Live data from Hacker News

Maybe you should store passwords in plaintext

qword.net

51–60 of 147 posts

Re: Maybe you should store passwords in plaintext

#51
post #40

Earlier quoted context omitted.

The goal of a manager or worker isn’t to be efficient, it’s to produce value. I suspect the diminishing returns of effort at most companies is astonishingly high. I would much rather a developer work 10 hours and accomplish what needs to get done than work 40 and negatively impact the business.

The funny thing is, that extra working does actually negatively impact the business at least in the software world. People seemingly end up having a lot more time for _defining processes_. There are people at nearly every large company I’ve worked on that so more meta work, and sometimes demand more meta work than actual work. Like there are folks that are actively costing productivity in exchange for the meta work.…

Ah yes, I've worked before with developers that believed that processes didn't matter. They produced amazing value, or so they thought. Except that...

Half of what they did was never committed into git, because a software versioning process is for dummies. And the other half could only be found in a random feature branch, because they didn't need any review process, their code was always faultless.

Whatever was running in production did not match any state of the repository, because CI/CD processes only get in the way.

The documentation never matched their code because documentation is only for people that don't know what they're doing, and we shouldn't hire such people anyway.

Not saying that's you. But that is the type of person you appear to me when you proudly proclaim that processes have no value.

Re: Maybe you should store passwords in plaintext

#52
I am a chump. I've SEEN passwords in plaintext and I even tried to remove it by figuring out how to remove it from git histories.

Heck, for one of those where it was not possible to get rid of plaintext due to the architecture, I even wrote some code to compare hashes instead of password so at least the attacker would need a rainbow table to crack it. Didn't bother salting it, since there's only one user effectively.

But meh.

Life of a chump, ain't getting no promotion and got the lowest possible bonus last year. It's better to be a chump cos I can feel better about myself

Re: Maybe you should store passwords in plaintext

#53

I am basically that employee in several ways. I know about wasteful cloud spend that I do nothing about. My last comment on HN actually was asking if anyone could give me a reason to report that cloud waste. The best arguments were for the sake of the environment and to build credibility with co-workers to make it easier to jump ship. Nothing from the company at all. I can't say I deliberately ship bugs, but I don't…

If your employer doesn't reward its employees for doing things that benefit the bottom line, it's perhaps time to look for another employer.

You’re replying to someone who claims to be working multiple full time roles. What employee rewards effort with multiples of your total comp?

None, to my knowledge.

Re: Maybe you should store passwords in plaintext

#54
I've done the AWS thing. We spent over $1 million on AWS and I couldn't be bothered to care. We were in eternal crunch mode, 10-14 hour days for 6 months. If I spoke up about AWS waste I'd get ripped apart by upper management.

Eventually it became apparent what was going on. I was pushed out and went to a competitor who paid me more and had better hours. I gave that competitor a lot of information about the previous company and transfered a lot of my knowledge. I delivered quite a bit of value rather quickly because of that and was recognized and rewarded for it.

We work in an enormous industry. It doesn't seem like there are any consequences.

Re: Maybe you should store passwords in plaintext

#55

Horribly cynical, and I can't imagine having that viewpoint. It's actually fascinating how the author first justifies that sort of malaise, and then does the "but of course not me " thing. Even if someone were that self-focused, in almost any group or organization, critical security vulnerabilities and significant costs do hurt everyone in the group. You're going to be the ones having the rough time when expenses exc…

I'm confused as to how you felt the author is justifying it:

> Now, I would personally feel shame if I did these things.

They seem more interested in trying to find a solution to it. Or just posing it as a legitimate problem, the solution to which is food for thought.

Re: Maybe you should store passwords in plaintext

#56
post #17

I am basically that employee in several ways. I know about wasteful cloud spend that I do nothing about. My last comment on HN actually was asking if anyone could give me a reason to report that cloud waste. The best arguments were for the sake of the environment and to build credibility with co-workers to make it easier to jump ship. Nothing from the company at all. I can't say I deliberately ship bugs, but I don't…

I’m hanging onto this post for the next time I see people on their high horse about integrity among engineers. The fact is, some people have it and some don’t, regardless of job. This makes me sad. Economically it makes sense, but it’s a sign of the sickness in our modern society. Everyone looking out for themselves first without much thought to the community around them. I say this having been burned by employees li…

> Everyone looking out for themselves

yes, including/especially employers.

maybe (or not) these employee started doing this after been burned by their employers before. the very same that talk about the community, greater good, and being in it together but suddenly change speech when they're on the benefiting side.

