Live data from Hacker News

Most “mandatory requirements” in corporations are imaginary

nibblestew.blogspot.com

61–70 of 405 posts

Re: Most “mandatory requirements” in corporations are imaginary

#61

Earlier quoted context omitted.

> That said.. why would a person use the corporate computer for their (allow me the use of the word) 'hobby'? Because my work computer is around 100 times faster than my personal one.

I have the opposite situation: My personal computer is faster .

Assuming both are laptops and you don't have some insane personal computer - you should seriously examine why your workplace is skimping on a few hundred dollars extra on a machine that might save you, an employee with a salary in the tens of thousands (or higher) a few days of waiting for things to load, render or compile a year.

There certainly is a logic around not wasting money where it'd do no good - but companies that are tight with employee capital expenditures make me really nervous. It's a thing I've avoided consciously in employers since my thirties - if you don't value me enough for a decent keyboard, a chair, and a sufficiently performing computer - then you don't have anyone who is sane at evaluating RoI at your upper echelons.

Re: Most “mandatory requirements” in corporations are imaginary

#62
post #33

Earlier quoted context omitted.

I think the problem with this logic is it hinders a hundred people on a daily basis to prevent one person from doing something stupid once a year. That’s just not great ROI.

I've seen individual engineers make a mistake that caused 100 engineer's salary worth of damage.

I suspect we all have. The question is rather: how much would it have cost to prevent that mistake?

The flip side is the insurance argument: given a big enough organisation, a mistake like that will happen, even if the probability of each individual mistake is very low. So assuming one of these will happen, what can you do to reduce the impact or to reduce the latency of fixing such a mistake?

Re: Most “mandatory requirements” in corporations are imaginary

#64

If i pay an external $1000 per day and that price doesn't change when they are in my office or at home, i would put them in my office for obvious security risks. If corona means i can't get my work done, i have a new risk. Security risk for external consultants having full access at their home vs. no one can work -> i might choose the externals giving access. Its not imaginary.

In my experience (I am a contractor) the real reason is control. Companies want to ensure you (who are a separate legal entity and therefore have certain freedoms) have your nose to the grindstone. It's understandable, but paranoid.

Re: Most “mandatory requirements” in corporations are imaginary

#66
post #55

Earlier quoted context omitted.

Anyone who has spent a bit of time trying to calculate the lost productivity caused just the meetings needed to discuss breaches (internal, accidental), knows it's great ROI.

Everyone greatly overestimates ROI in their own area of expertise and greatly underestimates costs in the rest. You might be right in some special instance, but generally you are not. One example: Sending files via Email is a security problem. So you prohibit this via settings, virus scanners, appliances, etc. Now you've solved the emailed worm problem. However, you've just created a "how do we move files/data/screen…

I appreciate you're giving an example, but this is pretty much solved at most big companies currently with OneDrive (or any other flavor of cloud storage). For external sharing, you just select if the link can be seen external to the org.

Re: Most “mandatory requirements” in corporations are imaginary

#67
post #61

Earlier quoted context omitted.

I have the opposite situation: My personal computer is faster .

Assuming both are laptops and you don't have some insane personal computer - you should seriously examine why your workplace is skimping on a few hundred dollars extra on a machine that might save you, an employee with a salary in the tens of thousands (or higher) a few days of waiting for things to load, render or compile a year. There certainly is a logic around not wasting money where it'd do no good - but compani…

No, both are desktops; and I work at computer engineering department of a (not so research-focussed) state university as an academic, with my specialisation being low-level software engineering; not at a software company. Even lab computers are not so better than my personal computer, except for the supercomputing lab.

Re: Most “mandatory requirements” in corporations are imaginary

#68
post #25

In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…

> Chesterton's fence

Is there a "reverse" version of this where you do understand the reasoning, explain clearly why it doesn't apply anymore, but the other side just refuses to think for themselves and just sticks with the status quo because it must've been done with good reason and they don't want to second-guess it?

Re: Most “mandatory requirements” in corporations are imaginary

#69
post #39

Related, after telling us for years how dangerous it would be if people flew with more than 100 ml of liquid, it's now allowed (i.e. no longer dangerous?) to carry a larger quantity of hand sanitizer because of coronavirus: https://www.tsa.gov/news/press/releases/2020/04/15/tsas-tips...

As an aside sounds like we would be doing away with the whole bin show, this is great if it stays through:

>Tip 5: Place items from your pockets into your carry-on bag. Prior to going through the security checkpoint, take the items from your pockets and place them into your carry-on bag so that you don’t have to place them in a bin. Remove the keys, tissues, lip balm, loose change, breath mints, mobile phone and anything else from your pockets and place them right into your carry-on bag.

Re: Most “mandatory requirements” in corporations are imaginary

#70
> The big question on managers' minds (either consciously or unconsciously) when approving a policy change is "if I do this and anything goes wrong, will I get blamed?". This should not be the basis of choice but in practice it sadly is. This is where things go wrong. The people who would most benefit from the change (and thus have the biggest incentive to get it fixed) do not get to make the call. Instead it goes to people who will see no personal benefit, only risk.

This cones very close to hitting the nail on the head but not quite. The crux of the matter is:

/Corporate risk aversion culture is only aware of the risk of change, and ignores the risk of stasis./

Post reply on HN