this post was submitted on 24 Aug 2026
392 points (99.5% liked)

memes

22494 readers
2669 users here now

Community rules

1. Be civilNo trolling, bigotry or other insulting / annoying behaviour

2. No politicsThis is non-politics community. For political memes please go to !politicalmemes@lemmy.world

3. No recent repostsCheck for reposts when posting a meme, you can only repost after 1 month

4. No botsNo bots without the express approval of the mods or the admins

5. No Spam/Ads/AI SlopNo advertisements or spam. This is an instance rule and the only way to live. We also consider AI slop to be spam in this community and is subject to removal.

A collection of some classic Lemmy memes for your enjoyment

Sister communities

founded 3 years ago
MODERATORS
 
top 38 comments
sorted by: hot top controversial new old
[–] AGD4@lemmy.world 93 points 5 days ago* (last edited 5 days ago) (4 children)

Y'all joke, but when that 'task' is run through process monitor, we see it's trying to overwrite a DLL in system32, create a directory at root of %systemdrive% or cache some data in the Program Files application itself, instead of utilizing ProgramData or Appdata properly.

When applications fail these simple practices and demand local admin, they shouldn't touch your network.

<3

[–] 4am@lemmy.zip 29 points 5 days ago (4 children)

As an insane person who moved all my folders to the D drive, it’s absurd how many big companies hard code C:\Users\you\AppData\Roaming

[–] Funkt4st1c@lemmy.world 10 points 4 days ago (1 children)

Easy fix, just mount your desired hard drive to a new root directory, call it /mnt/whatever and symlink... Oh.

[–] boobookittyfrick@lemmy.zip 2 points 4 days ago

Laughs in NTFS

[–] Quetzalcutlass@lemmy.world 3 points 4 days ago

The hardcoded AppData path is the main reason I had to spring for a larger system drive a few years ago despite not installing any programs to it. Gradle/NuGet/every other package manager were the main culprits, with Microsoft themselves coming second. Every few months I'd clear out their caches and "temporary" file folders and it'd free up tens of gigabytes.

I'd mess around with symbolic links to move it to another drive if I didn't half-expect Windows to break them at some point.

[–] MonkderVierte@lemmy.zip 3 points 4 days ago* (last edited 4 days ago)

I've had my PortableApps there. And the not so portable (but still standalone ones) too. Some of them could even permanently fuck up UAC, allowing acess to everything, as a side-effect.

[–] wonderingwanderer@sopuli.xyz 0 points 4 days ago

D drive
...
C:\

I... I'm sorry, I don't comprehend... Are you speaking some sort of archaic language or something?

[–] shininghero@pawb.social 20 points 5 days ago (1 children)

LUA Buglight is also good for documenting why a program needs admin when it shouldn't.

After that, you just write an admin shim with the app compatibility toolkit and just add write perms to the necessary folders.
...Unless it's system32. Then your software request can die in a fire, and I'm forwarding the info to your boss (and mine) before you can complain to them.

[–] wonderingwanderer@sopuli.xyz 2 points 4 days ago (1 children)

Can you please explain to the laity what the problem with System32 is? So we know why to avoid it

[–] shininghero@pawb.social 4 points 4 days ago (1 children)

It is the beating heart of Windows itself, the nuclear reactor at the heart of the facility. And much like with a nuclear reactor, you don't screw around in the core unless you have a damn good reason.
Doing so at random is a good way to make both go kaboom.

[–] wonderingwanderer@sopuli.xyz 2 points 4 days ago (1 children)

So is it like the kernel but for windows?

[–] shininghero@pawb.social 4 points 4 days ago

More of a combo of kernel and coreutils, but yeah. Pretty much.

[–] saltesc@lemmy.world 16 points 5 days ago* (last edited 5 days ago) (1 children)

I've worked for two organisations that distributed licences for users. Being able to prove, under scrutinisation, that your general requests do not need to be questioned for that level. Anything above your level of liberty in the data governance would be checked—though 99% of the time you already know this and explain in full detail on the request to help.

It worked perfectly and I don't know why it's still not the norm.

In a 'wet cement' org structure, often the specialists in an area know far more about what's going on than the juniors gatekeeping. If you aren't buddies with the person on top, you join the queue and a 5 min job becomes 6 months and several meetings; if you don't already botch a dodgy workaround before then.

Edit: I'm in year 3 of getting the Oracle SQL add-on allowed to direct query, read only, in Excel. My current workaround is to use the IDE to export to CSV, store on SP, then PQ that... And, yeah, I have write access in the IDE even though I keep telling them that's bad... Apparently, that solution is more secure. I've spoken to the CIO about the concerns and how it breaks the fundamentals of our data governance framework. The new infrastructure architecture gets it, but has to spin the better way of doing things as a "trial" which has taken 6 months to approve and counting...

[–] Shanmugha@lemmy.world 3 points 4 days ago

Reading your comment at night does feel like a horror story

[–] crunchy@lemmy.dbzer0.com 4 points 5 days ago* (last edited 5 days ago)

Too much jargon. Employee is just using an AI agent.

[–] horse@feddit.org 13 points 4 days ago (2 children)

As someone who is currently having to take away people's local admin rights along with a ton of other privileges: it's not like we do this for fun, we have compliance goals to reach that were agreed to by higher ups outside of the IT department in exchange for public funding (we're a public institution).

[–] zqps@sh.itjust.works 14 points 4 days ago* (last edited 4 days ago) (1 children)

You only need to experience what some people manage to do to their machines with and without admin access to favour a return to the abacus for the general workforce.

