Slashdot Mirror


Ask Slashdot: IT Personnel As Ostriches?

MonOptIt writes: I'm a new IT professional, having recently switched from a different sci/tech field. My first gig is with a mid-size (50ish) nonprofit which includes a wide variety of departments and functions. I'm the sole on-site IT support, which means that I'm working with every employee/department regularly both at HQ and off-site locations. My questions for the seasoned pros are: Do you find yourself deliberately ignoring office politics, overheard conversations, open documents or emails, etc as you go about your work? If not, how do you preserve the impartiality/neutrality which seems (to my novice mind) necessary to be effective in this position? In either case: how do you deal with the possibility of accidentally learning something you're not supposed to know? E.g. troubleshooting a user's email program when they've left sensitive/eyes-only emails open on their workstation. Are there protections or policies that are standard, or is this a legal and professional gray-area?

246 comments

  1. Simple Answers to Simple Questions by Anonymous Coward · · Score: 5, Insightful

    Yes

    IT has access to everything and should read nothing. The content is just that, content. It doesn't matter

    1. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 3, Interesting

      That wasn't the question. What do you do when you did read something inadvertently? You can't unread "Irregularities in the pension fund". Do you pretend that you don't know? What if it's something illegal / against company policy / unethical?

    2. Re:Simple Answers to Simple Questions by khasim · · Score: 4, Insightful

      I prefer the term "professionally disinterested".

      If it is NOT evidence of a crime then you ignore it. Or you use that knowledge to avoid finding out anything more about the topic.

      If you have any questions then you bring those questions to HR.

    3. Re:Simple Answers to Simple Questions by Raumkraut · · Score: 3, Interesting

      Does your country have laws protecting corporate whistle-blowers?
      It's a lot easier to defend your position if it's the FBI asking you to make surreptitious copies of documents, after they called you following an "anonymous" tip-off...

    4. Re:Simple Answers to Simple Questions by mysidia · · Score: 5, Insightful

      Your best bet is to "forget" you read it; never acknowledge that you saw it, and assume the best.

      For example, just because someone wrote about supposed "irregularities in the pension fund"; doesn't mean there are irregularities in the pension fund, it may just be some ignorant person spouting out / jumping to wrong conclusions.

      There are also paranoid folks who will say such things, until it's proven that no, there was just some minor typographical mistake and everything's fine.

      Just like when a person tells you "I turned off the firewall," but it still gave me the error message. Doesn't mean they managed to break into the server room and replace the corporate firewall with a closed circuit ------ they haven't a clue what they just said.

    5. Re:Simple Answers to Simple Questions by wisnoskij · · Score: 1

      You ignore it. Don't think about, don't gossip it around, pretend you did not see anything.

      --
      Troll is not a replacement for I disagree.
    6. Re:Simple Answers to Simple Questions by wisnoskij · · Score: 5, Insightful

      If it is actual evidence, and not just gossip, of real law breaking that is something only your conscience can decide. As for everything else, including things that are clearly breaking company policy, as long as it is nothing or little to do with your job ignore it. You are not paid to rat on your peers. And telling your boss that Bob in accounting steals office supplies is not going to earn you any promotions or friends.

      --
      Troll is not a replacement for I disagree.
    7. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 2, Insightful

      In my career I've had access to everything from HR data, payroll, ethics/legal investigations, etc... never really looked at it other than the few times I commented to the programming teams about them having debugging on in their code (in production), potentially spitting out private/sensitive information into the logs, etc (one time one team had company CC#'s with names, SSNs, etc). It is what it is - I just inform them they shouldn't do that, but don't really pay any attention to it.

      I have never, even though I've had access, actually gone into the databases doing queries or anything "looking". I'd consider that horribly unprofessional, unethical, and potentially illegal.

    8. Re:Simple Answers to Simple Questions by grcumb · · Score: 5, Insightful

      That wasn't the question. What do you do when you did read something inadvertently? You can't unread "Irregularities in the pension fund". Do you pretend that you don't know? What if it's something illegal / against company policy / unethical?

      We used to call it 'being trustworthy'. Not sure what the term is today.

      People need to know that they can rely on you under pretty much any circumstances, otherwise they'll stop calling and you won't be able to do your job. That means ignoring pretty much everything.

      I say pretty much, because there is a line past which you cannot remain silent. For me, it was child pornography on a customer's computer. I called the police and handed over the equipment.

      This was in a small town, and it ruined my life, by the way. The owner of the computer was a prominent citizen who immediately accused me of planting the material, then began a slur campaign against me. The town, as the saying goes, wasn't big enough for the both of us. After more than a year of this, I had to leave. I'd lost my job, and I'd lost half my friends.

      Some time later, I ran into an acquaintance from that town in an airport. His first bit of news that that the kiddie diddler had finally been convicted. His own smear campaign finally had the effect of bringing three adult victims of his out. They testified against him and put him away. The lesson I learned is that, sometimes, there is justice in this world. But it doesn't come free.

      So yes, you need to be - and you need to be seen to be - completely, implicitly trustworthy. How you do it is simple enough: Always be there, never be seen to be part of the gossip. Be open and obvious about everything you do, and never, ever work in someone's office with the door closed. Equally, though, you need to be seen to be the kind of person who will do the right thing. That's a little harder to do and, as I've recounted, sometimes comes at a cost.

      --
      Crumb's Corollary: Never bring a knife to a bun fight.
    9. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      Simple: I don't care. I really don't have the time or bother to read other people crap. What a waste of time. Unfortunately my job does required looking at lot of this, since I get Legal requests as well as users requesting data recover of lost emails and files and voicemail. It can be really annoying at times. I simply ignore it and just pass on the data to the requester and prey they don't need something more!

    10. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      You forget it the instant you see it, no matter what it is with one exception.

      The only thing I ever "see" when working IT is child pornography. I secure the machine and report it to the authorities immediately, then to my manager.

      Anything short of that? You Forget It. you never saw it, it never happened.

    11. Re:Simple Answers to Simple Questions by neilo_1701D · · Score: 2

      You ignore it. Don't think about, don't gossip it around, pretend you did not see anything.

      And start looking for another position if warranted.

    12. Re:Simple Answers to Simple Questions by MindStalker · · Score: 1

      As you don't know the details you simply stop reading. There could be any number of "irregularities in the pension fund", maybe a transaction was reversed or a simple typo, it happens all the time. Unless you continue reading to know the full details such a headline means nothing. In reality pretty much no matter what you accidentally read, most "small snippets" are almost never accurate towards the full content.

    13. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 2, Interesting

      As a sysadmin, there isn't the option of doing things the wrong way. Your job security and salary actually depend on you knowing "the right way", especially when everybody want to cut corners. This is why you always make sure you speak your mind, and if still the managers and leadership wants to do it their ass-backwards way, you get to say "I told you so".

      After a few years, most of the good ones will start listening to you, even if you're totally fresh in the role. THIS is why you never just bow your head and remain silent. Consider it an investment, not necessarily in salary, but getting a say in how things should be done. Otherwise, leadership and managers will think it's someone else's fault when they screw up, so there's really no other option to it.

    14. Re:Simple Answers to Simple Questions by guruevi · · Score: 1

      If I don't know any further details, I'll take it as if it were the best case scenario and someone found some irregularities and is fixing it. Irregularities doesn't mean something illegal happened, there are plenty of ways to siphon money out of a fund that don't break the law, that's what accountants are supposed to know and fix.

      If something is blatantly illegal, follow the corporate policy and report as necessary to superiors and if that fails or is not feasible, authorities. Remain as anonymous as possible, do an anonymous report to HR or at least ask them to keep your identity concealed etc etc. And trust me, authorities don't give a shit about what is and isn't legal within a corporation, you file a report and nothing ever happens unless millions of dollars are going in the wrong (read: not in their) pockets. Even the corporation won't care if an accountant syphoned 100k to their personal bank account; they'll fire the dude/dudette and carry on because the bad press will hurt their stock/client base more than the 100k. For the 'regular' guy, $100k or even $1M is a LOT of money, within the billion dollar corporation this is chump change and well within their calculated losses.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    15. Re:Simple Answers to Simple Questions by gweihir · · Score: 1

      Don't ever use that information (except to decide to resign your position _without_ giving honest reasons). While the moral thing might be to act on it, the practical thing is that you do not have the position/role to do so and it will always be to your detriment.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    16. Re:Simple Answers to Simple Questions by gweihir · · Score: 1

      Exactly. You are not an enforcer. You will always get to see things like that with enough access, just too many human beings are scum. But unless you have the power to do bad things to people (and you want to do that), walk away.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    17. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      > IT has access to everything and should read nothing.

      Then you're either really, really stupid, or just lying to prevent other people from using the data.

      When it's the discussion about budgets that affect your department, including laying off staff, you're a complete fool if you don't get your resume out there. Hunting for the data can be illegal, although *that* never stops most of middle management from collecting and trading in the data as part of how they protect turf and status. Believing otherwise just makes you a peon, and an expendable one.

    18. Re:Simple Answers to Simple Questions by currently_awake · · Score: 1

      Your ability to do your job requires trust. If they think you are spying on them they won't trust you. Ensure you don't say or do anything about anything you see, or your job will get harder.

    19. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      How do you read something? That takes effort. I've been in IT for 2 decades and I don't read anything. I may see a subject or part of a subject of an email or happen or catch part of the name of some documents as I go about my business but if you are seeing more than a sentence and starting to piece something together and thinking about it, you are going out of your way to do that. That is flat out WRONG. We've had people that were accessing documents that should not have and they do not work here any more. Now on the flip side.. We do backups over our MPLS WAN and we backup redirected my document folders of users from their laptops. If my nightly backup suddenly exceed their window or have an unexpected growth, I'll investigate but it is a generic file size search by user. If a specific user sticks out, I route a ticket to the T1 to ask the user if they put a lot of files on their computer. 9 out of 10 times, the backup size returns to normal the next day. If they don;t go away, it must have been legit or the person just wants what ever is there to be there. don't have to go through and see what they put on there, I have NO DESIRE at all. I could go through the backups and browse everyone's my documents folders from teh server and leave no trace but why would I or anyone want to do that? It is none of my business.

    20. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      If it's something illegal and your actions make you culpable, just walk away. Otherwise unless your job is compliance, do your job.

    21. Re:Simple Answers to Simple Questions by Wycliffe · · Score: 1

      When it's the discussion about budgets that affect your department, including laying off staff, you're a complete fool if you don't get your resume out there.

      When as IT should you ever be reading a "discussion"? You might see a subject or two about budget or even layoffs but
      you shouldn't be reading the actual emails and without violating your position and reading the emails you are usually just
      guessing at what is really going on. If you find yourself constantly curious and want to read other people's emails because
      of some snippet you saw then you might want to think of changing to a career where you are not constantly being
      tempted to do something illegal/immoral.

      The being said, I did once discover someone in the office was pregnant before it was announced after seeing a subject of
      "What to expect your 9th week". I kept my mouth shut and didn't say anything and she soon announced it but it could
      have had a different outcome. She might have been tracking her sister's pregnancy, she might have decided to have an
      abortion, or I could have misinterpretted the snippet that I saw. Either way, NOONE, not even your boss wants to know
      or think about the fact that you have access to their emails. When I log into someone's email I always ask them for
      permission and then ask them for their username and password. ALWAYS. I don't need their username and password
      to access their email but I don't need to draw attention to that fact as most people routinely treat their email as private
      and although if they think about it they probably realize that you have access to everything they would rather pretend that
      you don't. We run a web based service and our phone support actually do the same thing with our customers. They
      always ask for their username and password. Again, they don't need the password and amusingly enough they can't
      even easily verify that the password is correct but it seems to calm people when they voluntarily give you their username
      and password before you start messing with their "private" data.

    22. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 1

      "When I log into someone's email I always ask them for permission and then ask them for their username and password. ALWAYS. "

      I assume you mean you ask them to type in their password to the keyboard right?

      No IT policy should endorse users giving passwords to anyone, including IT staff. Otherwise social engineering becomes trivial.

      Great post, btw.

    23. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      Your best bet is to "forget" you read it; never acknowledge that you saw it, and assume the best.

      For example, just because someone wrote about supposed "irregularities in the pension fund"; doesn't mean there are irregularities in the pension fund, it may just be some ignorant person spouting out / jumping to wrong conclusions.

      Case to case basis. "irregularities in the pension fund" is something that could be ignored, "couldn't dispose of the corpse last night" puts you in a spot where you might be committing a crime by not reporting.

      Anyway, if you know that someone thinks that there are irregularities in the pension fund then you still have a personal choice to make. If you can't trust the pension fund (Either to someone tampering with it or to sloppiness and mistakes.) then the company might not be a good place to build a career.

    24. Re:Simple Answers to Simple Questions by Dan541 · · Score: 1

      Just ignore it. It's not your business to snoop.

      --
      An SQL query goes to a bar, walks up to a table and asks, "Mind if I join you?"
    25. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      Yes

      IT has access to everything and should read nothing. The content is just that, content. It doesn't matter

      Best answer to a very delicate question. IT *must* be invisible. Period.

    26. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      ....So you're actually teaching your users that it's OK to give out username and password?
      I ask people to type the passwords themselves in all the prompts where it's necessary.
      Yes, that implies that they have to be nearby when I assist, but I always stress that they must never ever give away their passwords, even to me (and yes, I am trusted at work and have access to everything).
      The only excuse is if somebody is holding their kids hostage.

    27. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      Using Business resources for private use is not protected, nor should you ever give the false impression that you CANNOT read/access/log it.

      There should be some sort of training or flyer somewhere that reinforces this.

      There is no issue that you CAN access anything you need to to perform your job. The only issue is if you should blab your mouth...

    28. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      The key thing is, knowing how to dissent without being seen as a subversive asshole.

      You may *personally* disagree with the decision made by the company - and by all means, send your boss an email saying, "Hey, this is a bad idea, here's why, here's what I expect the outcomes will be." But as long as the decision made by management is both legal and ethical, it doesn't matter if you *personally* agree with it or not - you execute to the fullest extent of your professional abilities. If you can't do that, you should leave your position and find a new one.

      And if it turns out you were right, you don't go "Nyah Nyah Told You So FUCKTARDS," you say "If you recall, my original email (attached) about this issue explored some suggested alternatives - maybe we should revisit some of those alternatives instead? I'm particularly fond of Option A, because it would be easy to implement and dovetail nicely with systems X, Y and Z."

      All you have to do is reference that original email to gently remind them - "I was right. I predicted this," without actually having to be the type of asshole who says, "I told you so." And being graceful to others when you're winning will pay off in the long run.

    29. Re:Simple Answers to Simple Questions by Etcetera · · Score: 3, Interesting

      Your best bet is to "forget" you read it; never acknowledge that you saw it, and assume the best.

      For example, just because someone wrote about supposed "irregularities in the pension fund"; doesn't mean there are irregularities in the pension fund, it may just be some ignorant person spouting out / jumping to wrong conclusions.

      Case to case basis. "irregularities in the pension fund" is something that could be ignored, "couldn't dispose of the corpse last night" puts you in a spot where you might be committing a crime by not reporting.

      Actually, you'd probably be committing a crime by not reporting there too... In both cases, if it could be proven you were aware of it. What you're talking about is the different levels of moral responsibility between the two cases.

      To answer the OP, as someone who's had root at large positions... Assuming you are not intentionally spying on something or doing something at the behest of a security directory, legal, or other internal affairs-ish agency (which probably doesn't exist at your smaller company), you should treat everything as if you were a cop and you didn't have a warrant. You're not going on a fishing expedition, but if something is "in plain view", it is not inappropriate to use common sense and reason to consider that information now available to you and make choices accordingly. If that means calling your CFO/Legal that's one thing, if it's police that's something else.

      Overall, it's hard to go wrong with the time-tested advice sudo lectures you with, specifically #1/#3:

              We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things:

              #1) Respect the privacy of others.
              #2) Think before you type.
              #3) With great power comes great responsibility.

    30. Re:Simple Answers to Simple Questions by JWSmythe · · Score: 1

      Right. The "irregularity" may be that the dates are showing in the wrong format on the monthly report. Or that it's 90% less than what it should be. It could be assumed that because there are emails going around, it's already being investigated by the appropriate people.

      It's not up to the IT people, even if you're a Chief- or Director- level, to follow up on problems in other departments. You could find your employment rather limited if you go to the CEO or CFO about the "irregularities".

      --
      Serious? Seriousness is well above my pay grade.
    31. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      That wasn't the question. What do you do when you did read something inadvertently? You can't unread "Irregularities in the pension fund". Do you pretend that you don't know? What if it's something illegal / against company policy / unethical?

