3 ms·
> Last week, we let go of 5 teammates from our security organization, which stemmed from a different set of reasons from the ones guiding today’s decisions. The
by bArray 4y ago
> Last week, we let go of 5 teammates from our security organization, which stemmed from a different set of reasons from the ones guiding today’s decisions. The change last week was part of a longer-term strategy to continue distributing security responsibilities across our entire engineering team, bring new areas of expertise into Patreon internally, and continue partnering with external experts. Unfortunately, the change generated concern that we were reducing our security investment, but I wanted to make it clear, especially in light of today’s changes, that we are in fact increasing our investment in security.
This is interesting, and I'm not entirely convinced. It seems as though their security team was not warned and you would expect a handover process.
> The change last week was part of a longer-term strategy to continue distributing security responsibilities across our entire engineering team
> Unfortunately, the change generated concern that we were reducing our security investment, but I wanted to make it clear, especially in light of today’s changes, that we are in fact increasing our investment in security.
This doesn't sound like an increased investment, it sounds like a decreased investment. "Why are we paying these people when we can just get the normal engineers to do this?". Maybe this is possible, but who's going to allocate sprint time to work on background pentesting and documenting?
You may say "we will get an external team to do this", but will they get access to source code? Will they get access to upcoming features?
- jeremymcanally 4y agoI have no idea how their team was composed previously, but it could be that they had a lot of folks who were analysts but weren't contributing much to remediating issues. It sounds like (and I have no idea again) that they're hiring a small number of security engineers (maybe even one) to not only actively look for security issues, but to also actively work to remediate them and improve code security posture as well. This function paired with a specialized external team to handle general SOC/network level security probably is a smarter investment for them right now. > You may say "we will get an external team to do this", but will they get access to source code? Will they get access to upcoming features? Most likely yes in my experience.
- bArray 4y ago> but it could be that they had a lot of folks who were analysts but weren't contributing much to remediating issues. Neither feature testers (does it behave as expected) or security testers (is it secure as it does it) are expected to write fixes. Writing fixes needs to be planned in the sprint and is better worked on by an expert on that system. > they're hiring a small number of security engineers (maybe even one) to not only actively look for security issues, but to also actively work to remediate them and improve code security posture as well. If this is true, it could seriously affect their ability to ensure the system remains secure. Sometimes a security issue will take a long time to hunt down, and perhaps require a large rewrite to deal with it. Whilst this person is dealing with this, they are no longer looking for new issues. I'm just not sold this is anything but a cost cutting exercise, and could (theoretically) lead to bad practices in the future.
- jeremymcanally 4y ago> Neither feature testers (does it behave as expected) or security testers (is it secure as it does it) are expected to write fixes. Writing fixes needs to be planned in the sprint and is better worked on by an expert on that system. ...on teams that are structured that way. That is far from a universal thing. But, yes, I'm with you that it could be just cost cutting or something weird with the team pushing back on some things. As I said, I have no idea, but there are universes where it makes sense to make those changes.
- dehrmann 4y agoWhy would you not wait a week and bundle these layoffs together? Unless the security decision came from a mid-level manager who didn't know this was coming.
- bArray 4y agoExactly. And why would it be so sudden? It's just not adding up.