3 ms·
I made the same seat belt point to him, and here's the section with his response: > I do have concerns when 10gen explicitly targets junior developers ... What
by nemild 8y ago
I made the same seat belt point to him, and here's the section with his response:
> I do have concerns when 10gen explicitly targets junior developers ... What [Eliot, MongoDB CTO] says makes sense say 20 years ago, but with 25% of new software engineers coming from coding bootcamps with non-engineering backgrounds, I worry that defaults matter ever more in dev tools (and even seasoned engineers may mess this up, if they’re coming from a database with different defaults). We discussed analogies like seat belt lights versus the responsibility of passengers to know better. He also argued that waiting to get all this right - not just auth - would impact database innovation, while I think there’s a balance that gets us a lot of the low hanging fruit (like security).
https://news.ycombinator.com/item?id=14804765 https://news.ycombinator.com/item?id=14804765
- acdha 8y ago> with 25% of new software engineers coming from coding bootcamps with non-engineering backgrounds This is unnecessarily elitist: I’ve seen no difference in security awareness based on anything other than specializing in security, and even then it can be surprisingly blinkered.
- nemild 8y agoThat's fair. I was mostly reflecting on the time that most bootcamps spend on a student (2-3 months) relative to other programs. But I agree that no matter the program, security best practices are rarely taught.
- acdha 8y agoAgreed — I often feel like we’re in the period where the germ theory of disease is known but it’s still a battle to get doctors to wash their hands.
- hinkley 8y agoMy position, which I'm starting to get loud about, is that defaults matter more because the most recent shift in developer 'standards', for better or worse, is to expect us to use a vast number of tools to do our work. If I have to use a vast number of tools, not only can't I be an expert in all of them, I can't even dedicate 5% of my attention to each one of them. Or really, to any of them. Because if I do, then I have nothing left to fulfill my job description. I'd just be curating a list of third party code all day long. We either need to back away from the 'npm install' model or we need to really start thinking about our libraries as cattle. Which means they all have to behave in a predictable fashion or we cull them from the herd. You can't have it both ways. We can't use peer pressure to stop people from writing their own (NIH), and then blame the victim when tools behave in surprising ways. The safeties need to be on by default, and only a few things in our lives can be so dangerous that we require special training to use them without killing ourselves. We only have space for a handful. We need to develop the humility to accept that our module should be boring to the people using it, rather than a special snowflake. Take pride in the utility, not the notoriety.