      Keep your mouth shut..
      Do your job.

    32. Re:Simple Answers to Simple Questions by Wycliffe · · Score: 1

      "When I log into someone's email I always ask them for permission and then ask them for their username and password. ALWAYS. "

      I assume you mean you ask them to type in their password to the keyboard right?

      No IT policy should endorse users giving passwords to anyone, including IT staff. Otherwise social engineering becomes trivial.

      Great post, btw.

      So when someone calls IT and asks for you to make a change to their account then you just make it?
      Of course you need to ask for their password and/or other information to verify that they are truly who
      they say they are before changing their account or you make social engineering of IT just as trivial.
      When I call my bank I fully expect them to ask me for my password, my account number, and/or my
      social security number before they start talking to me. IT is no different.
      Social engineering education is very similiar to educating kids. You tell kids "an adult should never
      ask you for help". You tell your users the same thing. IT should never ask you for help. If YOU
      need help and call them then expect them to ask you for personal information to verify your account
      before they help you but never give out information to anyone that calls you and asks you for the
      information.

    33. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      An irregularity can be as simple as, let's say it is 1983, and the fund manager bought 100,000 shares of Price Club. That would have been be irregular, but not stupid. Now if you witnessed someone shoulder surfing employee X. After the one who was surfed (employee Y) goes home, the surfer X logs in to the computer and 2 days later you are told Y was fired for messing up a large order 2 days later. If you asked what time was she logged in when this happened? They say 5:30 pm, which was same time X logged in to that computer. You mention it kinda funny that the time stamp is messed up cuzz she left at 5:00pm. They never asked you the IT guy, about anything. I would say it is time to abandon that snake pit & start looking elsewhere for employment. There is a probability there is a group working together to remove obstacles in their career path.

    34. Re:Simple Answers to Simple Questions by Ozymandias_KoK · · Score: 1

      You actually ask for user passwords? That's kind of a big no-no. Even worse as you mention you don't need it.

    35. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      Ask Snowden.

    36. Re:Simple Answers to Simple Questions by david_thornley · · Score: 2

      Of course you verify identity first. Just don't ask for the password.

      You don't want users accustomed to giving out a password on the phone. If they're accustomed to giving it to somebody in IT, they'll probably tell it to somebody who pretends to be IT. If you tell them never to help IT when they call, you're setting up a problem when somebody in IT needs to ask a question, like "Do you really need that 342M email attachment in your mailbox?".

      And, if you're giving your online banking password out over the phone, either find a new bank or stop doing anything online. Seriously.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    37. Re:Simple Answers to Simple Questions by Anonymous Coward · · Score: 0

      That reminds me when I worked at Siemens there was a guy who I trained with talking about some company he worked for yearrs before that where he found all this horse porn on a users computer and just ignored it.

    38. Re:Simple Answers to Simple Questions by stoborrobots · · Score: 1

      Indeed.

      Or the fragment might be part of a statement like "following the issues with the Enron case, we've put in some additional measures to prevent any irregularities in the pension fund" or even "Did you see that episode of the IT Crowd where the new boss was asking the IT department for help deleting the files which showed the irregularities in the pension fund? What a classic..."

  2. blahblahblah by retchdog · · Score: 3, Funny

    why the fuck are you asking here, of all places, about office etiquette? haven't you noticed that over half of the people here are bitter, miserable burnouts and misfits?

    are you also asking on the christian abstinence forums about finding prostitutes?

    --
    "They were pure niggers." – Noam Chomsky
    1. Re:blahblahblah by Anonymous Coward · · Score: 0

      Slashdot method, intentional or not, would be to display a slight case of Asperger's and talk about the pattern in the ceiling tiles or a new VM product that just came out
      'they' will cease to think of you as a threat and pretty much ignore you from there on out

  3. yes, ignore office politics by Anonymous Coward · · Score: 1

    Then you will be surprised when the players of office politics conspire to fire you. And they will. It's what they do. Because you're IT. You're the scum of the office by definition.

    1. Re:yes, ignore office politics by Anonymous Coward · · Score: 0

      Needed by all, hated by all?

    2. Re:yes, ignore office politics by 1s44c · · Score: 1

      If you help people, facilitate, make their work lives easier, you won't be the scum of the office.

    3. Re:yes, ignore office politics by Anonymous Coward · · Score: 1

      So you are saying he should scan all their data and build dossiers with inciminating information for every employee, that he can use later as blackmail if they start conspiring against him? Is that the solution?

    4. Re:yes, ignore office politics by SuricouRaven · · Score: 5, Interesting

      Ideally, but office politics is complicated. Sometimes making one person's life easier makes another's harder - teach the micromanager that he has the ability to add items to his underlings' outlook calanders, and said underlings are going to be annoyed. Sometimes people actually like their lives to be harder, for not-apparent reasons.

      For example, having worked at a school in IT support, part of my job was to maintain the various measures used to keep the students away from games in lessons. Due to some sadistic tendencies, I have become quite skilled at this. New games sites appeared all the time, and were quickly blocked - often while a student was trying to use them. We watched their screens.

      Until some of the teachers started acting very annoyed, and complaining about us interfering in lessons. Why would they do this? We were trying to make their lives easier, keeping the students from entertaining distractions so they would focus on their work. We were enforcing the usage policy, everything by the book. What we hadn't realised is that many of the teachers were well aware of the gaming going on in lessons, and turning a blind eye to the class clown. Games keep the disruptive student busy, and if he weren't playing the latest flappy bird clone he would just be jumping around the room, distracting his friends or demanding most of the teacher's attention. So when we stepped in to 'help' the teachers, we actually got in the way of a little trick of theirs by turning the silent non-working student into a class-ruining joker that kept everyone else from working too. All they needed was an excuse to stop us, and it wasn't hard to find one - they just argued to the boss's boss that we were performing 'classroom management,' a function that the union said must be the exclusive domain of teachers.

      The way the workplace actually functioned differed from the way it actually functioned. By not noticing the unwritten procedure in use, we disrupted it and caused friction with another department.

      We still block the games, of course. Teachers should learn to manage their students, not just give them an electronic pacifier. We're just a bit more subtle about it.

    5. Re:yes, ignore office politics by I'm+New+Around+Here · · Score: 1

      You misspelled "inseminating".

      --
      If you think I voted for Trump because of this post, you're wrong. I voted for Dr. Jill Stein of the Green Party. Again.
    6. Re:yes, ignore office politics by Anonymous Coward · · Score: 0

      Always watch your back when it comes to any other IT person no-matter how junior.
      Here's one that was totally unexpected.
      A woman department head, not in IT had a son attending college who wanted to 'break-in' to the field.
      My small IT department needed a part-time person so I put in a few great words for the woman's son to general manager.
      He got hired.
      A few months later...
      The same woman then began complaining daily to general manager how unresponsive I've become to her departments problems.
      Around the same time there was an email server problem that required looking at several emails root out the problem.
      Of course, the son next morning told upper management that I was poking into peoples emails.
      In the business world... no favor goes unrewarded.
      The mom was a bitch and the son a back-stabbing bastard.
      They teamed up in the hope to get me fired so the son could slip into the position.
      Months later, I left because they didn't fire the son or mom over it.
      The son did wind-up getting the IT position.
      About 2 years later there was a fatal server crash, he loaded the backups... all blank!
      I got the last laugh, there is a god !

    7. Re:yes, ignore office politics by ruir · · Score: 1

      If teachers are able to interfere in your job through politics, even more when it is in bad faith, then your manager is not doing his job. But then, nobody likes censorship. The best way to win this game is not to play it. I would not block games.

    8. Re:yes, ignore office politics by ruir · · Score: 1

      I have seen that movie too. Always a bad move to hire a son of someone with a ittle power.

    9. Re:yes, ignore office politics by bzipitidoo · · Score: 1

      Most answers to these questions are concentrating on the snooping. System admins should not snoop, unless specifically told to do so by someone in authority.

      But few are talking about office politics. Do not stick your head in the sand! Listening to the grapevine is not snooping. Learn what's going on the same way everyone else can, by keeping up with how the company's presentation did at the trade show and that sort of thing, not by abusing system administrator privileges to read private email and the like. You have an interest in knowing if the company is about to go bankrupt, be sold, or layoff a whole division. You also want to know if you have enemies and if so, who they are and why they hate and fear you so you can guard yourself. It may be that someone somehow views you as a threat to their job, and they'd like to get you before you get them. Doesn't matter that you aren't a threat, what matters is that they see you that way. You may be able to show them otherwise, and they'll stop trying to plant knives in your back. Or maybe not. There are a lot of sick bastards out there who want power so they can enjoy making others sweat, make their lives hell. You don't want to be surprised by your job being eliminated, and if that's likely, you want to know that with as much advance notice as possible.

      --
      Intellectual Property is a monopolistic, selfish, and defective concept. It is "tyranny over the mind of man"
    10. Re:yes, ignore office politics by SuricouRaven · · Score: 1

      I managed to mess up in editing to the extent of making a statement that cannot be logically true. Hmm.

    11. Re:yes, ignore office politics by Anonymous Coward · · Score: 0

      In my opinion it is not up to the IT department to regulate for what purpose the IT services are used. IT should provide te service that was requested. You say it is badly managed if teachers can influence IT, but isn't it equally bad for IT to influence class dynamics? Are the people in the IT department the teachers or are the teachers the teachers?

    12. Re:yes, ignore office politics by Anonymous Coward · · Score: 0

      Isn't it your job to help the teachers? It seems to me that if they ask nicely for you to do something a different way, and you ignore them like a jerk, they are totally justified in going over your head.

    13. Re:yes, ignore office politics by Anonymous Coward · · Score: 0

      Don't bother blocking games. just set the bandwidth for the appropriate ports to less than 1kb/second. So long as a single student is connected they'll just get crap performance. When a second or third student connects it's truly broken but they'll still sit around waiting for stuff to load.

      Result - no usable games, but the disruptive students still stay out of everyone else's hair.

    14. Re:yes, ignore office politics by SuricouRaven · · Score: 1

      Not network games. They wouldn't get through the firewall. In this school - and I assume most - the big problem is flash game sites. Students love them - flappy birds clones were for a while, but Happy Wheels used to be huge, and there was a big tower defense game fad too. We block them, of course - but students are persistent, and will go to great lengths. Even if that means spending an hour going through page after page of google results looking for a site that isn't on the blocklist. Some of them even discovered you can put 'game' into google translate and search on that to find whole new game sites that aren't blocked.

      We'd disable flash if we could, but a lot of education sites and various important testing services demand it.

  4. Use common sense by Anonymous Coward · · Score: 0

    Oops... this is the wrong site for that.

    1. Re:Use common sense by Anonymous Coward · · Score: 0

      What is common sense, exactly? It varies from country to country, culture to culture, town to town..

  5. Simple. by Anonymous Coward · · Score: 0, Informative

    "how do you preserve the impartiality/neutrality which seems (to my novice mind) necessary to be effective in this position" You keep your mouth shut about anything but your job.

    1. Re:Simple. by Z00L00K · · Score: 2

      I agree - unless something floats up that is outright criminal to the extent of prison time just leave it alone.

      If you find something that's severely incriminating, look for a new job.

      Being a sysadmin means that you have extreme rights and abilities to do stuff, but you shall also have the ability to keep your mouth shut. It's better to keep a distance than to end up on the wrong side in a conflict or legal proceeding.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    2. Re:Simple. by Anonymous Coward · · Score: 2, Insightful

      Snowden found a different job more important than the one he was doing. It was also his duty to report illegal activity. I think he did a great job.

    3. Re:Simple. by retchdog · · Score: 1, Funny

      this is a good guideline, but it's worth keeping an eye open for someone weak, yet brash enough to engage in criminal conspiracy. it's rare and i wouldn't plan on it, but it's an excellent opportunity to make a sideline income and develop a skillset suitable for a lucrative management position. i won't go into detail on the tactics, but they're pretty obvious. keep in mind, you want hush money and an intimidating rep; you don't actually want a confrontation. start with a moderate offer, on the lines of maybe 5% of their salary, and crank that up as time goes by.

      btw, start going to the gym now; yes, you can always kill the motherfucker, but it's much, much more effective to passively intimidate them.

      --
      "They were pure niggers." – Noam Chomsky
    4. Re:Simple. by Chas · · Score: 1

      Snowden found a different job more important than the one he was doing. It was also his duty to report illegal activity. I think he did a great job.

      Sure, but in the private sector, you don't have the luxury of exiling yourself to another country for the rest of your life and being seen as a hero.

      --


      Chas - The one, the only.
      THANK GOD!!!
    5. Re:Simple. by mjwalshe · · Score: 1

      To be honest for ano n profit the worst they might be ding is being naughty with donations - unless its a front for really naughty people in that case talk to you countries security service.

  6. Not sure why this is a question by GeekFreak · · Score: 5, Insightful

    I treat everyone's email the same: I don't read it. I may see subject lines but I don't see the technical reason requiring you to read them. If it's a temptation, might want to re-evaluate your own professionalism.

    The same with politics and gossip: keep it to yourself; do not participate. If asked a question, smile and decline to comment. Be polite and cordial but trust no one.

    Basically: do your job and stfu.

    1. Re:Not sure why this is a question by Anonymous Coward · · Score: 2, Informative

      I call bullshit on this. It seems to be true... but it isn't, not quite.

      IT is typically a support position, not the core business. That limits promotion potential. Worse, when done well it's supposed to be invisible by dint of not breaking down. You can do something about that by promoting yourself, by communicating really well, by showing what went well instead of having to announce another failure you're mopping up after. Like, you've done a bunch of maintenance and introduced a new service. You can announce that with a nice little (short!) blurb extolling the virtues of what you've done and how that helps the company in a way that'll be appreciated. Do this well and everybody'll know what IT is for, what it does for the company, and so on. You make yourself visible.

      The original question, though, was about office politics and gossipping you run into because you meet bloody everybody in the company, and about the accidental brushes (I would hope so, anyway) with stuff not really ment for your eyes. As to that, you indeed don't partake in and do STFU about.

    2. Re:Not sure why this is a question by Anonymous Coward · · Score: 0

      Also if you find stuff on their computer i.e. torrents, warez, porn and the whole reason you're even looking at the computer is because it is infected, clearly something more needs to be done otherwise you'll just be in that same spot in another week trying to clear up the computer again.

    3. Re:Not sure why this is a question by mysidia · · Score: 1

      I treat everyone's email the same: I don't read it. I may see subject lines but I don't see the technical reason requiring you to read them.

      What happens when you get a request from management to help them identify/bring to their attention people potentially 'abusing' the e-mail system, such as by e-mailing sensitive information out of the organization, or by identifying employee(s) sending e-mail that are obscene, abusive, harrassing, or contain inappropriate language?

    4. Re:Not sure why this is a question by Threni · · Score: 1

      Read it for a laugh, just don't tell anyone about anything you read, and you'll be fine!

    5. Re:Not sure why this is a question by Cheerio+Boy · · Score: 2

      I treat everyone's email the same: I don't read it. I may see subject lines but I don't see the technical reason requiring you to read them.

      What happens when you get a request from management to help them identify/bring to their attention people potentially 'abusing' the e-mail system, such as by e-mailing sensitive information out of the organization, or by identifying employee(s) sending e-mail that are obscene, abusive, harrassing, or contain inappropriate language?

      That's an official request from management and is part of your job at that point even if it wasn't before. Inform HR of what you've been asked to do and if there's a conflict let them hash it out. Document everything and keep a personal copy of the documentation in a safe offline place. If you get fired for doing your job you either have enough documentation to take legal action (if you can afford it) or enough to clear your name if it becomes necessary.

      --

      "Bah!" - Dogbert
    6. Re:Not sure why this is a question by wisnoskij · · Score: 1

      Well of course unless it goes strongly against your conscience or the law you do what you are asked.

      --
      Troll is not a replacement for I disagree.
    7. Re:Not sure why this is a question by Anonymous Coward · · Score: 1

      Here's "what happens":

      There's plenty of LEGAL reasons you might need to access them, but very little LEGAL reason for you to READ them, still. As an admin, it's just as easy to say "here's a text file dump of all email for User X's account in this handy password-encrypted file. To read it, log into heavily secured & audited system X, conduct your investigation, and let me know when you're completed, so I can blow away the VM you were working on and eliminate the chance of this data being improperly accessed.

      If you fear the request is somehow illegitimate, escalate to your own manager, HR, or corporate legal.

