Live data from Hacker News

How to gain code execution on hundreds of millions of people and popular apps

kibty.town

341–350 of 350 posts

Re: How to gain code execution on hundreds of millions of people and popular apps

#341

Earlier quoted context omitted.

> "we've fundamentally restructured our security practices to ensure this scenario can't recur." "Yeah it was a problem but it's fixed now, won't happen again" Sure buddy. It's not something you fix, when stuff like this happen, it's foundational, you can't fix it, it's a house of cards, you gotta bring it down and build it again with lessons learned. It's like a skyscraper built with hay that had a close call with s…

> It's not something you fix, when stuff like this happen, it's foundational, you can't fix it, it's a house of cards, you gotta bring it down and build it again with lessons learned. That's the last thing you should ever do within a large scale software system. The idea that restarting from scratch because "oh we'll do it better again" is the kind of thing that bankrupts companies. Plenty of seasoned engineers will…

I'm aware of that article. I'm saying file bankruptcy for the company, so yeah tear it down, it doesn't need to exist if it can get pwned.

Re: How to gain code execution on hundreds of millions of people and popular apps

#343

Earlier quoted context omitted.

It isn't exactly surprising that someone who is the beneficiary of a system which has no accountability is against the imposing of such, I was just hoping you had something better to offer back than 'I don't like it' and assertions that something is bad without ever explaining why. I have no idea why 'blameful postmortems' are bad because you never told me, you just say it is. Why should I change my mind in that case…

>I have no idea why 'blameful postmortems' are bad because you never told me Usually when you don't know something, you ask someone who knows. Since you sort-of asked here, I'll give you the answer: Blameless postmortems lead to fewer failures, which is ostensibly the goal here. So what do you get from your idea of blameful ones? Feeling good about punishing someone, even though you're increasing failures by doing so…

That you assign me the responsibility of asking you to explain your assertion sheds a lot of light on this interaction.

Either rhetoric and discourse are unfamiliar to you (for instance, that a basic tenant is that one does not make a strong claim which acts as foundational evidence for their entire premise and then assume it to be taken as fact based on statement alone -- if that were true then 3rd graders would win all arguments by saying 'nuh-uh'), or you don't understand that responsibility can also apply to you in many cases.

Re: How to gain code execution on hundreds of millions of people and popular apps

#344

Earlier quoted context omitted.

I am expressing long held frustration that software engineering as a culture is trying to eat its cake and still have it. Wanting to be called an engineer, demanding a high salary and running the largest sections of the economy and disrupting society in highly impactful ways, yet whenever someone asks them to take responsibility for any damage caused they downplay their role and anyone else's in the industry. It is t…

I'm on the side of freedom. If you want to run your company using vetted software and limit your developers to only use a small list of approved software. You can do that. I've worked in such environments. You can lock down the corporate firewall. The point is choice. It's completely different if you basically want a regulatory agency which will decide what software people are allowed to build. Outside of work I like…

What exactly is the difference between an official 'private' organization and an official 'state' organization? The only real difference I can see is that one can actually enforce the rules it makes. I think you may be using this ideological opposition to the State as a way to have something absorb blame for things you do not want to attribute to complex human mechanisms.

Re: How to gain code execution on hundreds of millions of people and popular apps

#345

Earlier quoted context omitted.

I'm on the side of freedom. If you want to run your company using vetted software and limit your developers to only use a small list of approved software. You can do that. I've worked in such environments. You can lock down the corporate firewall. The point is choice. It's completely different if you basically want a regulatory agency which will decide what software people are allowed to build. Outside of work I like…

What exactly is the difference between an official 'private' organization and an official 'state' organization? The only real difference I can see is that one can actually enforce the rules it makes. I think you may be using this ideological opposition to the State as a way to have something absorb blame for things you do not want to attribute to complex human mechanisms.

The difference is if people should go to jail for writing bad software.

I’d argue no.

Let the private sector regulate this. If you want to use an extremely locked down OS with a small handful of apps, go right ahead.

The State has no role in this.

I guess if you can prove negligence you can sue.

Re: How to gain code execution on hundreds of millions of people and popular apps

#347

Earlier quoted context omitted.

>I have no idea why 'blameful postmortems' are bad because you never told me Usually when you don't know something, you ask someone who knows. Since you sort-of asked here, I'll give you the answer: Blameless postmortems lead to fewer failures, which is ostensibly the goal here. So what do you get from your idea of blameful ones? Feeling good about punishing someone, even though you're increasing failures by doing so…

That you assign me the responsibility of asking you to explain your assertion sheds a lot of light on this interaction. Either rhetoric and discourse are unfamiliar to you (for instance, that a basic tenant is that one does not make a strong claim which acts as foundational evidence for their entire premise and then assume it to be taken as fact based on statement alone -- if that were true then 3rd graders would win…

You had (have?) your own premise that blameful postmortems were good -- the justification-free "yuh-huh!" matched by the justification-free "nuh-uh!" rebuttal, as you elegantly put it. After all, why provide more justification in rebutting a claim than was provided by the initial claimant in making it, unless they show a genuine interest in learning, or at least ask?

You aren't alone in your claim -- perhaps it is instinctive homo sapien thinking to believe punishment for mistakes & incidents always leads to fewer mistakes & incidents. Did you question those assumptions, though? When those assumptions were challenged, did you pause to think "Hmm, why DO I think that? Is it even true?"

There's perhaps an even deeper assumption here: you kept referring to blameful postmortems and punitive action as "accountability", which leads me to think that you might believe you can't have accountability for mistakes & incidents without punishing individuals. If this is indeed an assumption you hold, you should question whether it, too, is false.

The convenient part is, my existence isn't necessary for you to do any of this, so your personal preferences regarding my tone and my style won't affect your introspection and the resulting answers! :)

Re: How to gain code execution on hundreds of millions of people and popular apps

#349

Earlier quoted context omitted.

You're not thinking of it long term. In the short term you might be better off deciding when to update yourself, but in the long term you will be infinitely worse off because the reality of business practice is to delay updates until something catastrophic happens just to save a few bucks in the IT department. This approach merely means your system will run smoother over short time scales, while it becomes a complete…

The reality of auto-updates is that you get your workflow broken during critical project phases.

True, but only rarely and with foreseeable and preventable damage. The alternative leaves you open to basically infinite losses at an exponentially increasing risk over time. That tradeoff is simply not worth it if you want your company to exist long term.

Re: How to gain code execution on hundreds of millions of people and popular apps

#350

Earlier quoted context omitted.

And it's not like B2B doesn't get whacked by bad software or bad actors regulalry. The idea that software updates itself is vastly more benefitial than harmful in the very long term. There so many old machines running outdated software in gated corporate networks, they will get owned immediately once a single one of them is compromised in any way. They are literally trading minor inconveniences for a massive time-bom…

This mentality is how we get incidents like CrowdStrike. Relying on auto-updates for security is a crutch that allows insecure designs to spread.

Crowd strike was primarily an issue of running third party software in the kernel. If you're fine with this approach ad a company, you'll always be at the mercy of other people not screwing up in the lightest. Auto update issues are actually one of the nicer things you can run into over there.
Post reply on HN