I'll see your data loss and raise you a security policy violation
- Reference: 1693553406
- News link: https://www.theregister.co.uk/2023/09/01/on_call/
- Source link:
This week meet a reader we'll Regomize as "Huon" * who told us of the time he worked as site engineer for a company so enormous he dare not even hint at its name or area of business, lest the events described below be identified.
Huon came across the anonymous mega-corp's international finance department, in which about 30 souls toiled. Those folk were increasingly to be found on the phone to the helpdesk because their desktop hard drives were full, which made their PCs unreliable.
[1]
The helpdesk investigated and found something odd: the c:\temp directory was taking up a lot of space on the department's PCs.
[2]
[3]
At the time Windows often lived in a mess of its own making, so one of Huon's colleagues ran a script to empty the directory overnight, assuming – quite reasonably – that with the temp directory emptied the PCs would have all the space they needed to deliver a delightful user experience.
Wrong.
[4]
"The next day I had to visit the department to explain where all their data had gone," Huon told On Call.
In the course of that conversation, Huon explained that the mega-corp did nightly backups of its servers. Restoring the data should be a snap. Or just a snapshot away, if you want us to give the universe a second storage joke.
The first, for what it's worth, goes like this:
Q: Why was the rock band called 1023 megabytes?
A: Because it couldn't get a gig.
Clearly, we digress.
After Huon told the finance department manager about the likelihood of a swift restore, that worthy revealed he and his team had long regarded the servers as "unreliable" and had therefore stored all their important documents in the only local folder to which they had write privileges.
[5]
You guessed it: that directory was c:\temp .
Which meant the data was gone – sensibly scrubbed by Huon's colleagues in the name of freeing up disk space to make PCs behave.
[6]Windows screensaver left broadcast techie all at sea
[7]Resilience is overrated when it's not advertised
[8]Lock-in to legacy code is a thing. Being locked in by legacy code is another thing entirely
[9]How to get a computer get stuck in a lift? Ask an 'illegal engineer'
At this point Huon should have been in trouble. His team had, after all, just caused data loss.
But Huon pre-empted that charge by pointing out that the mega-corp's security policies did not allow local data storage. Those policies were properly written down in manuals, and not something finance departments should be ignoring.
"Fortunately it was the kind of place where the mere mention of security violation would silence any criticism," Huon told On Call.
Which is why Huon survived to write to On Call. We shudder to think of what happened to the finance chap!
Have users' bad security practices saved your bacon? Or has deleting data turned out to have an upside? Do you know any storage jokes? [10]Click here to send On Call an email and we may feature your feats here on a future Friday. Keep 'em coming, folks. We're especially keen to hear from younger folks, and women – two groups that have historically been very shy about sharing stories. We promise complete anonymity, as explained below.
Bootnote * On Call picks Regomized names by considering factors such as contributors' real names and the circumstances of the story. This week, for example, one name of the reader who contributed a tale included the letters "Hu" in sequence. Choosing "Huon" was a nod to that real name, and a little pun on "You on?" which has a teensy touch of tech about it. We considered "Hunter" but decided against it lest it fuel certain conspiracy theories. If any of you decide that Huon could also mean "Q-on", the exit door is to your left – use it now, please.
When we receive a contribution that involves burying cable in a trench, we might Regomize the reader as "Doug". We mention this partly so we could reveal the "Huon" pun and partly to give readers comfort that we strive to make it very hard to connect On Call stories with their real-world identities. Indeed, to the best of our knowledge nobody has ever landed in trouble for sharing a story with On Call.
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZPG2Q1IkuHbgIaGndRN2zgAAAMA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPG2Q1IkuHbgIaGndRN2zgAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZPG2Q1IkuHbgIaGndRN2zgAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPG2Q1IkuHbgIaGndRN2zgAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZPG2Q1IkuHbgIaGndRN2zgAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/08/25/on_call/
[7] https://www.theregister.com/2023/08/18/on_call/
[8] https://www.theregister.com/2023/08/11/on_call/
[9] https://www.theregister.com/2023/08/04/on_call/
[10] mailto:oncall@theregister.com
[11] https://whitepapers.theregister.com/
Re: Outlook...
