that any exceptions need to be eliminated. Maybe the use of binary code stimulates binary thinking.

    Of course, for any commercial organization, this can be a real killer in the long run. I've seen creativity and innovation totally stifled by regulation, until most people were so marinated in the status quo that they became completely incapable of independent decision-making, and the creative minds got frustrated and left. It's pretty much the reason why, if I were to make a SWOT analysis of our firm, I would classify much of our IT department under 'threats'. It's not because these people are of ill will, but the idea of trying, stimulating, or even supporting something new has become alien to them.

    They are taking care of the daily business, according to present regulation, and they just can't imagine that there might be more to the job than that. To be fair, most of them are so far from the "frontline" that they no longer hear the din of the battle for survival.

  37. No I don't by Usekh · · Score: 2, Insightful

    I have worked in helldesk for..far..too long. Far far far too long. Er anyway. I have to say no I don't feel expertise of users. I fear users who -think- they are experts and really have no clue.

  38. Business will always win by Avatar8 · · Score: 2, Interesting
    I've been in IT for 23 years. I haven't seen it all by any means, but I've seen enough to consider myself an expert on many things. IT, yes; business, no.


    At a previous company we were very flexible and provided everything we could for users, especially remote users: OWA, VPN, wireless, SSL-VPN, Terminal Server for those legacy apps that no one could do without, etc. et al. We held a pretty secure ship, filtered only what was legally necessary and monitored traffic/e-mail only when requested by HR.

    Regardless we still had this Shadow IT. Typically it was the guy who ran his own network and Exchange server at home telling us how we should run things, how he should have two monitors even though no one else had that and that he should be allowed unfiltered internet because it made him more productive.

    Then there was the time the top salesman left his laptop at home, connected to our VPN, his son used it and it began attacking our firewall with a SQL slammer worm. One time can be forgiven, but this was the third time in a year that this occurred.

    IT was thrown under the bus on these accounts and others.

    Mr. Know-it-all got his second screen and caused a chain reaction of others crying for them and costing the company a sizable chunk of change.He also won having the internet opened up for sports and games. IT watched productivity drop as non-business internet usage climbed.

    Mr. VPN received a third "warning" in his HR file, but IT had it's hand slapped because we hadn't really educated him on how to use his laptop, the VPN or the update programs. This in spite of us producing a document signed by the guy that stated "I understand IT policy and proper use of issued equipment and the network."

    Back and forth this struggle has continued for the past 20+ years I've been in IT. For a few years, we're heroes. We implement technology and methods that allow businesses to grow and profit at the speed of light. We save businesses from going under when disaster strikes because we backed up the data. Then for the next few years we're the villains. We don't implement the latest technology just because the CFO said not to spend any money. We're thrown under the bus because an executive sent an illegal e-mail and IT had the nerve to have it backed up and accessible for the legal system.

    The longer I'm in IT, the more I wish I'd have learned a real skill like cooking or carpentry.

  39. CIO by dlhm · · Score: 2, Insightful

    I have been recieving CIO magazine for a couple years, and I have come to think of it as a book of Humor. On occasion I find some of the articles interesting, but mostly just amusing. I don't fear my users, unless they can keep up with the learning curve, they will fall behind quickly after new products come out. Most Users don't want to know how things work, they just want it to work. On the other hand if you have a user that is trying to flex thier computer skills in your face, you can bet they are doing much more behind you. Watch those users.. this article may also be biased based on the the service/software the mention in it and those who buy ads in this magazine. After all, how can CIO say don't let users use Gmail, or IM's. I think thier sponsers would flip...

    --
    Ad eundum quo nemo ante iit!
  40. The nerdiness of IT warfare by Mutatis+Mutandis · · Score: 2, Insightful

    From the posts in this thread, one gets the impression that there are rather a lot of places where IT people and other employees are locked in a state of permanent warfare, or at best uneasily living together in mutual disdain.

    The curious thing is that rather a lot of IT people seem smugly satisfied with this. They are confident that they have everything "locked down" and that nothing can go wrong as long as they don't allow the users to do anything important -- whatever that means.

    To me this seems the ultimate in IT nerdiness. It gets pretty close to programmers who exclaim that they "didn't change anything" when their product suddenly starts to misbehave -- only applied to people, who are even more unpredictable than even the most chaotic software product.

