3 ms·
The kind where they used Chrome to browse to an internal testing website? Though using a real website, like Google, instead of a mock is quite wtf. What I'm cur
by wmt 11y ago
The kind where they used Chrome to browse to an internal testing website? Though using a real website, like Google, instead of a mock is quite wtf. What I'm curious about is whether the fired* Symanted engineers were just scapegoats or had they actually been reckless and unprofessional.
* http://www.symantec.com/connect/blogs/tough-day-leaders http://www.symantec.com/connect/blogs/tough-day-leaders
- TD-Linux 11y agoLooks like that article got pulled?
- captn3m0 11y agoDisable HTTPS-Everywhere for the site if you have that installed. Took me quite a while to figure out.
- newjersey 11y agoWhy does the https redirect to http? Symantec can't afford to give itself a certificate? the java server pages application that serves the main site has extended validation https://www.symantec.com/index.jsp https://www.symantec.com/index.jsp but connect doesn't. It seems like https://www.symantec.com/connect/ https://www.symantec.com/connect/ redirects to http://www.symantec.com/connect/ http://www.symantec.com/connect/ r.port="https"===o[0]?"443":"80" Why can't Symantec afford to put ssl on its connect site? It is not like they have to pay anyone for a certificate...
- StavrosK 11y agoNot even that, the domain already has a certificate, they're forcing a redirect to HTTP on a domain that already has a certificate.
- Pyxl101 11y ago> In addition, we discovered that a few outstanding employees, who had successfully undergone our stringent on-boarding and security trainings, failed to follow our policies. Despite their best intentions, this failure to follow policies has led to their termination after a thoughtful review process. Because you rely on us to protect the digital world, we hold ourselves to a “no compromise” bar for such breaches. As a result, it was the only call we could make. > As much as we hate to lose valuable colleagues, we are the industry leader in online safety and security, and it is imperative that we maintain the absolute highest standards. At the end of day, we hang our hats on trust, and that trust is built by doing what we say we’re going to do. Wow. I have to say that I respect that decision. Without knowing the circumstances, I have to say that willful disregard for security policy while handling materials as sensitive as a CA cert is indeed not something I'd want to see from employees at a CA.
- deepdiver16 11y agoAgreed that the steps taken vis-a-vis these employees may have been the right one if they indeed breached company policy. But I do have an issue with publicizing this so openly, and using this to showoff of how serious "we" are. Even with the best intentions, you will run into bad apples. You still need to have the right controls, preferably automated, to avoid sensitive material to be used for internal purposes. Blogging on how they terminated employees doesn't help to showcase their leadership imho.
- sowbug 11y agoThere is no basis for respecting a decision stemming from a "no compromise" policy. Such a policy is designed to substitute mechanical action for judgment and discretion. Cf. the child-porn case also on the front page now (kid has picture of self on phone; https://news.ycombinator.com/item?id=10247764 https://news.ycombinator.com/item?id=10247764). It's probably also based on some kind of zero-tolerance policy or campaign promise. Had the announcement merely referred to the "thoughtful review process" (which is good) but not then nullified the meaning of that process with a thoughtless "no compromise" standard (which is silly), then it'd be at least eligible for respect.