"Because doing shots of rum at my desk is not an option."
#LifeInIT
Vuln scan identified a Critical issue in a component deep in the guts of 3 products. For some reason it took more than a month for my suggestion to, ya know, ASK THE PRODUCT OWNER if their platform is actually vulnerable the CVE use cases.
And then another 2 weeks to get a reply that since we are busy replacing the platform and are on an unsupported version (urk!) that the PO is not interested in spending time opening a Support case.
And then 5 *minutes* for ME to open the Support ticket for them, 30 minutes to get an update indicating support is checking with engineering, and 14 more hours to get a PHONE call from Support walking me through what's vulnerable and what's not, and a well written follow-up email showing we are not at risk and can downgrade the severity and add this to the Risk Acceptance list.
And then I get people harping on me because "That's not your job to do!โ
FUCK IT, I solved the mystery, didn't I? And got a broad-scope CRITICAL off the VM list.
AND the vendor acknowledged that not even their most recent release has the fixed component, and now they are working to fix that!
Me this morning: I'm going to start out this year by staying completely caught up on my To Do List.
Me this afternoon: I'm going to start out this year completing urgent Side Quests while falling behind on my To Do List.
When you realize the weekend is over. ๐
When you've been in IT longer than 5 minutes. ๐ฏ๐
A Series of Unfortunate Events, a working title for way too many IT projects, incidents, and migrations. ๐ฌ๐
#lifeInIT
#noPlanSurvivesFirstContact
#neteng
#securityEngineer
It's always DNS. ๐ฌ๐
https://techcrunch.com/2023/09/11/square-daylong-outage-dns-error/