Live data from Hacker News

Accountability Sinks

250bpm.substack.com

161–170 of 407 posts

Re: Accountability Sinks

#161

My go-to example of a whole mesh of "accountability sinks" is... cybersecurity. In the real world, this field is really not about the tech and math and crypto - almost all of it is about distributing and dispersing liability through contractual means. That's why you install endpoint security tools. That's why you're forced to fulfill all kinds of requirements, some of them nonsensical or counterproductive, but necess…

Security is closer to product management and marketing than engineering. It's a narrative and the mirror image of product and marketing, where instead of creating something people want based on desire, it's managing the things people explicitly don't want. When organizations don't have product management, they have anti-product management, which is security. We could say, "There is no Anti-Product Division."

Specifically on accountability, I bootstrapped a security product that replaced 6-week+ risk assessment consultant spreadsheets with 20mins of product manager/eng conversation. It shifted the accountability "left" as it were.

When I pitched it to some banks, one of the lead security guys took me aside and said something to the effect of, "You don't get it. we don't want to find risk ourselves, we pay the people to tell us what the risks and solutions are because they are someone else. It doesn't matter what they say we should do, the real risk is transferred to their E&O insurance as soon as they tell us anything. By showing us the risks, your product doesn't help us manage risk, it obligates us to do build features to mitigate and get rid of it."

I was enlightened. Manage means to get value from. The decade I had spent doing security and privacy risk assessments and advocating for accountability for risk was as a dancing monkey.

Re: Accountability Sinks

#162

My go-to example of a whole mesh of "accountability sinks" is... cybersecurity. In the real world, this field is really not about the tech and math and crypto - almost all of it is about distributing and dispersing liability through contractual means. That's why you install endpoint security tools. That's why you're forced to fulfill all kinds of requirements, some of them nonsensical or counterproductive, but necess…

> "we've implemented all best practices, contracted out the hard parts to world-renowned experts, and had third party audits to verify that - there was nothing more we could do, therefore it's not our fault" The amount of (useless) processes/systems at banks I've seen in my career that boil down to this is incredible, e.g. hundreds of millions spent on call center tech for authentication that might do nothing, but th…

What's funny is that checklists in hospitals have been shown, empirically, to be massive life-saving devices.

cyber perhaps not so much...

Re: Accountability Sinks

#164

Earlier quoted context omitted.

I watched a season of Chicago PD , and noticed that they had a convenient "plot accelerator." Whenever they got to a point, where the detectives and CSI would be painstakingly going through the evidence, sifting out clues, they'd throw the suspect into "the cage," and beat a confession out of them.

Every police show aggressively pushes the "civil rights bad" angle. Maybe once a season they will graciously consider "maybe civil rights good?" for part of an episode before concluding "no, civil rights bad."

It seems to be a hallmark of Dick Wolf's shows.

His son is getting into the act, but seems to be more interested in depicting "the right way."

His show is an Amazon show, named On Call: https://www.imdb.com/title/tt14582876/

I enjoyed it.

Re: Accountability Sinks

#165

Interesting article, but picking Johnson and Cummings's handling of Covid as a positive example is a very odd choice, given their falling out and the numerous corruption allegations and parliamentary inquiries into their actions since then.

Surely it is that specific example that counts. It seems perverse to dismiss one sensible decision on the grounds that the persons concerned made many other bad decisions. It's the decision that is the focus not the persons making it.

Re: Accountability Sinks

#166

> Bad people react to this by getting angry at the gate attendant; good people walk away stewing with thwarted rage. I disagree, slightly. We have to expect some degree of ethical behaviour from everyone, even those who nominally have no room to manoeuvre. If everyone in such positions were to disobey unjust orders the orders would eventually have to change. Walking away stewing in rage does nothing except fill you w…

If I ever feel like writing my own "12 Rules for Life", one of them is going to be called "Don't yell at the Barista" or some version of that. You can get angry, but not at the person who would probably get fired for showing initiative. Find the people actually responsible and yell at them.

Being angry is not synonymous with being abusive. Your assumption that they would be fired for showing initiative says a lot about the society that you live in. I'm glad that generally where I live we expect people to take responsibility and their managers to support them. It doesn't always work of course.

