mintplant
a day ago
My dad headed up the redesign effort on the Lockheed Martin side to remove the foam PAL ramps (where the chunk of foam that broke off and hit the orbiter came from) from the external tank, as part of return-to-flight after the Columbia disaster. At the time he was the last one left at the company from when they had previously investigated removing those ramps from the design. He told me how he went from basically working on this project off in a corner on his own, to suddenly having millions of dollars in funding and flying all over for wind tunnel tests when it became clear to NASA that return-to-flight couldn't happen without removing the ramps.
I don't think his name has ever come up in all the histories of this—some Lockheed policy about not letting their employees be publicly credited in papers—but he's got an array of internal awards from this time around his desk at home (he's now retired). I've always been proud of him for this.
dclowd9901
a day ago
It's funny how the thankless jobs of quality assurance become so critical so quickly. And I mean that ironically of course.
To folks out there: do the important work, not the glamorous work, and you'll not only sleep well, but you might actually matter as well.
jacquesm
a day ago
Yes, but first it has to go horribly wrong. Same for security. After the breach there is plenty of budget.
michaelcampbell
18 hours ago
I worked in security for a while, but luckily on the vendor side and not the consumer side. The old yarn in that area is when everything (security wise) is fine, management asks you "What are we paying you for?". When it inevitably turns pear shaped they ask, "What are we paying you for?"
Fun times.
jacquesm
8 hours ago
It's a variation on the prevention paradox.
arethuza
a day ago
Many years ago I had a fascination with security and fancied becoming the CISO for the multinational I was working for at the time - my boss at the time, the CIO, said the role would really have no power and would be there as a sacrificial lamb should there actually be a serious security breach. This rather put me off the idea.
jacquesm
a day ago
Your comment should be required reading for any CISO that finds themselves without mandate, budget or support from upper management.
arethuza
a day ago
In retrospect, after the 2008 crash in the finance world how the role of a CISO was described to me sounded an awful lot like risk officers in a lot of financial organisations.
GiorgioG
20 hours ago
On the flip side, some companies have gone to extremes. I now have to MFA and provide a pin-code to authenticate. I have to do this several times a day. It's fucking mind-boggling how I can get anything done in a day when I spend so much time verifying who I am. I'm waiting for the next innovation...require a drop of my blood to log in.
jacquesm
19 hours ago
Why is that extreme? I have to provide a pin code using MFA to my bank to authenticate, and their sessions are a lot shorter than your average developer or operator session.
And their actions impact far more than just my own account. Is it inconvenient? Yes. Does it work? Yes. Is it perfect? No, absolutely not but it is a useful layer in the cake.
michaelt
18 hours ago
Requiring a user to MFA once per day per device is normal for a work account - but that's already a lot compared to services like gmail.
After all, workers are mostly working in an access-controlled office or their private home; and your endpoint protection will be ensuring they're connecting from a company-issued laptop and that they have screen lock on a timer and a strong password.
I'm already validating something-they-know (FDE password) and something-they-know (OS password) and something-they-know (SSO system password) and something-they-have (company laptop). And once a day I'm validating another something-they-have (TOTP code/Yubikey).
Asking people to provide the second something-they-have several times a day seems like security theatre to me.
michaelcampbell
18 hours ago
The Risk Management manager character played by Demi Moore in the "Margin Call" movie is another example of this in the financial industry.
jacquesm
11 hours ago
Awesome movie.
salawat
18 hours ago
Head of Quality Assurance is often also treated as ablative armor for existing management.
jacquesm
15 hours ago
That's a very poetic description.
phasetransition
21 hours ago
We had a meaningful amount of {industrial accident happened} added to the pipeline every year. We made outdoor lighting.
Serious injuries or deaths is a terrible feeling, even if the end result was better safety for the rest of the workers.
kstrauser
a day ago
Well, I’m proud of him, too. Thank him for helping us return to the stars.
RHSman2
a day ago
I hope he knows you are proud of him.