Live data from Hacker News

Accountability Sinks

250bpm.substack.com

201–210 of 407 posts

Re: Accountability Sinks

#201

My go-to example of a whole mesh of "accountability sinks" is... cybersecurity. In the real world, this field is really not about the tech and math and crypto - almost all of it is about distributing and dispersing liability through contractual means. That's why you install endpoint security tools. That's why you're forced to fulfill all kinds of requirements, some of them nonsensical or counterproductive, but necess…

That is also why so much of the security[tm] software is so bad. Usability and fitness for purpose are not box-tickers. The industry term in play is "risk transfer".

Most security software does not do what it advertises, because it doesn't have to. Its primary function is for the those who bought the product, to be able to blame the vendor. "We paid vendor X a lot of money and transferred the risk to them, this cannot be our fault." Well, guess what? You may not be legally the one holding the bag, but as a business on the other end of the transaction you are still at fault. Those are your customers. You messed up.

As for vendor X? If the incident was big enough, they got free press coverage. The incentives in the industry truly are corrupt.

Disclosure: in the infosec sphere since the early 90's. And as it happens, I did a talk about this state of affairs earlier this week.

Re: Accountability Sinks

#202

My go-to example of a whole mesh of "accountability sinks" is... cybersecurity. In the real world, this field is really not about the tech and math and crypto - almost all of it is about distributing and dispersing liability through contractual means. That's why you install endpoint security tools. That's why you're forced to fulfill all kinds of requirements, some of them nonsensical or counterproductive, but necess…

We should really define a new term for such work.

Perhaps "Risk Compliance Security" or "Security Compliance Engineering"

Where "Security Compliance Engineering" is the practice of designing, implementing, and maintaining security controls that satisfy regulatory frameworks, contractual obligations, and insurance requirements. Its primary objective is not to prevent cyberattacks, but to ensure that organizations can demonstrate due diligence, minimize liability, and maintain audit readiness in the event of a security incident.

Key goals:

- Pass external audits and internal reviews - Align with standards like ISO 27001, SOC 2, or NIST

- Mitigate organizational risk through documentation and attestation

- Enable business continuity via legal defensibility and insurability

In contrast…

Cybersecurity is focused on actively detecting, preventing, and responding to cyber threats. It’s concerned with protecting systems and data, not accountability sinks.

Re: Accountability Sinks

#203
post #162

Earlier quoted context omitted.

> "we've implemented all best practices, contracted out the hard parts to world-renowned experts, and had third party audits to verify that - there was nothing more we could do, therefore it's not our fault" The amount of (useless) processes/systems at banks I've seen in my career that boil down to this is incredible, e.g. hundreds of millions spent on call center tech for authentication that might do nothing, but th…

What's funny is that checklists in hospitals have been shown, empirically, to be massive life-saving devices. cyber perhaps not so much...

Checklists work well in high stress situations where you cannot forget a step (medicine, aviation).

A checklist in a security incident? Probably helpful.

A security checklist to satisfy auditors and ancient regulations? This is an entirely different kind.

Re: Accountability Sinks

#204
post #143

Another major accountability sink is employment. Employee is shielded from financial responsibility for the damage he incurs while working. While he may be punished for disobeying orders or acting criminally, he's not financially responsible for the fallout (especially if he was only doing the things he was ordered to do and/or reasonable things). Doing a job is inherently risky behavior. If you are doing it in a con…

I would say that corporate personhood is a better example. It seems very natural to us, but I'm not sure if it's an idea other intelligent species would also independently arrive at.

I think GP's example is better, definitely more familiar. That's the fundamental difference between employment and running your own business: you're trading away both the downsides and upsides of business risk, in exchange for a stable, predictable salary.

Re: Accountability Sinks

#205
post #91

I always remind myself when I have to go to the DMV[0] that I should plan on leaving with nothing more than another action or set of actions to take. I never enter the DMV expecting to complete a process, and the workers behind the counter always have this visible, visceral response when I DONT lose my fucking mind at their response to something. When I continue to be pleasant and understanding it’s like they suddenl…

Interesting distinction is deliberate vs unintentional accountability sinks. DMV sounds more like incompetence than design. Compare with airline where the system is “better” when you have no recourse.

The DMV is frequently just a case of under resourcing. For the most part, once you get to the counter your business can be handled in a few minutes. It’s the fact that it takes a while to get to the counter that’s the issue.

