Earlier quoted context omitted.
"and thinking obviously changes" Sometimes it doesn't - sometimes people vehemently insist on application of policies even though what they produce is ridiculous. At a former employer I was quoted £70K (yes seventy thousand) for internal hosting of a not particularly business critical single static HTML page that would be accessed by maybe 100 people. I actually got a breakdown and it all made sense if you applied th…
What does one have to do to get to such crazy numbers for a task so simple?
Most “mandatory requirements” in corporations are imaginary
101–110 of 405 posts
Re: Most “mandatory requirements” in corporations are imaginary
#102Earlier quoted context omitted.
"and thinking obviously changes" Sometimes it doesn't - sometimes people vehemently insist on application of policies even though what they produce is ridiculous. At a former employer I was quoted £70K (yes seventy thousand) for internal hosting of a not particularly business critical single static HTML page that would be accessed by maybe 100 people. I actually got a breakdown and it all made sense if you applied th…
What does one have to do to get to such crazy numbers for a task so simple?
Turns out the internal infrastructure recharging model didn't scale down and as it was a "process" it couldn't be changed.
Re: Most “mandatory requirements” in corporations are imaginary
#103My reason for this rule would be: if you allow consultanta to work from home, how do you make sure they are not double- selling their workhours? Like they bill you 8h, but only work 4h on your project.
What stops your employees doing the same thing?
Re: Most “mandatory requirements” in corporations are imaginary
#104Related, after telling us for years how dangerous it would be if people flew with more than 100 ml of liquid, it's now allowed (i.e. no longer dangerous?) to carry a larger quantity of hand sanitizer because of coronavirus: https://www.tsa.gov/news/press/releases/2020/04/15/tsas-tips...
Batteries were dangerous and had to be removed until Apple started making devices without removable batteries then magically they are not dangerous anymore. Next you had to start turning your devices on as-if somehow it was impossible to make something dangerous that didn’t turn on. Security theater.
I used to have to take my belt and shoes off every time I passed through security but because I paid a $120 fee now I’m not dangerous anymore and can walk through security. I get to skip to the head if the line at the security checkpoints and coming back from international flights I get to breeze through the diplomatic lane at JFK (you can too! https://www.cbp.gov/travel/trusted-traveler-programs/global-...) Security theater.
I could go on for a while.
Re: Most “mandatory requirements” in corporations are imaginary
#105Earlier quoted context omitted.
I've seen individual engineers make a mistake that caused 100 engineer's salary worth of damage.
I would love to know more about the details of this example :-)
In response, the company has now sort of swung the other way: lots of things that have a perfectly valid reason and are reasonably safe have been forbidden or suddenly have needed to be justified in the face of extreme skepticism.
That wasn't a case of a single engineer causing 100x engineers worth of damage, but it was the case where something made hundreds of people's jobs a tiny bit easier for two decades, then caused a massive public loss of face and who knows how much reputational damage.
And I'd be willing to bet that a fair number of HN readers work at a company which has at least one system with similar properties (a bit more convenient, a bit less secure) to the one implicated in our security breach; but failure is a once-a-decade event, and their company isn't nearly that old yet. Would those engineers defend that setup using the argument from this article?
Re: Most “mandatory requirements” in corporations are imaginary
#106In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…
> Chesterton's fence Is there a "reverse" version of this where you do understand the reasoning, explain clearly why it doesn't apply anymore, but the other side just refuses to think for themselves and just sticks with the status quo because it must've been done with good reason and they don't want to second-guess it?
The point of the article is that's kind of correct - the cost (risk) of deregulating is concentrated, but the benefit is distributed. There needs to be some way to capture the value-add of removing a rule.
But if you do that the easiest way - turning the global metric of productivity into a target - then managers will asset strip, fire security (ahem, Mozilla), and walk off with a fat bonus (short-term productivity is up!) before people realise what's left is a the empty shell of a company.
And that's why good management is hard.
Re: Most “mandatory requirements” in corporations are imaginary
#107I find these types of articles to be truisms. We have some imperfect system. Everybody knows about the problems it has. Somebody writes an article about how stupid and wrong those problems are. How does that help anybody? The real question is how you fix those problems without introducing others. Passed a certain age and work experience you start to notice that the bureaucracy that stops you from doing quick smart fi…
Maybe it could stimulate reflection? Granted, my hopes are dampened too.
> Passed a certain age and work experience you start to notice that the bureaucracy that stops you from [...] doing serious damage to the company.
If you get even older, people might even stop you from running around without supervision to stop you from doing damage to yourself. Doesn't mean it should always be the case.
There will hopefully always be forces the evaluate practices. Bureaucracy can be good and it can be bad. It behaves just like french fries.
But I think the general trend that large corps seem to get a bit slow on innovation holds true. Doesn't mean it is not working well with lots of accomplishments.
Re: Most “mandatory requirements” in corporations are imaginary
#108In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then a…
The issue is that all the policy documents often only contain the One True Way to achieve their goals, while the goals remain unstated. The documents should always come with a rationale. And appending "exceptions may be granted for equivalent or better processes" to requirements would also help. I was faced with a password "security policy" that pretty much only whitelisted SHA2 + salting for password hashing. We were using a time-hard (not memory-hard though) password hashing function instead and several levels of auditors were effectively asking us to downgrade to comply with their policy without even understanding the difference.
It's terribly demotivating to have to argue with people enforcing policy they do not understand and erodes any willingness to engage with those policies instead of seeing them as theater and working around them.
Re: Most “mandatory requirements” in corporations are imaginary
#109Aren't all rules imaginary? > Every time someone in the management chain has axed the proposal with some variation of "this policy can not be changed because this is our policy and thus can not be changed", possibly with a "due to security reasons" thrown in there somewhere. That's circular, no doubt there. We've decided this rule must remain in place, because it's a rule . This decision-making process doesn't make a…
> Aren't all rules imaginary? No. The Laws of Football and the Laws of Australia are imaginary in the sense you mean, but the Law of Gravity isn't. Mother Nature's rules are different than ours, stubborn far beyond all reason and not recorded anywhere for our inspection. Video games are interesting because we make them, yet for the most part some of their rules are like Ma's rules not ours. Watching Mario Maker 2 tro…
I'm not a scientist but should the law of gravity not be seen as a human understanding of what gravity is rather than the handed down from God definition of gravity?
I get the point you're making though.
Re: Most “mandatory requirements” in corporations are imaginary
#110Earlier quoted context omitted.
I've seen individual engineers make a mistake that caused 100 engineer's salary worth of damage.
I would love to know more about the details of this example :-)