Live data from Hacker News

Amazon insiders sound alarm over security

politico.eu

21–30 of 63 posts

Re: Amazon insiders sound alarm over security

#21

Every time I read articles like these, I get dissapointed about the state of the internet. The only thing you know that is likely to be true is that someone got fired from Amazon, and thats it. You don't know if they are telling the truth. You don't know if they were in the right. You don't know if Amazon was fixing the problem, and they decided to be an asshole and go over their bosses because they felt that not eno…

The only way to prove it, would be a massive data leak.

Re: Amazon insiders sound alarm over security

#22
post #16
post #13

Earlier quoted context omitted.

The only thing you know that is likely to be true is that someone got fired from Amazon. From the article: > The warnings about privacy and compliance failures at Amazon come from three former high-level information security employees — one EU-based and two from the U.S. So 3 employees involved with security and not 1 employee. Also, they were pushed out AFTER alerting about security issues.

> So 3 employees involved with security and not 1 employee. Also, they were pushed out AFTER alerting about security issues. How much credibility do you put in such testimonies though? Especially if everyone is a "anonymous source", you can basically invent just about anything and publish it and pretend for it to be a genuine article without any fact under the hood.

You get sued, because such claims are business damaging.

Re: Amazon insiders sound alarm over security

#23
post #20
post #16

Earlier quoted context omitted.

> So 3 employees involved with security and not 1 employee. Also, they were pushed out AFTER alerting about security issues. How much credibility do you put in such testimonies though? Especially if everyone is a "anonymous source", you can basically invent just about anything and publish it and pretend for it to be a genuine article without any fact under the hood.

Presumably if you trust the reputation of the newspaper or journalist writing the article, you trust the testimony.

Thank you, this is exactly it. And it's not either like anyone should consider a newspaper report the final word on the issue, but there is a reasonable amount of information presented here, and it should warrant an official investigation into Amazon's data practices at the very least.

Re: Amazon insiders sound alarm over security

#24

Somehow I am not surprised given all the talk about toxic culture at Amazon from current and past employees.

I personally know a couple ex-Amazon people who thought it was a good place to work and thrived there. Of course, that's not worthy of writing a newspaper article about :-/

I'm not saying it is or it isn't. But ask yourself, which viewpoint sells more newspapers?

Re: Amazon insiders sound alarm over security

#25

Every time I read articles like these, I get dissapointed about the state of the internet. The only thing you know that is likely to be true is that someone got fired from Amazon, and thats it. You don't know if they are telling the truth. You don't know if they were in the right. You don't know if Amazon was fixing the problem, and they decided to be an asshole and go over their bosses because they felt that not eno…

So you have to read it with a just a little critical thinking.

Is politico.eu a site with a reputation or just someone's uncle's blog? Do they have an incentive here? Have they done hatchet jobs before? Do they do them commonly?

This is a claim about a particular company? Is this kind of claim contrary to that company's historical record? Is it consistent with it?

Are the claims specific? Are they capable of being falsified? Could other people familiar with what has been claimed confirm it somehow? Will the publication and journalist take a reputational hit if it is all false because they've been had?

And do you know something? We always needed to do this. In life when hearing claims verbally at work or wherever. When reading old-school newsprint. When listening to politicians, public servants, experts, academics.

And here we are still assessing sources and looking for argument from evidence.

Now yours:

> "The only thing you know that is likely to be true is that someone got fired from Amazon, and thats it."

Not looking so hot. But that's fine. That's really ok.

Re: Amazon insiders sound alarm over security

#26
post #21

Every time I read articles like these, I get dissapointed about the state of the internet. The only thing you know that is likely to be true is that someone got fired from Amazon, and thats it. You don't know if they are telling the truth. You don't know if they were in the right. You don't know if Amazon was fixing the problem, and they decided to be an asshole and go over their bosses because they felt that not eno…

The only way to prove it, would be a massive data leak.

The fact there have been no data leaks should tell you more then some anonymous sources

Re: Amazon insiders sound alarm over security

#27

Every time I read articles like these, I get dissapointed about the state of the internet. The only thing you know that is likely to be true is that someone got fired from Amazon, and thats it. You don't know if they are telling the truth. You don't know if they were in the right. You don't know if Amazon was fixing the problem, and they decided to be an asshole and go over their bosses because they felt that not eno…

Disgruntled employees can be risky. Like Stamos, and the way the NYTimes took Facebook's efforts to tackle abuse in 2019 as evidence of their previous "indifference". If anything you do can be twisted against you, why bother?

I want to see more information about their background. If they've been fired already, they're not going to lose much from going public with this.

Re: Amazon insiders sound alarm over security

#28
post #16
post #13

Earlier quoted context omitted.

The only thing you know that is likely to be true is that someone got fired from Amazon. From the article: > The warnings about privacy and compliance failures at Amazon come from three former high-level information security employees — one EU-based and two from the U.S. So 3 employees involved with security and not 1 employee. Also, they were pushed out AFTER alerting about security issues.

> So 3 employees involved with security and not 1 employee. Also, they were pushed out AFTER alerting about security issues. How much credibility do you put in such testimonies though? Especially if everyone is a "anonymous source", you can basically invent just about anything and publish it and pretend for it to be a genuine article without any fact under the hood.

Journalists do check the credentials of the people they include in articles like this. They don't just take randos at their word. These people are anonymous to you but not to the journalist. If you simply don't believe the writer that's a totally different issue - but people at major outlets like Politico don't just invent sources and stories out of whole cloth like you suggest.

Re: Amazon insiders sound alarm over security

#30
“We had an insecure vulnerability that we knew about for five years," the second former U.S.-based employee said. "That's unacceptable. I mean, we knew about it."

In my experience, knowing about a vulnerability and knowing how to fix it are magnitudes of effort apart. Main reason I saw companies avoid fixing vulnerabilities was third party libraries. Third party libraries had switched to a new version of JDK or Node and upgrading production environments carried a lot of risk or would break other libraries. Companies stayed on old versions because they “worked” and eventually were unable to pick up security fixes. It’s one big advantage that startups have over the behemoths.

Upgrading dependencies on products with millions of users without breaking anything is one of the most thrilling and rewarding things I’ve ever done.

Post reply on HN