It's hilarious how these companies handle security breaches.
I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.
I had just started working there and found it in the first week.
Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.
Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).
-----
I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
I was at a much smaller YC company when I found that AWS root credentials were checked into the repo, purely for S3 file uploads for logos. When other engineers and I brought it to the CEO (he required infrastructure stuff get brought up to him first), he handled it with zero urgency and didn't see why it was a big deal.
I explained to him how the EC2 instances would assume the role that already had the permission and it took so long to convince him.
Needless to say, we had to explain lots of basic security and networking concepts to him, which he wouldn't believe until given live demos of basic things like public versus private IP addresses in AWS.
At a few companies I've worked at, they squelch this kind of bug/security breach reporting by immediately making it the discoverer's job to fix the problem and champion it through the system to production, taking on all responsibility if something breaks of course. You only have to go through that once to get the message.
More proof that software engineering isn't real engineering. If a civil engineer made a mistake that bad in my country, he'd likely lose his engineering licence.
I studied physics, did a PhD and postdoc, the whole science shebang. When I got into software development a few years ago, I was put into a well functioning pizza sized team that developed an internal app for another company. The crew was as software-dev as it gets,:
- one architect who was there from the apps inception yen years prior, who knows all the ins and outs of the application
- one project lead, who was with the project two years, who could also code in the classical sense, but was mostly the connection to the customer
- a tester who could not code, but also knew the app in and out (from the user perspective) and found things or relayed and reproduced bugs reported by the customer
- a technical writer who could also code (somewhat), but was more responsible to think of user behavior, undefined app behavior, edge cases, logic issues etc
- and several disposable code monkeys, who were exchangeable and expendable, who did most of the tickets. I joined as one of these
The work was great, the team functioned great and we delivered what the customer wanted. But what really struck me was that software dev is not science, or engineering, or an art form, it's most akin to a trade like plumbing or carpentry. I had computer science as minor in university and pretty much none of what I learned there helped for "real" work. I learned SVN in university, but obviously the team used git. And all of the software development and programming courses I did taught me nothing of how real software is structured or how a team works.
That impression only more strongly once I had to train new hires, PhDs in comp science, who knew basically nothing about real software development.
Again, it's a trade, something you learn on the job from someone who already knows it, like a master carpenter.
Heh, that idea resonates with me. I’ve been contemplating some projects that will require pulling permits, and as part of that process have been trying to understand how an engineer reviewing my submitted plans would think.
While you could absolutely generate a list of compliance checks to execute like a formula, at the end of the day you need to have absorbed enough experience that, when presented a physical or imagined project, your brain is immediately able to make connections between what it sees and the general principles of how you build something correctly.
Since I don’t have that experience, I know I need to stick to the well-trod path. No clean-sheet deck construction methods for me. :)
Software lost that status in the vibe coding era. It's an art form now, not necessarily something worse or easier, just different than engineering. But probably not the career path anymore for those who prefered math over philosophy in college.
It was this way well before vibe coding. Over a decade of zero interest rates combined with talent wars and other anticompetitive behaviors by large tech companies did the industry in.
Software engineering has always had that perception, long before vibe coding. Also you might call it an "art" but most normal people will not see it as such (if you actually care about defintions, in theory we can call anything anything if we want)
Software never had that status. I was disgusted by the decline I could see in the 90s even, and I was a teenager, I had no clue and still don't. I cannot imagine how it must be for people who do have a clue. They're probably all drinking.
Of course it's not real engineering, and most software development never was real engineering.
Trying to apply real engineering licensing ideas to software would just result in the word "engineering" no longer being used in the vast majority of cases. If that's your goal, then sure, great. But it won't stop ridiculous security mistakes from being made, they'll just be made by people with different job titles.
If a civil engineer made a negligent mistake that bad which "made it to production", rather than being caught before the structure collapsed, he would spend a decade in prison for negligent homicide.
To be fair, if the story in the comment you are replying to is actually factual and the company is found to be leaking private information on this scale, it can face pretty harsh legal consequences.
They violated their termination agreement with me already when they went way out of their way to make sure I would not get hired at certain other companies when I left.
