Honestly, kind of sad that Tim Cook’s reply was so generic. I don’t think I’m off base in saying this, and from personal experience, he is really not connected to the people at the company.
From: Steve Jobs. "Great idea, thank you."
31–40 of 312 posts
Re: From: Steve Jobs. "Great idea, thank you."
#32It's interesting that they can just reassign an email alias to someone else without any approvals. Could this be a permissions oversight? Or could the person who designed the system thought that heck it's always permitted to reassign an email alias owned by the current user?
It was 1991. They were an up start tech company. It was a different time.
Re: From: Steve Jobs. "Great idea, thank you."
#33It's interesting that they can just reassign an email alias to someone else without any approvals. Could this be a permissions oversight? Or could the person who designed the system thought that heck it's always permitted to reassign an email alias owned by the current user?
You’ll have 1,000x more headaches and burned operational cash getting everyone to approve everyone else’s every step than handling one security incident in a decade. And even with very tight security, something will still happen. It’s best to have backups, a good restore plan, and a relaxed culture*. Or that’s what I think, anyway.
I’m in SME land though, not big tech. But then again, 99.99% companies are.
* common sense exceptions apply.
Re: From: Steve Jobs. "Great idea, thank you."
#34[flagged]
Re: From: Steve Jobs. "Great idea, thank you."
#35It's interesting that they can just reassign an email alias to someone else without any approvals. Could this be a permissions oversight? Or could the person who designed the system thought that heck it's always permitted to reassign an email alias owned by the current user?
The bigger issue is probably being allowed to set up an arbitrary one at _all_ without approvals. Once you have one, redirecting it is maybe not the biggest issue? Could still be problematic though. This story is quite old, security culture in tech was really quite basic and forgotten in a lot of places. I would hope that a similar thing would not be allowed today at anything like a big company.
This is 1991, the actual number of people on the internet was tiny back then. Things like SMTP servers were commonly open relays (for some reason I'm remembering sendmail being an open relay out of the box).
A lot of the internet culture wasn't based on security, but of the premise you shouldn't be a dick.
It quickly changed in the next few years as the number of people online exploded.
Re: From: Steve Jobs. "Great idea, thank you."
#36Honestly, kind of sad that Tim Cook’s reply was so generic. I don’t think I’m off base in saying this, and from personal experience, he is really not connected to the people at the company.
Re: From: Steve Jobs. "Great idea, thank you."
#37Have to ask…what’s up with that avatar for Tim Cook?
Re: From: Steve Jobs. "Great idea, thank you."
#38Earlier quoted context omitted.
Hey, running into someone who is exceptional and having a fun story to tell about it is reasonable and doesn't deserve this negative energy. That time I ran into Larry Bird, or just missed having dinner with Douglas Adams, or the time I talked to Jonny Kim-- they're little markers of time in my existence. I know they're not gods, and I've done pretty cool things myself, but I'm still in awe of the cool stuff they've…
Kevin Nash and I peed next to one another in an airport bathroom one time.
Re: From: Steve Jobs. "Great idea, thank you."
#39Honestly, kind of sad that Tim Cook’s reply was so generic. I don’t think I’m off base in saying this, and from personal experience, he is really not connected to the people at the company.
The experience as CEO of a company with 10e2-10e3 headcount is a lot different than the experience with 10e4-10e6 headcount.
Re: From: Steve Jobs. "Great idea, thank you."
#40Earlier quoted context omitted.
The bigger issue is probably being allowed to set up an arbitrary one at _all_ without approvals. Once you have one, redirecting it is maybe not the biggest issue? Could still be problematic though. This story is quite old, security culture in tech was really quite basic and forgotten in a lot of places. I would hope that a similar thing would not be allowed today at anything like a big company.
>security culture in tech was really quite non-existent This is 1991, the actual number of people on the internet was tiny back then. Things like SMTP servers were commonly open relays (for some reason I'm remembering sendmail being an open relay out of the box). A lot of the internet culture wasn't based on security, but of the premise you shouldn't be a dick. It quickly changed in the next few years as the number o…
Fun times :)