Live data from Hacker News

Most “mandatory requirements” in corporations are imaginary

nibblestew.blogspot.com

21–30 of 405 posts

Re: Most “mandatory requirements” in corporations are imaginary

#21
To state a corollary of this: most "mandatory experience" on tech job requirements are imaginary.

Therefore, if you're a job seeker, and especially if you're a woman or a minority, you shouldn't let not having any of these imaginary requirements stop you from applying for whatever job you want, especially if it's a junior role.

Re: Most “mandatory requirements” in corporations are imaginary

#22

Aren't all rules imaginary? > Every time someone in the management chain has axed the proposal with some variation of "this policy can not be changed because this is our policy and thus can not be changed", possibly with a "due to security reasons" thrown in there somewhere. That's circular, no doubt there. We've decided this rule must remain in place, because it's a rule . This decision-making process doesn't make a…

The management could be keeping the real reason from the contracters. It's not good for moral to say "No - cause we don't trust you".

Re: Most “mandatory requirements” in corporations are imaginary

#23
I find these types of articles to be truisms.

We have some imperfect system. Everybody knows about the problems it has. Somebody writes an article about how stupid and wrong those problems are. How does that help anybody?

The real question is how you fix those problems without introducing others. Passed a certain age and work experience you start to notice that the bureaucracy that stops you from doing quick smart fixes also stops a lot of people from doing serious damage to the company.

And yes, in some cases external factors will force a quick reevaluation of that bureaucracy. And you can say "I told you so all along!". But again, that's zero value to the business. The real value is in the work done to plan and execute a change is a way that assures no collateral damage and also to satisfy humanly needs/desires in the hierarchy.

People want to cover their asses, but guess what, when you put the responsibility of a change on the smart ass that always annoys coworkers with his brilliant ideas they tend to back away from it cause his ass is precious to him too.

TLDR: https://en.wikipedia.org/wiki/Wikipedia:Chesterton%27s_fence

Re: Most “mandatory requirements” in corporations are imaginary

#24

If i pay an external $1000 per day and that price doesn't change when they are in my office or at home, i would put them in my office for obvious security risks. If corona means i can't get my work done, i have a new risk. Security risk for external consultants having full access at their home vs. no one can work -> i might choose the externals giving access. Its not imaginary.

But shouldn't you have to weigh this against the fact that a bit more freedom makes people happy?

Re: Most “mandatory requirements” in corporations are imaginary

#25
In BigCorps, if there's a stupid requirement, there's usually a reason for the stupid requirement to be there in the first place but getting to the reason might require un-peeling a few org layers to since the people enforcing the policy will not be the people who wrote the policy. A more productive use of time would be to understand the reason for the policy, document out why it doesn't apply to your case and then attempt to get approval.

For instance, there's a restriction at my workplace (not a software company, a regular old industry fortune 500) which prevents git installs from pushing to any non corporate GitHub repo from our work machines.

The obvious reason it exists is to prevent people (a lot of who are analysts or data scientists - not professional programmers) from shooting themselves in the foot by pushing code to their personal repos in error.

It's annoying to work around if you need to say push a contribution to an open source project and you could rage at the infosec for enforcing it - but it obviously exists because stupid errors would have happened.

This principle is also called Chesterton's fence

https://en.m.wikipedia.org/wiki/Wikipedia:Chesterton%27s_fen...

Re: Most “mandatory requirements” in corporations are imaginary

#26

Aren't all rules imaginary? > Every time someone in the management chain has axed the proposal with some variation of "this policy can not be changed because this is our policy and thus can not be changed", possibly with a "due to security reasons" thrown in there somewhere. That's circular, no doubt there. We've decided this rule must remain in place, because it's a rule . This decision-making process doesn't make a…

No, in short, the real point seems to be while the actual workers (non-management) would benefit the most from the rule change, managers (and further up the chain) mostly sees the risk and not the benefits, so they are the most likely to avoid changing the rules. Since the chance of getting blamed for changing the rules and impacting something negatively is bigger than getting blamed for _not_ changing the rules, and they are the ones actually allowed to making changes, you don't see a lot of the rules changing.

Re: Most “mandatory requirements” in corporations are imaginary

#27
post #12

Once you have people in your organization, you can manipulate the internal economy of favors and perks in order to increase your ability to control their behavior.

A Gervais principle man?

Forget INTP, Sociopath|Clueless|Loser is definitely the most effective categorisation of roles in organisation I have encountered:

https://www.ribbonfarm.com/the-gervais-principle/

Re: Most “mandatory requirements” in corporations are imaginary

#28
post #5

I feel that as organization size increases, individual responsibility decreases. At some point there’s a limit where individuals become responsible for nothing and everything is a policy or process. It would be interesting to try to study or quantify this with different orgs and roles.

Funny enough i though so as well but discovered quite quickly that without this stuff, a lot of people are doing shit. Do i think someone needs to tell me not to put every shitty tool on my work laptop which has a corp certificate? Access to vpn and corp network? With access to HyperScalers? No. What do my collegues? Everything. Oh there is a nice new shiny tool and it sends metrics to an external service, lets try t…

I'm not in favour of the "BigCorp controls my entire machine" approach, but this is silly. It's not a lot of people doing shit, it's a problem of scale.

Have you verified that every single application installed on your machines sends no telemetry, no crash reporting, and has no random web servers running that run arbitrary code? It's likely that you've missed one application. Now multiply that by 10,000 employees - all it takes is one application per person, and you have a massive amount of data being leaked.

Re: Most “mandatory requirements” in corporations are imaginary

#29
post #4

Founders should keep this in mind anytime they are negotiating contract terms with a corporation also. There is no such thing as a "standard" contract and almost all "mandatory" clauses are not actually mandatory. This also applies to real estate transactions and almost any other high stakes negotiating. Standard and mandatory are terms used to trick inexperienced or less powerful people/entities into agreeing to ter…

Everyone should keep this in mind for every type of contract.

In the beginning of my adult life, I was under the expression that contracts were static and immutable. As I got more experience, I tried being more demanding (and my skills were also more in demand) when setting up contracts and I have at multiple points managed to change what was supposed to be "mandatory" and "unchangable" many times, from rental contracts to employment contracts and many other things.

Re: Most “mandatory requirements” in corporations are imaginary

#30
You see this in a lot of security pushback.

"I want to do X" / "I am too lazy to do Y instead" becomes "We can't do Y, it's a mandatory requirement to do X"

Very high on your response agenda should always be to ask for details. Who mandated this and how? If there's a regulation, cite the exact text of the regulation. There's a good chance the person telling you it's mandatory either knows it isn't or has never actually wondered why, and you can divert them from insisting on doing X / not doing Y to an exciting journey through their bureaucracy to find out that indeed there is no such mandate and never has been.

Back when TLS 1.3 was being finalised EDCO and other groups trying to preserve RSA key exchange tried really hard to pretend that what they were doing was mandatory (it isn't and wasn't) and that their use cases were legitimate (most of them don't even appear to have a sound security rationale, let alone a legitimate purpose).

When we get to September and companies that were asleep at the wheel suddenly notice the 398 day rule (Apple unilaterally changed the maximum lifetime of new certificates in the Web PKI to 398 days starting in September) you can guarantee that some of them will insist that having longer-lived certificates is somehow mandatory.

[ Edited: It's the Enterprise Data Center Operators thus EDCO not ECDO ]

Post reply on HN