Is anyone else tired of vendors documenting global complete network and system access.
Hey, let me come in, install my software, add servers, have domain admin rights to your network, remote access for the those credentials...trust me. Everything will be fine, we are secure.
If you are going to write software you need to understand that we are entering an era of "explicit allow security" instead of "explicit deny security"
What I mean is as more customers require security more and more servers and networks are being built under the concept of deny all access except what I specify from a to b. This is a long overdue transition that vendors are not prepared for.
If you write software you need to undertand and document everything it does and requires as it pertains to network traffic and security.