5 ms·
I don’t think the issue they worked on adult sites. I think the issue is they worked on AdultFriendFinder, who basically didn’t care about user privacy.
by saber6 7y ago
I don’t think the issue they worked on adult sites. I think the issue is they worked on AdultFriendFinder, who basically didn’t care about user privacy.
- dkdk8283 7y agoHaving previously been in the adult biz it is now considered a black mark on your resume. It was all mostly black hat work at one point or another.
- latchkey 7y agoThat is a load a bs. If anything, it has been enabling for me. Any business that wouldn't want to hire me based on the incredible scalability experience I gained from working on a super high traffic/revenue project, isn't a company I would want to work for anyway. Nothing I did was black hat.
- dkdk8283 7y agoI was in the business pre-tube. I learned a lot too. It’s probably very different now but affiliate shaving, spamming, cpc fraud were all ubiquitous in the late 90s/early 2000s.
- latchkey 7y agoMay 2006 - April 2010 Yes, we had to deal with all of that as well. Also built a lot of automated tools to deal with those sorts of things. My favorite one, I named 'the cockblocker'. ;-) This sort of experience you just can't get elsewhere and has been extremely valuable for me.
- komali2 7y agoThat sounds crazy to me. I'd be much more interested in a conversation with a devops engineer from pornhub than one from YouTube.
- dkdk8283 7y agoI was in web hosting, we hosted over 120k sites at our peak. Rent a /21 for a week? No problem. Interesting times for sure.
- dmix 7y agoI still think that's a silly reason not to hire their programmers, unless they played a role in creating weak security. Security is often a whole company exercise that needs to be prioritized by management, putting blame on some individual programmers seems to show a lack of understanding of how infosec works.
- aguyfromnb 7y ago>needs to be prioritized by management If the attitude of these engineers is "we don't emphasize security unless management tells us to" maybe they don't deserve to be hired elsewhere? Management are not omniscient; they depend on their staff.
- sillysaurusx 7y agoYeah, that's not how infosec works. You've almost certainly written code that has exposed user information (unless you've written no user-facing code). Are you, as an engineer, going to organize a pentest for the software? Even if you encourage management to do so, it's still up to management to actually book the deal.
- aguyfromnb 7y ago>Are you, as an engineer, going to organize a pentest for the software? Are you, as an engineer, going to sit back and watch the project you built (containing very personal information in this case) get compromised? Even if you know management isn't paying proper attention? See, that's the problem with every developer in Silicon Valley calling themselves an "engineer"; they want the title without the obligations that a professional engineer has. "Not my problem" would cost you your designation.
- _jal 7y ago> Are you, [...] going to sit back and watch the project you built get compromised? How does this work? Do you rip off your glasses, strike a manly pose and run for the data center, stopping only to force the infra team to give you the credentials? More seriously... Organize your own IR tiger team outside of management channels? Congrats, you're unemployed tomorrow, together with anyone silly enough to buy in. Start making rogue code changes you think are appropriate? That would run in to "want[ing] the title without the obligations". Oh, and also probably end up with you unemployed. So, really, what are you proposing?