    8. Re:Not sure why this is a question by Anonymous Coward · · Score: 1

      HR

      You tell them you need to get approval from HR before you give them access to anything, and even better, you tell them you cannot sift through the email, that they will have to designate another non-IT person to read/go through the documents/email (best if it is HR).

      Stand your ground and they cannot give you crap for requesting that you do not put yourself in liable.

    9. Re:Not sure why this is a question by Anonymous Coward · · Score: 0

      Stand your ground and they cannot give you crap for requesting that you do not put yourself in liable.

      And at that point is where you get fired for refusing to do a job task from the higher ups.

    10. Re:Not sure why this is a question by X0563511 · · Score: 1

      Don't just decline to comment, that's far to open to interpretation.

      Play dumb instead.

      --
      For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
    11. Re:Not sure why this is a question by Anonymous Coward · · Score: 0

      Ask yourself: For most companies today, what is the differene between their "core" business operations and IT?

      I'm not talking about workstations here, but servers serving important business needs. If they are not operating to customer's needs, have outages, or other problems, the consequences doesn't necessarily reflect immediately on the bottom-line above other "noise" in business-data, but aren't they critical to success and customer trust? So why are companies and IT departments so afraid to measure those KPIs? Because they're afraid to expose how weak they really are, or how flawed their security-model is? And then they expect success??

      Even if email, phone or even network is down for a week, what are the effects?

      From my experience: The longer distance between "IT" and the "business-side", the less effective the organization, processes and even technology (because it's not truly supported or understood by the leadership). This is core ITIL knowledge btw, but sadly sorely neglected due to said "office politics", for lack of true leadership and organizational competence. And no, it's not just about having email up and running, those are simply the fundamentals.

      So, in order to bridge gaps between "IT" and the rest of the company, we absolutely have to be professional and trustworthy, but also talk with people and make personal connections!

      Mark my words: If "IT" is just servile and silent, it will be outsourced. There'd be no reason to have it in-house in the first place!

      On the other hand: There's ALOT synergy to be gained from making deep connections with IT and the rest of the organizations. Its there, ripe for the taking in most organizations! It's much more fun too, and you'll gain respect, not just for being a geek, but because you see the potentials and connections that many non-technical people just can't see!

      The BEST companies, look at ie. Steven Jobs-owned Apple and Pixar, have competent leadership. They know what they're doing AND know how to communicate with other (one way or another) AND focus holistically on the bottom-line.

    12. Re:Not sure why this is a question by ruir · · Score: 1

      I dont have them time to read their emails, I dont want to, and frankly, I dont give a shit about their emails.

  7. politics and stuffs by Anonymous Coward · · Score: 0

    Unless you're a professional ladder climber and/or backstabber (most MBA middle-management types), it's best to just stick to IT and keep stuff to yourself.

  8. Sound advice I was given by tyggna · · Score: 2

    Just keep the guy who does your yearly reviews happy and make him look good. Also, make his boss look good. If you're like me and have multiple bosses, develop your relationship with the one you think will hold that position longest. Don't burn any bridges unless you have to in order to keep your job. Every company has different standards of security, and an even wider variation of enforcement. Don't intentionally be a butt-head to anyone, and if you see anything that's off policy or could get someone fired, just politely point it out to the individual so they can correct it.
    As for dealing with sensitive information, I usually ignore it. You'll see lots of stuff you probably shouldn't as the only IT guy. Just file it away and don't bring it up again--even if it seems like a good idea or a neutral situation to do so. You don't want upper management finding out the IT guy knows more about the company than they do, or they'll (often unintentionally) make your life miserable.
    IT can be likable, but there will be a lot of people who will make your job harder because of their ignorance. Just do you best to educate them in a friendly way so you can work on more important things than dealing with office dunce's all the time.

  9. Don't look for logic by Zero__Kelvin · · Score: 4, Insightful

    Always remember that you are dealing, in your case where your internal customers are not IT savvy, that there is a reason why we refer to them as lusers:

    1) They have no idea how to do what you do, and need you to help them perform even the simplest of tasks
    2) What you do is so simple any moron can do it
    3) Their son / brother-in-law / uncle, etc. is much more of an expert then you. They re-install Windows for them every six months, and made their system much faster by upgrading from a 512GB drive to a Terabyte drive as well as much safer by installing three, count them three different Antivirus products!
    4)You are some kind of idiot, because you haven't done what their expert relative has done

    I wish I was kidding. The reality regarding your question is that as an IT professional you will have access to said sensitive information. It will only make you jaded if there is good reason to be jaded. If there is good reason to be jaded, run don't walk to a better gig.

    --
    Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
    1. Re:Don't look for logic by gnasher719 · · Score: 5, Insightful

      Always remember that you are dealing, in your case where your internal customers are not IT savvy, that there is a reason why we refer to them as lusers:

      If I ever hear any IT professional at a place where I work referring to end users as "lusers", I can promise you that the shit will hit the fan.

    2. Re:Don't look for logic by Kuroji · · Score: 1

      Local user, you twit. It doesn't mean 'loser'.

      The fact that the end users tend to look at IT as utterly useless except when something goes wrong, in which case it should have been fixed and prevented from going wrong even when it was the end user's fault, does however tend to promote such an attitude. But the IT guys would have to be idiots to use that term openly.

    3. Re:Don't look for logic by Anonymous Coward · · Score: 0

      He's not referring to end users dumb ass. He's referring to his co-workers.

    4. Re:Don't look for logic by Threni · · Score: 1

      Luser is most definitely loser. Because most users are idiots. No ability to partially diagnose or even use common sense to solve any problem (ie. if the problem persists when you log onto another PC why do you think your PC has a problem?)

    5. Re:Don't look for logic by RoombaRampage · · Score: 1

      In this case co-workers are end users. They are the consumers of the services that IT provides.

    6. Re:Don't look for logic by Belial6 · · Score: 2

      BS. the term 'luser' is specifically juvenile IT people thinking that they are being witty. They are not, and the lame excuse of 'local user' doesn't make their openly hostile attitude OK. The fact that you recognize one would need to be an idiot to use that term openly shows that you know full well that it is intended to be a double entendre.

      Any IT person that uses that term should immediately look for a different career path.

    7. Re:Don't look for logic by Zero__Kelvin · · Score: 1

      Any decent software developer will tell you that your if conditional results in a Code can't be reached compiler warning :-)

      --
      Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
    8. Re:Don't look for logic by epyT-R · · Score: 1

      My aren't we feeling superior today.

    9. Re:Don't look for logic by Anonymous Coward · · Score: 2, Interesting

      No, they don't need a master's, just a bachelor's degree and continuing education and training that will exceed the time invested in a master's and NEVER. STOPS.

      If you're considering IT to be equal to janitors, you are not the person who should be doing the job you are doing.

    10. Re:Don't look for logic by Bing+Tsher+E · · Score: 1

      This is a discussion of IT Personnel. It'd be hard not to feel superior.

      (the toner cartridge in that LJ5 on third floor east isn't changing ITSELF, btw...)

    11. Re:Don't look for logic by SuricouRaven · · Score: 1

      Everyone who has worked in end-user support thinks of lusers. Some of them say it, some have the social awareness not to utter the word, but they all think it or something to that effect. There are websites devoted to swapping stories of luser ignorance.

      My personal favorite is the user I met who used to manage all her documents by running word, going to save-as and dragging files around in the little save dialog, right-clicking to make folders and delete things. In her years of using a computer, she never figured out that you could go to start->documents.

      Runner-up is shared between all of those who have summoned me from across the building because 'sound not working' when someone has turned off the speakers.

    12. Re:Don't look for logic by katarac · · Score: 1

      Hilarious. Pointing out petty condescension is condescending, I guess.

    13. Re:Don't look for logic by Anonymous Coward · · Score: 0

      No, they don't need a master's, just a bachelor's degree and continuing education and training that will exceed the time invested in a master's and NEVER. STOPS.

      If you're considering IT to be equal to janitors, you are not the person who should be doing the job you are doing.

      And people that are real engineers never need to learn new stuff to keep up with times?

      I am an engineer. I build hardware and software. We have sales peoples to, that sells the stuff we engineers build.
      IT and helpdesk is a cost centre and a drain to the company. When was the last time the IT folks provided reveune?

      As I said, support folks, like janitors and receptionists but slightly better paid.

    14. Re:Don't look for logic by Anonymous Coward · · Score: 0

      Again, If I ever hear that derogatory term used by non-essential staff, like IT, Receptionists, Janitors, etc I would immedialtely have a meeting with that persons manager and a representative from HR.
      I would there suggest termination of employment, but would settle for counceling it manager or HR strongly wants to keep that person and it was a firsdt offence.

      If it was essential or otherwise valuable staff and it was just a first offence I would suggest counceling before termination.

      In any case it would go to that persons file.

    15. Re:Don't look for logic by I'm+New+Around+Here · · Score: 1

      Everyone who has worked in end-user support thinks of lusers. Some of them say it, some have the social awareness not to utter the word, but they all think it or something to that effect. There are websites devoted to swapping stories of luser ignorance.

      My personal favorite is the user I met who used to manage all her documents by running word, going to save-as and dragging files around in the little save dialog, right-clicking to make folders and delete things. In her years of using a computer, she never figured out that you could go to start->documents.

      Either we've met the same person, or that method is now taught in college.

      --
      If you think I voted for Trump because of this post, you're wrong. I voted for Dr. Jill Stein of the Green Party. Again.
    16. Re:Don't look for logic by I'm+New+Around+Here · · Score: 1

      You are too full of yourself. How productive are you when the computer network is down and you can't do your highly paid job? I'm sure you don't pull out a paper and pencil and design your next product. You call and demand the support team fix it, so you can work. So, without them, you are not bringing in any revenue either.

      By the way, you are as replaceable as the IT guy who knows how to fix the system.

      --
      If you think I voted for Trump because of this post, you're wrong. I voted for Dr. Jill Stein of the Green Party. Again.
    17. Re:Don't look for logic by Anonymous Coward · · Score: 0

      The IT support is likely needed more than you, don't let the door hit you on the way out.

    18. Re:Don't look for logic by Anonymous Coward · · Score: 2, Insightful

      Suffice it to say my experience differs from yours. Too often I ran into users of my software and of those that I may have written portions of, that discerned solutions and detected deficiencies I missed or did not take seriously, respectively. The former was an entire package I wrote to specifications given to me by the head of the firm I worked for (cryptic scribbled / partially illegible notes on scrapes of paper) who was a professional with at least one masters in computer science and the owner of the firm that was our client. Get the picture, the user of the software asked how to do something that the owner specified should never be allowed. So I said it was not possible, because I constructed to the specs I was given. That user found a way around it. I learned later the best specs are inclusive, where you get an overview from the upper level and details from the actual users on what their needs on how the package will actually be used. Now for the latter, the user of this accounting package told me records were disappearing and I assured her that was not possible. However, later when I was reading the code (probably to make a custom change) I discovered, yes the deletion code moved to an arbitrary record and deleted that record. So what you might perceive as a "Luser" was an intelligent human being that knew nothing about coding or database theory, but she knew enough that something was amiss. At the time I thought it was the lead of our firm's code and one of his "customizations", since in most respects I was a novice I was utterly stunned but kept my mouth shut. Later I was canned (rightly and soon gratefully) and my replacement, who I trained, though more experienced than I had the same fate at that company.

      I knew my knowledge was lacking, since I have never been formally trained to code. I like the writer of the request for guidance came from another science field, which made me see complexity that were for the most part absent. For example, Analysis is not quantum mechanics despite some overlapping terms.

      Advice to you, please control your excessive arrogance.

    19. Re:Don't look for logic by Anonymous Coward · · Score: 0

      2) What you do is so simple any moron can do it
      3) Their son / brother-in-law / uncle, etc. is much more of an expert then you. They re-install Windows for them every six months, and made their system much faster by upgrading from a 512GB drive to a Terabyte drive as well as much safer by installing three, count them three different Antivirus products!
      4)You are some kind of idiot, because you haven't done what their expert relative has done

      Regarding some of your bullet points, I've never had this problem. If you know what you're talking about and are confident with your knowledge and statements to back up that knowledge no one would ever make these kind of statements to you.

    20. Re:Don't look for logic by Cederic · · Score: 2

      You condescending fuck.

      If the IT support teams at my company downed tools we'd start losing revenue within minutes, start losing profit within hours and start losing customers daily.

      I'd give the company around 3 weeks to reach an irreversible point from which it wouldn't recover.

      IT may be a cost centre but good luck running your business without it.

    21. Re:Don't look for logic by Anonymous Coward · · Score: 0

      If there is good reason to be jaded, run don't walk to a better gig.

      And this has been a key to noticing when a company is soon to fail. If they're hemorrhaging IT staff (externally noticed by lack of growth but large number of advertised IT positions), that means the IT staff knows something is up. And it doesn't have to be from reading confidential-info. Workstation support IT are usually the first to get all the good gossip in a large org since they're constantly moving from desk to desk, and people will blab away while they're working on their computer. If a whole IT group leaves a company. Sell, quit, whatever. Just don't deal with the company any more.

    22. Re: Don't look for logic by Anonymous Coward · · Score: 0

      Non-essential? I would love to see how a modern business would run without any of those people you've mentioned. Your arrogance is just as bad as person you're trying to chastise.

      While I do agree that IT needs to use terms like 'luser' inn any method pointedly derogatory, I highly disagree with your reasoning as to why.

      Your tone conveys the exception it's for 'essential' staff demean and belittle someone for a lack expertise/savvy. Users are the reason any business there, you don't insult them.

      To your comments about IT being support, a cost centre and non-essential... That is a joke. IT isn't support, it is enablement. Without it a vast portion of business couldn't run, especially as it is scaled upwards.

      While IT may not be the direct provider of income in most businesses, it enables that provider and has the potential to amplify it.

    23. Re:Don't look for logic by Ol+Olsoc · · Score: 1

      BS. the term 'luser' is specifically juvenile IT people thinking that they are being witty. They are not, and the.

      And how! The real term is "looser.'

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    24. Re:Don't look for logic by Anonymous Coward · · Score: 0

      That's just arrogance, limiting YOUR potential. I've met many highly competent people, who just can't see further than their own knowledge, as if anything outside their brain and domains somehow doesn't exist.

      Btw, part of enlightenment is to acknowledge that we are so small, such attitudes really are just comical. This is scary for most people, because to go outside your own expertize, would be to boldly step into the unknown. It'll stay mostly unknown too, since you can't be an expert on everything, no matter your own deluded belief in your own individual intellectual processes (which is limited). But this is what managers need to do anyways, because there is a step UP from pure technical specialization, and that is organization and process management. We actually need more competent people into such positions, but such attitudes are preventing that effectively.

      Do you think the airline crew and passengers are referred to as losers by the captains as well, and would you want to fly on such a plane piloted by such short-sighted remarks?

      Moral: People working in a company have different roles to in order to complement each other. If they'd all have the same role and knowledge, you'd need to fire most of them. Also: Any person can probably fill at least one other role (probably several) at the company, if given the chance and having a willing attitude.

      Why do you let your ego limit yourself?

    25. Re:Don't look for logic by sjames · · Score: 1

      When was the last time the IT folks provided reveune?

      Every time a sales guy enters an order into the system and a sale actually takes place complete with product delivery. Shut down IT and the sales guys' productivity will plummet.

      In all honesty, do you really think anything that didn't actually contribute somehow to profit (or even continued existence) wasn't tossed out the window long ago?

    26. Re:Don't look for logic by dbIII · · Score: 1

      or that method is now taught in college

      Seems frequent enough. I've had to populate desktops with icons for people who seem scared of the "start" menu.

    27. Re:Don't look for logic by dbIII · · Score: 1

      You don't provide revenue either but instead contribute to the product that eventually gets sold. Others also contribute. You are a "support" person to the salesfolk if I apply the same reasoning you are applying to IT.
      BTW, I am also a professional engineer but I mostly run computer systems for others these days and assist with the development projects for others. "IT" is not as cut and dried as you like to pretend. Many people would call your job of hardware and software development "IT" and be confused that you seem to be lumping yourself in with janitors.

    28. Re:Don't look for logic by Anonymous Coward · · Score: 0

      You're wrong. Want to know why you're wrong? You apparently have never served IT support directly for type A business people who believe they know every facet of their company because they have an MBA. These people exist and they are real. Sometimes they tell you what their nephew did to fix their problem. Sometimes they just ignore your memos detailing why sharing passwords for user accounts is a bad idea.

    29. Re: Don't look for logic by Anonymous Coward · · Score: 0

      Methinks the term fits him like a glove, and in his adolescent rage he needs to lump IT with Secretarial and Janitorial staff in a pathetic attempt of self validation/elevation.

