Live data from Hacker News

I'm not burned out, I'm pissed off

myname.website

51–60 of 335 posts

Re: I'm not burned out, I'm pissed off

#51
post #26
post #14

I asked my SO recently how she view the Internet, what it is and how it works. She was honest and told me that, "If I click this button, this websites loads. If that works I'm fine! If it doesn't I will call you. Don't stop working with IT please, if you get it, we need you badly!" I believe that is a good reason to be accepting towards the current state of affairs. People just don't care. They have more important is…

Thing is, it took me a long time to accept that people not caring was ok. Now I realize that my dad is frustrated I never learned something as simple as changing the oil on my car. My mom does not understand how I can't name more than two flowers and can't bake a pie. My legal-minded friends are astounded I do not take a day to work on my legal status to pay less taxes. Hell, my wife does the paperwork I am not even…

Your mom and dad, or grandparents probably didn't need to know, even though they know how.

Most of their interactions were with local businesses, with people who, like themselves, were part of the local community. The unofficial grapevine worked pretty well for rooting out the good and bad mechanics, lawyers and florists. Your dad could change the oil, but almost certainly knew which mechanics could be trusted to have done what was on the invoice, and the few to avoid at all costs. Mostly if really was OK not to care, because they knew someone who did. The network meant something. Doubly so in smaller towns, and yes, small town life came with some downsides too. :)

That breaks horribly when recommendations are of global mega-multinationals, and most businesses on most high streets are national and international chains. A recommendation counts for nothing for a business of that scale, and an individual vote may be an employee you might never encounter again. The network means nothing, except as something to be gamed. Taking your custom elsewhere means nothing unless a million or two others do too. You have to care as no one else gives a shit about your interests, just the sale or commission. Except precisely none of us have the time for that.

If we want the benefits of larger scale business I think we need to start giving them some responsibilities too. Like a duty of care in law as exists in some areas already, but further reaching to consider the public interest as a priority. Without something the power imbalance is impossible.

Without constraint, large business takes the piss. It's time for some constraint. Then maybe we actually can depend on each other again.

Re: I'm not burned out, I'm pissed off

#52
post #26

Earlier quoted context omitted.

Thing is, it took me a long time to accept that people not caring was ok. Now I realize that my dad is frustrated I never learned something as simple as changing the oil on my car. My mom does not understand how I can't name more than two flowers and can't bake a pie. My legal-minded friends are astounded I do not take a day to work on my legal status to pay less taxes. Hell, my wife does the paperwork I am not even…

I can't accept that not caring is ok. The small "I don't care" extends into "I don't care about anything outside my immediate environment" and that has political and eventually global consequences. If their bank account is drained they will care, and get angry, and then maybe do something (but preferably the bank will recompense them in which case they feel better and go back to not caring). Some stuff you just can't…

"I really do not understand people."

Indeed.

Re: I'm not burned out, I'm pissed off

#53
"A new car built by my company leaves somewhere traveling at 60 mph. The rear differential locks up. The car crashes and burns with everyone trapped inside. Now, should we initiate a recall? Take the number of vehicles in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don't do one."

No one in management wants the expense or the overhead of actual security. They want the "theater" of security, the good feeling, the box to check on their resume (as management) so everyone can pretend everything is fine and go back to the business at hand. Then something real happens, a leak of user data, or credit cards or internal memos... suddenly everyones job is security and no one knows what to do. The last problem gets solved, there is more "theater" and a few quickly forgotten changes that get worked around or just ignored in the long run.

Furthermore your average engineer wouldn't eat a ham sandwich handed to them on the street by a stranger but will happily run code from 100's of other people on their servers with out even looking at it. Note: I too am guilty as charged. Sure you can vendor it, and miss out on future security patches (it was already broken). Or you could just pull it from whatever repo you got it from to begin with and pick up new flaws. Never mind the fact that pulling from random places assumes that all those other chains of trust remain un-compromised.

Management and Engineers should be the ones most concerend and most thoughtful regarding security and both seem to ignore it for cost and convenience reasons till it is (far too late and) a REAL problem.

