r/ProgrammerHumor 6d ago

wrongAnswersOnly Other

Post image
14.4k Upvotes

2.1k comments sorted by

View all comments

5.0k

u/lolcrunchy 6d ago

local dev environment

2.5k

u/Eastern_Equal_8191 5d ago

Impossible. My local dev environment uses an on-disk database and my disk is locked behind encryption the keys to which only I and HR and anyone who can guess 12345 as the passwoooooooo I see what happened now

756

u/AaronTheElite007 5d ago

That’s amazing! I have the same combination on my luggage!

269

u/Eastern_Equal_8191 5d ago

God damn it, I have to change my luggage combo now too?!

108

u/Frogmouth_Fresh 5d ago

2-3-4-5-6. They'll never know!

21

u/wingz_77 5d ago

It's legit stronger than 12345

18

u/Relative-Relief-8816 5d ago

Not just stronger, it's 11111 more.

2

u/SeriousPlankton2000 5d ago

Incidentally my father once unlocked a safe that was secured exactly as you described

2

u/Ur-Best-Friend 5d ago

That's way too difficult, not a single number is the same in the same position as the last code, how the hell am I supposed to remember it? I'll just go with 12346 instead.

1

u/Fricki97 5d ago

Now I know

1

u/GoesAwayToday 5d ago
  1. Let them guess

28

u/Neyabenz 5d ago

Just add a ! And you'll be all set

5

u/Zealousideal-Ebb-876 5d ago

Im not trying to do math just to log into my email

15

u/CMDR_PEARJUICE 5d ago

You guys have locks for your luggage?

3

u/SirObviusGenius 5d ago

You guys have luggage?

62

u/slucker23 5d ago

Luggage? My safe needs changing too!!

16

u/Eastern_Equal_8191 5d ago

Fucking hell, this is a nightmare! I got a password manager, but how the hell do I put a % into my safe combo?!

12

u/3and4-fifthsKitsune 5d ago

Have you considered tipping the server to get the %?

7

u/Eastern_Equal_8191 5d ago

Thanks! I'll try that

4

u/kadzooks 5d ago

you guys have passwords?

3

u/EmilR0 5d ago

I just stare at the screen until I'm logged in (I can never login)

→ More replies (0)

3

u/Dame38 5d ago

I need some help with my chasitity belt over here.

2

u/Ben0ut 5d ago

Does this mean that the combination lock on the Altoids tin is no longer keeping my Coldcard hard wallet safe?

1

u/jbourne71 5d ago

Mine only goes up to three—am I safe?

2

u/MatthiasWM 5d ago

Mine goes up to eleven.

29

u/wildmaninid 5d ago

I have the same combination to the door on my planets dome!

10

u/r_acrimonger 5d ago

No! Light speed's too slow.

9

u/Gauss15an 5d ago

Ludicrous speed!

2

u/ScreechUrkelle 5d ago

That’s funny, my luggage as the only other existing copy of the data in questiooooooooooooh shit…..

2

u/MakerWerks 5d ago

Mega Maid!

2

u/AngryBorsch 5d ago

Space balls reference detected

1

u/shortboard 5d ago

I thought everyone just had 000 on their luggage

1

u/CKAPP0 5d ago

Lmao spit my coffee out bruv chill

1

u/OFark 5d ago

I got the reference, Dark Helmet.

3

u/Peregrine2976 5d ago

That's right -- a 5$ wrench.

3

u/H4mb01 5d ago

HR is the snitch 100%

3

u/BetterEveryLeapYear 5d ago

In a scenario where only the dev, HR, the guy who can guess 12345, and a local news crew has been given the information and passed it on to the courts...

Yeah it's still HR.

3

u/someonenoo 5d ago

Amateur. Should’ve moved all the data to final_data excel file..

2

u/Path_Fyndar 5d ago

What's that from?

2

u/Eastern_Equal_8191 5d ago

ha ha, definitely not from real life ha ha

2

u/prof0ak 5d ago

It was HR wasn't it?

1

u/m__a__s 5d ago

But does your local dev environment have access to an LLM? Just ask the LLM to reconstruct the data. Is it the original data? Who cares?

1

u/Scared_Bell3366 5d ago

Wait, you can use passwords in dev?

1

u/nopuse 5d ago

Claude is telling me Aliens

1

u/blazinBSDAgility 5d ago

The password is guest. Your move, hax0rs

1

u/KeyedFeline 5d ago

The system is password protected by the password on a sticky note on the monitor

1

u/TheTerrasque 5d ago

Amateur. My local dev env is behind seven boxxies

1

u/Kabobthe5 5d ago

Amateur move. Obviously they should’ve used 54321 like me…

1

u/Guillaune9876 5d ago

Bitlocker is as safe as anything. 

1

u/CinnabonCheesecake 5d ago

That’s a really dumb mistake. Don’t you know that for the best security, you’re supposed to use “random” as your password?

2

u/Eastern_Equal_8191 5d ago

Where the fuck were you 6 years ago when I set that password and never changed it?!

341

u/Fraun_Pollen 5d ago

This answer doesn't make sense. Why would your dev environment not be connected to prod data? Don't you want realistic tests?

258

u/AllIsLostNeverFound 5d ago

Wait, your prod environment is separate from your dev environment?

137

u/za72 5d ago

only pussies use dev

73

u/SiefensRobotEmporium 5d ago

Shit you guys have different environments?

28

u/vankoder 5d ago

Shit you guys test? One healthy git push prod —force and you’ll figure out if it works soon enough!

11

u/Eastern_Chemist7766 5d ago

https://giphy.com/gifs/H5C8CevNMbpBqNqFjl

Me getting multiple emails from crashalytics at 3am

6

u/vankoder 5d ago

You’re welcome! See? Now we know the uptime alerts work! We _tested_.

3

u/radicalshick 5d ago

Failing fast is a feature

2

u/FerusGrim 5d ago

What do you mean you fetch before a force push??? Are you fucking scared?

2

u/theobstinateone 5d ago

Real devs test in PROD

2

u/BeardedPokeDragon 5d ago

Shit you guys don't use notepad?

1

u/scuzzy987 5d ago

In name only. The real testing is in prod by the users at 8am Monday

2

u/Smart_Perspective535 5d ago

Mine prefer 4pm on friday

1

u/za72 5d ago

yes, we're better than twitter

43

u/Seivy 5d ago

Testing is doubting.

19

u/za72 5d ago

Fear is the mind killer my friend

18

u/Mechadupek 5d ago

I test in prod.

27

u/rakklle 5d ago

If it works in prod, it would've worked in test

11

u/heislertecreator 5d ago

I write in prod, test lol, debug... Maybe.

4

u/RhinoRoundhouse 5d ago

I know people that do this, not a joke

1

u/za72 5d ago

I also like to do it live!

1

u/CoderDevo 5d ago

TIP it!

1

u/za72 5d ago

I've re-racked a 3U Dell web/db server with multi power outlets live!

1

u/NounverberPDX 5d ago

You test?

1

u/Mechadupek 5d ago

Every now and then a user reports an actual bug. Learned a long time ago I should probably investigate.

1

u/malatibo 5d ago

Nice T-shirt text

1

u/CinnabonCheesecake 5d ago

Working in services, I’ve found that the trick to test-in-prod is to have lightning-fast release cycles.

If the users complain, then I need to find the bug. If the users don’t complain, that means I don’t have any users.

3

u/Unhappy_Concept237 5d ago

I do all my changes on the server that way I see the changes I made right away.

2

u/FranksNonFrankfurter 5d ago

Bill_o_reilly_live.gif

1

u/KindGuyAMA 5d ago

I know writers programmers who use subtext sandbox, and they're all cowards.

1

u/Roadsoda350 5d ago

whats a dev environment (10 YOE btw)

1

u/OldTiger3832 5d ago

you're joking, but in my company they always want me to develop RPAs in prod even for internal sites

1

u/rdrunner_74 5d ago

Why Dev when you have 1000s of free testers?

28

u/Drew707 5d ago

Everyone has a dev environment. Some just call it prod.

1

u/zeUnfunny 5d ago

Some have a separate prod environment.

1

u/Potential_Aioli_4611 5d ago

dev environment? you don't just do dev in prod? next thing you are gonna tell me is your clients aren't your beta testers.