    30. Re:Don't look for logic by Anonymous Coward · · Score: 0

      Broseph, I've served IT support directly for nearly every C-level executive at my very large, very recognizably-named financial services firm. Many of the people I've helped have been "Type A business people," (you don't get to be C-level at this company without being pretty "Type A") and not a single one of them has ever talked shit to me - and we're talking that I get shipped off to their private residences to resolve issues for them at home, on weekends, on vacation - not just string the cable to their offices at headquarters.

      Why don't I get shit-talked?

      I've got a pretty good bet I know the reason. The reason is, I'm actually good at my job, and don't treat "people who are ignorant of IT practices" as if they're subhuman shit-stains. I treat them with respect, I ask the right questions to arrive at a diagnosis, and I listen to them and allow them to speak when they're describing the problem to me, instead of interrupting them to tell them to shut the fuck up because I don't care about their nephew.

      And yes, I've *heard* that line - "My son told me to try X, Y, Z... but it didn't seem to help." I then file that away, because sometimes the smallest comment they make has extreme relevance to their issue. Then, I proceed to redirect them away from being "helpful", and inquire about their family, if they seem inclined to talk or hover.

      "My son said I should..."
      "Ah, that's close, but this problem is a little different, and can't be solved that way. What's your son do?"
      "He's a lumberjack."
      "Oh I bet that's a job with a hundred interesting stories."

      I'm not there to insult the guy's family and yell at him about how a lumberjack couldn't possibly know how to fix this problem. I simply redirect the conversation while I work. If the kid's a college student, "Oh really? What school's he at? What's he studying? Wow, that's great - Ivy League!" If the kid's an unemployed hobo, "Ah, taking some time off to see the world and think about his options, huh? Tell him to try and make a stop in Lisbon, it's a beautiful city!" It's called redirecting the conversation, and it's an invaluable tool for anybody who has to deal with human beings on a day-to-day basis.

      If you're so thin-skinned that you can't handle someone saying, "So my nephew said I should try X," without losing your mind or getting butt-hurt about it, then you don't belong in IT, or any other job which entails responsibility and interaction with humans. And if you're not smart enough to explain why what the nephew said is incorrect, perhaps you should stay in the basement imaging new laptops instead - there's always a call for push-button monkey work like that.

    31. Re:Don't look for logic by Dan541 · · Score: 1

      I am an engineer. I build hardware and software. We have sales peoples to, that sells the stuff we engineers build.
      IT and helpdesk is a cost centre and a drain to the company. When was the last time the IT folks provided reveune?

      As I said, support folks, like janitors and receptionists but slightly better paid.

      You're IT, why are you mocking it?

      --
      An SQL query goes to a bar, walks up to a table and asks, "Mind if I join you?"
    32. Re:Don't look for logic by Anonymous Coward · · Score: 0

      Yes, one who looses the rope knot so that one may untie the rope.

    33. Re:Don't look for logic by Anonymous Coward · · Score: 0

      If I ever hear any IT professional at a place where I work referring to end users as "lusers", I can promise you that the shit will hit the fan.

      We only do it when the lusers are out of earshot.

      Grow a sense of humour man.

    34. Re:Don't look for logic by ArhcAngel · · Score: 2

      (the toner cartridge in that LJ5 on third floor east isn't changing ITSELF, btw...)

      Toner is a consumable and IT does not provide toner nor facilitate their replacement. Please feel free to open a ticket to IT once you have managed to jam the toner cartridge in upside down and sideways for technical support.

      --
      "A person is smart. People are dumb, panicky dangerous animals and you know it." - K
    35. Re:Don't look for logic by ArhcAngel · · Score: 1

      Wait? You haven't met anyone who's monitor is broken because the power was off?

      --
      "A person is smart. People are dumb, panicky dangerous animals and you know it." - K
    36. Re:Don't look for logic by Anonymous Coward · · Score: 0

      I know plenty of engineers that build life safety equipment but don't understand the security risks of leaving an open telnet port on a device that requires access to the internet to function. It saves money by both cleaning up the messes that engineers create, teaching them how to code and troubleshoot, telling them what error messages mean, and generally making sure you can even function. I'm not being hyperbolic here, I've literally had all of those come from "engineers" in a large corporate environment. Let me put a point on this for you, without IT you make absolutely zero dollars in revenue. All your money comes from the work that we do.

    37. Re:Don't look for logic by Anonymous Coward · · Score: 0

      Perhaps you should learn grammar and spelling and then take a good hard look at what your organization does to earn that title before pissing off the one group that pulls your bacon out of the fire on a regular basis. Sometimes people just need to blow off steam, it's common and it's necessary. You're obviously a terrible manager if you've never dealt with this in any way other than firing, and you're probably shooting yourself in the foot you pretentious moron. Now get back to work, your content is being monitored.

    38. Re:Don't look for logic by david_thornley · · Score: 1

      Alternately, how productive are you when you don't get paid? That could be a function of HR or Accounting. When there's nobody to greet your customers and refer them to the right person? When the smell from the men's room starts reaching your desk and your wastebasket is stuffed to overflowing?

      There's numerous things a business just can't do without, but which don't really make money themselves. These are cost centers. If they weren't important for the company, the company would just cut them, but it's a question of minimum cost to ensure normal functioning, as opposed to possibly adding resources to improve functionality beyond normal.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    39. Re:Don't look for logic by Anonymous Coward · · Score: 0

      Someone sounds butthurt, honestly. Most IT at all the fortune 500 companies I've worked in, which is all of them, refer to end users in far more graphic and disparaging terms than the comparatively clever "luser." Which no one ever says local user, ever, ever. We either call you local, or remote. Here in Houston at least.

    40. Re:Don't look for logic by Anonymous Coward · · Score: 0

      As someone who has spent no less than 4 years off and on in various service desk and desktop support roles which force you to interface with the customer, this is 150% correct. There are always the belligerent, stupid, impatient assholes. They are the worst, and they are why we use terms or why we envision end-users as fat Jabbas spilling mountain dew and cheetos on their keyboards. There are also people that fancy themselves tech-savvy and they kind of want to learn, but only enough to be dangerous and annoying. And their relative, or their IT guy friend, did it differently, so you are automatically wrong and unqualified.

      Even the smart people, the programmers and engineers who inevitably need help - they can be the worst. I grew up with people far better at programming than me and they don't know SHIT about computers. They are utterly helpless when it comes to anything Windows or application-related if it breaks, some won't even google because they think fixing it is beneath them. I literally just had a best friend who worked for Harris and then Nintendo over in Frankfurt, come back to America and he shipped his desktop back. His motherboard somehow died in transit. He straight up paid some mom and pop IT guys in Melbourne, FL to fix his computer - including a new graphics card and replacing the mobo with a ghetto one from the sounds of it - about $200 or $300 because he didn't want to take the effort to do it himself.

      End users are idiots. There are no exceptions. Ever. Depending on what you do to your machine, and how you behave to us, you will be treated accordingly behind closed doors.

    41. Re:Don't look for logic by Anonymous Coward · · Score: 0

      There are also end users that you honestly do want to help because they are nice people, they admit that they aren't God and they don't blame you for the system that in all likelihood is something you aren't responsible for.

  10. Seriously by Anonymous Coward · · Score: 0

    If colleagues cannot depend on the discretion of their IT support, then they need new IT support.

    OTOH if the information involves illegal activity, perhaps one ought to consult management. If management does not respond, or responds in an unethical way, maybe IT support needs to find new colleagues.

    Fwiw

  11. ignores by ghighi · · Score: 1

    You can't be liable for having knowledge of information that people couldn't be bothered to encrypt. Executives can be lazy with their data and you can't be expected to do special efforts when they didn't do any to begin with. That being said, I would chose to ignore. I have been there, with information very sensible for a very big company, and just ignored that. A colleagues acted upon that same knowledge in not so subtle way and we almost got troubles for it; it was harmless so they pretended they did not realise we had access to the documents and left it at that. It could get you fired though, so you might want to just stfu. Now there would be two exception to that rule: I you were in a position where you could blow the whistle on some important information for the public good, or if you could get personal gains in the process. It's a moral decision q:

    1. Re:ignores by sumdumass · · Score: 1

      You can't be liable for having knowledge of information that people couldn't be bothered to encrypt. Executives can be lazy with their data and you can't be expected to do special efforts when they didn't do any to begin with.

      I completely disagree. It is in fact your job to assist in this if you are IT. You are in a trusted position and if you gain access to something due to that trust, it is a duty to keep that trust (unless it reveals something so unconscionable that you have to remove yourself from that position of trust).

      The rest, I agree with. An example was not something that happened to me but to a lawyer in a firm I administrated. The IT for another law firm for the plaintiffs in a lawsuit was having drinks bragging about some things he saw. He was making the statements as if in idolization of a couple of the lawyers at the firm. Turns out, one of the defendants of the same suit was there also and over heard some of the conversations. This led to finding evidence that completely nullified the lawsuit as the contract had been essentially broken but not officially broken by the plaintiffs before the breach in question they were suing over. In essence, the plaintiffs wanted out of a contract and were taking steps to void it before those steps ended up causing a failure in another party to the contract from delivering. Their steps to secure resources when they voided the contract removed the availability of resources from the market making the defendant in default of the contract obligations. Instead of voiding the contract, they decided to sue for the breach to recover expenses of setting up their in house facilities to do the contract work themselves- which they planned to do all along.

      So even just telling friends outside of the job can cause things to come back at awkward moments. You have to forget you even noticed the information.

    2. Re:ignores by Anonymous Coward · · Score: 0

      I completely disagree. It is in fact your job to assist in this if you are IT. You are in a trusted position and if you gain access to something due to that trust, it is a duty to keep that trust (unless it reveals something so unconscionable that you have to remove yourself from that position of trust).

      I worked for a big company that is known to be slightly paranoiac when it comes to information. It's big enough that the encryption policies were set way higher up the chain, and paranoiac enough that every single employee was given the tools for encryption (PKI, smartcard based software) and the corresponding training. It's worth noting that the company had outsourced IT everywhere else - our team being a notable exception - so company policy clearly stated that anything stored on a server that is sensibe must be encrypted.

      So no, I can't be held responsible if an executive can't be assed using the tool he was trained to use and crypt this very sensible information. That's also why we got away with nothing more than a dubious frown from our bosses. We may have had knowledge of the information but making a fuss about it would have meant scolding an executive which nobody want to be doing.

  12. LOPSA/LISA Code of Ethics by David+E.+Smith · · Score: 5, Informative

    Read the System Administrators' Code of Ethics and take it to heart. Even if your job title doesn't include the words "system" or "administrator."

    It's actually pretty easy to ignore the content of an email if you're focused on the email delivery process (mail server logs, the headers of forged/spam mails, things like that). Similarly, if you're doing FTP hosting or file drops for customers, you rarely need to dig into the content of the files themselves to troubleshoot upload/download problems. There are rarely reasons to dig into the content of whatever you're working on. It does come up, if (for instance) some piece of email has wacky malformed content that keep crashing the mail client, but IME those situations are uncommon.

    I used to work at a mom-and-pop ISP, in a small town. Our customers included the local police and fire departments, City Hall, and most of the larger law offices and accountants' offices. Since we provided email and Web hosting (among other services), I certainly could have made some locals' lives very interesting. Hell, I had access to the email of everyone in my company, including that of the owners to whom I reported. I'll admit to having been tempted once or twice, but I'm proud to say I never abused my privilege.

    1. Re:LOPSA/LISA Code of Ethics by The_Revelation · · Score: 1

      I'd say David is fairly spot on. The only additional thing I recommend is when arranging to do work on any computer is to ensure the users know to close any sensitive documents and save all their work to relieve any responsibility in this area.

    2. Re:LOPSA/LISA Code of Ethics by sjames · · Score: 1

      I prefer to avoid seeing (or at least actually reading and comprehending) stuff on other people's PCs. Not just for legal liabilities and such, but there are some things they might be emailing about that are perfectly legal but might send me running for the brain bleach. I'd rather avoid that and the subsequent awkwardness.

  13. Just ignore it by Anonymous Coward · · Score: 2, Insightful

    Whether I'm working in IT or another area, I try to ignore what is on people's screens. I consider this a simple matter of manners, not an IT issue. You don't read over other people's sholders, do you? Do you feel the need to act on every piece of overheard gossip or twitter/facebook post? Dealing with other people's computers should be treated much the same way you treat overheard snippets of conversation on the street. Ignore it and move on.

    1. Re:Just ignore it by Anonymous Coward · · Score: 0

      I do the same. I used to have a guy who works at a major telecom company who has an office here in Texas - before I actually moved to texas (Not comcast fuck those fuckers) and he always had the same iron maiden wallpaper, or would eventually change it to another iron maiden wallpaper, and I always wanted to be like "Dude I too am a giant maiden fan" but in general I always just ignored everything that existed on the end users machine whether it was cool or not.

  14. well.. by Anonymous Coward · · Score: 0

    it gets better..wait 'til some higher up comes and asks for a dump of so-and-so's inbox

    1. Re:well.. by 1s44c · · Score: 1

      Fix that before it happens. Tell everyone to never use a work email for personal mail. Tell them to get a free webmail account for personal stuff instead.

  15. Not sure why this is a question by Anonymous Coward · · Score: 0

    for the most part people who stfu and do their job go unnoticed and usually see no promotions.

  16. I've been in your position by neiras · · Score: 5, Insightful

    You can never ignore office politics. You don't have to play the game actively, but you do need to be aware of what's going on around you, who is in what camp, what the major conflicts are. You have to cross battle lines regularly to do your job; you can't afford to be seen as a member of the 'enemy camp' by *anyone*.

    As an IT guy you need people to trust you, which means you need to be ethical. If you see something you shouldn't know, don't go chattering about it.That kind of thing does get around, and you'll lose trust instantly.

    Nothing's stopping you from making personal career decisions based on the information that you come across in your daily work. For instance, if you see that the company is about to be liquidated and you don't want to be around for the mess, by all means polish your resume and start interviewing. Just don't assume that just because you saw something you have the whole picture. You could end up feeling stupid when the private email you saw turns out to be a deliberate test of your trustworthiness. It does happen.

    Keep your mouth shut about the things you see. Look after your career and reputation. Be aware of politics, but abstain from participating wherever possible. After a few years when you have trust and credibility, you can consider climbing the ladder a bit and playing the game - you'll have capital to spend.

    1. Re:I've been in your position by Anonymous Coward · · Score: 0

      I love being an outside software consultant. I get to see everybody else's office politics and leave them behind. The downside is... I have no idea what is going on in my own office. And I dont care.

    2. Re:I've been in your position by KevMar · · Score: 2

      In IT we have access to everything and that means that our trust and integrity means everything. We will see things that are very personal, we will know things that are very sensitive, and people will trust us.

      If they question our integrity, our trust worthiness, or even our respect for authority then we lose our value to the organization. Once they start to question that, then you won't be able to get it back.

      But if you maintain high standards in IT and gain absolute trust from your coworkers and administration, then you can do some amazing things.

      --
      Im a gamer, not a grammer major. This post is full of spelling and grammer mistakes.
    3. Re:I've been in your position by Anonymous Coward · · Score: 0

      As an outside consultant you are usually the potential enemy of everyone working for your client.

    4. Re:I've been in your position by __aaclcg7560 · · Score: 2

      I did a PC refresh project where I came upon a cubicle that had 40+ half-filled cups of coffee with mold growing at different stages. After consulting with my project manager, the user didn't get a new computer and the daily report noted why. Both the user and the moldy cups got the boot shortly thereafter.

    5. Re:I've been in your position by Antique+Geekmeister · · Score: 1

      > As an IT guy you need people to trust you, which means you need to be ethical.

      You need to _appear_ to be ethical to gain trust of co-workers, and to improve your position. I'm afraid to say that this is orthogonal to doing a good job at IT. It's often much, much easier and safer to appear trustworthy by being clear, honest, and open. It reduces the complexities of maintaining various approaches to various people.

      But don't mistake such approaches with technical competence or business success.

  17. Be a Professional by Anonymous Coward · · Score: 1

    Regrettably, it seems you have no one to show you what a "professional" is or how to do "excellent" work. I pity you.

    Your job is to do IT work. The person, the persons attitude, the person's opinions and beliefs do not preclude their need for good-to-excellent IT work. Do the work and you will please most people. Do, as a previous poster stated, please your boss and the one who signs your check.

