4 ms·
> What are we really expecting here? Perfection? No, I don't expect perfection. However, I do expect very careful implementation of access management for very
by throwawayjava 7y ago
> What are we really expecting here? Perfection?
No, I don't expect perfection. However, I do expect very careful implementation of access management for very large databases containing lots of PII and other sensitive customer information. Things like huge databases being accessible without credentials shouldn't require perfection on the part of some human. That sort of stuff should be continuously audited in an automated fashion.
But the software industry is quite bad, as a whole, so even the relatively competent actors make surprising, high-impact mistakes.
Maybe it's because the stakes are relatively low (c.f., bridge collapsing vs. PII leak) and the competition relatively fierce? Maybe software engineering is still very young and moving quickly?
In any case, I think it's totally reasonable to hold the opinion that MSFT is doing things pretty well relative to the rest of the industry and also that the industry as a whole is doing a pretty poor job.
IDK, for me the story has to be one of the following:
1. MSFT made a huge and inexcusable mistake, so maybe there's something systemically wrong with MSFT; or,
2. MSFT is very competent, and even very competent people are making very big mistakes, so maybe there's something systemically wrong with the entire industry.
- Tallasatree 7y agoArchitect here: from the outside looking in, you hit the nail on the head. In addition to The industry being so young the _relatively_ low-impact when bad things happen make things like this 'not a big deal'. When your mistakes result in a public outcry for a day, then fades into obscurity into the night, why change? why invest money into figuring out a better way? When your mistake makes a building fall over...well, there's a reason why that almost never happens.
- keithnz 7y agoI don't think this is quite right. Most buildings don't get all their design parameters tested in reality. But say when there is an earthquake, and the building collapses and you find that various checks and balances in the design process went wrong. I know here in NZ where we have had a number of significant earthquakes all kinds of known and unknown things have been discovered about buildings, either ones that have ended up killing people or ones which now are condemned because things played out differently than the designers thought they would
- Tallasatree 7y agoSpeaking about America, almost everything in a building beyond aesthetics is designed to a CODE MINIMUM. from the hangers that hang the ACT ceiling all the way, and especially to, the structural system. These systems have been designed and tested ad nauseam to provide minimum life safety standards. People in any industry can cut corners and screw up. Special situations can arise that surpass a minimum level standard (Fires started at every exit door, 9.0 earthquake...good luck) The forest you're missing through the trees here is the structured process that forces designers in a mature industry to design to a minimum agreed upon standard. Ironically, I'm highlighting the benefits of regulation...where it makes sense. the forest I might be missing through the trees is that maybe there is an industry agreed upon standard within the Tech industry. My understanding is almost all of these breaches happen because comically silly mistakes (pw = password), not super high sophisticated attacks.
- keithnz 7y agosame with NZ, which has pretty strict codes as we are sitting at the junction of 3 tectonic plates. Regulation including inspection is great, and generally works great, but until you get an earthquake, you really don't know if all the checks and ticking of boxes actually did its job. Microsoft and others likely catch multiple problems through checks, but occassionally a perfect storm happens and things break down. You then adjust your "regulations" to cover any short comings (hopefully). The entire planet you are missing through the forest is that all buildings aren't constantly "penetration" tested to find where they have problems. A quick search shows that USA suffers from many live deployed buildings that have been shown that they don't meet compliance. By Engineers that should've known better....
- deleted 7y ago[deleted]
- twodave 7y agoI can respect the sentiment, and I agree your points are reasonable. And I think the problem actually stems from software development culture more than anything. Developers don't want the level of oversight you're suggesting. Many would make career decisions in order to avoid that kind of babysitting. At the same time, the tech world is bigger than it used to be, the stakes are higher, and more is on the line than ever before. Mistakes are more costly (though in this particular case I don't think you could prove any real damages). And worst of all, the political world remains incredibly tech-illiterate. So, those in charge of guiding us in this realm are ill-equipped to do so. I don't have a good answer for this. In an ideal world I'd like businesses to take this sort of thing more seriously, but in reality I don't see any reason that they should.