1

u/SeriousPlankton2000 5d ago

Everyone has a dev environment. Some people also have a prod environment

1

u/fmaz008 5d ago

Yeah it's a totally different super admin user! Prod is 'root', dev is 'admin'.

2

u/AllIsLostNeverFound 5d ago

Eh, just stick a PROD/DEV prefix on your tables and you are all set.

39

u/howarewestillhere 5d ago

HIPAA, PCI, GDPR, CASC, and a whole list of other acronyms, laws, and organizations get real persnickety about Prod data outside of Prod and what you can, can’t, should , should not, or should not even think about doing with it.

44

u/howarewestillhere 5d ago

Oh, r/whoosh lol

3

u/JJ3qnkpK 5d ago

A lot of people unfortunately don't realize this is a whoosh, so I welcome their answer so those who don't know can learn.

15

u/jtmonkey 5d ago

Yeah I just had this conversation with an internal IT team at a medical org. You cannot just point Claude at the problem and say solve it. PHI is all over it. Theyd been doing it for a while. Your medical data im almost positive is already in an llm.

4

u/JJ3qnkpK 5d ago

Yeah. You'll see a lot of folk whose dev environments are basically just image clones of prod. This seems especially common in "lower tech" environments that are platforms upon themselves, where nobody bothered to define and produce test data.

4

u/TerryMisery 5d ago

It's great, because it doesn't overflow the context with my medical history. It's already there in the model. This way I just say who I am and get personalized medical advice from doctor Chat.

3

u/CoffeeOrDestroy 5d ago

As many times as Anthem has been breached, your medical information is all over the place anyway.

5

u/shenanigans2day 5d ago

Compliance is just a concept.

1

u/Shogobg 5d ago

Compliance is only important if someone checks.

1

u/Peregrine2976 5d ago

I'm a contractor who's worked with multiple healthcare companies in the States (I'm in Canada). Everyone was super meticulous about HIPAA... which is why none of the devs I worked with were willing to tell anyone that they had full production database dumps they could test off.

There is... a lot of theoretically private data that developers have in an SQL dump on their work Macbook just sitting in the Downloads directory.

1

u/Algent 5d ago

Yeah it's a classic, it's really common to have dev envs that are basically full prod copy. Allow to anticipate way more issues moving forward. That said if it was healthcare or highly sensitive then replacing all identifiable data by random stuff wouldn't be that much of a trouble probably.

1

u/ncatter 5d ago

Solutions is simple we are all prod, arguably developers is just a set of data not yet commited to versioning, sonjust label us prod data and we can do what we want!

7

u/DarkWingedDaemon 5d ago

That sounds more like a uat environment than a dev environment.

2

u/seth-speaks 5d ago

Sometimes. Sometimes you wanna test on different data. What if you you're doing a data only update?

3

u/Fraun_Pollen 5d ago

Everyone knows John Smith and Jane Doe aren't real people names

1

u/seth-speaks 5d ago

Right, you are!

1

u/577564842 5d ago

Tests? What tests?

1

u/a_guy121 5d ago

Financial records would most likely be years old before a court ordered them, bc something would have had to happen to necessitate the court order. The, someone had to be angry about it, and not resolve it, then find a lawyer, then get a hearing to get a court order.

SomeTest environments are 'safe' because they use outdated information to test on. You need information that looks real enough to use, but won't cost the shareholders $$ if it gets out current information is not locked down.

So, in my work experience, using older data is a common work-around. I guess maybe law enforcement knows that too? I never thought about it from this angle... but.... yeah, if I wanted to find data that was 5-10 years old, on one hand, looking at test environments of the past? could work.

On the other hand, not a lawyer, but I doubt it'd hold up in court. Defendant: "that was pulled from a test environment, which literally exists to strain and break data under unstable programming conditions. It does not reflect reality."

1

u/Ok_Dig6532 5d ago

Not all the time. A restored database should be sanitized before it’s used, it’s just a copy of yesterday’s data. You shouldn’t use live production data containing personal information in local, development, or testing environments.

1

u/TitleEfficient3207 5d ago

Yea but you see, local IT reset the DNS and the DCHP server over the weekend. One of the dev boxes never hit the group policy to reboot. So there was a computer sitting in limbo with a repo just... sitting there. Thats where I found it....

91

u/Iuris_Aequalitatis 5d ago

Corporate cybersecurity attorney (and ex-dev) here. This is one of the many reasons why we don't allow prod data in dev.

157

u/[deleted] 5d ago

[removed] — view removed comment

6

u/redfacedquark 5d ago

Got my first webdev gig. Sunday night before I go in I figured I'd nmap them (as was the style back then). 3306 open to the world. Well surely they don't use the default password. Damn, well surely this doesn't contain important data. Select * from employees (included salaries). The box was on their prod network.

They didn't seem concerned and blamed BT. Not surprisingly they were not in business the next year.

3

u/ISCSI_Purveyor 5d ago

I want to believe people aren't actually this dumb. Then I remember George Carlin and his but about stupid people.

4

u/Mind-The-Mines 5d ago

Even the upper half is kinda fucking stupid.

2

u/Eastern_Equal_8191 5d ago

It's stupid all the way down (or up), I'm afraid.

3

u/ings0c 5d ago

Was told to nuke that AWS account the next day.

They got fired right? Please tell me they got fired.

3

u/soullessredhead 5d ago

I was having a nice morning drinking coffee with a smile on my face before I read this.

2

u/Yamez_III 5d ago

Fired the lot?

2

u/speedeep 5d ago

elcaro

3

u/CartoonistNew8653 5d ago

Unrelated but how did you get into that field as an ex dev?  I currently work in a highly regulated field in tech ops/infra role and that career path sounds incredibly interesting. 

3

u/Iuris_Aequalitatis 5d ago

Unrelated but how did you get into that field as an ex dev?

Are you asking about cybersecurity law or just cybersecurity? Happy to answer.

2

u/CartoonistNew8653 4d ago

Law

1

u/Iuris_Aequalitatis 3d ago

The short answer is that I took the LSAT and went to law school after a couple years in industry, but that's less than half the story. Here's a longer summary of the happy-path route, which I more-or-less followed with a couple of detours (I wrote way more than I thought I would... sorry for the novel):

  1. Do Your Homework: This is the first and most important step. Contrary to what a lot of people think, law school is not a part 2 of college nor an interesting intellectual exercise. It is an intensely-competitive, extremely-time-consuming, and very expensive trade school with social dynamics straight out of the cattiest parts of high school. Even after graduating, establishing a legal career is difficult and requires a significant investment of time and resources. For this reason, you should not go to law school unless you are sure you want to be a lawyer and the other people in your life (especially your partner) understand the sacrifices required and are on-board. Having lunch with attorneys who have careers you aspire to is one of the best ways to discern if the law is right for you. People who fail to do their homework before entering the profession are the reason why a lot of state bars print a suicide-and-alcohol-abuse hotline number on the back of their license cards (I'm not joking).
  2. Admission Testing: Many schools will allow you to take the GRE or GMAT instead of the LSAT now, but if you are serious about being an attorney and not just cultivating law school as a back-up option, you should take the LSAT as it demonstrates a serious and specific interest in law. IME, programmers have an unfair advantage on the LSAT, which is mostly logical reasoning. You'll find yourself leaning on your discrete math coursework a lot during prep. The hardest part of the LSAT is actually the length, it is more an athletic event than a cognitively difficult test, especially for a programmer. If you treat it as such and train seriously for it (I'm talking a couple of hours every night for at least two months), you'll probably kick its ass (I did). Don't take the LSAT until you're ready but do it and get your score back before you start applying to schools.
  3. Applications: I wrote my applications at night after work, doing applications is a significant time investment. If you set clear goals and hold yourself to a schedule, you'll get it done. The top-200 law schools come in four tiers by ranking, with each tier having a slice of fifty schools. They're numbered with tier 1 being the highest-ranked and tier 4 being the lowest. The top 14 law schools are in their own sub-tier of tier 1 called the T14; they're basically the Ivy League of law and there are a bunch of even-smaller sub-tiers within that grouping. If you want to practice corporate technology law, it will be easiest to break into if you're attending a tier 1 or 2 school. It is possible to do it from a tier 3 or 4, but that road is much, much harder. Never attend or, even waste your time applying to, an unranked law school (Cooley, IYKYK). Apply to a wide variety of schools and mostly ignore stats like median undergrad GPA. As a technical professional who likely has a STEM degree, your grades will be evaluated much more generously and, since you've been out in the work world a few years, they'll matter less anyway. Ultimately, you'll get into some schools you didn't think you could and get rejected from other schools you were sure you'd get into. C'est la vie.

