Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So create a second AD account for the test environment like most shops do?


But then you don't get the joy of throwing the baby out with the bath water.

90% of the time someone insists AD is too insecure for them, it's because they're unwilling to maintain hygiene (logging into an untrusted machines with overscoped credentials 8 times a day), or unwilling to use the provided security features (what do you mean use kerberized services? ldap binds work just find and give me an anti-ad security straw man!)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: