Earlier quoted context omitted.
This particular post-mortem by Stripe makes me trust them less as it's a fairly simple mistake that shouldn't have been made. Plenty of companies also communicate the status and that something is happening but don't fully expound on all the internal details. Not sure why it's such a big difference if they did. It feels like fake PR trust to me.
> This particular post-mortem by Stripe makes me trust them less as it's a fairly simple mistake that shouldn't have been made. You are, of course, entitled to your opinion. I don't think its going to hurt their business at all.
Stripe – Outage postmortem
131–132 of 132 posts
Re: Stripe – Outage postmortem
#132Earlier quoted context omitted.
I guess its very common, but this is a financial institution. What you describe as a solution strikes me as an amazing way to destroy production data. Upgrading every user can basically lead to one hell of an amazing outside attack. I now only have to get one user / password to compromise your database. A certain amount of red tape is a needed thing to make sure you don't affect your customer's business.
True, I didn't stop to consider the financial aspect. Was more just pointing out that there's often this separation between the people making the changes and the people making sure it's safe to release. But really, the safe to release step is often not going to catch things – in many cases because it's barely checked. To be fair, I only upgraded my user to give full access to my db and I revoked the permissions once…
I just didn't want to hear that you had set yourself up for a CEE (career ending event). People tend to be a tad bit wacky and whacky after a security breech.