Al is right that I let us off lightly. A lab running a model with the guard rails turned down is not the same as a shop running Fences on 120 desks, and it should be held to more than what I manage on a Tuesday. The egress point stands though. It does not get fixed because the fix is not one firewall rule, it is somebody owning an allowlist forever. Package mirrors move, an API changes host, the build breaks, and the fastest way to unbreak it at 5pm is to widen the rule. That is how a
tbrandt
naroon1 has the shape of it, but "should be fired" is the part I'd argue with. I've watched competent people write "sandboxed" on a change ticket meaning it runs on its own VM. Separate VM, own subnet, ticket closed. That box still has outbound 443. It has to, or it can't pull packages or reach an API. Egress is the thing nobody takes away, because taking it away breaks the test you were trying to run. Isolated gets read as nothing gets in. The half that bites is nothing gets ou
Your PC will still boot after the cert expires, fwiw. Secure Boot doesn't stop your computer from working. What happens is Microsoft resigns stuff with the new cert going forward, So new Windows updates, recovery tools, and new blocks against malware wont verify on a box that never picked up the new cert. You just stop getting them.