It's always baffling that no matter how much we try to use familiar concepts and real-world analogies when designing applications, some users just completely miss it.
Imagine someone putting important paperwork in the recycling bin, and complaining when they find out cleaning staff threw it out overnight.
Re: Outlook...
Or having a massive pile of photos, random bits of paper and possibly even DVDs on the surface of their desk, and complaining they can't find anything, while the desk drawers are completely empty. Oh and I suppose in this metaphor the recycling bin would actually be on the top of the desk too.
Re: Outlook...
My working theory is that some users haven't developed object permanence yet.
Storing things out of sight just makes it disappear for them.
Can be quite problematic when combined with sticky notes.
Re: Outlook...
In at least a few cases, I've seen the recycling bin ending up inside one of the DVDs on the surface of the desk, in apparent violation of all laws of both physics and common sense.
Re: Outlook...
Don't you hate it when you're casually dragging your recycling bin across your desk, it slips out of your hand, and just disappears into a different object?
Re: Outlook...
"a massive pile of photos, random bits of paper and possibly even DVDs on the surface of their desk, and complaining they can't find anything"
This is the One Pile filing system. It's advantage is that you always know where something is. It's in that pile.
Not being able to find something happens when it gets tidied into drawers. Anyone who uses that system can tell you that. Those empty drawers are a dangerous temptation.
Re: Outlook...
Another advantage of the One Pile system is that it is self-sorting. The "important", recent, stuff can be found near the top, whilst the "it can wait another week" stuff magically works it's way lower down.
Re: Outlook...
Way back when I was a civil servant any papers you threw out had to be torn through before binning otherwise you'd find them back on your desk the next day. Apparently it was a measure to stop claims of, "It must have been thrown away accidentally!"
Out of habit I still do this.
Re: Outlook...
I'd be surprised if anyone who administered SVS2K3 hasn't encountered exactly this problem!
Re: Outlook...
Predictable that this would be the first comment. It's a consequence of (a) email clients not being designed with reasonable use cases in mind and (b) admins not keeping up with growing storage requirements which is also part of Huon's users' problem.
Another punnery well done.
I'm on my way for celebrating it with that --->
Others may groan at the punnery. Let us have our punning funnery.
To be fair...
...you should really take a look at the folder you're going to purge before pushing a script like that.
Even a quick glance at the folder structure would've revealed that the users didn't quite understand the definition of "temporary".
Don't get me wrong, it's definitely the bean counters' fault, but it could've been prevented.
Wouldn't be the first time important files or mails end up in a temp folder or the recycling bin.
Re: To be fair...
...the users didn't quite understand the definition of "temporary".
In IT there is nothing more permanent than temporary.
Re: To be fair...
Not just IT! There is nothing more permanent than a temporary fix that works.
Re: To be fair...
Tell me about it. When I moved to France and discovered that unfurnished meant no kitchen units either, I built a temporary kitchen from the moving boxes and duct tape. Lasted two years.
Re: To be fair...
Ha! I guess we are all guilty of that one.
Have one of these--->
Re: To be fair...
This also applies to staff.
Re: To be fair...
"you should really take a look at the folder you're going to purge"
Security might have prevented that. OTOH an enquiry wouldn't have been out of place.
BTDT
Doing clear out/tidy up of /var/tmp on a Solaris server and deleted a file - which apparently was vital to the operation of the application. At least the app team lead acknowledged it shouldn't have been there and was able to recreate it.
Then I did it again about a year later... oops!
The saving grace for me was that app was pernickety as hell and prone to falling over at the best of times.
Posting anonymously because, well....
Sounds familiar
I worked for an insurance company (long since gone) and we were moving from Windows 3.11 to Windows NT 4.0. We weren't a rich company so we were upgrading the OS using the `ghost` application, one machine at a time (two if we had two floppy disks and a spare source hard drive)
Before each upgrade we visited or emailed the users and told them that they would lose everything that was not in the "C:\DATA" folder (which we had created for them when we built the machine in the first place). We stressed this several times as that was the only folder we were going to back up to the Netware 3.1.1 server (see the kinda era we're talking about here?) so if they wanted to keep it, the data needed to be in that folder and nowhere else. Everyone understood. We repeated it. They understood even more.
