Live data from Hacker News

I'm not burned out, I'm pissed off

myname.website

321–330 of 335 posts

Re: I'm not burned out, I'm pissed off

#321

Earlier quoted context omitted.

I worked at a healthcare company in the US (we provided HIPAA data connections between insurance and providers) and discovered all the production passwords were storied in a text file in the code repo half the company had access to. The CTO told me "we trust our employees". There was also no auditing on who access the DB and servers, and they never changed the passwords because the chief architect did not want to rem…

I worked at a retailer (not Target) that did something similar. Once Target got breached in 2014, they mandated security training and began making changes to some things in the org. This was one - instead of storing those passwords in plain-text, they were encrypted. So people encrypted them, commited them into the repositories, and deployed the now encrypted files to production. Cool, right? They didn't actually cha…

There's something both comforting and absolutely terrifying that everyone has similar stories of software negligence.

I would love to see a whistle-blower company formed, where you could report software engineering malpractice, and be compensated and/or protected from being punished. Not necessarily a union, but an industry body that could verify your security concerns and either "out" a company for punishing you, or provide you x months of work and a reference to compensate the termination of your employment.

Re: I'm not burned out, I'm pissed off

#322
post #214

Earlier quoted context omitted.

Do you have any counter-example in mind ?

The best architectures, requirements and designs come from a team with a fantastic lead/architect/product manager?

This isn't a counter-example, but a counter-motto.

Since you want to stick with theoreticals, a lot of great projects come from groups of close friends working together. You need a "fantastic lead/architect/product manager" when a team like that isn't available, and you need to compose one artificially.

Re: I'm not burned out, I'm pissed off

#323

Earlier quoted context omitted.

That is as they say "a brave choice"

My job switched completely to GSuite a year ago, management first. If anyone needs Excel they get it. So far I've spotted I one person that probably uses Excel. No complaints that I've heard or seen.

Ah so how do you handle working with external people who use excel.

Most of my work with a wildly spread organisations and we can have excel go through US to Russia to Uk Back to Ukraine and then back to me in the UK

Re: I'm not burned out, I'm pissed off

#324

Earlier quoted context omitted.

> Been doing extreme over-hours in the hope of fixing stuff once and for ever, only to realize your job becomes more and more like shit-shoveling, since management starts to feel invincible (and protected by your contributions) Isn't that when you start earning a lot of money?

> Isn't that when you start earning a lot of money? This is very dangerous thinking. Figure out why this true if it is not already obvious. * Not sustainable * Not healthy * Not scalable No sarcasm here. Try to avoid this thinking-trap.

Correct. Also, they won't give you that money if they know your motivation is the will to fix things. The money flows instead to the ones who have receiving more money as their motivation.

Re: I'm not burned out, I'm pissed off

#325
post #297

Earlier quoted context omitted.

I think there is some economic theory that states the price of products will tend towards the marginal cost over time. I haven't seen anything that makes me think software is any different. I don't think there is much profit in hardware, most companies seem to work on razor thin margins.

> I don't think there is much profit in hardware, most companies seem to work on razor thin margins. Consider that Apple is America's most profitable corporation. They do squeeze people with software restrictions; and it is a core part of their strategy. But the focus of Apple has never been 'our software is rare', it has always been 'faster processor, thinner phone, better screen'. The artificial restrictions on the…

Apple does seem to be the exception, that's why I did say "most companies".

Re: I'm not burned out, I'm pissed off

#326

I 100% agree as a consultant working in product development. I think what drives this is a lack of ability for anyone to understand the end-to-end product from a technical standpoint and make coordinated decisions about direction. Instead, you have 30 teams with their own architects and roadmaps (which often overlap functionality) so you build the same thing 5 times across the org, then 3 of them end up drawing meani…

I experienced this several times as an employee. It becomes hard to stand when you realize that every positive contribution just results in more money being shoveled out of the window behind your back (mainly because of greed, inefficiency, keeping the status quo, and wreckless behaviour caused by trust in your capabilities to somehow fix it again, every time over again) -- as opposed to contributing to a more effici…

This is actually a very common systemic problem, even happened at organizations like NASA. When the risk is reduced in a single area within a system, people would tend to increase risky behaviors in other areas because they unconsciously justify those behaviors with a perception that the entire system has now become safer.

I'm afraid there's no solution to this. In the end we are all humans. How does one even begin to solve a psychological problem at a large scale like this?

Re: I'm not burned out, I'm pissed off

#327
I feel like a large part of the responsibility lies with the people implementing these networks to be able to document, compatramentalize, and organize these various systems in the least convoluted manner.

The biggest problems I see achieving that are all the different ways of accomplishing the same goals. For example, many endpoints in a network will have 3 or 4 DRM agents on them for licensing certain products. What do they connect to? What are they sending? What infrastructure variables need to be in place to support those connections? How do I configure or troubleshoot this service/ connections?