Re: Accountability Sinks

#206
post #49

One example that's missing from the list is the TV series 24. A recurring plot point was that, yes, of course torture is bad and it's against the rules and we don't do it, etc etc, but it just so happens that here is such an exceptional, unprecedented, deeply urgent emergency situation where we need to have the information now or horrible things will happen, we need the hero who breaks the rules and goes on torturing…

Star Trek: Deep Space Nine introduced Section 31, an organisation which regularly acted in the way you describe the characters from 24. They operated outside official channels and used questionable methods to do whatever was necessary “for the good of the Federation”. The character of Odo criticised it well:

> Interesting, isn’t it? The Federation claims to abhor Section 31’s tactics, but when they need the dirty work done they look the other way. It’s a tidy little arrangement, wouldn’t you say?

https://memory-alpha.fandom.com/wiki/Section_31

Re: Accountability Sinks

#207
post #184

Earlier quoted context omitted.

I was once on the phone with a cell phone company customer support rep who was clearly as dis-empowered as it's possible for a worker to be. He was obviously forbidden to hang up on me, so I used my normal tactic of just refusing to give up - I was friendly enough but refused to end the call. He was refusing to escalate my call, but couldn't help me himself. 20 or 25 minutes in I realized that wasn't going to work, s…

> He was obviously forbidden to hang up on me Plenty of big companies found a workaround. The "forever on hold" routine where they don't hang up, you will eventually. This works perfectly for toll free numbers (so you can't claim you had to pay for the call) and provides just the right amount of plausible deniability (took longer than expected to find an answer, it was an accident, etc.). I have my suspicions that in…

Call in on a second line and ask when you will be taken off hold.

Re: Accountability Sinks

#208
post #169
post #139

Earlier quoted context omitted.

> MOTs (annual vehicle safety tests) happen at any local garage. Oh, I think we should have that in Croatia, since I'm doing yearly car service at my dealership and than still need to take my car to our national inspection station to get the car certificate renewed. Not sure why can't they organize a system were certified car garages can also inspect the vehicle and notify the Center for Vehicles. Maybe that would al…

The incentives are very different - private garages would be very incentivized to find nothing wrong with your car and business would gravitate to those with the least checks. The government stations would not have that incentive (actually maybe incentivized the other way - to make up problems that can be waved away with money, depending on how corrupt things are there)

I'd have thought the private garages would also be incentivised to find problems - that they can then offer to fix for an additional fee.

As it is, I think most garages that offer MOTs in the UK are fair and honest, as the test is relatively strictly regulated, but I'm sure people do get ripped off.

Re: Accountability Sinks

#209
post #184

Earlier quoted context omitted.

I was once on the phone with a cell phone company customer support rep who was clearly as dis-empowered as it's possible for a worker to be. He was obviously forbidden to hang up on me, so I used my normal tactic of just refusing to give up - I was friendly enough but refused to end the call. He was refusing to escalate my call, but couldn't help me himself. 20 or 25 minutes in I realized that wasn't going to work, s…

> He was obviously forbidden to hang up on me Plenty of big companies found a workaround. The "forever on hold" routine where they don't hang up, you will eventually. This works perfectly for toll free numbers (so you can't claim you had to pay for the call) and provides just the right amount of plausible deniability (took longer than expected to find an answer, it was an accident, etc.). I have my suspicions that in…

Is it even possible to keep someone "on hold" forever? My experience (in Poland) was that it'll take at most 20-30 minutes before something somewhere timeouts and the call gets disconnected.

Re: Accountability Sinks

#210
post #156

I read most of this agreeing with everything the author was saying, sometimes in a "I already thought that" but often in a "huh, that's a really cool insight." I quite like the style too. As a Brit though, I was completely blindsided by the inclusion of Dom Cummings. I'd forgotten he existed. Seeing his and Boris' attitude to PPE provision discussed in a positive light without any mention of the associated scandal[1]…

In an American context, this part also struck me:

>> We did that. But only the Prime Minister could actually cut through all the bureaucracy and say, Ignore these EU rules on Blah. Ignore treasury guidance on Blah. Ignore this. Ignore that. “I am personally saying do this and I will accept full legal responsibility for everything.”

> By taking over responsibility, Johnson loosened the accountability of the civil servants and allowed them to actually solve the problem instead of being stuck following the rigid formal process.

Of course this also can have pretty severe negative consequences. In the U.S., thanks to a recent Supreme Court ruling, the president has immunity from criminal prosecution under certain (yet to be fully determined) circumstances. If the president then "takes over the responsibility" for obviously illegal actions, and is immune from prosecution for those actions, you now have a civil service unburdened by any responsibility to follow the law. And there are some 3 million odd workers in the U.S. federal government.

That the conservatives on the Supreme Court did not consider this danger, especially in light of who occupies the office, is still astounding to me.

Post reply on HN