6 ms·
I'm in engineering of a financial services. When we built our front-end UI for eKYC our marketing requested for google tag manager / facebook pixel and various
by artellectual 6y ago
I'm in engineering of a financial services. When we built our front-end UI for eKYC our marketing requested for google tag manager / facebook pixel and various other tracking features to be built.
I had to fight hard as an engineer to make sure that it does not happen. We had meetings after meetings, and it took a lot of effort for me to explain the risk of data leakage. I was questioned on my "insecurity" for not "trusting" people. It was not a nice experience. I had to inform them that tracking needs to be dealt with properly, not just lazily install google tag manager because it gives marketing 'flexibility'.
- 0xy 6y agoNever ever give marketing access to deploy arbitrary JS onto your website under any circumstances. Google Tag Manager is an absolute cancer on web development. Once it's in, you'll never get rid of it.
- artellectual 6y agoAgreed!
- Natsu 6y agoThe only thing I knew about 'tag manager' before this was that it was always blocked by NoScript. Your comment made me go look up what it does and now I know that I will never unblock it. Apparently it lets people drop in random code from a bunch of different analytics platforms, so it's pretty much guaranteed to consist entirely of the sort of stuff I have NoScript enabled to block in the first place.
- 0xy 6y agoI've seen GTM take down production multiple times because of marketing shipping random JS with no approvals. Some random guy in his basement assured someone in marketing they could handle our volume? Chuck their tag in and watch their website get DDoS'ed with millions of requests per minute, which takes out our website because marketing made it fail loudly.
- aembleton 6y agoI'm surprised that GTM doesn't handle that. They would have a good idea of how long requests are taking to different domains and limit requests to the slower ones.
- at_a_remove 6y agoI mean, yes, true, but it kind of misses the point: marketing doesn't ask you, they ask up. And we're just the BOFH pinheads who make everything so harrrrrd with our stupid "concerns." IT can often be "we make someone else's bad idea happen," and that's because we simply lack veto power.
- rodgerd 6y agoI'm surprised and disappointed that you didn't have your InfoSec and risk people in your corner.
- artellectual 6y agoThe reason for that is I'm the CTO, responsible for building out the tech / engineering team. Hiring people is difficult as there is lack of supply of talented people. We hire InfoSec on contract basis not full-time and they don't join such meetings due to the nature of the contract. So all the responsibility fell on me to defend our technical decisions at that point in time. I'm working on building out the engineering culture / awareness within management now, to ensure these things do not happen, and I don't have to be questioned as to why we cannot install "google tag manager" in our front-end. It all comes down to creating awareness, and making people understand. Fortunately for me our CEO gets it, he ended up siding with me.
- ahmedfromtunis 6y agoHonest question: how can a financial services company not have an in-house infoSec team? To me, this is an even more concerning issue. But then, I have no idea how the finance services world works, so maybe this is more common than I think?
- Narkov 6y agoFinTech doesn't always mean global mega bank. There's lots of small scale start-ups that fit into the financial services category that wouldn't/couldn't afford full time InfoSec roles. Outsourced CISO/InfoSec is a valid and reasonable thing for some companies.
- deleted 6y ago[deleted]
- yellowapple 6y agoI feel like a small scale startup needs internal infosec and audit teams even more. Unlike the incumbents, who are "too big to fail" and therefore are able to get away with blatant insecurity, a startup's in a much more vulnerable position, and any security breach is significantly riskier in terms of corporate longevity. If I was running a financial services startup, those groups would be near the front of my list in terms of internal hiring.
- xfz 6y ago> I was questioned on my "insecurity" for not "trusting" people. Personal attacks for doing your job? If you're still there, the stock options had better be enormous!
- mitchdaily 6y agoThat's par for the course for technically orientated roles. I was labelled 'defensive' and denied a pay increase because a business development executive wanted to make our documentation dynamic based on user access, and I pointed out it was difficult to find a solution when users can have over 400 access permissions, which varied depending on country, and our documentation was 900 HTML pages, some of which were equavlent to 200 A4 pages. If you are the most knowledgeable person then you get blamed for their bullshit fantasies being impossible or unwise (or illegal)
- drevil-v2 6y agoI’m going through the same dance at my company. Could you post the arguments that you made against GTM? It would help a lot. Thanks
- artellectual 6y agoSure, in the end I asked our head of compliance to join the meeting. I made it very clear to everyone what was at stake, and that I’ve done my duty in raising awareness. If they would like to proceed I hold 0 responsibility. Usually when you do it like that no one wants to put their neck on the line. Our head of compliance take this stuff really seriously as he has to report to central bank, so him and our CEO ended up agreeing to not use GTM. You really need to present well and be careful about arguments like “millions of websites use GTM”. I did days of research and presented that while yes using GTM on Wordpress sites that hold no sensitive data might be fine however we are a financial services and we collect customer private data. So getting everyone on the same page and presenting alternative ways of solving the problem was critical.
- newscracker 6y agoThanks for this comment. It would be quite useful to read a more detailed write up extending from your second paragraph here.
- fencepost 6y agoI was questioned on my "insecurity" for not "trusting" people. "I trust people just fine. I trust people working for outside companies dependent on information gathering to gather information. Google has no fiduciary duty to our clients. Same with Facebook. We DO have a fiduciary duty to our clients and it includes not doing things that may send their confidential information to third parties because SOME of the information used may be useful to our marketing department."