Live data from Hacker News

Stolen laptop contains cancer research data

news.cnet.com

61–70 of 81 posts

Re: Stolen laptop contains cancer research data

#61

I find it hard to believe that someone with the possible cure to cancer wouldn't bother backing it up. If this is legitimate, I think it's beyond irresponsible. Also, why such a minimal reward?

Probably because it was coming out of her own pocket, and researchers generally don't make that much (especially if she was a post-doc). I'm pretty sure that the NIH won't let you charge "stolen laptop reward" to your grant, and your university sure as heck isn't going to shell out for something like that.

Re: Stolen laptop contains cancer research data

#62
post #41

Earlier quoted context omitted.

You need a license to operate your car, not so with your PC. {edit} Some of your users might well be incompetent computer users and wont pass the "test". I have often thought about why people dont do backups even when the new tools are easy for most to handle. I think the reason is psychological in nature. Backup implies that you are at least cognizant of the impending disaster scenario. many people avoid even thinki…

Really? Then how the heck to insurance companies stay afloat? How do home security companies profit? Sorry, this doesn't pass the absurdity test.

Perhaps that is the point, you shell off the responsibility to somebody else, pay some money to some 3rd entity and you have insurance, and you pay premium the more lacking you are in responsibility. Thats not to mention the case that some insurance policies are a legal requirement, case in point car insurance.

Re: Stolen laptop contains cancer research data

#64
post #41

Earlier quoted context omitted.

I'm sick of this attitude of "Always be super nice and make sure you over mother your users" crap. You know what: If my car engine seizes because I haven't changed the oil, no one tells the car makers or the mechanics they didn't do thier job right. If I leave the oven on all night and get CO poisoning, no one blames the oven maker for it. If someone doesn't buy renter's insurance we don't blame the apartment owner f…

You need a license to operate your car, not so with your PC. {edit} Some of your users might well be incompetent computer users and wont pass the "test". I have often thought about why people dont do backups even when the new tools are easy for most to handle. I think the reason is psychological in nature. Backup implies that you are at least cognizant of the impending disaster scenario. many people avoid even thinki…

> You need a license to operate your car, not so with your PC.

I own a car, pay insurance on it, but never in my life had a driver license. My wife drives it, working on my insurance bonus. But since it's my vehicle, am still responsible for all the stuff around maintenance, meeting requirements for road worthiness, etc.

Re: Stolen laptop contains cancer research data

#65
post #26

If you buy a car, it comes with seat belts. Safety is not optional - it's built in. If you buy a computer, safety of your data is seen as a luxury add-on, like leather seats. It's crazy when you think about it.

Both Windows and OSX come with built in backup software, but no one can force the user to use them.

Re: Stolen laptop contains cancer research data

#66
post #21

Sorry guys, but most of the comments in this thread remind me of why we IT people have so much bad PR to overcome. We're blaming the user for our mistake. That's like blaming the cow for leaving the pasture because one of us forgot to lock the gate. The simple fact is that this user should have never been able to be in a position for this to happen. Where were the IT security policies and procedures? Why was mission…

I'm sick of this attitude of "Always be super nice and make sure you over mother your users" crap. You know what: If my car engine seizes because I haven't changed the oil, no one tells the car makers or the mechanics they didn't do thier job right. If I leave the oven on all night and get CO poisoning, no one blames the oven maker for it. If someone doesn't buy renter's insurance we don't blame the apartment owner f…

Emphasis on Mission critical. We're not talking about an arcane enterprise IT organization keeping you from going on Facebook (or HN for that matter) on your lunchbreak, or considering an upgrade to IE7 over the course of 2011.

We're talking about mission critical data. Data, without which the mission cannot succeed. It was not even backed up. That's not the users fault, it's a systemic failure of the organization, a failure it was/is ITs responsibility to fix.

Re: Stolen laptop contains cancer research data

#67
post #60

Earlier quoted context omitted.

I'm sick of this attitude of "Always be super nice and make sure you over mother your users" crap. You know what: If my car engine seizes because I haven't changed the oil, no one tells the car makers or the mechanics they didn't do thier job right. If I leave the oven on all night and get CO poisoning, no one blames the oven maker for it. If someone doesn't buy renter's insurance we don't blame the apartment owner f…

Just because this person did not bother to find out about backups from her IT does not make it ITs problem. It was IT's problem before this person ever came along. That's the whole point. A few quick questions: 1. Are you capable of implementing an IT infrastructure where it is impossible for a user to lose mission critical data? If not, then you're incompetent. Move along, please. 2. Are you willing to implement an…

Bullshit. The vehicle fleet manager doesn't make it impossible to run out of gas. The accounting department doesn't make it impossible to max the corporate credit card you have. They provide infrastructure, you have responsibilities in it too.