    If you do a good-to-excellence job, you may have earned the right to answer questions about your person, your opinions and beliefs IF YOU WANT. Even Democrats and Republicans can wholeheartedly agree about things like the local sports teams or colleges. You don't have to talk about everything that enters your head to every other person.

    You don't need to be impartial or neutral to do your job.

    A sysadmin has a code of ethics. Check SAGA for the official organization's code. The information you receive through actual IT work is not yours. For example, it may be necessary to see stuff that is confidential but it is not your right to disclose it. Keep your mouth shut. It also means that when the manager wants to look at all his employees files, you refuse unless it is a bona fide emergency (and provable). You have to protect the privacy of all the people on your network.

    God help you because nobody else is.

  18. Career options ... by Anonymous Coward · · Score: 0

    Just about everyone where I work has a foible that makes them unique ... but they know they can trust me to keep it to myself. There's apparently a coffee-machine crowd that talks, and tells each other who can be trusted, without needing to reveal details ... go figure.

    If you want to 'advance' in your career, use all the info and dive into office politics, it's the only way.
    If you want to be a professional, your work is to enable their work, and the content of mail is none of your business.

  19. risk vs reward by irond · · Score: 1

    You always need to look at the risk vs reward aspect when determing whether or not you should pay attention or stick your head in the dirt. If the potential consequences are high, but reward is little, then stick your head in the dirt. If the consequences are low, but the reward is high, then I would pay attention.

    The hard part for you, is determining what really matters to you and what risks are unnaceptable. And this is also highly dependant on what normative ethical system you subscribe to.
     

  20. There's no "grey area" by msobkow · · Score: 5, Insightful

    As an IT professional, you will have access to data that regular employees don't. You keep your mouth shut and you don't snoop. Period. You only look at as much as you have to diagnose and fix problems; the details are irrelevant.

    It's called "being professional."

    Think of it as the equivalent of lawyer-client or doctor-patient relationships.

    --
    I do not fail; I succeed at finding out what does not work.
    1. Re:There's no "grey area" by irond · · Score: 1

      Legally speaking, and depending on where you live, lawyer-client and doctor-patient relationships have defined limits, and so should "keeping your mouth shut". For example, if I accidently discovered plans, documents, or other communications that would otherwise be in violation of the law, or indicate conspiracy to violate the law. I would speak up. If I could help spare someones pain and suffering, I would speak up.

    2. Re:There's no "grey area" by gweihir · · Score: 2

      There is only one advice here: Do not. Unless you are a police officer (or live in certain fascist states), you have no obligations to report suspected crimes. And if you make a point of not reading the data you have access to (and you decidedly have no obligation to read it), you cannot be tempted anyways. And then you can always say honestly that you were being professional and did not look if it hits the fan.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    3. Re:There's no "grey area" by Anonymous Coward · · Score: 0

      Think of it as the equivalent of lawyer-client or doctor-patient relationships.

      Except you are not getting paid like one.

    4. Re:There's no "grey area" by Reziac · · Score: 1

      Not only that, but there are enough examples of the person who brought something to police attention being the one who is suddenly under the hot light, that reporting a possible crime is not a personally safe action. (And IMO anonymous reporting is questionable; it's too often abused.)

      As to clients' data -- the GP has a good point. If you're still interested in snooping, you're not mature enough to behave professionally.

      --
      ~REZ~ #43301. Who'd fake being me anyway?
  21. Sgt. Shultz from Hogan's heroes ... by urbanotter · · Score: 1

    I see nothing ... I hear nothing ...

  22. I'm really hoping you are smarter than that by Vip · · Score: 5, Insightful

    Never get involved with reading others' emails, documents, etc., that you are not required to be privy to.

    Never ever let the temptation allow you to see others' performance reviews, salaries, politics. I've seen how it leads to telling someone else and then they become the go to person for information. And if the information is bad and they didn't share it, even though they had no idea, well, they didnt' say that there was a problem, the @$$#013! Hell, I've seen someone with access to the HR database pull up salaries of EVERYONE and share it out. "Oh, can you tell me how much Jason Mcboogerhead is making? What?!? I'm making $1k less?! WTF, time to march off to the manager!!!" [A manager who was stunned at the level of knowledge! AFAIK, no info was given out about how the salary info was found. I found out later when it was offered to me.]

    Ignore any overheard conversations, it'll only be a couple of people talking, who knows the truth and what really is going on? You must throw out any info you "accidentally" pick up too. The obvious is the missing context of the info. As a manager, I've had other directors and managers openly talk about staffing, budget, bonuses, performance or lack thereof, in front of me. In all cases I threw away what I heard, after all, all I'm hearing is a snippet of a longer discussion. It's not my business to try to save John's job if he's pissed someone off, so I'm better off not worrying about it.

    Sometimes I received a list of users to be locked out of their accounts. The only reasons to receive such a list is that they are being laid-off/let-go or in a heap of trouble. I never shared such a list with anyone. It was given to me, as a manager, in confidence. Keep that confidence. Even after the firing, I still didn't tell anyone, there's no point or net positive to be gained.

    In another instance I was at a company that changed their HR such that you logged into a page, and it told you your salary, OT rates, etc. You could print your confirmation of employment for loans and such there too. But there was a bug. This bug allowed me to view everyone's salary, their bank account info and some other stuff in a nice neat chart. I immediately picked up the phone and called head office IT Security and talked them through the bug. They fixed it, phoned me back to test with me on the phone, thanked me and sent off a thank you cc'd to my manager, director, etc., praising my immediate response and "help" in fixing it.

    What I didn't do was say, "Hey everybody, look at this!" and print it off, etc. Nor did I read further than a few lines and then remove it from my screen. To this day, I run into some of the higher-ups from then from time to time, they still remember me, who I was, only because of that email and that to them I was trustworthy.

    It's not up to you to solve office politics, who said what to whom, or anything else. You are there to do IT. So do it and maintain your dignity and professionalism and just don't even think of looking.

    You, and hopefully everyone else, will hopefully see that you are in a position of trust. You are trusted by many to keep secrets. If you can do that, it only helps your reputation. If someone can actually say you are trustworthy in your IT job then you've accomplished a lot and it only helps down the road when you want to switch jobs.

    Vip

  23. So this is how it works by Anonymous Coward · · Score: 1

    In either case: how do you deal with the possibility of accidentally learning something you're not supposed to know? E.g. troubleshooting a user's email program when they've left sensitive/eyes-only emails open on their workstation.

    Pretty simple really. To do your job professionally and ethically, you avoid discovering sensitive information to the greatest extent. If the situation truly needs exposing you to private information or, you do it accidentally, you keep your mouth shut about it.

    Unless, of course, you are someone eating fish tacos inside an NSA control room and delightfully reading all the data that passes through.

  24. Have you ever thought about going to the darkside? by Anonymous Coward · · Score: 0

    I have a friend who was in a government IT position and was sometimes required to investigate people for misconduct and ultimately get them fired or jailed. It was basically his job to snoop and it weighed on him very hard. He ended up going working at a little, low stress computer repair shop for about 100k less and was happier for it.

    Me, on the other hand :) I always remind people that I don't want to know what they are doing on their computer, and if I do come across something I can't unsee it will stay with me. The implication here is that I'm cool and just want to help them, but in the very back of their minds they know that I AM NOT TO BE FUCKED WITH, because I have a firm grip on all their secrets/balls. This unspoken understanding has kept me employed and duely respected for 17 years in IT now. I've been told many times that I would be pretty dangerous if I decided to use my skills for evil, and I'm always like: "Yah, never forget that. Please don't hesitate to call me if their is anything I can do for you and I hope you have a splendiforous day!"

  25. The mind is a dangerous thing by gwstuff · · Score: 1

    Just for fun, answer this question and quickly move on to reading the rest of my post. Explanation at the end.

    "HOW MANY animals of EACH KIND did Moses take on the Ark?"

    The mind is a dangerous thing when presented with incomplete information -- it just extrapolates it, sometimes even substituting the incomplete original version with the extrapolated raw version. You might *think* you saw something noteworthy, but it was only your mind showing you a rabbit on the moon.

    This is one of the chief values of privacy - to be able to keep information that was meant for your perspective, and is not ready to show to the outside world, to yourself.

    So I would say ask yourself this question: Is there any ambiguity in your mind about your anticipation of the needless loss of life or property based on what you have seen. If there is, then the benefit of doubt goes to the person you spied on. Consider what you saw as an aberration... mangled data that cannot be trusted.

    As for that question - Did you answer two? It was Noah, not Moses who gathered animals on an Ark.

    1. Re:The mind is a dangerous thing by gweihir · · Score: 0

      Nice! Of course I am an atheist, so I am not an expert on any elaborate fantasy people cook up to explain reality, but still.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  26. Ignore it by 1s44c · · Score: 1

    If you were not officially told then ignore it.

    Don't backstab anyone. Don't read anything without permission. Don't get involved in anyone's infighting. Do your best to help all your customers, even if they are trying to undermine you. Play politics only as much as you have to, people will try to play you. You have to be aware of it and respond tactfully.

    Your duty to report serious criminality overrides these rules. Your duty to report gross immorality may override these rules, you have to decide that one based on what you believe in.

    1. Re:Ignore it by gweihir · · Score: 1

      Typically, there is no duty to to report serious crimes or any crimes at all, except for police officers. (They are not human beings in that regard, just functional elements. Their personal morality has been removed.) Some limitations apply, especially in states with fascistic tendencies. But there basically is no way to commit a serious crime via email or files, so in most cases you have zero obligations to report anything even if you know. Of course, it is better not to know ad the very act of snooping could put you into jail as well, and rightfully so.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  27. CYA by Anonymous Coward · · Score: 0

    Cover your ass.

    Explain to a user before working on their system that they should close all content (not just E-mail) and that they should save as appropriate to ensure data loss protection. This way, you can also reboot their system as necessary, and if ever something comes back regarding eyes only material, you can say you asked the user to close all content before working on the machine and that this is your personal policy to prevent such situations.

  28. Ostriches sometimes, yes by Trepidity · · Score: 3, Insightful

    Other animals that IT personnel may impersonate include canaries and guinea pigs.

  29. Rules for IT is "IT Rules". by 140Mandak262Jamuna · · Score: 0
    The main goal of IT is to provide security to the company network. You must accomplish this by any means necessary. If it means stopping every one else from doing their job, so be it. Stop them. Most of these dim wits who think they are working, always create problems for IT. For IT to be efficient they have to be stopped. So stop them.

    Once you have established the rule, "IT rules", most people will cower before you and try to get their work done without offending you or getting on the wrong side of you. That means you can celebrate "Mission Accomplished". Your company will have a few that know how networks work and know a smattering of knowledge about Unix or Linux. They might have even served as root of some lab or the other in the grad school. Find them, stop them completely on their tracks. Thwart every one of their moves. Either they leave you alone, or the leave the company. I T should have unquestioned authority over the corporate infrastructure, and ideally there should be no one in the company capable of questioning you.

    So the rules for IT is "IT Rules".

    --
    sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
    1. Re:Rules for IT is "IT Rules". by dbIII · · Score: 1

      Well that appears to be one workplace that sucks.

  30. You are not Switzerland by Anonymous Coward · · Score: 0

    > Do you find yourself deliberately ignoring office politics

    It's a slow form of career suicide. The corollary of being neutral is that there are few, if any, people in the higher echelons on your side when it comes to promotions, good assignments, and layoffs.

  31. Information Is Power by Anonymous Coward · · Score: 0

    From the 1940s through the 1960s do you know who the most powerful and feared man in Washington was? It sure as hell wasn't the President, or any congresscritter. It was J. Edgar Hoover. This was a man in a position to dig up dirt on anyone and everyone. Every politician from Presidents to lowly clerks feared crossing him for what what he knew could end careers. Many People believe that he may or may not have ordered the assassinations of many high profile figures in the 60s.

    The point is use that information for your own benefit. Don't share it, and don't use it unless absolutely necessary. Wait for the right moments to strike. You are in a prime position to find the key players, make friends on all sides and play them against each other. If you play your cards right, in a short period of time, you should have a prime high-paying, do-nothing executive position and nobody would dare fire you.

    Also, read some Nicollo Machiavelli some time. Great stuff!

    1. Re:Information Is Power by Cederic · · Score: 1

      Sure, good luck with that one.

      After all, you're talking about playing with the big boys here. They got where they are because they're good at it, not because they lucked into some useful information.

      Make just the slightest mistake when you make your moves and you'll be obliterated. And lets face it: if you're in IT it's probably not because you have great people skills, political acumen, charisma or connections.

    2. Re:Information Is Power by Anonymous Coward · · Score: 0

      *woosh*

      Let's project something on you: lack of irony much? ;-)

      Truth be told, this is exactly how IT rules some companies, especially those dependent on long-term employees who "built it up" (from my own experience).

  32. part of the job by markdavis · · Score: 1

    First, I wouldn't say a "50ish" people company is "mid-sized" :) But that isn't really your question.

    I can only speak for myself- I can and do see things that are confidential. It is pretty much impossible for me not to. I deal with it by focusing only on my work. Most of the time I don't even really "see" what it is I am looking at... intentionally glancing away or closing things that are not part of the scope of my assistance. Unfortunately that doesn't always work and am exposed to things that get "registered" in my mind. Sometimes I see things that are disappointing or disturbing... but it is my job to retain confidentiality; that is part of being a professional.

    The hard parts come when/if I see something that is:

    1) Against our IT policies (mostly security practices)
    2) Against company policy
    3) Against the law
    4) Immoral

    Thankfully, after doing this for 27+ years, I have yet to consciously run into anything illegal or immoral. I have run into things against policy and there have been times I had to report it or deal with it... just depends on how severe it was.

    Think of it this way- it could be MUCH worse... you could be a defense lawyer.

  33. Explains all the introverts.... by djsmiley · · Score: 1

    Well most of us are introverts, maybe thats why we end up with these roles. So yes.

    --
    - http://www.milkme.co.uk
  34. Ignore it and move on by Virtucon · · Score: 1

    Don't read it even if you inadvertently see it. Don't repeat things you may have overheard or seen. Testicles, Spectacles, Wallet and Watch all apply.

    --
    Harrison's Postulate - "For every action there is an equal and opposite criticism"
  35. Once again... by Anonymous Coward · · Score: 0

    Slashdot Beta really sucks. Please...stop trying to f up Slashdot. Everyone, everyone hates it. People who have never seen a computer hate it. For the sake of the world, end this pointless and reckless project.

  36. Tell me more, tell me more by Tablizer · · Score: 1

    So tell us, what's it like working there at the NSA?

    1. Re:Tell me more, tell me more by __aaclcg7560 · · Score: 1

      Boring as hell. NSA people lived uninteresting lives. No wonder they're spying on the rest of America.

    2. Re:Tell me more, tell me more by Tablizer · · Score: 1

      Splains a lot

  37. a cautionary tale by John_Sauter · · Score: 1

    There is a lot of good advice here, so let me add a cautionary tale. I used to work for a local government as their “computer guy”. I got a call from a user who was unable to watch some video he had on a thumb drive. As part of diagnosing the problem, I logged in to his computer using my own account, copied the contents of the thumb drive to the hard disk, and played it from there. It turned out that playing the video worked from the hard drive and the rear USB connector, but not from the front. I told him this and closed the call, but didn't delete the video from his hard drive. I noted the call in my log, but didn't mention that the video was pornographic.

    Much later, about a year after I my employment had been terminated, I got a call from the town's police. One of the detectives wanted to talk to me, and asked me to drop by the police station. It seems that someone had discovered that this user had been watching porn on his computer, and when they examined his computer they found that same porn on his hard drive, under my name. They gave me the third degree, wanting me to admit that I had been the source of the porm. I suspect they wanted me to be the scapegoat, since I was no longer an employee.

    I acted calm, pleasant, truthful and stupid. They told me that I could be in big trouble if I didn't cooperate, and I responded by saying if I lied in order to tell them what they wanted to hear, in the long run I would get confused about what lies I had told, and get caught in a contradiction. Of course, it helped that they all knew me, so I had credibility when it came to being stupid. It also helped that these were small-town cops; I probably wouldn't last five minutes in an NYPD interrogation room.

    This happened more than five years ago, and I haven't heard anything about it since.

