5 ms·
I work at a games company, I get that hackers take up an enormous amount of developer work but reading this article made my jaw hit the floor. This couldn't hav
by aclelland 9y ago
I work at a games company, I get that hackers take up an enormous amount of developer work but reading this article made my jaw hit the floor. This couldn't have been a single developer making the decision. There must have been multiple levels of management involved and no-one saw the legal or moral issues?
To make matters worse, the additional statement at the bottom of the article they outright admit they used the tool and it wasn't a mistake:
>We found through the IP addresses tracked that the particular cracker had used Chrome to contact our servers so we decided to capture his information directly
- Y_Y 9y agoThey must have backtraced it. IP addresses ending in a 5 are chromes.
- deleted 9y ago[deleted]
- dx034 9y agoI think it's a small shop, probably only a few developers working there. That said, it's likely everyone knew about this. Not sure if that can get employees into trouble in case of a criminal investigation (installing malware on computers without the user's knowledge is likely illegal even if you don't use it).
- bjl 9y ago> Not sure if that can get employees into trouble in case of a criminal investigation Hopefully they can. We need to make it clear that 'just following orders' is no excuse for criminal behaviour.
- nugi 9y agoAbsolutely. 'Just following orders' is becoming a common excuse and it sickens me.
- IntronExon 9y agoSoftware need a governing body with professional standards (like the AMA) and it needs it yesterday.
- eberkund 9y agoWhat does this have to do with software? What about the executives and managers who gave the go-ahead on this?
- IntronExon 9y agoA professional standards body can reign in those excesses from the bottom up, just as it does for so many other fields of endeavor. The top is always going to demand what they can get away with.
- eberkund 9y agoHow so? Are you suggesting that the guys at the top are going to suddenly start caring about these things because there is a standards body that their employees belong to which says so? Or are you saying that the employees are going to refuse to do things that contradict code maintained by the standards body? Or are you saying that employers will care that a software developer doesn't belong to a standards body and won't hire those that aren't?
- IntronExon 9y agoHow so? Are you suggesting that the guys at the top are going to suddenly start caring about these things because there is a standards body that their employees belong to which says so? Or are you saying that the employees are going to refuse to do things that contradict code maintained by the standards body? The second, leading to the first, which then naturally leds to the third. The AMA, APA, and many others operate this way. Very effectively. Journals need to buy in, schools do, and eventually employers and licensing bodies. This is not really a new concept, just new for the increasingly unacceptable Wild West or software. Software is not a frontier anymore, it’s the biggest thing going, in our medical devices, cars, banks, etc. it is time to grow up.
- aerique 9y agoNevertheless a developer will be scapegoated.
- Kagerjay 9y agoThey probably think too highly of themselves and rationalized that two wrongs make a right (doing something bad is OK so long as its against bad people) passed down by upper management. At some point down the line, they probably figured they could just install in on all machines to save them some effort of having just 1 version of the software. But they've really dug themselves a hole though. Reading the article indicates this wasn't just a 1-off decision, but a multi-level decision made by several people over a long time frame. That all of this was premeditated and well thought out / given enough consideration to go ahead and install a backdoor on all their PCs. In any case, this is also why I don't save any passwords via chrome. Its not secure at all for storing passwords, so long as you have access to the localdb, you have a vulnerability.