Further, and I'm really really suggesting you read this slow, and look up words you don't understand in the dictionary, universities just don't work this way. There is no central authority that can force this sort of behavior in them. The researchers themselves push for it, and the people who pay IT then demand it be set up that way. No matter how nice it would be to force backups -- IT can't override the fucking dean. Researchers are to be given autonomy is the usual directive. This leaves IT to provide easy access infrastructure, but not go that last step, as they are forbidden.

Are you sure your customers love your "DO AS I SAY IT IS THE ONLY WAY DAMMIT" attitude? Having dealt with sanctimonious asshats like you many times, and further talked to the mormons and jehovia's witnesses at my door, I realize my words won't sink in, but I will make a futile attempt anyway: Give up the judgemental bullshit. Your way is not the one true way. Your smug little smirk makes lots of people fucking hate you, and you know what, you don't even realize they smile and agree with you just to get you to shut up and go away.

tl; dr- go jerk off to your authority some more, the rest of us have real worlds to live in.

Re: Stolen laptop contains cancer research data

#68
post #62

Earlier quoted context omitted.

Really? Then how the heck to insurance companies stay afloat? How do home security companies profit? Sorry, this doesn't pass the absurdity test.

Perhaps that is the point, you shell off the responsibility to somebody else, pay some money to some 3rd entity and you have insurance, and you pay premium the more lacking you are in responsibility. Thats not to mention the case that some insurance policies are a legal requirement, case in point car insurance.

So, like companies such as mozy and backblaze, which I explicitly mention? Essentially they provide insurance in the form of backups. Trivial to use too. I'm not sure of your point anymore.

Re: Stolen laptop contains cancer research data

#69
post #39

Earlier quoted context omitted.

I voted you up, but I wanted to note that I (we?) have no idea how her department is run, and the negligence could rest as well in her hands as it could in her employer's hands. Another post here said "Blame the IT department for not establishing rigid policies." These sentiments are good, but... What if the IT department clearly outlined policies for how to store and secure the data? What if the researcher is one of…

I work in the physics department of a top university. The majority of work people in the department do involves a computer at some stage, from computational physics (likely involving supercomputers and months of compute time) at one end of the spectrum to using Excel as a data store at the other. We do not have an IT department (we have one or two post-doctoral researchers who keep a couple of servers running for und…

To add to the anecdotal evidence, I have contacts in the strong IT department of a top university near me. So it could indeed go either way.

Re: Stolen laptop contains cancer research data

#70
post #21

Sorry guys, but most of the comments in this thread remind me of why we IT people have so much bad PR to overcome. We're blaming the user for our mistake. That's like blaming the cow for leaving the pasture because one of us forgot to lock the gate. The simple fact is that this user should have never been able to be in a position for this to happen. Where were the IT security policies and procedures? Why was mission…

I'm sick of this attitude of "Always be super nice and make sure you over mother your users" crap. You know what: If my car engine seizes because I haven't changed the oil, no one tells the car makers or the mechanics they didn't do thier job right. If I leave the oven on all night and get CO poisoning, no one blames the oven maker for it. If someone doesn't buy renter's insurance we don't blame the apartment owner f…

Flip that "entire freaking life" comment around, and ask yourself whether the current IT schemes and the current common IT approaches are working as well as might be desired.

Whether the current IT plans have survived contact with the end-users.

If IT assumptions and approaches and plans aren't working and if errors are repeating, then IT is left to continue to spend on and work on More Of The Same and on Just Try Harder solutions, or IT can look at different approaches and different solutions. At performing some Root Cause Analysis, or whatever that might be called, and at shifting strategies and tactics.

Computer hardware and software vendors have the same issues, too. Sooner or later, the "blaming the users" for a repeating failure modes isn't going to be a viable product strategy, and somebody (else) then ends up owning the problems and the costs, or your product ends up cast aside.

Look to ways the most serious of these repeating problems can be eliminated.

Backups? IT has to expect some users won't do backups. Something akin to Apple Time Capsule with Mac OS X Time Machine is an absolute killer feature for home users. Your data ends up archived with minimal end-user involvement.

Passwords? How long will we repeat the IT password mantras? IT has to expect some users will continue to pick passwords. So what to do about that?

With a large enough breach or a large enough data loss, IT can be forced start deploying its own CA chains and certificates, and moving to tokens or analogous. Or backups. Or whatever. Why not start ahead of that breach?

As for alternatives and depending on your local user requirements, look to add and to migrate to embedded and tablet devices and automatic backups; trump the problems where you can. At certificate chains and VPNs. At automated backups.

Look for, but don't repeat mistakes.

...Don't expect existing mistakes to fix themselves.

...Don't assume that longstanding approaches and solutions are still the best available solutions.

...And don't plan that end-users will grok IT. They know and think about cancer research, or whatever their job is. Not about IT.

Post reply on HN