Live data from Hacker News

Accountability Sinks

250bpm.substack.com

291–300 of 407 posts

Re: Accountability Sinks

#291
post #230

Earlier quoted context omitted.

Having been on both sides of this—working behind a counter and answering phones at various jobs long ago, and being someone who often surprises family and friends with my ability to extract good outcomes from customer service—I think it’s somewhat of a misconception that being as unpleasant as possible is actually effective at getting results. I fully understand that the godawful CS mazes many companies set up wind u…

As an exception to the exception, a lot of automated telephone systems have a tree of options, and they try really hard to avoid giving you a real person, and none of the options are helpful. But some of them are programmed to detect swearing and direct users to a representative. So a valid strategy is to swear at the automated system and then be polite to the real human that you get.

> As an exception to the exception, a lot of automated telephone systems have a tree of options, and they try really hard to avoid giving you a real person, and none of the options are helpful. But some of them are programmed to detect swearing and direct users to a representative.

It usually just works to hit 0 (maybe more than once) or say "talk to an agent," even if those aren't options you're explicitly given.

Detecting swears just seems over-compliated.

Re: Accountability Sinks

#292
post #162

Earlier quoted context omitted.

> "we've implemented all best practices, contracted out the hard parts to world-renowned experts, and had third party audits to verify that - there was nothing more we could do, therefore it's not our fault" The amount of (useless) processes/systems at banks I've seen in my career that boil down to this is incredible, e.g. hundreds of millions spent on call center tech for authentication that might do nothing, but th…

What's funny is that checklists in hospitals have been shown, empirically, to be massive life-saving devices. cyber perhaps not so much...

Checklists are a good tool for making sure you don't forget something. They're a terrible replacement for actually thinking.

Re: Accountability Sinks

#293
This is the same reason that computers suck.

Every program you ever run will precisely follow the same set of rules, because it is those rules.

There's a missing piece that no one has really managed to implement on computers: backstory. The reason why a program's rules are written is much more important than the rules themselves, yet we haven't found any way to write the reason why.

The most important feature of backstory is that it's dynamic. The meaning of a story can be completely changed by simply replacing its backstory. Whether it's a computer program or a societal organization, a decided system must be ignorant to its backstory. There is no place in a decided system to implement context. It turns out that this is a core feature of computable systems: they are context-free.

---

I've been working on a way to change this, but it's such an abstract idea, it's been hard to actually find (and choose) where to get started.

Re: Accountability Sinks

#294

Earlier quoted context omitted.

Yes unfortunately I've observed this in some support systems. The best way is to thread the needle between being extremely personally polite to the other human on the line, but going through the required machinations on their runbook to trigger an escalation. That is - you don't really have to behave unpleasant (raise voice, swear, be impolite, threaten) but you should just refuse to get off the line, demand escalati…

I ask for something, when they say they can’t do that. I say the magic words “Maybe your manager can do it?” You just don’t accept the possibility of your request not being fulfilled, say they are contractually obliged to do, even if you’re not sure, if all else fails reverse the charges on your card. Threatening small claims court works well. I now do that on the on the second email, do I look like a fool? Yes. Do I…

Look at the ToS. Frequently there are clauses that force binding arbitration and require the company you are dealing with to pay the arbitration fees.

Re: Accountability Sinks

#296
post #281

Earlier quoted context omitted.

You've clearly never worked customer support. A very disproportionate number of people who call in to customer support are totally and utterly unreasonable. That's why it's such a pain to interact with customer support as a reasonable human: The systems aren't designed for you, they're designed for the abusers who represent something like 20% of the phone calls and 80% of the work.

Having lived it seems to me that nice people never get anything.

Depends. Started in CS and I would go out of my way to help nice people. Assholes were dealt with nicely but I’d follow the rules to the T. That was before CS was hamstrung.

Re: Accountability Sinks

#297
post #284

Earlier quoted context omitted.

Checklists work well in high stress situations where you cannot forget a step (medicine, aviation). A checklist in a security incident? Probably helpful. A security checklist to satisfy auditors and ancient regulations? This is an entirely different kind.