  38. yes and no by adwww · · Score: 1

    Welcome to the club, it's such a strange position and one that gives us much more de facto power than one would think at first glance. As the systems grew over time from fancy calculators to automating all business processes this issue creeped in and many organizations haven't addressed it directly. Yes you should attempt to be as impartial as possible. However you should consider a serious discussion with your direct supervisor about the reality of having access to all company data. I would go into that meeting with some options you find palatable like: I won't involve myself or notify you unless it's a violation of the organization's fair use policy (which I hope you have). That policy should eliminate any possible crime or directly harmful behavior from a grey area. It is a delicate area but everyone in the organization should be made aware that the systems don't belong to them (likely in the non-profit sector they belong the public with the board as decision makers) and may be actively monitored at any time. This has nothing to do with you directly it's a reality of all modern networks and email. The policy should be clear enough to communicate to all employees so they are aware of your duty. All of this is especially difficult in dysfunctional political environments but I've never had a problem letting them establish the rules and applying them fairly. These matters should be communicated with all the top management and board President if applicable. What they choose to do with their careers isn't our affair unless they misuse the systems or break rules we are responsible for monitoring. I've been primary IT for several non-profits and served many small and medium sized organizations in a similar capacity since 1994.

  39. Some common sense by Livius · · Score: 1

    The problem with reading an e-mail that's incriminating is that it may be out of context. If you do not have the knowledge required to fully understand the implications of the data, then there really is nothing you can do.

    For example, at one job I have access to medical files, but I am not the doctor treating the patient and I am not in a position to judge anything about a patient no matter what information I might see. A man could be prescribed Viagra because of a heart condition, or a woman the pill because of the uterine condition.

    If something does unambiguously require some initiative from you, you'll know. And when that happens pay for a consultation with your own lawyer before doing anything.

  40. Mouth Closed plus Education by QA · · Score: 1

    This would be a good time to subtly remind your users, or at least the higher up ones that they should never put something in an email they would be afraid to see in court, or directly read to the recipient, face to face. In the same conversation, you would mention that due to your job, you have access to everyone's email account (as you must) because SOMEONE has to administer it.

    You cannot evade office politics, ever. Just don't do stupid things like buy a new hire a 27" Dell Ultrasharp while your bosses son in accounting is using a 19" Chinese knockoff. Common sense.

    Don't take sides, remain neutral when Sally tells you what an asshole Bill is. DO NOT run over to Bill and tell him. That is what Sally wants.Eventually the peons will stop and perhaps your boss will realize he can share something with you, without the entire company knowing 5 minutes later. Common sense.

    Dont play favorites. If the biggest dick head in the company needs a new workstation, get it for him. If you dont, you are only hurting your company, not the dick head.

    I could continue, but you probably get the drift by now.

  41. Do you find yourself deliberately ignoring..... by Anonymous Coward · · Score: 0

    YES!
    You have privileged access, but that is NOT a privilege to read/discuss/gossip about things you see and hear.

  42. The practical answer. by pla · · Score: 1

    We have an awfully lot of boy-scouts in this discussion, and while I only believe about 10% of them, they do actually give the right answer if for the wrong reasons.

    The real problem with knowing things you shouldn't comes from your (in)ability to act on them, and the risk of accidentally letting something slip at the worst possible time.

    Consider the best possible case - You find out about a major organizational change, and have some ability to position yourself to exploit it. That happens once a decade, at best, and a lot can go wrong (while you position yourself to take over as the regional director of IT after a merger, you later learn that the buying company plans to 100% centralize their IT infrastructure and you don't even have a job - Or the exact opposite, you start looking for a new job and later learn that those employees who stuck it out through the merger got some insane multi-year severance package).

    Now consider the worst case - You company's stage four drug looks awesome, highly effective with low side effects, and the FDA will rule on approving it next week. You buy a shitload of stock. Option 1) The FDA approves it, you make a fortune, and the SEC immediately starts breathing down your neck. Option 2) the FDA rejects it for unknown reasons, and you take a bath.

    Basically, your FP has the right idea - Play ostrich. Every time you visit Joe's computer, he has facebook/youtube/a game up and you have to clean out hundreds of porn-related spyware sites? You see nothing. Who cares about Joe - Best for your sanity.

    1. Re:The practical answer. by Krishnoid · · Score: 1

      Option 1) The FDA approves it, you make a fortune, and the SEC immediately starts breathing down your neck.

      It's ok, Martha, I still think they just like persecuting individuals instead of corporations. Plus I continue to use your decorating tips.

    2. Re:The practical answer. by Anonymous Coward · · Score: 0

      That's what "fuckshiscompany.com" was for. I loved when layoffs at my dotcom booming firm were announced there two days before they happened, and entire departments were calling their managers to confirm the rumors. And the managers flat out lied to them. I watched them doing it. They didn't even pretend ignorance, they lied like hell, and were instructed from further up the food chain to lie like hell, *while the VP;s cashed out their stock options by hook and by crook*.

  43. Professionalism. by ledow · · Score: 5, Interesting

    In my field, education, it's quite common for the IT guy to be the one with absolute access to more things than anyone else. Nobody else, not even the data-protection officer, or the people on the senior management team, or the people ultimately in charge of the school (the heads and governors) has as much access to information as the IT guy.

    Senior-management team files, HR databases, etc. are part and parcel of the job. The web filter logs are generally very revealing and, hence, why I anonymise them by default (Usually squid logs - which only contain source IP addresses, which can only be correlated to a machine using the DHCP logs, which can only be correlated to a user using the Windows event logs on the AD servers - NOT something you can do accidentally, but also allows you to analyse, spot trends and find dodgy things without immediately revealing the source. When I come upon something that worries me, I go to my boss, ask permission to de-anonymise those records, provide them with my results. I've had to do it a couple of times and it turned out to be nothing, but I've also worked with colleagues who've spotted a paedophile on the staff that way and got them prosecuted).

    Despite all that data access, tou don't look. It's that simple. If I'm asked to work on a confidential file or database, that's what you do. It's just data. What you see is just numbers and letters and then forgotten. You do not dig. Not only are there alerts and warnings for digging into certain things (and I don't want to KNOW what triggers those alerts or warnings necessarily, but I know that they are in place on the MIS databases, for example - I only trigger them when it's been part of my job to go into that part of the databases), but it's a matter of professionalism.

    If I become "exposed" to salary details, or witness protection details (children in schools rarely have as simple a home life as they might at first appear to have), or that some child's father is a Colonel in the Army who's asked for his address details to be maintained private, or whatever... that's what you do. You're not there to suck up data, you just treat it like anything else and move on.

    If I suspect illegal activity - there's a lot of activity you CANNOT ignore in a school - I'd go through the proper channels and report it however I'm supposed to. It came up as part of my job, it's not like I was snooping for it.

    I *STILL*, fifteen years into my career, look away when I ask people to set their passwords. I don't WANT to know. I want the deniability if someone gets into their account to say "There is no way I could know their password, without triggering a reset of their account, which would lock them out and inform them immediately anyway". My boss keeps trying to tell me his password "to save time". I don't want it. With it, I could - in theory - change my own salary, or modify any amount of details. Chances are it would get picked up eventually but if you were clever enough, you could get away with an awful lot very quickly, or very discretely.

    Hence, I don't WANT to know those things. I choose to forget them, unless there is a reason to immediately report them. I suggest you get into the habit of doing the same.

  44. I've been in exactly your position. by hey! · · Score: 4, Interesting

    Long, long ago, early in my career, I spent about fifteen years in the non-profit sector.

    You don't ignore office politics, but you don't take sides either unless there is a crisis brewing -- something illegal, highly unethical, or financially dangerous. When you work in IT, you're in a "support" position, rather than a "line" position. Your job is to support. So when there's a big pissing match between two line functions, your job is to support *both* sides.

    Often this means documenting business processes that sort of evolved via the lava flow antipattern; 50ish is the size where things start to get out of hand, because it's the size where the amateurishly hacked-together processes that keep the organization running start to break down because everyone can't be aware of everything that's going on in detail, in real-time. Make it your business to understand what business systems (not necessarily computer systems) *accomplish*. That puts you in a position to offer a third way, the one that emerges as obvious to everyone once somebody has figured out what's actually going on.

    It's supposedly hard to implement changes in non-profits because of the consensus-driven decision making processes, but I found that I could make that process work for me. Lack of understanding is a vacuum; presented with a clear picture people usually line up behind the obvious solution quickly. But you do have to do your homework. Never surprise anyone with anything in a meeting. Bring people up to speed with things you're going to say about their work *before* the meeting so they don't feel blind-sided.

    In a crisis be prepared to do the right thing. If you're in a non-profit they're paying you below market rates, so you can do better elsewhere. There is no call for getting yourself sucked into something that offends your self-respect. I resigned one job because my superior (the COO) was doing things that were financially reckless and improper (spending without proper authorization). I informed the CEO in my exit interview. That was my solution to the problem of not getting drawn into a persistent pattern of dysfunction.

    When you handle sensitive information, just ask yourself what is the professional thing to do? Be discreet. Resist the temptation to peek at data, and when you *do* accidentally learn something you're not supposed to know, disclose that to the responsible parties. Be trustworthy, and present a trustworthy face.

    Finally, don't let them pay you far below the market rate for your services, and expect a really good benefits package, including 1.5x to 2x the vacation you'd get in a for-profit. Insist on the respect due a professional. Non-profits are full of young people who haven't learned that the IT guy isn't there to be kicked around when they're frustrated, and the fact that you're in a support position rather than a more glamorous line position doesn't make your work any less important.

    --
    Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
  45. NYJ! by Chas · · Score: 1

    As an IT worker, your job is to see that the company assets you are assigned are functional and delivering proper service to end users.

    It is NOT your job to audit the company's books.
    It is NOT your job to Big Brother company e-mail (unless it is).
    It is NOT your job to run the company.
    It is NOT your job to set business policy for the company.

    This is what they have financial wonks, sales wonks and managerial types for.

    You never know when something you see "accidentally" is:

    A) Blown out of proportion
    B) A test
    C) Misleading
    D) Legit

    So going all "I've locked myself into the server room and am calling the police!" could be both wildly inappropriate AND career-ending.

    Sure, you don't want to aid, nor abet immoral/criminal activity.

    But it isn't your job to arbitrarily decide what that is!

    Now, if the feds come knocking on your door, asking for data, go ahead! At that point, you're pretty much safe.

    Until then, you're simply a disruptive influence to the company that needs to be let go.

    --


    Chas - The one, the only.
    THANK GOD!!!
  46. Secretaries by patabongo · · Score: 5, Insightful

    If a secretary with no professional qualifications can take minutes in a senior management meeting and maintain confidentiality about what was said there's no reason you, as a theoretically highly-educated IT worker, can't do the same about the content of emails you happen to read in the course of doing your job.

  47. I worked helpdesk for a large employer by scorp1us · · Score: 3, Insightful

    I started out all full of piss and vinegar and eventually learned to relax.

    You will only make enemies if you play politics. Only play in politics that involve you directly. Let everything else go. It's not your job to know it though you have the ability to. You won't be faulted for not disclosing something that your privileges allowed you to know, but declined to know.

    Be everyone's friend. I made friends and gained people's trust by being fair. They told me even more. I could go around uninstalling their games and stuff... But I didn't because it's just piss them off. So I just told them I saw the game and if something starts behaving weirdly, I'm going to blame the game first, and that they should uninstall it before I came back. That seemed to be enough to cover my ass in the event someone else found it and reported it to the head of IT. It kept me from making enemies. Exercising restraint is the key to success. If no one likes you, they won't put in the good word.

    --
    Slashdot's rate-of-post filter: Preventing you from posting too many great ideas at once.
  48. Counsel users and warn them by Anonymous Coward · · Score: 0

    The best bet , besides discretion and trust, is to tell users to close open programs and demonstrate issues with non sensitive materials when they do not do so. Explain the issue in a non confrontational fashion and if the user continues to expose you to sensitive materials discuss the matter only with your direct supervisor (or HR or Legal depending on corporate structure, content and sensitivity) . Alternatively ask your direct supervisor how to react. you could also ask for a company wide email or reminder to close sensitive materials before it or contractors arrive.

    nb: about illegal content (pr0n, harassment, etc) that could get you fired if you see it , or are accused of knowing about it, protect your assets and report the matter to direct supervisor following corporate policy.

  49. Wow. . . . genuinely surprised. by Anonymous Coward · · Score: 0

    Don't forget that in Europe privacy does extend to your work email account.

    If for example I use work email to communicate with my wive, the company is not allowed to read the contents of those emails.

    Even work related emails have been seen as a private communication and should not be read. The reason for this is that work related communication is more effective when both parties know it is private. If employees know they are being monitored, their communication will be more careful and use words that won't make then look bad toward the monitor.

    Even if phone calls and other communication is being recorded; in case the recording is need to solve a dispute with a third party; then it will note in the policy of the company exactly when and how these recordings can be accessed. Often these recordings can only be accessed by the employee who was being recorded.

  50. happier the less you know by davemchine · · Score: 2

    I spent about twelve years as an IT director. I had access to every email account and every document created including financials. I discovered that most of my co-workers where doing their absolute best to stab each other in the back. The lies were rampant. Management was also lying to the employees (leading from the top down?) about company finances. It made me very unhappy to know about all the horrible things they were doing to each other. I think I would have been much happier not knowing all of those things. So my recommendation is to ignore all of that information you could "see" and just do what's necessary for your job.

  51. Listen but don't speak or read. by GrantRobertson · · Score: 1

    I was the IT manager of a hospital. The HIPAA rules apply. You can't repeat what you hear and you can't read what you weren't supposed to see. Seriously, learn to not even focus your eyes on private information. However, there is nothing wrong with using what you hear to help you make decisions about what you should do, such as leaving a business that is in financial trouble or setting aside some server space for that expansion someone is planning but didn't think to consult with IT about.

  52. Do you have morals? by Anonymous Coward · · Score: 0

    If no, move to another job.

  53. Unless it is blatantly illegal... by BobandMax · · Score: 1

    ...it stops with you. I saw many embarrassing/absurd/job threatening/demeaning things while servicing employee computers. One of them belonged to the company president. None ever appeared to be criminally illegal and did not go beyond me. Part of the job.

    --

    "Computers are useless. They can only give you answers."
    -- Pablo Picasso
    1. Re:Unless it is blatantly illegal... by gweihir · · Score: 1

      Even if it is criminal (or rather looks criminal), look the other way. You are not a cop. Except for rare exceptions in some fascistoid states, you are not required to report crimes. If you think you need to report something, consult a lawyer first. Really, do it, and not the company lawyer. Pay for one yourself.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  54. Be a Professional by axor1337 · · Score: 0

    I manage a computer repair shop. I teach my guys that discretion is paramount. First of all I'd they snoop on customer files they get fired. Second if the do see something they aren't to discuss it. Finally if they stumble on something criminal (like kiddy porn) they report it to me and I deal with it. In the case of the aforementioned I'll call the cops. But I make the decision and the responsibility.

    --
    there are 10 types of people in this world, those who read binary and those who don't. which are you!
  55. Integrity by Anonymous Coward · · Score: 0

    As an IT professional you must be trustworthy. In smaller unregulated industries you may not be subject to restricted audited access to production data or even email. The employer should probably have you sign an NDA, non-disclosure agreement. In larger financial and healthcare institutions your access will be highly restricted and when you do access production data you will be audited and logged.

    I maintain a servant attitude when dealing with my customers and yes, I do see things I shouldn't but I simply ignore it and keep my mouth shut. Most of the time I simply dont care. It is nome of my business. I can know about termimations, downsizing, corporate changes that would affect the stock price, etc. I could be arrested and sued if I were to leak any information.

  56. do your job, shut the fuck up by ruir · · Score: 1

    You are in an excellent position to learn, you are forced to as you are alone. Stay away from politics, learn a lot, prioritize your work, study a lot on your free time. In 1.5 or 2 years, leave this job for a better place.

  57. eye on the prize... by Anonymous Coward · · Score: 0

    Your eyes as an I.T. professional are to focus on the issues not what people are doing. With great power comes great responsibility. As the keeper of the kingdom you do just that, keep it safe.

  58. Like a priest at confession by Rick+Zeman · · Score: 1

    Anything you learn during the course of your duties should never be discussed. What you learn around the coffee machine should be not talked about either lest people jump to the wrong conclusion.

  59. Ignore everything except child pornography... by __aaclcg7560 · · Score: 1

    You can pretty much ignore everything around you that doesn't violate company policies. Except child pornography. I did a PC refresh project at a local hospital when my coworker came across child pornography on a workstation. He reported it to our supervisor. Together they reported it security. They each had separate meetings with the security chief and the hospital attorney.

    The worker -- a high-level administrator -- freaked out when he didn't get a new computer and his old computer sat on his desk without the hard drive. We stonewalled him on what happened to the hard drive, as security confiscated the hard drive as evidence. He spent a whole day running around like a chicken with his head cut off, unable to do any work and no one saying anything to him. Police were waiting for him the next morning. Because this was a hospital that had a reputation to protect, the news media didn't report on the case.