I've been on both side of the equation so I understand. I also have acquaintances that were too, they used to behave the same way as mentioned in the article but once they had their own company started talking the same way you do, suddenly what was acceptable for them to do is unimaginable and unacceptable behavior for other people to do. that society should not have such things. not because they changed their opinions but because their incentives are what changed, so if they go back to their previous position so would their attitude.

at the end of the day, the reason people work is not because they want to, it's because they have to in order to get what they want.

wanting to have employees that go above and beyond, are the most productive, the most knowledgeable, most skilled, and accept the least pay is what best for you when you're the employer. but when you play in the other camp it's the reverse: the best job is the one that demand the least out of you for the most pay.

the payoff functions for the different actors roles are the not same, trying to appeal to a sense of shame, duty or merit is just a way for one actor to hijack another's perception of the game for their own benefit.

Re: Maybe you should store passwords in plaintext

#57
post #52

I am a chump. I've SEEN passwords in plaintext and I even tried to remove it by figuring out how to remove it from git histories. Heck, for one of those where it was not possible to get rid of plaintext due to the architecture, I even wrote some code to compare hashes instead of password so at least the attacker would need a rainbow table to crack it. Didn't bother salting it, since there's only one user effectively.…

I cost my company over a million dollars because I was lazy and spiteful. I made an L+1 hop to a competitor and now I make more money for less hours and I'm learning a ton.

Re: Maybe you should store passwords in plaintext

#58

Earlier quoted context omitted.

The goal of a manager or worker isn’t to be efficient, it’s to produce value. I suspect the diminishing returns of effort at most companies is astonishingly high. I would much rather a developer work 10 hours and accomplish what needs to get done than work 40 and negatively impact the business.

> I would much rather a developer work 10 hours and accomplish what needs to get done than work 40 and negatively impact the business. It feels like there is a third option here that I can’t quite put my finger on.

i see two additional options. one is, find something else to do that actually benefits the company. that only works if the climate in the company supports that. the other is to reduce the size of the team because apparently so many people are not needed to get all the work done.

Re: Maybe you should store passwords in plaintext

#59

I agree with Nihilartikel’s comment. It’s nice when you’re the one doing business development. But as a manager at any organization, the correct answer is to fire people like this because they become insidious and take over your business. Have a moral backbone. Is it fair? No. Lots of corporate decision making will never ever be fair. Deal with it, or work with these people. Find ways to financially incentivize moral…

> One guy didn’t know how to fork a repo and maintain an internal copy of a project with clean portable diffs.

Or don't care about it. I started my new job by forking 2 or 3 repo (one was from an almost new project), but then i looked at the commit history and i was like "Fuck it, i'll just branch out and rebase before the merge to clean up my shit". I know how to do it, i do not bother.

My commit titles are often enough, i sometimes add a commit comment but i know no one really cares. I just do my job well enough, and try to stay motivated by doing the most interesting parts well, and do not forces myself on the boring parts.

Re: Maybe you should store passwords in plaintext

#60
post #51
post #40

Earlier quoted context omitted.

The funny thing is, that extra working does actually negatively impact the business at least in the software world. People seemingly end up having a lot more time for _defining processes_. There are people at nearly every large company I’ve worked on that so more meta work, and sometimes demand more meta work than actual work. Like there are folks that are actively costing productivity in exchange for the meta work.…

Ah yes, I've worked before with developers that believed that processes didn't matter. They produced amazing value, or so they thought. Except that... Half of what they did was never committed into git, because a software versioning process is for dummies. And the other half could only be found in a random feature branch, because they didn't need any review process, their code was always faultless. Whatever was runni…

i think you are misreading the parent comment. it's not claiming that processes have no value but that busybodies use their free time to invent additional processes beyond those that are actually needed.
Post reply on HN