Most of these agents are critically ineffectual and simply add bloat. I've done pentests in my own environment and broken, cracked, or bypassed three. My point is, the company who hired you can't change their entire operation because of your requirements. That's why we go to work. Especially at small or medium size businesses with limited resources.

"Stop using the ERP system with 12gb of data that you've had 30 people using for the past 15 years! We found a bug and the vendor won't fix it!"

You can see how that's not viable. So you find a way to mitigate the bug yourself.

"You need to get rid of XXX in engineering. They keep falling for phishing emails."

No. You need to find some resources or setup training to combat phishing. Create rules or modify this person's environment to reduce surface area and increase visibility on that endpoint.

And sometimes you can't solve it! But you can usually pick off some low hanging fruit and iterate to a more secure state than you started at.

Re: I'm not burned out, I'm pissed off

#328

I feel like a large part of the responsibility lies with the people implementing these networks to be able to document, compatramentalize, and organize these various systems in the least convoluted manner. The biggest problems I see achieving that are all the different ways of accomplishing the same goals. For example, many endpoints in a network will have 3 or 4 DRM agents on them for licensing certain products. Wha…

> You need to find some resources or setup training to combat phishing.

Honesty it’s so bad I think we’re best off just figuring out ways to do away with email as a primary communication mechanism altogether. When my company was smaller we had more technically savvy people, but as we’ve grown the average level of competence has sunk just to meet staffing needs and it’s impossible to keep up with training and expect people to actually really listen.

So if I had my druthers it would be a blanket ban on email for all internal communication. Formal taskings get done through a PM tool, general requests for information done through Slack, and documents managed and shared by the GDrive.

Email restricted only to communication with outside partners. All links and URLs are blocked. All attachments are stripped and send an email telling them to send it via an upload portal that pings the person on Slack that they have a [filename] waiting for them.

Part of the problem is how much we’ve habituated people’s email habits to behave badly. We tell people over and over again not to blindly click URLs, and then by default Microsoft Teams is here emailing people every time they get mentioned in a chat with a big “view in Teams” button to click through. Users get mixed messages all the time so can we blame them for not knowing what to do?

And the worst part is that the worst actors in this request are senior executives. The higher up the chain the less regard they have for following established processes.

Re: I'm not burned out, I'm pissed off

#329

I 100% agree as a consultant working in product development. I think what drives this is a lack of ability for anyone to understand the end-to-end product from a technical standpoint and make coordinated decisions about direction. Instead, you have 30 teams with their own architects and roadmaps (which often overlap functionality) so you build the same thing 5 times across the org, then 3 of them end up drawing meani…

I experienced this several times as an employee. It becomes hard to stand when you realize that every positive contribution just results in more money being shoveled out of the window behind your back (mainly because of greed, inefficiency, keeping the status quo, and wreckless behaviour caused by trust in your capabilities to somehow fix it again, every time over again) -- as opposed to contributing to a more effici…

> Been doing extreme over-hours in the hope of fixing stuff once and for ever, only to realize your job becomes more and more like shit-shoveling, since management starts to feel invincible (and protected by your contributions), which leads them to make even more errors without accountability.

Legal departments have been dealing with this problem forever too. Such is the plight of being in an assurance function.

Induced demand doesn’t just apply to traffic, it turns out. https://en.m.wikipedia.org/wiki/Induced_demand

Re: I'm not burned out, I'm pissed off

#330
post #68

Earlier quoted context omitted.

Bro (or Sis? :) )! They're not supposed to care about security, you are! Our job in infosec is to show others how insecurity affects what they care about so in order reduce,transfer or eliminate risk to what they care about they allow us to implement good security. The failure is on the infosec side of the equation. It confounds and mildly pisses me off when people get pissed and get burned out over suits not caring…

Why doesn't legal have to fight the same fights? Their domain seems similar: Legal problems take years to surface, and when they blow up, they explode spectacular. Implementing procedures involving legal is a huge drain of time, motivation and opportunities. Yet, in many companies the power dynamics is inverted: Anything non-trivial has to go through legal and is blocked by default. Why don't new deployments have to…

> Why doesn't legal have to fight the same fights?

Legal constantly fights the same fights. They get those systems put in place because they acknowledge that fighting these fights is a critical aspect of their job and they make sure those control points are in place. Before I became an InfoSec PM I consulted for legal departments to fight those internal fights for them. They’ve had decades to refine and develop best practices around how to do these things.

Also places where everything is blocked by default by legal are generally badly run legal departments and have plenty of handshake agreements and covert business activity going on the same way places with intransigent and uncooperative InfoSec or enterprise architecture ends up with tons of shadow IT. They’ve been moving towards automated review and self-service tools to speed things up for a while now.

Post reply on HN