    1. Re:Ignore everything except child pornography... by Dan541 · · Score: 1

      If he was smart he would simply blame the IT department. They are the ones who can install anything on any computer.

      --
      An SQL query goes to a bar, walks up to a table and asks, "Mind if I join you?"
  60. Certainly no logic there by dbIII · · Score: 1

    Well at least you've managed to get a sense of superiority out of replying to these comments even though you do not seem to have grasped the context of the discussion.
    Calling an IT person a janitor as an insult shows a lack of respect for both and is as stupid as calling a marketing person a hooker or a finance person a thief.

  61. You ignore the shit. by jtownatpunk.net · · Score: 1

    I remember the first time an employer realized that I had access to everything . She froze for a few seconds while she processed the idea, shrugged, and went on with her request.

    You're going to learn things you don't want to know and see things people don't expect you to see. My least favorite experience was someone who had an email stuck in their outbox. "Subject Re: Re: Re: Re: Re: My widdle wuvvy bear From: Not His Wife" And thank you so much, preview line, for confirming the content. So, with a straight face and chipper tone, "Next time a message gets stuck, you can just select it and hit delete." I didn't add, "And you, of all people, should know better than to use company email to conduct that sort of activity because we archive everything. I just did an archive search for you last month."

    My most favorite was when I was helping someone with some simple thing and minimized her browser to discover that her desktop wallpaper was a picture of her frolicking in a bikini. Again, just go on like it's nothing out of the ordinary. Heck, if I looked like that, I'd want to look at me all day, too. Oh, and there was an intern who, when she finished her assignment, cleared everything off her desktop except a topless pic of herself.

    If I'd seen evidence of blatant criminal activity or harassment, I would have reported it to the person's manager and my boss and let them deal with it. But politics and gossip and salaciousness were ignored. I was employed to keep the equipment running, not be the morality police.

  62. Here's 18 years ... by CaptainDork · · Score: 2

    We have the same job and I've been at it 18 years.

    The first thing to bring up to management is a Technology Administration Policy.

    In there provide the expectations of the Firm, and include any prohibitions regarding use of social media, games, personal email accounts, and other productivity-related issues.

    State that all of the Firm's technology, and the products of that technology (documents, spreadsheets, emails, etc.) are owned by the Firm and WILL be inspected as management directs.

    In the Policy inform all employees that they are to report violations, or suspected violations of the Technology Administration Policy to you.

    There are other issues you can cover in there like password rules, prohibitions for using business email for personal use. Get management to work with you so everybody's on board.

    Here's some other stuff:

    Don't snoop. Ever. Tell management point blank that you are not snooping, and will not snoop unless management tells you to. When they tell you to take a look-see, especially if they are concerned about abuse of one person, snoop and report on several others. This covers you and management later, if questioned.

    For some systems like financials, payroll, time card, etc. tell management you don't want entry passwords. You'll work with the individuals responsible for those systems and have those operators log in for you and THEN do your work.

    If something odd happens in there, you want to be the first eliminated.

    I see stuff I shouldn't a lot. If it's a violation on the part of a co-worker, I work it out with them. You want to have a good working relationship with all of your people. If they fight you, remind them that they are actually fighting the Firm. If things get nasty, take them to management.

    When I see stuff I'm not supposed to on management computers, I just keep my mouth shut. NEVER gossip about that stuff. It WILL get back to the wrong people.

    Your job and mine are atypical in that everyone is our boss. Make recommendations via email so you have a trail and let management do informed risk assessment. Remember that you are on the wrong side of the ledger. You are a cost center. Most times when you meet with management, it will be about spending money. That means everyone in the Firm will have to swim a little harder.

    Make life easier for yourself by adopting the right attitude BEFORE you make contact with a coworker: They are absolutely right, and you agree with them. You are on their side, always. It's not you vs them. It's you and them vs the problem.

    Last tip: You're gonna get yelled at. People have apologized to me afterwards. I tell them it's OK. I understand. I'm the guy to yell at because I'm the only one who will fix it, " ... and thanks for the apology. It means a lot to me that you want to clear things up."

    If you and I are professional, we will get past each incident without anyone getting pissed.

    Good luck.

    --
    It little behooves the best of us to comment on the rest of us.
  63. Ignore nothing. Pretend to ignore everything. by Lord+Kano · · Score: 1

    To mangle a phrase, just because you take no interest in office politics doesn't mean that office politics won't take an interest in you.

    Pay attention to little things. Watch the comings and goings of those who think they're players. Listen to everything that people try to tell you and never take sides out loud.

    "Yeah, really?" is pretty much all I say when people try to drag me into their battles.

    I hate the games of office politics but I'm a realist and I understand that I have to know the game to avoid it.

    LK

    --
    "Hi. This is my friend, Jack Shit, and you don't know him." - Lord Kano
  64. If you've seen something and don't report it. Yo by Anonymous Coward · · Score: 0

    I hate to break up the ostrich fest here however... At least in the United States... If you know something and don't report it.. You're complicit and will get in whatever trouble you're sticking your head into. The gold standard for the prosecution is, "should you have known". It's not.. Can I prove with evidence that he knew. Also.... Be aware.... They can and WILL subpoena you and there's not a single thing that you can do about it. You can't even plead the fifth to quash the subpoena because it's a subpoena for company records not your own records. As someone with experience in the above.. Do yourself a favor. Report bad things. Yes there is a cost... But it's way less then being charged with a crime because you should have known.

  65. Discretion, always by Doghouse13 · · Score: 1

    Think three times before talking about, or using, anything that you learn accidentally in the course of doing your job.

    You'll undoubtedly take note of office politics (although you don't necessarily talk to others about the detail, or how you came about it); office politics may well affect how you go about your job anyway, and it often helps to know where the potential traps and difficulties are, so that you can attempt to step around them.

    You never, under (almost) any circumstances, discuss anything confidential that you came upon by accident and weren't entitled to know, if you do so, you are likely to find yourself looking for a new job very quickly - and quite right, too. The only exception I can think of to that would be if you were to come across something that the law or your employer would expect you to bring to an appropriate person's attention, where not doing so could land you in serious trouble if it subsequently came out that you hadn't done so. If unsure, consider covering yourself by questioning it, confidentially but in writing. Escalate, with care and tact, if not happy with the reply. And understand that, in doing so, you're not so much doing so doing so out of duty, as covering your own position.

    (Putting things in writing is a good policy anyway, for almost all aspects of almost any job - NEVER assume that people will choose to remember things the way that you do, or that "nice" people won't attempt to hang you out to dry at a later date, if it serves their purpose. When you agree something verbally with someone, if it's even remotely important, drop them a note confirming YOUR understanding of what was agreed.)

  66. You will get used to it. by Anonymous Coward · · Score: 0

    I remember those feelings, when I started my current job.

    We sell email servers that do encryption- we have different kind of services, some where it is not possible for us (programmers/supporters) to ever see those mails(Expensive) and the cheaper ones, where if a mail as an example gets cutted off during transmission it ends up in folder for failed mails- where we have to look at it and decide what to do.

    When a mail fails I have to look at it, to make a guess about why it failed- and I skim the mails- if it is something interesting- sorry but i read the mail.
    It is not like if it is base64 encoded i go and decode it, but I need to see the data.

    All of us do that- everyone in our company. It is not something we talk about loudly, but if we see something funny, we read it.

    Some companies have "secure distribution mail boxes" where if x@companyA.com sends to y@companyb.com the mail will be encrypted for secure@companyb.com and after decryption it will be routed to y@companyb.com in their internal network.

    Sometimes if a mails fails, we know the automated distribution will not work- and it will end up in the distribution folder, for everybody in receiving company to read.

    One time a mail failed that involved sextalk with a married goverment official and another in the same goverment.

    We knew the mail would end up in the "distribution mail folder" for companyY to manually forward.

    So we deleted it.

    There is no formal training or ethics for this I think- so that is how we do it.

    But that is the way it is, because an unencrypted mail is just a postcard- people should except it to be read.

    That is why we have laws about personal information should not be in emails.

    So if people are stupid enough to put you in a situation where you cannot avoid getting a glimpse of information- it is not your fault.

    And it is nothing special that you get that information, lots of people do- information is dealyed in all steps of the chain.

    The director is the first to know someone is getting cutted, the the middle leaders, the those that will get cutted.

    If everybody else can be trusted in not abusing that information- so can you!

  67. Probably no way to get compensated? by dutchwhizzman · · Score: 1

    The perv probably didn't have enough money to pay for damages to his victims and you? In some countries the government will actually make sure you get a reasonable compensation for the financial and social losses you had, even if the perpetrator didn't have any.

    --
    I was promised a flying car. Where is my flying car?
    1. Re: Probably no way to get compensated? by Anonymous Coward · · Score: 0

      Sounds like he was run out of town, where probably had deep roots, maybe family.

      I doubt cash compensation is relevant.

  68. In short... Yes. by Mysticalfruit · · Score: 1

    Obligatory Uncle Ben quote here.. As someone who has access to everything, you need to exercise a certain level of discretion. However, at the same time you need to have some common sense.

    --
    Yes Francis, the world has gone crazy.
  69. Code of Ethics by Anonymous Coward · · Score: 0

    The System Administrators Guild has a statement of ethics I have always tried to adhere to,you will learn things about people in your careet that you would rather not know. It helps to maintain a split mind when dealing with content.

    Code of Ethics

    Fair Treatment

    I will treat everyone fairly. I will not discriminate against anyone on grounds such as age, disability, gender, sexual orientation, religion, race or national origin.

    Privacy

    I will access private information on computer systems only when it is necessary in the course of my duties. I will maintain the confidentiality of any information to which I may have access. I acknowledge statutory laws governing data privacy such as the Commonwealth Information Privacy Principles.

    Communication

    I will keep users informed about computing matters that may affect them -- such as conditions of acceptable use, sharing of common resources, maintenance of security, occurrence of system monitoring and any relevant legal obligations.

    System Integrity

    I will strive to ensure the integrity of the systems for which I have responsibility, using all appropriate means -- such as regularly maintaining software and hardware; analysing levels of system performance and activity; and, as far as possible, preventing unauthorised use or access.

    Co-operation

    I will co-operate with and support my fellow computing professionals. I acknowledge the community responsibility that is fundamental to the integrity of local, national, and international network resources.

    Honesty

    I will be honest about my competence and will seek help when necessary. When my professional advice is sought, I will be impartial. I will avoid conflicts of interest; if they do arise I will declare them.

    Education

    I will continue to update and enhance my technical knowledge and management skills by training, study, and the sharing of information and experiences with my fellow professionals.

    Social Responsibility

    I will continue to enlarge my understanding of the social and legal issues that arise in computing environments, and I will communicate that understanding to others when appropriate. I will strive to ensure that policies and laws about computer systems are consistent with my ethical principles.

    Workplace Quality

    I will strive to achieve and maintain a safe, healthy, productive workplace for all users.

  70. Here's how I handle it by fisted · · Score: 1

    Simple rule: I don't (physically) touch computers where someone's logged in. ssh is okay. If in the process of troubleshooting an issue I need to look into someone's data, they are asked for permission beforehands. If some sort of maintenance on an office computer requires some sort of physical/local access, and there's someone currently logged in on the box, I ask them to log out. Finally, if a user seeks assistance with something where physical presence is required (say, KDE misbehaving (does it ever well-behave?)), then it's the user's responsibility not to make me see sensitive information in the okay-just-show-me-what-you-did step.

  71. Legal versus interesting by Anonymous Coward · · Score: 0

    When my daughter did tech support at college she was told to ignore everything except child porn. That was reported.

  72. As a last resort, maybe.. by s.petry · · Score: 3, Informative

    I have designed, built, tested, audited, and supported security compliant environments for over 2 decades. A decade at a DOD site, and about the same time afterwards with PCI and HIPPA compliance. In many cases, you need to report seeing things you are not supposed to see. "Forget" is illegal in many cases, so claiming it's a viable answer is dangerous.

    That said, from TFA it does not appear to be a legal issue here. Just warning that it's not good advice in general.

    The biggest single thing to put into your debugging arsenal is test data. Need to debug mail, send test mail. Need to test encryption/decryption, make dummy files to encrypt and test. A user can't do something, provide them test data to work with that you know is clean. A user has a display problem, have them bring up the application with NO data loaded. These are extra steps, but worthwhile steps. If users complain about loading test data explain it to them.

    The second biggest thing for you to have handy is a big dose of honesty. If you open something confidential, make sure that someone knows you saw it (you report to someone as an IT professional, even if it's the CEO directly). If you have to access a users desktop, ask them to watch and make sure you don't open a file that they may not want you to see. If you have to open something you know is sensitive, get permission first (preferably in writing).

    There are surely exceptions (Edward Snowden), but that's a much longer discussion. Sysadmins by nature have access to more than any single person in the company. Good sysadmins don't flaunt or take advantage of that fact.

    --

    -The wise argue that there are few absolutes, the fool argues that there are no probabilities.

    1. Re:As a last resort, maybe.. by Anonymous Coward · · Score: 0

      "A decade at a DOD site, and about the same time afterwards with PCI and HIPPA compliance."

      During that decade, perhaps you should have read enough to remember that is it HIPAA, not HIPAA.

    2. Re:As a last resort, maybe.. by JWSmythe · · Score: 2

      I don't see how ignoring is a hard thing.

      I've had access to countless mailboxes, confidential files, and sat down at executive's computers to fix problems. The magic secret is, don't read it. If someone's mail isn't working, so I repair the problem and check it, I see that there are words. I don't read the words. It's nothing more than a passing glance.

      When I have been specifically (and legally) tasked with reading email, I can say that it is amazingly boring.

      Usually, just as you said, if I'm testing functionality of a server, I make something to test with. If I'm testing a mail server, there's no reason to spam a real user's box with. I'll create my own test account, do whatever testing needs to be done, and then when I'm satisfied with the resolution, delete the account.

      I have a client who does have confidential data. They are contractually bound not to release that data to any third parties, which could include me. I create my own test files, and move them around. If I only need a small file, it may just be a file that contains the string "testing". It may be a huge file created with dd.

      He also asks about eavesdropping. Simple enough, don't do it. If someone is talking about something to you that you probably shouldn't know about, just say it. "Don't tell me about that." It's been both a joke, and good for covering my own ass.

      --
      Serious? Seriousness is well above my pay grade.
    3. Re:As a last resort, maybe.. by mysidia · · Score: 1

      A decade at a DOD site, and about the same time afterwards with PCI and HIPPA compliance. In many cases, you need to report seeing things you are not supposed to see. "Forget" is illegal in many cases, so claiming it's a viable answer is dangerous.

      This may be the case in the DOD if you open a document you weren't supposed to have opened, as the military in principle doesn't trust anyone and wants to audit any admin's activity --- you could later suffer a judicial inquiry for opening such and such document and not reporting it, whether you actually saw or read any of the text or not; that could in theory be true within any organization, however, whether you reported it or not.

      My argument is you should ignore and forget the content as early as possible, as in before you have actually "seen" or begin to have any comprehension of whatever is there. If you would know what the content is and you would know that you are not supposed to have seen it, then by the time you realize what it is about and you realize it's something you shouldn't be seeing, then you have already failed to practice this strategy.

      This doesn't mean you won't make the proper note or annotation for your reason of opening such and such document and finding it miscategorized or inappropriate from a security standpoint, if you did.

      HIPAA and PCI do not require you to remember if you incidentally saw something you were not meant to, such as a primary account number, or hex string representing an auth token; the potential legal violation would come in if you started making an effort to memorize or remember the number or code or write it down, extract it, etc. PCI does not have the force of law, either; it is a contractual agreement merchants agreed to adhere to.

      Neither PCI nor HIPAA require a specific security policy, however. I believe your "remember if you ever happen to see anything you think you are not supposed to" must have roots outside private industry.

      The violation would be if you disseminated the information, acted upon it, or appeared to act upon the information.

    4. Re:As a last resort, maybe.. by s.petry · · Score: 1

      Under HIPAA and PCI you are also supposed to disclose information on breaches (and yes, this is considered a breach). Disclosure is not unique to DOD in the slightest. The difference is obviously in how breaches are handled. HIPAA can result in severe fines as opposed to being jailed for treason (both extremes). The only punishment available to PCI is a loss of accreditation.

      I will however admit that neither the DOD, PCI, or HIPAA encourage disclosures. HIPAA's minimum fine layout probably causes many people to keep their lips sealed when a breach occurs.

