9 ms·
It's hilarious how these companies handle security breaches. I once reported superadmin user/pass committed to github at a major YC backed background check com
by purplemoonx 1mo ago
It's hilarious how these companies handle security breaches.
I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.
I had just started working there and found it in the first week.
Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.
Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).
-----
I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
- mschuster91 1mo ago> I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it. The main problem is that the IT industry for a loooooooong time "self-regulated" itself, the only areas that did have regulation had it come in externally (i.e. automotive, aeronautic, astronauts and maritime). Only in the last years, GDPR + insurances forced a bit of change and accountability, but still, it's far removed from the standards that company owners, workers and planners are held to in construction (licensed engineers), legal or medical practice. Mess up there and everything can happen from fines over a license suspension to a permanent removal, or even jail time. In contrast, mess stuff up as a CTO and you'll probably be "asked" to voluntarily depart in exchange for a nice golden parachute.
- purplemoonx 1mo agoIdk licensing and regulation sounds like involving more institutional arrogance. We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed). The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doing. Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing. People who have done it a thousand times should get that job, not some dumb kid who just got out of school.
- QuadmasterXLII 1mo agothis idea that government regulation is the problem and the companies need economic incentives to self regulate is a religion around here, and after incredible amounts of evidence that is untrue, like all religions, it’s practitioners have made zero changes to their opinion.
- perpetuallunch 1mo agoThere is exactly zero evidence that any religion isn’t true. How could there be? Evolution can’t disprove the existence of God.
- arethuza 1mo agoAll depends which god we are disproving the existence of?
- purplemoonx 1mo agoProve Zeus didn't fart the Earth into existence, otherwise that's what happened
- goatlover 1mo agoWelcome to Invisible Pink Unicorns and orbiting tea pots. You're just a fleeting experience of a Boltzmann Brain in the background of high entropy universe. We don't need to disprove radically skeptical or outlandish beliefs. They're not consistent with everything else we know. There's no good reason to take them seriously.
- purplemoonx 1mo ago[dead]
- purplemoonx 1mo agoAllow me to introduce you to: Burden of Proof.
- jjice 1mo agoI was at a much smaller YC company when I found that AWS root credentials were checked into the repo, purely for S3 file uploads for logos. When other engineers and I brought it to the CEO (he required infrastructure stuff get brought up to him first), he handled it with zero urgency and didn't see why it was a big deal. I explained to him how the EC2 instances would assume the role that already had the permission and it took so long to convince him. Needless to say, we had to explain lots of basic security and networking concepts to him, which he wouldn't believe until given live demos of basic things like public versus private IP addresses in AWS.
- purplemoonx 1mo agoSo bad. At these types of startups, developers will find themselves in some debate about the time complexity of a click handler (which is debounced anyway). Meanwhile Joe CEO is like "HAY GUYS" -drops db- "CAN U FIX IT BY MONDAY"
- purplemoonx 1mo ago[dead]
- ThrowawayTestr 1mo agoMore proof that software engineering isn't real engineering. If a civil engineer made a mistake that bad in my country, he'd likely lose his engineering licence.
- siva7 1mo agoSoftware lost that status in the vibe coding era. It's an art form now, not necessarily something worse or easier, just different than engineering. But probably not the career path anymore for those who prefered math over philosophy in college.
- batshit_beaver 1mo agoIt was this way well before vibe coding. Over a decade of zero interest rates combined with talent wars and other anticompetitive behaviors by large tech companies did the industry in.
- customguy 1mo agoSoftware never had that status. I was disgusted by the decline I could see in the 90s even, and I was a teenager, I had no clue and still don't. I cannot imagine how it must be for people who do have a clue. They're probably all drinking.
- altmanaltman 1mo agoSoftware engineering has always had that perception, long before vibe coding. Also you might call it an "art" but most normal people will not see it as such (if you actually care about defintions, in theory we can call anything anything if we want)
- 8n4vidtmkvmk 1mo agoAmusingly i specialized in both AI and philosophy in college. Guess I'll be ok.
- purplemoonx 1mo ago[dead]
- suzzer99 1mo agoAt a few companies I've worked at, they squelch this kind of bug/security breach reporting by immediately making it the discoverer's job to fix the problem and champion it through the system to production, taking on all responsibility if something breaks of course. You only have to go through that once to get the message.
- purplemoonx 1mo agoHahaha nightmare. Like I'm pretty sure I had that nightmare
- tonyhart7 1mo agounfortunately, that just how organization was
- mettamage 1mo agoMany SWE teams don't care about security. Even talking about security annoys them. I get it though. I've had offensive security training at uni (VUSEC Amsterdam). It's a way different type of thinking.
- suslik 1mo agoI hate hearing about security because I saw orgs decimated by paranoid (and incompetent) security to such degree that nothing could be done there and I had to look for a new job.
- purplemoonx 1mo agoOne time a startup I worked at (NOT YC THIS TIME) had a "secret shopper"[1] [1] Some old guy who I'm pretty sure was a severe alcoholic Send us Gmail links that were 1000000000% obviously fake, like from a fake version of the CEO saying to wire him cash. I opened the email in gmail to copy the text to Slack, and was like "Did anyone else get this?" One other guy goes "lol yeah wtf" Next day in standup, security alcoholic is there. He goes: "2 people opened the malicious email" I'm like dude. Nothing will fucking happen if you open the Gmail message We didn't DOWNLOAD anything or visit any URLs. No. In the boomer mind, we were retards. We should be fired. We weren't, but we should have been. ??????? I'm like "GUYS" "I have some React components to make, what the fuck are you doing today?????" There are so many instances I wish technology was removed from "the pedestal" and just treated how it is. What it actually is, there is no non-determinism we can prove everything. I don't care if that makes it $30/hr work at this point, I just can't handle the pretentiousness anymore especially around faux security