purplemoonx
3 hours ago
It's hilarious how these companies handle security breaches.
I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.
I had just started working there and found it in the first week.
Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.
Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).
-----
I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
jjice
2 hours ago
I was at a much smaller YC company when I found that AWS root credentials were checked into the repo, purely for S3 file uploads for logos. When other engineers and I brought it to the CEO (he required infrastructure stuff get brought up to him first), he handled it with zero urgency and didn't see why it was a big deal.
I explained to him how the EC2 instances would assume the role that already had the permission and it took so long to convince him.
Needless to say, we had to explain lots of basic security and networking concepts to him, which he wouldn't believe until given live demos of basic things like public versus private IP addresses in AWS.
purplemoonx
2 hours ago
So bad.
At these types of startups, developers will find themselves in some debate about the time complexity of a click handler (which is debounced anyway).
Meanwhile Joe CEO is like "HAY GUYS" -drops db-
"CAN U FIX IT BY MONDAY"
mettamage
16 minutes ago
Many SWE teams don't care about security. Even talking about security annoys them. I get it though. I've had offensive security training at uni (VUSEC Amsterdam). It's a way different type of thinking.
suzzer99
2 hours ago
At a few companies I've worked at, they squelch this kind of bug/security breach reporting by immediately making it the discoverer's job to fix the problem and champion it through the system to production, taking on all responsibility if something breaks of course. You only have to go through that once to get the message.
ThrowawayTestr
2 hours ago
More proof that software engineering isn't real engineering. If a civil engineer made a mistake that bad in my country, he'd likely lose his engineering licence.
remuskaos
12 minutes ago
I studied physics, did a PhD and postdoc, the whole science shebang. When I got into software development a few years ago, I was put into a well functioning pizza sized team that developed an internal app for another company. The crew was as software-dev as it gets,:
- one architect who was there from the apps inception yen years prior, who knows all the ins and outs of the application - one project lead, who was with the project two years, who could also code in the classical sense, but was mostly the connection to the customer - a tester who could not code, but also knew the app in and out (from the user perspective) and found things or relayed and reproduced bugs reported by the customer - a technical writer who could also code (somewhat), but was more responsible to think of user behavior, undefined app behavior, edge cases, logic issues etc - and several disposable code monkeys, who were exchangeable and expendable, who did most of the tickets. I joined as one of these
The work was great, the team functioned great and we delivered what the customer wanted. But what really struck me was that software dev is not science, or engineering, or an art form, it's most akin to a trade like plumbing or carpentry. I had computer science as minor in university and pretty much none of what I learned there helped for "real" work. I learned SVN in university, but obviously the team used git. And all of the software development and programming courses I did taught me nothing of how real software is structured or how a team works.
That impression only more strongly once I had to train new hires, PhDs in comp science, who knew basically nothing about real software development.
Again, it's a trade, something you learn on the job from someone who already knows it, like a master carpenter.
purplemoonx
2 hours ago
The entire reason the company was funded is the US government started enforcing FCRA compliance on 1099 Uber drivers.
So the government did get involved and regulated Uber and the entire gig economy, and the private sector is so powerful they just made their own background check company with hundreds of millions of dollars in VC and hype, gave them Uber as their flagship customer and wiped their hands.
No doubt in my mind these people were "just happy to be here" at best, criminals at worst, and have no business working with PII and background checks. Founders and everyone there.
But I still think the company should be found liable, not an individual engineer. They would be a lot more incentivized to hire based on merit, and not incentivized to literally be corrupt like they are now.
With your idea of punishing the engineer... these VCs would love that. Shift even more blame onto the worker, why not, we've taken it for everything else
siva7
2 hours ago
Software lost that status in the vibe coding era. It's an art form now, not necessarily something worse or easier, just different than engineering. But probably not the career path anymore for those who prefered math over philosophy in college.
batshit_beaver
2 hours ago
It was this way well before vibe coding. Over a decade of zero interest rates combined with talent wars and other anticompetitive behaviors by large tech companies did the industry in.
8n4vidtmkvmk
15 minutes ago
Amusingly i specialized in both AI and philosophy in college. Guess I'll be ok.
altmanaltman
33 minutes ago
Software engineering has always had that perception, long before vibe coding. Also you might call it an "art" but most normal people will not see it as such (if you actually care about defintions, in theory we can call anything anything if we want)
customguy
2 hours ago
Software never had that status. I was disgusted by the decline I could see in the 90s even, and I was a teenager, I had no clue and still don't. I cannot imagine how it must be for people who do have a clue. They're probably all drinking.
mapt
an hour ago
If a civil engineer made a negligent mistake that bad which "made it to production", rather than being caught before the structure collapsed, he would spend a decade in prison for negligent homicide.
https://www.constructiondive.com/news/contractors-sentenced-...
https://www.reddit.com/r/AskEngineers/comments/cjpva1/is_it_...
https://www.monitor.co.ug/uganda/oped/commentary/it-s-a12-ye...
altmanaltman
29 minutes ago
To be fair, if the story in the comment you are replying to is actually factual and the company is found to be leaking private information on this scale, it can face pretty harsh legal consequences.
purplemoonx
11 minutes ago
Someone should investigate, interview me.
They violated their termination agreement with me already when they went way out of their way to make sure I would not get hired at certain other companies when I left.
tonyhart7
an hour ago
unfortunately, that just how organization was
mschuster91
3 hours ago
> I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
The main problem is that the IT industry for a loooooooong time "self-regulated" itself, the only areas that did have regulation had it come in externally (i.e. automotive, aeronautic, astronauts and maritime). Only in the last years, GDPR + insurances forced a bit of change and accountability, but still, it's far removed from the standards that company owners, workers and planners are held to in construction (licensed engineers), legal or medical practice. Mess up there and everything can happen from fines over a license suspension to a permanent removal, or even jail time.
In contrast, mess stuff up as a CTO and you'll probably be "asked" to voluntarily depart in exchange for a nice golden parachute.
purplemoonx
3 hours ago
Idk licensing and regulation sounds like involving more institutional arrogance.
We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).
The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doing.
Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing. People who have done it a thousand times should get that job, not some dumb kid who just got out of school.
QuadmasterXLII
2 hours ago
this idea that government regulation is the problem and the companies need economic incentives to self regulate is a religion around here, and after incredible amounts of evidence that is untrue, like all religions, it’s practitioners have made zero changes to their opinion.
perpetuallunch
2 hours ago
There is exactly zero evidence that any religion isn’t true.
How could there be?
Evolution can’t disprove the existence of God.
arethuza
2 hours ago
All depends which god we are disproving the existence of?
purplemoonx
an hour ago
Prove Zeus didn't fart the Earth into existence, otherwise that's what happened
goatlover
16 minutes ago
Welcome to Invisible Pink Unicorns and orbiting tea pots. You're just a fleeting experience of a Boltzmann Brain in the background of high entropy universe.
We don't need to disprove radically skeptical or outlandish beliefs. They're not consistent with everything else we know. There's no good reason to take them seriously.
purplemoonx
2 hours ago
Allow me to introduce you to: Burden of Proof.
toomuchtodo
2 hours ago
As a cybersecurity practitioner, regulation and oversight is the only incentive that moves the needle in my experience. If there are no costs or negative outcomes for not caring about security, security will not be prioritized. Big fan of SEC Breach Reporting via Form 8-K, as well as state reporting requirements.
https://www.sec.gov/newsroom/speeches-statements/gerding-cyb...
https://www.ncsl.org/technology-and-communication/security-b...
purplemoonx
2 hours ago
Kinda feel like you get corruption no matter if it's pure socialism or pure capitalism, and that any system is a reflection of the people.
mschuster91
2 hours ago
> Idk licensing and regulation sounds like involving more institutional arrogance.
Well it works. Aviation for example is incredibly safe if you think about it, and mostly because the governments worldwide joined forces and introduced an amount of safety regulations everywhere that sounds insane until you remember that these rules were literally written in blood. And similarly, losing your life or getting injured on a modern ship is a pretty rare thing to happen (either as employee or passenger) if you contrast it with the situation just five decades or so ago.
> We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).
Degree mills aren't the kind of gatekeeping I'm talking about. If you screw up, you still can go to another company and continue screwing up there, which also means there is barely any incentive to hold education institutions accountable to deliver good education. In the regulated trades however? Screw up enough and you're out for good.
> Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing.
Trades licensing is merit based.
purplemoonx
2 hours ago
Commercial aviation involves other people's lives in real-time. I put that more like being a lifeguard or EMT.
Recreational aviation has a lot less regulation. I saw a guy with nothing but a fan and a parachute just flying around the cliffs off Hwy 1. No license or certification needed.
Shouldn't need a license to make React components, sorry.
mschuster91
an hour ago
> Recreational aviation has a lot less regulation.
Yup, and the result is that GA has orders of magnitude worse accident rates.
> I saw a guy with nothing but a fan and a parachute just flying around the cliffs off Hwy 1. No license or certification needed.
In most of Europe, this just doesn't fly (pun intended), you need a license for almost all aeronautical activities, and on top of that a fair few countries (most notably Germany) only allow start and land from official airstrips.
> Shouldn't need a license to make React components, sorry.
Oh I'd say, yes, a license is a good idea, simply given how often developers put in stuff from marketing that violates laws. Forcing a license that can be revoked now gives engineers the ability to push back against management because now their licenses are on the line.
purplemoonx
an hour ago
> this just doesn't fly
How dare you. And to your point, you'd never catch me on one of those paraglider things!
> Oh I'd say, yes, a license is a good idea, simply given how often developers put in stuff from marketing that violates laws.
My only license is MIT :cool:
bluGill
2 hours ago
> Trades licensing is merit based.
Only on the bottom end. People with zero merit get forced out - eventually in most cases. However a lot of people who have merit are not allowed in.
mschuster91
21 minutes ago
> People with zero merit get forced out - eventually in most cases.
Yeah but in many cases often only after decades and still with a sizable final paycheck on departure. "Failing upwards" is a thing, and it happens far too often.