    The reality is that if people hate you, they will find a way to subvert your systems, and IT won't know. People are resourceful. I strongly believe that a security system that is not supported by the people who have to live with it, will be valueless in the long run. People are your major threat and your strongest vulnerability, but potentially they are also your best line of defense. A serious outside attack is not unlikely to have a strong social engineering aspect to it.

    I've met IT technicians who blithely assumed that outsiders could never guess an internal password, because their systems strictly limited the number of login retries and required frequent password changes. It never occurred to them that someone might entice out a password by putting on a lab coat and looking official, that people are rather stimulated to write down passwords if they have to change them too often and any mistake brings about a clash with IT, or that the use of incremental suffixes permits any outsider to predict the new passwords years in the future. They sought refuge in strict IT rules, but their psychology (and their logic) was all wrong.

    Apparently, there is this curious notion in some places that IT is about managing machines. Curious, because any engineer in another field could tell the IT staff that a big part of effective support is dealing with people, their needs, expectations, and perceptions. An IT group that is just busying itself with keeping the hardware and software in a good state and not positively interacting with and educating users, is an IT group that is failing in its job.

    Of course it is much easier to concentrate on the machinery and ignore or crush the users. Machines are far more predictable and easier to work with, and sadly a lot of IT people are still conforming to stereotype and not blessed with great social skills. But at the end of the day they should watch out for their own interest --- there is no future in being a glorified window(s) cleaner.

  41. Smart users; smarter IT. by brxndxn · · Score: 2, Insightful

    Any IT department that fears its users are learning too much is a goddamn shitty IT department. Seriously.

    I'm an IT guy.. at an engineering firm. Pretty much everyone here is a 'computer guru' by todays' standards. So, for about 100 employees, the three of us 'IT guys' get to spend most of our time doing real engineering, programming, HMI design, drafting, etc. Our job is made much easier since we can give users full administrative control over their own computers/laptops (necessary in engineering anyway). We just 'lay down the law' in terms of what users are allowed to install and uninstall and we never have to take away privileges from people that know what they're doing.

    So, for years, the entire network and seven servers is managed as a 1-10hour/week job for one of our three 'IT guys.' We secure the network and the servers.. and we don't even bother to secure the servers per user - we just have them making tons and tons of backups so if a user does remove/move files that are important, we just replace them with backed up copies from whatever date we want.

    Having a smart userbase allows a 'smarter' IT dept. to spend less time on IT unless the IT dept. is a bunch of bumbling idiots who find it hard to stay ahead of the curve. It's really nice not to have users that need help just because they cannot map a drive.. or because they cannot install a different version of Industrial Software X because it is incompatible with Industrial Software Y.

    --
    --- We need more Ron Paul!
  42. Where's this guy been for 25 years.? by Animats · · Score: 2, Funny

    1982 called. They wanted to tell you that some people now have PCs and aren't using the mainframe like they're supposed to.

  43. Re:I don't see a problem by misanthrope101 · · Score: 4, Insightful
    No problem, twinkletoes. All that work that was getting done because I was working around your restrictions just stop getting done. That 1.4MB Powerpoint presentation I was working on at home, off the clock? Well, I guess the ETA just got pushed back, since I'm certainly not living in my office for you.

    Just a few days ago I ran an entire meeting of 12 Powerpoint presentations from my USB drive because the network drive went down the very morning the VIP showed up to have his apple polished. I thought ahead, realized that our network goes down all the time is about as reliable as the Iraqi army, so I had the foresight to copy the files to my personal USB drive. No longer--now I'll just shrug my shoulders and the organization looks only as competent as we really are for a change. I'm actually ecstatic when they lock the computers down a bit more. Already my workplace has cut off webmail, much to the joy of all the workers who now can't be held responsible for not knowing about (and completing the tasking from) an email sent out at 10PM Friday. Lock everything down, please. Could you please take my printer? Who knows what sort of shenanigans I might get up to with that.

    Give me a diskless workstation that only works during business hours, and make sure it's the only place from which I can access company data, and I'll buy you lunch for a week. Don't forget that company cellphones and blackberries and PDAs are also the spawn of Satan. Keep up the good work! We love you!