We spent weeks doing the upgrades one department at a time. We had smaller offices around the country (Glasgow to Bristol) so we'd visit for a day, do the deed, and then either head home or onto the next closest office (Newcastle and Glasgow were usually done in one trip over a couple of days. Where else was I going to get a proper Scotch Pie from?).
The only problem we had was at Head Office in the Finance Department. We did HO machines over night (mainly to minimise disruption, but also for the overtime). We'd spoken to the sub-head bean counter and he was ready. We backed up his DATA folder, ghosted the machine, then copied his documents folder back again. Job done. Beer deserved.
The next morning we got a phone call from sub-head bean counter asking where his data was. We told him that it was in his DATA folder. He replied:
SHBC: But I have data in other folders. I need that back too
IT: It's gone
SHBC: I need that data back. It's important
IT: We told you that we'd only back up the C:\DATA folder
SHBC: I thought you meant all my DATA folders, not just that one
IT: It's not happening. We didn't know about those other folders, and we don't have time to search hard drives for data
SHBC: But it's important company critical data
IT: Oops.
We had a good boss. Ken was big. Ken was scary. Ken was the one who decided what was allowed on his network. No one messed with Ken and, if he knew you didn't do anything wrong or had been proven guilty of something, he'd defend you to the end. He went and had "a chat" with said bean counter. Nothing was ever heard about it again. EVERYONE got their documents into the right folder after that
When?
At the time Windows often lived in a mess of its own making
Doesn't help narrow it down, really.
No local storage allowed ?
You're using Windows and you do not allow local storage ?
You clearly don't know Windows users.
Re: No local storage allowed ?
I recall my university had rooms of PCs (this would be '95 or '96) which had no local hard drive, everything was done over the network.
Given that we were stringing our own PCs together via ribbon cable between parallel ports for Duke Nukem, this was serious voodoo.
Re: No local storage allowed ?
Lovely solution for situations like that, especially considering the cost of storage at the time.
PXE made this a lot easier, but i believe that wasn't released until '98 or '99.
Also, not sure if the Voodoo pun was intended, but have one of these either way --->
Re: No local storage allowed ?
"You clearly don't know Windows users."
And forgot what the P in PC stands for.
Re: No local storage allowed ?
PC nowadays is most likely "Probably Crap"...
What's in a name?
I'm not sure whether The Reg doesn't mention Huon, brother of Hurin, of Tolkien's Silmarillion fame, because it does know us so well, and doesn't need to point that out to us, or because it doesn't, and overlooked that aspect of it.
ETA: I'm an idiot. Of course, that's Huor, not Huon. Stoopid brain association.
Re: What's in a name?
Re: What's in a name?
Well, I was thinking the submitter was a dark ent, to be honest
Hunter?
"We considered "Hunter" but decided against it lest it fuel certain conspiracy theories"
I suspect that little comment won't age very well. A bit like someone in the New York Times during 1973 saying "What's all this fuss in the Washington Post about Watergate, it's just a conspiracy theory".
Let's wait and see.
Re: Hunter?
I saw that and initially thought of 'hunter2' https://knowyourmeme.com/memes/hunter2
Bad storage joke
On a clear drive you can seek forever
I know someone who keeps documents in GMail drafts. Occasionally they send one of the documents to someone, then copy it from Sent back into Drafts. I sometimes provide some unofficial IT support for them, but after having tried to explain why this is such a dreadful idea and suggesting several more reasonable ways of doing things to no avail I've simply had to refuse to provide any support for such a fundamentally misguided setup.
Outlook...
Client had SBS2k3 server which, as they always did, was butting up against the Exchange storage limit.
A quick review revealed, as they always did, that high-use users had massive Deleted Items folders.
Set a quick group policy to 'empty deleted items on exit' and pat self on back for a job well done.
Nope.
Several of them had worked out that hitting 'delete' was quicker than dragging a completed email to a different folder or flagging it as complete, so that was their workflow for archiving messages. It was absolutely essential, of course, that they were able to retain them.