5 ms·
> After requesting the SU password, they were told flat out > it doesn’t exist and referred to the manual by the vendor. This kind of flat out lying happens a
by bArray 6y ago
> After requesting the SU password, they were told flat out
> it doesn’t exist and referred to the manual by the vendor.
This kind of flat out lying happens a lot. I suspect some of it is that the customer service teams have zero to no interaction with the developers, so if it's not written down it doesn't exist.
I think this is a good argument for developers spending at least some time working on customer service per week (even just a few hours). You could escalate queries such as this one to a developer, where clearly somebody is asking a more technical question.
Before anybody says "that's unrealistic, they don't have time" - first consider the amount of ridiculous meetings a developer will normally find themselves in, or how long they spend answering emails every day.
Of course, it doesn't mean that such a password would be given away, but at the very least it could start an internal discussion about it's existence. Having a single shared super-password is a problem waiting to happen.
Regarding the point with small firmware-based devices and security (i.e. IoT), I believe the practice is changing where each device will have entirely unique credentials (something that's relatively easy to do these days).
- m463 6y ago> I believe the practice is changing where each device will have entirely unique credentials I believe some regulations require unique credentials and this goes against that.
- bArray 6y agoGreat to hear regulations moving in this direction, security shouldn't be optional for such devices! I guess in the future we'll see this even effect SMBs like the Raspberry Pi... I guess they will need some new methods for such devices to store a default password independent of the flashed OS?
- m463 6y agoI don't think the raspberry pi qualifies as an iot device. It has no built-in storage and you cannot remotely access raspbian unless you modify the image to write 'ssh' in the root folder. (I don't think pxe qualifies either)
- youngtaff 6y agoSome versions of the Compute Module have built in storage but as it's user programmable think your point still applies
- pabs3 6y agoRequiring unique credentials often leads to hardcoded but predictable credentials derived from the MAC address or some other public information about the device. I like the way the Turris Omnia does it, on first boot you get to set a password and there is a password strength meter.
- denkmoon 6y agoHaving devs on level 1 support is a good way to have high turnover imo. The support process should have a way of escalating to developers though. I've found plenty of bugs in products and had no way to get in contact with someone that would actually be interested in hearing it.
- hn_throwaway_99 6y ago> Having devs on level 1 support is a good way to have high turnover imo. I pretty much agree with rblatz comment. From my opinion it's a good way to have high turnover of people I don't want on my team anyway. Note I don't think developers are bad if they don't want to do customer support, but I am particularly interested in hiring product focused developers. That is, developers who really care not just about difficult technical problems, but who care about how solving those problems actually affect the customers for whom we're building the product. I have found that, on the contrary, product-focused developers love doing customer support (some small portion of the time). They like to see how their features and fixes affect the customer experience, and they get a kick out of fixing small annoyances that overall build a more polished product, but might get just "triaged away" if it went through multiple levels of CS -> product manager -> engineers.
- msh 6y agoI have worked support part time during my studies and I think it can be a good thing having developers do support but some developers do not have the "people" skills to do proper support but are still good developers who care about customer experience. Another options is to have them sit with customer support and listening to their phone calls with them. It might also be that while the developers might not be skilled enought in the problem domain to provide general support as many questions might be more general.
- hn_throwaway_99 6y agoFor many companies that have moved to primarily a chat-based first-line support model (e.g Intercom, Help Scout), this can help a lot with this concern. Many engineers don't like talking on the phone but IMing with a customer in real time is fine.
- reaperducer 6y agoI think this is a good argument for developers spending at least some time working on customer service My company does this. (Or at least, did before the pandemic.) My job is to build web sites. My company is in healthcare. that means this web dev has been literally hands-on with actual customers. Actual patients. And their children. It really changes your view once you're back in the office in front of a keyboard. You start to think about what you design and build in a different way. You start to remember that the people using your web site aren't on the latest whiz-bank iPhone 16. They're on a craptastic pre-paid piece of garbage that they bought at 7-Eleven and share with other members of their family. A phone you and I would use as a weekend burner is all the internet access some people will ever have.
- foepys 6y agoIt's very important not step outside the ivory tower regularly or else one loses touch with non-IT people. The way something is design and how it's used can differ extremely. My company is selling software for industry automation and the people using it often enough don't even have a PC at home. They learned using a PC at work and anything happening that isn't part of their trained workflow (sometimes even a simple additional optional input field) overwhelms them. Getting to know customers is very, very important for developers.
- gigatexal 6y ago“ My job is to build web sites. My company is in healthcare. that means this web dev has been literally hands-on with actual customers. Actual patients. And their children. It really changes your view once you're back in the office in front of a keyboard. You start to think about what you design and build in a different way. You start to remember that the people using your web site aren't on the latest whiz-bank iPhone 16. They're on a craptastic pre-paid piece of garbage that they bought at 7-Eleven and share with other members of their family. A phone you and I would use as a weekend burner is all the internet access some people will ever have.” That perspective must be awesome in every aspect of the word: hope inducing and inspiring but also instilling a bit of fear in that real people, possibly sick or terminal people, will be using your work. I guess this is the mantle of “mission critical”.
- 6y ago
- randmeerkat 6y agoI’m sure there was at least one engineer that was like this is a bad idea and everyone laughed at them. Having a discussion about bad security practices doesn’t change anything. Companies just don’t care about security. It’s why we see major companies hacked time and time again. Even if the team agreed it was an issue, a project manager is never going prioritize security work over new features.
- bsnetworkinst 6y agoTp-link enables Telenet by default and cannot be disabled in the newer routers at least in their firmware - https://community.tp-link.com/en/home/forum/topic/166016 https://community.tp-link.com/en/home/forum/topic/166016.
- gumby 6y ago> I think this is a good argument for developers spending at least some time working on customer service per week I don't know about "per week" but definitely from time to time. I've run some B2B companies selling to the enterprise and always had each member of the exec team come along on a sales call every quarter (obviously different calls!). This has been especially valuable for the CFO, the most inward-facing of executives. It's surprisingly common for the CFO not to really know what the product is beyond what's in the company's own sales literature and what comes through by what's discussed on the P/L. Very enlightening.
- ajdegol 6y ago> I think this is a good argument for developers spending at least some time working on customer service per week (even just a few hours). This is always a good idea; it fosters better teamwork throughout the organisation and makes the abstract work we do more concrete. The last time I did this I remember asking the person if the page load (on the internal system) was always so slow, they replied "yes" - next hackday I optimised it by a factor of 100. That's not something ops people will generally even know to ask for, but when they're dealing with a high call volume, that speed up is like an extra person.
- baybal2 6y ago> I believe the practice is changing where each device will have entirely unique credentials (something that's relatively easy to do these days). Not so easy at all. I still see cheapest netdevs with same hardcoded, or random MAC addresses. Cheapest devices are made with exactly zero per-device interactions/customisation. They are made to fly out from highly automated manufacturing lines like bullets from a machine gun.