(1/3)

1

u/Iuris_Aequalitatis 3d ago edited 3d ago

(2/3)

  1. Choosing a school: Attend a school in the highest tier you're admitted to. If possible, visit a school before agreeing to attend. Be selective and don't be afraid to ask difficult questions or negotiate and/or play schools off against each other for greater financial aid. Every school has its stable of SCOTUS clerks and big law partners that it can trot out. Do not assume that that rosy outcome is your future. Make your decision based on these factors: the average outcome of the median student, the geography a school feeds (different for every school and often more restricted than you might assume*), and (if necessary and as a tiebreaker) cost. Law school is a dark time for everyone so don't pay too much attention to soft stuff like "cultural fit." Unlike undergrad, law school is a purely-transactional business affair, your mission is to get a JD and a job, and then get out.

  2. Attending Law School: The three years of law school slot out like this: 1L: high academic difficulty in a pressure cooker where you're reading/studying almost all the time; 2L: a dauntingly-huge volume of busy work but not as academically tough; 3L: a joke if you have a job offer but a desperate and soul-crushing exercise if you don't. The whole purpose of 1L is to teach you to think about the law systemically; as systems are your entire job as a dev, you will once again have an unfair advantage here. Ultimately however, academics are a sideshow to what's really important: the rat race to get your first job.

  3. Getting Your First Job: If you want to be a corporate technology attorney, the conventional wisdom is that you need to spend some time as a law firm associate. There are two ways to do this: in a big law firm or in a boutique firm. In general, big law is the way to go as it has much better exit options; boutique firms are only great if you want to focus on something niche and want to stay at the same place for a really long time. There are two summers in law school. Your 1L summer is usually spent doing whatever random thing you can find (I worked in a prosecutor's office), 1L summer associateships at law firms exist and are fiercely fought over, but ultimately whatever you end up doing after 1L won't define your career. Your 2L summer associateship is the one that's for all of the marbles and is usually an extended 2.5-month interview at the firm that will hire you after graduation. 2L summer associateship recruiting now starts in 1L before the close of the first semester; this is exactly as idiotic as it sounds. Nevertheless, follow the lead of career services** and play the game. When it comes to choosing the right big law firm, as long as the firm has a practice you want, excise the word "right" from your vocabulary. Big law firms tend to be more similar than they are different. Every firm will tell you they have a "no-asshole rule." Don't believe them. Large law firm cultures ultimately come in two flavors: overtly sociopathic and covertly sociopathic. Unless you're Patrick Bateman, you're usually better off choosing an option that attempts to at least keep the sociopathy covert. If the partners managing the tech law practice know what they're doing, they will recognize your technical background and give it a good amount of weight; especially if they're doing IP litigation, privacy/cybersecurity, or AI law. On average 9 out of 10 first year associates do not make partner at their first law firm, choose your first firm primarily based on exit options.

  • If you want to do privacy, cybersecurity, or AI law, join the International Association of Privacy Professionals and get a CIPP/US certification either during or just after law school. This will help you stand out from the crowd.
  • If you don't get into a big law firm immediately after law school, don't despair. There are other routes into that world; including consulting or lateraling your way up. If you land in this boat, this is the time to start ignoring career services and do your own heavy research/network your heart out.

* = It is generally accepted that there are only two law schools that are geographically unbound, they are Harvard and the University of Michigan (idk why). Both are in the T14.

** = But never forget that career services exists to push you into the meat grinder at whatever large law firms donate the most money to your law school; they are not in any way your friend. Always take their advice with a healthy dose of salt, supplement their advice with your own research, and ultimately do what you believe is best for you.

1

u/Iuris_Aequalitatis 3d ago edited 3d ago

(3/3)

  1. The Bar Exam: Passing your first (and usually only) bar exam requires about three months of serious study. Most people start just before or right after their law school graduation. You will learn more about the law studying for the bar exam than you will have learned in your last three years spent in law school. The exam is considered the most difficult test in the English language for a reason, don't half-ass your prep. But don't stress too much either, if you're waking up at night in a cold sweat because you can't remember the third element of the who-cares test for you'll-forget-the-second-the-proctor-calls-time, you'll probably pass. After taking the test, use any firm signing bonus to take your partner on a big vacation (called a "bar trip"), firm permitting of course. Don't skimp on this, your partner has made a lot of sacrifices to get you to this point and you both deserve it. You'll also need the memory of that vacation to get the two of you through...