Yea, the problem most often in computer security checklists is misapplication of the checklist. I do cyber security related stuff for the finance and they have some of the dumbest checklists ever. A more recent one I got was "We only allow the HTTP verbs 'GET' and 'POST', your application can only use that and the verbs PUT, PATCH, and DELETE cannot be used. After not replying 'are you fucking stupid' I said "You do…

> For those who wonder, typically these verbs are disabled to prevent the accidental enablement of WebDAV on some platforms, especially Windows/IIS that had some issues with security around it. It makes zero sense for such a rule in a modern API application.

Thanks. One thing that's more interesting than the revealed stupidity of such rules is the actual (and often sensible) reason they were first created long ago.

"Temporary" hacks outliving both the problem they solved and the system they were built for seems to be a regular occurrence in bureaucracy as much as it is in software and hardware.

Re: Accountability Sinks

#298
post #278
post #264

This reminded me of my favorite David Greaber book: The utopia of rules ( https://en.m.wikipedia.org/wiki/The_Utopia_of_Rules ). Greaber, if I remember right, argues that modern bureaucracy started with efficient means of communication. He squares the Deutsche Post as the milestone, as they made the whole population available to be controlled. Now the state could send them letters, count them, enlist them in the mili…

More reachable, more accountable, and more surveilled by whom ? And can we flip the relationship, creating dashboards or whatever from which agentic systems reach, hold to account, and surveille right back? I'm thinking pro-active agents that escalate for you, sinking their teeth into interactions with large organizations like a dog with a bone.

It's the upper layer in the hierarchy that creates the impersonal "I'm just following the rules" behavior, aka accountability sinks. Surveillance is basically strengthening this, as every step of an employee can be traced. And you are 100% right, these technologies, as I wrote above aren't malicious or something and can be used on the opposite, and should. Ease of access to someone with decision making capability should make desicion makjng easier, not harder. We should be able to hold higher ups responsible.

Re: Accountability Sinks

#299
You can't get a credit card because your name is too long?

You can't pass immigrations because you don't have a last name?

The future is not made for you, because progammers and designers didn't get requirements that match the diversity of this beautiful world.

It remindes me how someone I know often makes complicated food orders in restaurants (modfying or replacing items on the menu), and then they get disappointed or complain because their wishes are forgotten or screwed up. I never make changes to a menu item, because I assume they are unable to accommodate me (either due to stress, lack of intelligence/memory, bad process e.g. not writing down customers' orders etc.). As a result, I get disappointed less often on average - make your oder "compatible" with the realities of this world to avoid disappointment and stress.

There is actually an official procedure for U.S. Immigrations dealing with people who have names that cannot be split meaningfully into first/last names, e.g. some people from India. Assume your name is "Maussam", then you are permitted and expected to fill in that string in BOTH fields, first name and last/family name, when booking a flight or applying for visa. (A similar hack could be devised for names that are "too long".)

Overall, these examples are reminiscent of the movie Brazil (1985), which is about a dystopian future in which a plumber that helps people fix their toilets gets hunted as a terrorist because he didn't fill in the right form.

My theory is the world has been gradually converging towards the absurd state parodied in that movie.

Airlines are not the only ones that get less and less accountable. We should stop spending our money with companies that communicate with us using email spam services the address of which begins with noreply@fubar.com.

https://de.wikipedia.org/wiki/Brazil_(1985)

Re: Accountability Sinks

#300
post #269

Earlier quoted context omitted.

Actual accountability. Do not let companies be like "Well, we were SOC2 compliant, this breach is not our fault despite not updating Apache Struts! Tee Hee" When Equifax got away with what was InfoSec murder by 6 months of jail time suspended, Executives stopped caring. This is political problem, not technology one. >So -- how do we get rid annoying checkboxes and ensure people do the right thing as a matter of cours…

It's a two-sided coin though. We should be stopping leaks, but we also need to reduce the value of leaked data. Identity theft doesn't get meaningfully prosecuted. Occasionally they'll go after some guy who runs a carding forum or someone who did a really splashy compromise, but the overall risk is low for most fraudulent players. I always wanted a regulation that if you want to apply for credit, you have to show up…

The problem with "identity theft" specifically is that, in itself, it's just a legal term for allowing banks to save on KYC by letting them transfer liability to society at large.

If someone uses your SSN to take a loan in your name, it shouldn't be your problem - in the same way that someone speeding in the same make&model of the car as yours shouldn't be your problem, just because they glued a piece of cardboard over their license plate and crayoned your numbers on it.

Post reply on HN