      The most obvious difference is that PCI and HIPPA do not have the same auditing requirements as NISPOM/JFAN. It's easier to get away with minor breaches if nobody is looking. Getting away with them does not mean that the standards don't require disclosure, it just means people don't get caught.

      --

      -The wise argue that there are few absolutes, the fool argues that there are no probabilities.

    5. Re:As a last resort, maybe.. by mysidia · · Score: 1

      Under HIPAA and PCI you are also supposed to disclose information on breaches (and yes, this is considered a breach).

      I think you are living in an imaginary world, if you believe that enterprises perform disclosures of "breach", in the event that some sensitive record happens to be inadvertently revealed to an administrator, operator, helpdesk person, or other staff, who is not committing a privilege misuse --- this is not a security breach in the accepted sense.

      This is likely a quite common thing to occur, and yet, we don't see daily disclosures of supposed breaches of this nature.

      My fundamental argument here, is that what you are saying is not aligned with the real world.

    6. Re:As a last resort, maybe.. by Anonymous Coward · · Score: 0

      During that decade, perhaps you should have read enough to remember that is it HIPAA, not HIPAA.

      ??? Now I'm confused...

  73. SysAdmin Code of Ethics! by Anonymous Coward · · Score: 0

    Read the:
    USENIX System Administrators' Code of Ethics
    LOPSA System Administrators' Code of Ethics

    You're an IT PROFESSIONALl now. Act like it. Ignore the politics.

    With "root"/"Administrator" account access to IT systems, you're basically God and have access to everything in IT. TRUST IS EVERYTHING between IT administrators and your users.

    There was a time when bankers and accountants were highly respected because they had a fiduciary duty to their clients/customer. Following the recent economic crash of the Great Recession and Enron-type scandals, the reputations of companies like Goldman Sachs and Arthur Anderson were significantly tarnished and people's perception of them have noticeably changed. Sure, there's always been other scandals/incidents before but most people only remember the most recent big ones.

    Physicians have their Hippocratic Oath, Professional Engineers have their Obligation of the Engineer, and lawyers have their professional code. Yes, every day, there's some new news story of a medical doctor, engineer, or lawyer violating all or some part of these oaths. The intention is that we all like to think/hope that as professionals, we can strive to maintain these goals and call out the ones who have gone astray.

    All workplaces have some sort of internal office politics. This is what happens in any size or type of company or organization of humans due to company/organizational policies and just the nature of individuals (which tends towards being selfish or fiefdom-protecting). Being a "non-profit" is ultimately more of a tax status issue and does not automatically mean the entire non-profit organization or that all of its workers are 100% perfect, selfless, always altruistic individuals who all agree on everything.

    More criminal minds might call such altruistic people "suckers" depending on the situation. Or what sometimes happens is that the altruistic individuals in charge made false assumptions about the costs or labor involved for operations and refuse to believe that we can't just all work for free or get stuff/materials for free just for the "good of the children blah blah blah". How many rich donors can you really get?

    The goal is to find a job that has office politics which you can reasonably tolerate. Since you said you're new, there may be other background history in your organization that you're not aware of that you're just stumbling across now.

    And yes, there's always 1 (or more) "crazy people" in any company/organization. Be cautious in dealing with them. Do your job (e.g. fix their computer if broken) but don't get looped into whatever personal agenda they're advancing.

    Really doing something about any of the office politics sometimes might mean getting your manager involved (or becoming a manager). A good manager can serve as your "shield" (or "scapegoat" depending on your viewpoint) so you can defer/blame certain things to them ("I'd like to help you but my boss lady said I can't. Talk to her about it."). This is not a path to be chosen lightly.

    All that being said...always keep your resume/CV up-to-date and your co-worker and business relationships cordial. Separate your work stuff from your personal stuff. Getting too entangled in this can turn into utter poison for yourself and your future career.

    Sometimes, you've just go to bail. Really. If you can describe your workplace with the one word of "miserable" and you've made reasonable efforts to deal with it in a reasonable time period (maybe 3-6 months?), it's really time to go.

    Even though it's kind of really targeted towards managers, Patrick Lencioni's book

  74. Remember: What has been seen can not be unseen by UncHellMatt · · Score: 1

    I work for a small police department, about 50 people and one of the 3 civilian full time staff. In the 13 years I've been in this job, I've learned several things, first of which is my subject line: "What has been seen can not be unseen". I learned this the hard way after someone asked me to assist in ghosting the hard drive of someone who was, in the local parlance, a potential "Diddler", child pornographer. As asked, I ghosted the drive, then when staff found no illegal images, I dug through the drive searching for hidden directories.

    Yes. I found them, all right. Now, I have a daughter, 15 today but only 4 at the time, and some of the images I saw, frankly, haunt me to this day. Back then we had no direct resource for digital discovery / evidence collection, and after seeing those images.... I wrote our discovery and extraction policy and worked out a deal with another law enforcement agency to have their people take care of that. I'm well paid, but there is not enough money on this planet to get me to again see what I saw.

    Over the course of day to day IT stuff, I have seen emails or documents which yeah, maybe I shouldn't see. Sure, I'm CJIS (Criminal Justice Information Services) certified, etc, but I don't need to see some things. But my boss, the Chief, and my coworkers know that all I'm interested in is making sure we're secure, that the officers and staff can perform their jobs, get email, track cases, track safe keeping, evidence, etc and it's going to work. That's it. I'm not the moral compass. Of course, if I saw someone was up to something illegal with my babies (computers) I would gather evidence and present it immediately! And I'm a very vocal advocate for privacy AND freedom of civilians to record police activity, something my coworkers now agree with me on. But if I, for example, read that one officer gets paid more than another officer for his hourly construction detail, that's none of my business. I mostly stay in my office, work on the things I need to work on, study, and do my job.

    IMO that's what we do. We fix things, we keep the show running. That said, you may find yourself with perhaps some leverage. For example, I had one troublesome user who asked my help on installing a piece of software. I went to his desk, asked where the installer was, and he had no idea. So, first thing I did was check the "Downloads" directory. Sure enough, there was the installer, as well as a metric crapton of video files with titles like "Pegging" and "Tranny". He went white... as ... a... SHEET. Not missing a beat, I move the installer to the C: drive and set to. Finish install, enter registration keys, configure, done. As I'm getting up to go, I turned and said "I trust I'll receive no further complaints from this office, right?" He looked, nodded vigorously, and I walked out.

  75. traditional issue by roc97007 · · Score: 1

    These are traditional issues for the corporate sysadmin. Perhaps less now as corporations are segmenting services more.

    Early on, I realized that as an admin I had access to everything, and I had to adopt some sort of moral code in order to function. So things I inadvertently learned I kept to myself, and tried to forget, and even under pressure, consistently refused to use my access to, for instance, allow a manger to spy on another manager (a real example).

    It takes a long time to build trust, and only a single incident to blow it. After awhile, employees would come to me with serious private issues, like a potentially damaging email inadvertently sent to the wrong person, secure in the knowledge that if the need was legitimate I would fix it and not talk about it afterwards.

    --
    Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
  76. go with it by Anonymous Coward · · Score: 0

    Knowledge is power. It's just more info that you can use as leverage later.

  77. Like a janitor by roc97007 · · Score: 1

    Some people are in sensitive positions due to the nature of their jobs. Janitors have keys for every office, including the CEO. Security personnel are in the position to spy on the entire plant. Sysadmins potentially have access to all communications, data, perhaps even HR records. What you do or don't do with this access is a test of your character. And should, in a perfect world, have bearing on whether your career continues. (Example: TSA personnel saving naked photos for later viewing.)

    --
    Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
  78. Handling confidential information. by paultscott · · Score: 1

    In IT we have access to info that is usually reserved for C level execs. Either accidental reading when troubleshooting or shared in meetings. I have always looked at IT work as a sort of priesthood. What people do on their computer is their business. I don't share it with others. All data is kept confidential. Sometimes knowing when someone is going to be terminated that is sometimes a little awkward. But you just do your job like you always do and try to avoid office politics.

  79. post to spiceworks community by JeremyBenisek · · Score: 1

    Your the watcher now. Ignore what does risk human life. Speak up if it does. Snowden is a good example.

  80. Simple rules... by Anonymous Coward · · Score: 0

    Simples.

    If it's a data security issue or grossly offensive (kiddie porn, financial fraud, etc) hand it over to your boss, make it his problem. If he fails to act, forward your concerns to the appropriate VP/board member.

    Anything else, stay well away from the firing line. Who's screwing who (both literally and metaphorically) is none of your business. You didn't read it (even if you did) and it's up to local management to do their own dumpster diving.

    The only exception is the "f**ked company" scenario which should be communicate discreetly to all IT personnel so they can get their CV into the recruiters hands before the s**t hits the fan.

  81. I was a Sysadmn for a spook house by Anonymous Coward · · Score: 0

    I was a Systems Administrator for a 3 letter government agency. Yes, I had access to everything under the Sun (ignore the pun --Sun Workstations--). I kept my nose to the tasks at hand. Data is data. The operating system, and everything related to it were my business. System uptimes, disk loads, data rates, software performance, network security, hardware/software interaction: these were my business. It included very specialized (bespoke) hardware attaching to COTS computers with bespoke software that sometimes needed a lot of tweaking. If it works, and performs well, we are good (Classified/Secret/Top Secret/Ultra stamped at the top of documents was rightly ignored too). I don't do that anymore though, and since my name isn't Snowden, that's where my description stops.

  82. First have user close windows w/ sensitive content by sydbarrett74 · · Score: 1

    Before I work on someone's machine, I ask that person to close all windows that may have sensitive content s/he may not want me to see. This policy establishes a certain amount of trust with the user. Put the onus on the user to determine what s/he considers private and sensitive. Easy-peasy, and it only takes 30 seconds.

    --
    'He who has to break a thing to find out what it is, has left the path of wisdom.' -- Gandalf to Saruman
  83. Seldomly happens by tigersha · · Score: 1

    After 20 years in the business I find that very few people will leave sensitive documents open on their screens when they know you are going to be there so it seldomly happens.

    --
    The dangers of excessive individualism are nothing compared to the oppressiveness of excessive collectivism
  84. Be a butler. by Anonymous Coward · · Score: 0

    Here are some tenets of being a good tech.

    1) First, do no harm.
    2) Don't judge. Your job isn't to care about the content of the data, except spam and illegal stuff; your job is to care that the data is available and accessible.
    2) People are boring; computers are interesting. You're not going to find anything interesting, and a good tech should be more interested in the tech then contents of people's data. If you do find something by accident, keep your mouth shut about it unless it's illegal and harmful to the company/institution.
    4) Play your cards close to the vest. There is no need to tip your hand or be anything but neutral.

    In general, I don't care about people. I don't care about their lives, their kids, their dogs, or their mountain of cat pics. I have my own stuff to take care of, personally and professionally, and I'd much rather spend time dealing with that then other people's crap.

    That position sounds really callous and cold, but

  85. Your obligation is to your paycheck by Anonymous Coward · · Score: 0

    Your only obligation is to do your job. As an IT professional that includes security and such - so you can't ignore everything.

    I did learn after my first couple of jobs though, it doesn't pay to get involved with the drama.

    At the last job that I had the only "involvement" I had with the inter-office drama was in telling the CEO that she was breaking a licensing agreement. She argued(?) with me for over an hour at which point I said, "Listen, you can do what you want. I've done MY job by letting you know, and it's in writing."

    Fortunately I was able to move on to a much better environment - one which largely keeps me away from other people.

  86. You have access to everything by Anonymous Coward · · Score: 0

    Just do your job, if someone put in a ticket complaining their email won't open, you fix their email so it opens. It is impossible to avoid seeing sensitive information. On a daily basis I see SSID's, bank account numbers, loan letters, discussions about customers, etc... You just ignore it. If you come across something illegal or suspicious then you speak with HR as to what process they prefer you follow for reporting it. If they do not have a process for reporting it then you report it to the appropriate legal authorities. You are not a cop, it is not your responsibility to take any direct action to stop anything or talk down to someone. If you can't handle any situations you consider immoral then you resign.

  87. Reply from OP by MonOptIt · · Score: 1

    Thanks to everyone for your responses. The mean response is, frankly, what I expected: be professional & trustworthy, because it's not our job to be otherwise. This is both heartening and worrying; some of the examples above from admins who did "the right thing" set my teeth on edge. I like to think that I'm an honest, open person. However, as Feynman famously said: "The easiest person to fool is yourself". Thanks to the folks who shared the USENIX/SAGE links above. I've now got a copy of the sysadmin code posted right above my KVM/WIP stack, so I'll see it regularly. Optics was easier: photons don't concern themselves overly much with morality and ethics.

  88. Keep your mouth shut by Anonymous Coward · · Score: 0

    I tend to take the see no evil, hear no evil, speak no evil approach. Unless I'm being subpoenaed for evidence I saw nothing.

  89. There is a good book I read about 15 years ago by Anonymous Coward · · Score: 0

    The book was about the 'professional' executioner for the King of France, whom found himself responsible for actually having to behead the King and his family whom had employed him for so many years. I apologize for not remembering the name, but it discusses this exact topic throughout history.

  90. HYES by Anonymous Coward · · Score: 0

    Yes. My first post-college gig was with a small company, barely 100 people including off-site. I was one of three IT people in house. One who ha dseniority over me pretty much exclusively handled the PBX and DNIS routing for our phone systems. One was our manager, who was also pretty much everyones manager and he had bigger problems than IT. I was the programmer and the two of us basically juggled SQL tasks in the database, as well as web programming, system imaging, software installation, troubleshooting, talking with our off-site guys and coordinating everything with them - and to top that off, we assisted with general crap like printer issues, and we had meetings we had to attend. All while being overly micromanaged.

    So we worked in the middle of a different department who did nothing but talk all day about things I'd classify as office politics. We had to ignore them - literally had t, because they were basically immune to everything unless they massively fucked up, so it was just a retarded idea to ever even acknowledge that you had any idea there was a world outside of technology and what they hired you to do.

    Piece of advice: NEVER respond to all. Never acknowledge any office politics. If ylou do ever confront anyone or make a disparaging or even slightly sarcastic remark about any person or any thing, do it in private where no one can hear you and if it's talking with someone - make absolutely sure you trust that person entirely. Even in strictly IT firms, people are bitches. Seriously. Don't even play their games.

  91. If you play god then you have to be a god. by Anonymous Coward · · Score: 0

    I have worked in IT/MIS for many years (15+) and what I have learned is that you look without looking. I can look at a screen full of text and read none of it. I don't notice things that ordinary people would look at. You train your mind not to remember things that people say. You are only responsible for what you know in most cases. But learn when you are and aren't. Know your environment and what you have to report and what you should avoid seeing.

    Some good rules are:
    1. when you look at someones email don't read any of it. You will regret it!
    2. If a user needs you to work on their system ask them to close all their windows first. I cant tell you how many times I've seen pictures of people I didn't want to see because someone left their browser open.
    3. When you are moving peoples data don't open files to verify them. Ask the owner to or do a check sum by verifying size or MD5 Hash tags.
    4. Never query a database unless you want to know whats in it. I was once working on something and I didn't know what a table held. Well it was the financial info for the company more or less. I know how much my bosses made last year and they told me I couldn't have a raise because of loss of profits. Well that was bullshit...I did not need to see.

    Always keep in mind "Know what you need to to do your job effectively; But ignorance is bliss! "

  92. As a sysadmin who also sidelines tech support by phorm · · Score: 1

    I'd say that home-user support is often worse than corporate support. Rarely have I had to delve deeply into the guts of somebody machine. Usually email is either just some headers floating by on a mailserver, or a list of message as I'm doing a transfer/restore on somebody's machine.

    If a user's machine is somehow infected, you dump an image and restore a fairly well-known list of applications from scratch. Documents are on the network (also to be double-scanned by AV as necessary).

    Home users though. Files can be anywhere. Documents can be anywhere. Going through an infected machine to clean out nastiness that came in deity-knows-when by deity-knows-how can involve sifting through a lot of crap. Copying to a fresh re-image still involves going through old accounts/files and trying to find what should be copied over. People have copious amounts of downloaded crap from the internet. Person documents. Personal finance info. Saved passwords. Very "personal" videos/pictures, etc
    The first question I usually ask before digging in is "is there any location you DON'T want me looking on your computer while I do a backup/restore". I also generally get clients to log in themselves rather than providing me with a password (or just reset the password with an admin disk/account) since many people use the same login for a lot of stuff.

  93. I've been in your position by Anonymous Coward · · Score: 0

    I found it just much easier to not care and it was much easier to ignore stuff in peoples email.