Re: I'm not burned out, I'm pissed off

#54
post #25

If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers.…

I work as a contractor for a bank. A few months ago everybody was up in arms about a "major" security issue discovered by an auditor (you could see the settings of random users by changing an id in a url). I've just shown them you can credit money to your account, yet this is low priority and they provided a fix that I'm 100% percent sure didn't fix anything, unfortunately the functionality is down on all but the pro…

> I'm tempted to just credit myself 1 monetary unit in production and just show them the statement.

I would be tempted too, though I could bet that this will be a termination of an employment, instead of the problem being fixed.

I would like to be proven wrong on this speculation..

Re: I'm not burned out, I'm pissed off

#55
post #47
post #44

Earlier quoted context omitted.

This type of drum circle commentary is so unhelpful. Raising the bar for security in the software industry requires much more than just self reflection and elbow grease from individual engineers. The solution requires buy in from all stakeholders. Especially management.

We are not talking about the same problem. Yo are not seeing the fact that it is only you who are responsible for what’s happening inside you . And you are taking the wrong path fixing that by fixing everything else but you.

"Yo are not seeing the fact that it is only you who are responsible for what’s happening inside you ."

This kind of pop-psych babble is naive and abusive.

Re: I'm not burned out, I'm pissed off

#56

If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers.…

I've heard from someone selling security products that some companies prefer to pay ransonware to a hacker, instead of investing in building up their defense and paying for security products

The easiest security investment is to switch your shop from Windows, cutting like 98% of threats out there cold.

Re: I'm not burned out, I'm pissed off

#57
post #56

Earlier quoted context omitted.

I've heard from someone selling security products that some companies prefer to pay ransonware to a hacker, instead of investing in building up their defense and paying for security products

The easiest security investment is to switch your shop from Windows, cutting like 98% of threats out there cold.

As well as cutting 98% of your workforce as no office employee knows how to work on anything different.

Re: I'm not burned out, I'm pissed off

#58

If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers.…

[deleted]

Re: I'm not burned out, I'm pissed off

#59

Earlier quoted context omitted.

What about those of us who don't get crazy compensations, but instead work at a midsized company selling a "security" product? All of the complexity in my field comes from stupidity, either by certifiers, or legacy protocols that can't die or sales people playing "defect/defect" with oneanother so nobody fucking talks with each other. If the complexity at least came from software I would have a reason for my knowledg…

Well, it sounds like you need to be learning things outside your domain in the hopes of entering the job market. Sometimes you can't fix the game. BTW I'm quite wary of "security products" for enterprise; it reeks of antivirus software writ large. That said I can see some benefit to services like audits, or even things like honey pots or "dark net scans" for detecting leaks. But something tells me that's not what you…

> BTW I'm quite wary of "security products" for enterprise; it reeks of antivirus software writ large. That said I can see some benefit to services like audits, or even things like honey pots or "dark net scans" for detecting leaks. But something tells me that's not what you're talking about...

The product itself is quite reasonable on paper [1]. (And, yes, it would provide value even if all of the software industry would ramp up their security practices, so it's not a band aid like antivirus software.) The execution is the problem. Despise selling "nation state attacker secure" appliances, we are not internally focusing on producing a high security product but give priority to certifications and features. The disconnect between marketed identity and day-to-day developer experience is breathtakingly depressing... at least to those of us who have an interest in security. Management doesn't care of course. It sells (because of certification and little alternatives on the market), so all is well.

[1] Sorry for being so vague. Given the set of statements I've given already, anything more would make me personally identifiable to my coworkers.

Re: I'm not burned out, I'm pissed off

#60
post #55
post #47

Earlier quoted context omitted.

We are not talking about the same problem. Yo are not seeing the fact that it is only you who are responsible for what’s happening inside you . And you are taking the wrong path fixing that by fixing everything else but you.

"Yo are not seeing the fact that it is only you who are responsible for what’s happening inside you ." This kind of pop-psych babble is naive and abusive.

Blame the whole world, why don’t ya
Post reply on HN