The entire reason the company was funded is the US government started enforcing FCRA compliance on 1099 Uber drivers.
So the government did get involved and regulated Uber and the entire gig economy, and the private sector is so powerful they just made their own background check company with hundreds of millions of dollars in VC and hype, gave them Uber as their flagship customer and wiped their hands.
No doubt in my mind these people were "just happy to be here" at best, criminals at worst, and have no business working with PII and background checks. Founders and everyone there.
But I still think the company should be found liable, not an individual engineer. They would be a lot more incentivized to hire based on merit, and not incentivized to literally be corrupt like they are now.
With your idea of punishing the engineer... these VCs would love that. Shift even more blame onto the worker, why not, we've taken it for everything else
> I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
The main problem is that the IT industry for a loooooooong time "self-regulated" itself, the only areas that did have regulation had it come in externally (i.e. automotive, aeronautic, astronauts and maritime). Only in the last years, GDPR + insurances forced a bit of change and accountability, but still, it's far removed from the standards that company owners, workers and planners are held to in construction (licensed engineers), legal or medical practice. Mess up there and everything can happen from fines over a license suspension to a permanent removal, or even jail time.
In contrast, mess stuff up as a CTO and you'll probably be "asked" to voluntarily depart in exchange for a nice golden parachute.
Idk licensing and regulation sounds like involving more institutional arrogance.
We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).
The CTO shouldn't have to pay, the company should. And then maybe they will be incentivized to hire somebody who knows what they're doing.
Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing. People who have done it a thousand times should get that job, not some dumb kid who just got out of school.
this idea that government regulation is the problem and the companies need economic incentives to self regulate is a religion around here, and after incredible amounts of evidence that is untrue, like all religions, it’s practitioners have made zero changes to their opinion.
As a cybersecurity practitioner, regulation and oversight is the only incentive that moves the needle in my experience. If there are no costs or negative outcomes for not caring about security, security will not be prioritized. Big fan of SEC Breach Reporting via Form 8-K, as well as state reporting requirements.
The primary evidence that religions aren’t “true” are the religious texts themselves: filled with easily disproved falsehoods and a primitive understanding of the world. Evolution is not compatible with creation myths. The biblical Exodus never happened. Jesus was barely noticed historically, i.e. extra-biblically.
The issue is not “disproving the existence of God”, any more than we have to disprove the existence of Frodo Baggins. (Which gods, btw?)
The question should be, why should we take these obvious myths as anything more than that? The answer is that there’s no reason to.
Ultimately science can’t explain why there is anything at all, rather than the more likely scenario of there simply being nothing.
It’s not a question science can answer.
Once there is something, rather than the obviously more likely nothing at all, science won’t help you understand why physics > chemistry > biology is ever so precisely tuned to be able to give rise to everything necessary for complex life to arise.
Without resorting to circular reasoning.
There’s definitely an aspect of mythos in the, well, “creation myths”.
The religious texts of Christianity, Judaism, and Islam, have anything but a primitive understanding of the human condition, the human world. My understanding of the worlds other great religions is very limited, other than to say they appear to have served their adherents well enough to have got them this far.
The problems the world faces today are primarily those of frivolity, corruption, excess. No amount of science is going to help there.
> Once there is something, rather than the obviously more likely nothing at all
Why is that "obviously more likely"? It's clear that you haven't really thought about this outside of the confines of your indoctrinated religion.
> ever so precisely tuned to be able to give rise to everything necessary for complex life to arise.
Citation needed. This is just mythical nonsense that doesn't stand up to even the lightest scrutiny.
Not to mention that the argument "we can't perfectly explain the universe, therefore 'god'" is so ridiculously nonsensical that it makes me question whether or not I'm talking to an intelligent being.
> The problems the world faces today are primarily those of frivolity, corruption, excess. No amount of science is going to help there.
No, ethics will help. That's the domain of philosophy. There's no ethical religion in the world today, because they all delegate ethics to an imaginary source with no evidence.
Perhaps you want to claim that Christianity is ethical? Oh yes? What's its position on gender equality, on gay people, etc.? And why does it hold that position? Because "God" supposedly said something to some Bronze Age goat herders 4000 years ago?
