Is it just me, or did was the annoying sales guy completely right about the technology being possible, able to satisfy the client, and successful in closing a profitable deal for the company? What weird dailywtf parallel universe is this?
The WTF is the fact that a single employee would cost a company several tens of thousands of dollars plus several weeks of development time all because that employee didn't want to remember a password.
The Single Sign On
31–40 of 73 posts
Re: The Single Sign On
#32“But we don’t need to change it for everyone,” Craig jumped in, “just one client. Surely, you can do that!” That's probably the most frustrating thing I hear from non-technical people, because they really think they're making it easier. Sadly Kolmogorov complexity is not yet a required course in schools.
Can you elaborate on Kolmogorov complexity and its relevance to someone who has not encountered the term before? (I have wikied it: http://en.wikipedia.org/wiki/Kolmogorov_complexity but sleep deprivation may be hindering my ability to spot the link)
The link with Kolmogorov is, I believe, that each piece added moves the set away from being simpler.
First time I read about Kolmogorov, hopefully I got it right. Anyway my first paragraph is true!
Re: The Single Sign On
#33“But we don’t need to change it for everyone,” Craig jumped in, “just one client. Surely, you can do that!” That's probably the most frustrating thing I hear from non-technical people, because they really think they're making it easier. Sadly Kolmogorov complexity is not yet a required course in schools.
Can you elaborate on Kolmogorov complexity and its relevance to someone who has not encountered the term before? (I have wikied it: http://en.wikipedia.org/wiki/Kolmogorov_complexity but sleep deprivation may be hindering my ability to spot the link)
Re: The Single Sign On
#34Those of you with sales teams, what guidance do you have about sales people promising features that don't exist without getting input from the rest of your team?
Fine as long as it's for a lot of cash. If the customer is willing to pay for it, I'm happy to jump through crazy hoops.
Please don't take this too literally and tell me all the reasons why 3D holograph is feasible, you get the point.
Re: The Single Sign On
#35OK, I'm not a web developer: I do embedded systems and hardware interfacing, so go easy on me :-) Assuming that the hospital network was secure, then why couldn't the system, when receiving a request from that single IP, request a cookie? If the cookie doesn't exist, then that user has never logged in and is then given an identifying, non expiring cookie and from then on is allowed access and is identified? Knowing t…
Re: The Single Sign On
#36HIPAA doesn't prescribe specific technological mechanisms or official certifications. IIRC, a username and password assigned to an individual user is sufficient. I believe there are some audit-ability (who saw/wrote what) requirements as well, but it's been a few years since I dealt with HIPAA.
As a user of a system for which inappropriate data access can get you fired, you should be concerned if it does not have strict authentication mechanisms. Sally can blame Bill for having looked at some famous person's medical record.
Such snooping is actually is a recurring real problem at major hospitals which treat famous people. The Cleveland Clinic sort of solved it by assigning people like Drew Carey (widely known to be a Clinic patient) a pseudonym. All electronic records are under that name, so most people looking wouldn't realize who the patient was. A VIP office handled billing reconciliation. It's a cute security through obscurity mechanism although it's probably well known on which dates Drew visited the Clinc and which physicians likely saw him.
Re: The Single Sign On
#37Is it just me, or did was the annoying sales guy completely right about the technology being possible, able to satisfy the client, and successful in closing a profitable deal for the company? What weird dailywtf parallel universe is this?
The WTF is the fact that a single employee would cost a company several tens of thousands of dollars plus several weeks of development time all because that employee didn't want to remember a password.
Re: The Single Sign On
#38That was actually a pretty clever solution he came up with. I didn't see the punchline coming.
Re: The Single Sign On
#39I don't think it's funny and I don't think either the hospital or the consultants/contractors/employees who built this system are worth their weight in salt. It was a horribly expensive move and had very little benefit to the system or the patients or the hospital. It was a huge waste of money and it is decisions like this that are sending health care costs through the roof. How incompetent must you be to go through…