Re: Accountability Sinks

#167
post #153

The conclusion of Davies' second extract — about e.g. being bumped off a flight — is recognisable but the conclusions are actually wrong. The situation in these cases is actually more subtle. The person you're speaking to does normally have some capacity to escalate in exceptional cases. But they can't do it as a matter of course, and have to maintain publicly that it's actually impossible. The people who get what th…

Yes unfortunately I've observed this in some support systems. The best way is to thread the needle between being extremely personally polite to the other human on the line, but going through the required machinations on their runbook to trigger an escalation.

That is - you don't really have to behave unpleasant (raise voice, swear, be impolite, threaten) but you should just refuse to get off the line, demand escalation, and importantly emphasize with their predicament in needing to escalate you. Possibly including phrasing like "what do we need to do to resolve this issue".

I had a cellphone provider send me a $3000 bill because someone apparently was able to open 5 lines & new devices in my name/address. I went through the first few steps of their runbook including going to police department, getting report filed, and providing them the report number. They then tried to demand further work from me and I escalated.

At that point I turned it around - what evidence do you have that I opened this line. Show me the store security footage of me buying the phones, show me the scan of my drivers license, show me my social security number? Tim, are you saying I can just go to the store with your name & address and open 5 lines in your name? Being able to point out the asymmetry of evidence, unreasonableness of their demands, and putting the support staff in my shoes.. they relented and cleared the case.

Re: Accountability Sinks

#168

My go-to example of a whole mesh of "accountability sinks" is... cybersecurity. In the real world, this field is really not about the tech and math and crypto - almost all of it is about distributing and dispersing liability through contractual means. That's why you install endpoint security tools. That's why you're forced to fulfill all kinds of requirements, some of them nonsensical or counterproductive, but necess…

Rhyming with this observation - the only time I've ever heard someone getting fired over a phishing incident anywhere I've worked.. was a guy on the cybersecurity team who clicked through and got phished.

Re: Accountability Sinks

#169
post #139

Earlier quoted context omitted.

Off-topic, but since you mention it, I've always been confused about what Americans always seem to be doing at the DMV. It seems to be a staple of pop culture that people are always there and the queue is always very long, but I've never known what anyone is actually trying to achieve. The DVLA in the UK doesn't have a high-street presence. I took my driving test once, then received my driving licence in the post. Wh…

> MOTs (annual vehicle safety tests) happen at any local garage. Oh, I think we should have that in Croatia, since I'm doing yearly car service at my dealership and than still need to take my car to our national inspection station to get the car certificate renewed. Not sure why can't they organize a system were certified car garages can also inspect the vehicle and notify the Center for Vehicles. Maybe that would al…

The incentives are very different - private garages would be very incentivized to find nothing wrong with your car and business would gravitate to those with the least checks. The government stations would not have that incentive (actually maybe incentivized the other way - to make up problems that can be waved away with money, depending on how corrupt things are there)

Re: Accountability Sinks

#170

My go-to example of a whole mesh of "accountability sinks" is... cybersecurity. In the real world, this field is really not about the tech and math and crypto - almost all of it is about distributing and dispersing liability through contractual means. That's why you install endpoint security tools. That's why you're forced to fulfill all kinds of requirements, some of them nonsensical or counterproductive, but necess…

> "we've implemented all best practices, contracted out the hard parts to world-renowned experts, and had third party audits to verify that - there was nothing more we could do, therefore it's not our fault" The amount of (useless) processes/systems at banks I've seen in my career that boil down to this is incredible, e.g. hundreds of millions spent on call center tech for authentication that might do nothing, but th…

The fun part of bank bureaucracy is you get to experience it 10x worse if you actually work at one.

I once worked on a global, cross-asset application. The change management process was not designed for this and essentially required like 9 Managing Directors to click "approve release" in a 48 hour window for us to do a release.

We got one shot at this per week, and failing any clicks we would have to try again the next week. The electronic form itself to trigger the process took 1-2 hours to fill out and we had 3 guys on the team who were really good at it (it took everyone else 2x as long).

Inevitably this had at least 3 very stupid outcomes -

First we had tons of delayed releases. Second the majority of releases became "emergency releases" in which we were able to forego the majority of process and just.. file the paperwork in retrospect.

Finally, we instructed staff in each region to literally go stand in the required MD delegates office (of course the MD wouldn't actually click) until they clicked. The conversations usually went something like this "I don't know what this is / fine fine you aren't gonna leave, I'll approve it if you say it won't break anything / ok don't screw up"

Post reply on HN