It's absolutely incredible and insane that anyone with even a minimal modern education would believe such nonsense. You should be ashamed of yourself, not least because of the damaging "ethics" that your religion has convinced you to believe and to inflict on the people around you. Shame.
The reason you're even discussing this is because somewhere, deep inside, you recognize that you've been sold a bill of goods. It's time to become an adult now, and put away childish things.
Welcome to Invisible Pink Unicorns and orbiting tea pots. You're just a fleeting experience of a Boltzmann Brain in the background of high entropy universe.
We don't need to disprove radically skeptical or outlandish beliefs. They're not consistent with everything else we know. There's no good reason to take them seriously.
> Idk licensing and regulation sounds like involving more institutional arrogance.
Well it works. Aviation for example is incredibly safe if you think about it, and mostly because the governments worldwide joined forces and introduced an amount of safety regulations everywhere that sounds insane until you remember that these rules were literally written in blood. And similarly, losing your life or getting injured on a modern ship is a pretty rare thing to happen (either as employee or passenger) if you contrast it with the situation just five decades or so ago.
> We effectively have that kind of gatekeeping now with the University degree and University recruiting pipelines (all other candidates are "external" and illegally deprioritized but it's somehow allowed).
Degree mills aren't the kind of gatekeeping I'm talking about. If you screw up, you still can go to another company and continue screwing up there, which also means there is barely any incentive to hold education institutions accountable to deliver good education. In the regulated trades however? Screw up enough and you're out for good.
> Licensing just gatekeeps it more to even more dumbass people with connections getting good roles. It should be more merit based to avoid this kind of thing.
> People with zero merit get forced out - eventually in most cases.
Yeah but in many cases often only after decades and still with a sizable final paycheck on departure. "Failing upwards" is a thing, and it happens far too often.
Commercial aviation involves other people's lives in real-time. I put that more like being a lifeguard or EMT.
Recreational aviation has a lot less regulation. I saw a guy with nothing but a fan and a parachute just flying around the cliffs off Hwy 1. No license or certification needed.
Shouldn't need a license to make React components, sorry.
> Recreational aviation has a lot less regulation.
Yup, and the result is that GA has orders of magnitude worse accident rates.
> I saw a guy with nothing but a fan and a parachute just flying around the cliffs off Hwy 1. No license or certification needed.
In most of Europe, this just doesn't fly (pun intended), you need a license for almost all aeronautical activities, and on top of that a fair few countries (most notably Germany) only allow start and land from official airstrips.
> Shouldn't need a license to make React components, sorry.
Oh I'd say, yes, a license is a good idea, simply given how often developers put in stuff from marketing that violates laws. Forcing a license that can be revoked now gives engineers the ability to push back against management because now their licenses are on the line.
Many SWE teams don't care about security. Even talking about security annoys them. I get it though. I've had offensive security training at uni (VUSEC Amsterdam). It's a way different type of thinking.
I hate hearing about security because I saw orgs decimated by paranoid (and incompetent) security to such degree that nothing could be done there and I had to look for a new job.
One time a startup I worked at (NOT YC THIS TIME) had a "secret shopper"[1]
[1] Some old guy who I'm pretty sure was a severe alcoholic
Send us Gmail links that were 1000000000% obviously fake, like from a fake version of the CEO saying to wire him cash.
I opened the email in gmail to copy the text to Slack, and was like "Did anyone else get this?"
One other guy goes "lol yeah wtf"
Next day in standup, security alcoholic is there. He goes:
"2 people opened the malicious email"
I'm like dude. Nothing will fucking happen if you open the Gmail message We didn't DOWNLOAD anything or visit any URLs.
No. In the boomer mind, we were retards. We should be fired. We weren't, but we should have been. ???????
I'm like "GUYS" "I have some React components to make, what the fuck are you doing today?????"
There are so many instances I wish technology was removed from "the pedestal" and just treated how it is. What it actually is, there is no non-determinism we can prove everything. I don't care if that makes it $30/hr work at this point, I just can't handle the pretentiousness anymore especially around faux security
I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.
I had just started working there and found it in the first week.
Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.
Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).
-----
I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.