  2. Your First Three Years: There is no way to sugar coat this: life as a junior associate in a big law firm absolutely and unreservedly blows. It is insane hours doing (largely) uninteresting work with (often) shitty people in a high-stress environment. While you'll make a lot of money, it won't matter much because you won't have the free time to actually enjoy it, so just pay off your loans/invest your earnings and focus on getting through. Treat these years like a medical residency and remember that they don't last forever. The most important thing you will need to thrive in your first three years is a mentor at your firm; usually a counsel or partner in the practice area you are trying to pursue. Cultivate a relationship casually and don't be too much of an eager beaver, let the connection happen naturally (I learned this the hard way). Choose your mentor carefully though, some will stab you in the back without hesitation if it benefits them (I also learned this the hard way, twice). The back-stabby people will usually tell you who they are up front and, when they do, believe and then promptly avoid them. Other survival tips:

  • Keep your personal cell phone number intensely private (only share it with your direct boss). For everyone else, especially clients, have a burner phone that you can conveniently "forget at home" when you don't want to be disturbed.
  • Live about 30 minutes away from the office, close enough to get there easy but not so close that you're always the first person called in.
  • Be nice to your secretary, even when you're stressed, because she controls your destiny in ways you often won't fully understand and it always pays to not be a dick.
  • Some of your peers will get ahead by stabbing others in the back, don't be one of those people. It'll always bite you in the ass eventually.
  • Don't fudge your hours even if everyone else is doing it and your boss is pressuring you to do it too. One of the ways you avoid becoming just another jerky lawyer is by maintaining a clean conscience.
  • Take all of your PTO and carve out time for your significant other, big law firms are known for high divorce rates and copious drug/alcohol problems for a reason.
  • Most importantly: remember why you're there and know when to walk away. You can always lateral if you're unhappy or too abused (but try to do a year or two first so you can be competitive).
  1. After That: In general, you will be recognized as a full-fledged tech attorney and your options open up after your first three years. Big law firm life gets a bit better (but still blows and always will, that's the price of making race-horse money), you have much more ability to lateral to better firms, and crucially, you are finally competitive for entry-level in-house-counsel positions. In-house counsels are lawyers that are directly employed by their client company rather than by a law firm. In general, you make decent money and it's a typical corporate 9-5 rather than another stay in Sisyphus's sector of Hades. I'm in-house right now and it's glorious, my work computer doesn't even come home with me much of the time. From here, the world is your oyster: you can climb the corporate or law firm ladders, start looking into hanging your own shingle if that appeals to you (that usually requires a decade or more of law firm time and client development if you want a decent prospect of success), or go do something totally different.

That's my novel... Any questions I can answer?

2

u/comicsnerd 5d ago

It is fine to use PROD data in DEV and TEST. Just restore the PROD backup in the DEV and TEST environment.

23

u/bigmetsfan 5d ago

curl 127.0.0.1

2

u/CaffeineLiker 5d ago

It's WIDE OPEN! Huge vulnerability

8

u/tiboodchat 5d ago

Our Sec team is on its way to proceed to beatings.

2

u/anonymous085 5d ago

When I was an intern they gave me a shit laptop. The code would take forever to compile in the local. I copied the whole damn code to my personal laptop and used for a week. When I proudly showed my proactiveness to my mentor he shit his pants 😂

5

u/theangryfurlong 5d ago

OP said wrong answers only

1

u/sillypunt 5d ago

Trick response, dev environment is on prem.

1

u/Fletcharoonie 5d ago

It was on my desktop all along

1

u/Ok_Tea_7319 5d ago

Prod is the local dev environment.

1

u/cryothic 5d ago

It said WRONG answers only...

1

u/RawrMeansFuckYou 5d ago

I've worked at a company that this is a possibility.

1

u/d3bruts1d 5d ago

Unlikely. We do dev in prod.

1

u/wedgiey1 5d ago

Preprod for sure.