And software developers are simultaneously the best and absolute worst users.

[–] 123@programming.dev 3 points 4 days ago

Our record was less than a workday for a developer to get infected with malware after their machine just got re-imaged. After that everyone lost admin access by default unless they had an exception since he was not the first that month.

[–] ivanafterall@lemmy.world 3 points 4 days ago (1 children)

"I was just following orders." 🙄

[–] horse@feddit.org 3 points 4 days ago (1 children)

Whatever that is, it's not loading for me.

[–] bitjunkie@lemmy.world 2 points 3 days ago

It's Mel Gibson screaming "Freedom!" in Braveheart.

[–] Rat_in_a_hat@lemmy.ca 39 points 5 days ago

Sorry, gonna need a ticket to escalate that

[–] anewfox@lemmy.zip 8 points 4 days ago* (last edited 4 days ago)

everyone thinks they can pull it off just fine, but believe me, it's not a bad bet that your IT dept knows better than to bend to someone just dangerous enough to be a problem. it's probably happened before and that's probably why the policy is in place.

[–] groet@feddit.org 11 points 4 days ago (2 children)

Cool, here is a VM without domain join and no access to internal resources. Feel free to use your admin permissions on there.

Seriously though: developers need admin access during prototyping unless you are a giant enterprise that already has CI\CD, dependency management, staging environment etc all set up and properly configured. For everything else, devs should have their contained sandboxes with admin permissions

[–] Shanmugha@lemmy.world 8 points 4 days ago* (last edited 4 days ago) (1 children)

*and all those environments come with admin teams (devops, sysops, call them whatever) actually good at what they do. Because I have a long list of things to vent about exactly because:

  • you're a dev, so fight us for access and permissions (edit: that I already have ssh access to prod servers and thus could wreak havok any moment if I wished to is completely ignored)
  • here's a botched something you asked. It is not configured/improperly configured - well, who da fuq cares. Let's have another kanban card for fixing this
[–] zqps@sh.itjust.works 6 points 4 days ago (1 children)

Most of the damage is done with good intentions.

Recently one of our devs was caught running Chrome portable (because he wasn't given admin access), where he logged in to his personal google account and saved his company credentials, where they were promptly synced to his personal malware-infested home system and ended up in a paid dataset on the darknet. IT Security, InfoSec and Governance policies have to be written with this kind of employee behaviour in mind.

Incidentally him and his team had just complained loudly about MFA being required for our critical apps.

[–] Shanmugha@lemmy.world 1 points 4 days ago

Well, that is bad all over. And also can be seen as an evidence towards "if someone requires access that does not look suspicious, give it to them": he wasn't given access, so he went another way and fucked up spectacularly. On the other hand, though:

  • if it is a company machine, then not having admin access can be expected
  • I would expect that "do not ever use personal accounts for work and vice versa" does not need reminding, but here we are
  • yeah, the rules should account for malicious behaviour, intended and not
[–] AllHailTheSheep@sh.itjust.works 2 points 4 days ago (1 children)

I'm forced to use windows to work. but having wsl2 with root makes it almost bearable.

[–] groet@feddit.org 1 points 4 days ago

What's relay funny about WSL2 is how you can be root in Linux but the whole WSL is still just a windows process with user permissions. So root!=administrator. Its actually pretty smart. Like root in podman container or in rootles docker.

[–] underscores@lemmy.zip 13 points 5 days ago

The holy war between good (IT) and evil (npm) but my feature needs to be out end of month and I can't have everything installed immediately blocked or I won't meet the deadline

[–] IrateAnteater@sh.itjust.works 18 points 5 days ago (2 children)

IT tried to get super strict with that at my company, but they relented when ticket volumes went up by a couple thousand percent.

[–] picnic@lemmy.dbzer0.com 4 points 5 days ago (1 children)

We have done this, and it took years.

We audited every exe and whitelisted like majority with over 50 users. Some occasional victims here and there (I lost access to my self compiled ones, too) but overall no THAT signigicant rise in ticketing

[–] IrateAnteater@sh.itjust.works 8 points 4 days ago (1 children)

I do industrial controls. The software we are forced to use is usually proprietary, sometimes old, and always very poorly written. Plus there's the networking issues. A huge amount of stuff is just statically addressed, so I might be switching the ethernet port on my laptop from an 89.89.x.y subnet, to a 10.10.i.j subnet, to a 192.168.a.b subnet, and back again multiple times a day. When IT first took admin rights off our laptops, it took away our ability to change IP addresses. There may have been some small amount of malicious compliance.

[–] mojofrododojo@lemmy.world 2 points 4 days ago (1 children)

approximately how many windows XP instances running CNC shit do you support?

seeing these in the wild blew my mind

[–] IrateAnteater@sh.itjust.works 2 points 3 days ago (1 children)

Haven't come across many of those, since we tend to do small to medium sized production line type machines, as opposed to individual CNC stuff. That being said, it is wild how hilariously insecure everything is.

[–] mojofrododojo@lemmy.world 1 points 3 days ago

it is wild how hilariously insecure everything is.

yerp. I get it, who wants to throw away a machine that costs $120k because there's no modern software to run it, but holy hell....

[–] apftwb@lemmy.world 2 points 4 days ago

My company would respond by not processing tickets any faster and just let deadlines slip.

[–] majster@lemmy.zip 2 points 4 days ago

Heh. At my $dayjob we develop software for automated permission audit and revoking/granting.

All is fine until it isn't. Security really is a bitch.