Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

excuse me, but no. this is harmful bullshit.

Yes, backups are vitally important, but no it is not possible to accidentally rm -rf with proper design.

It's possible to have the most dangerous credentials possible and still make it difficult to do catastrophic global changes. Hell it's my job to make sure this is the case.



> not possible to accidentally rm -rf with proper design.

Can you say more about this?

I understand rm -rf, but not sure how I could design that to be impossible for the most dangerous credentials.


You can make the most dangerous credentials involve getting a keycard from a safe, and multi party sign off, not possible to deploy to more than X machines at a time with a sliding window of application, independent systems with proper redundant and failback design, canary analysis, etc etc etc.

I didn't even mean you can only make it difficult, I meant you can make it almost impossible to harm a real production environment in such a nuclear way without herculean effort and quite frankly likely collusion from multiple parties.


He said "difficult", not impossible.


Just don’t use the most dangerous credentials.

The most dangerous credentials are cosmic rays and we use the Earth’s atmosphere and ECC to fight that.


Difficult, but not impossible. Which was the point, I think.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: