4 ms·
I work for a company like this right now. About the same number of employees, same mistakes and same time to market on innovative stuff. Here's my two cents on
by donkeyd 3y ago
I work for a company like this right now. About the same number of employees, same mistakes and same time to market on innovative stuff. Here's my two cents on how this can happen:
> Which product manager in his/her right mind
There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more.
> How do these managers get jobs in these big name companies?
Because they talk well and they've delivered before. Have they delivered something good and secure? Nobody cares, deadlines were met and functionality was shipped.
I notice the same in IT sales. Sell too much for too little, collect bonus and move on. Nobody comes back to you if the project fails or becomes too expensive and if they do, you blame the one engineer you had glance over the proposal before sending it to the client.
> It's the best way to uncover shoddy dev and security practices
As a project manager, that's the last thing you want. First, it'll show what you didn't manage well. Secondly, it costs money. Finally, negative findings will delay delivery and means you failed to deliver on time, which is your only priority.
Maybe I sound overly cynical, but I've seen this exact thing happen everywhere, from small firms to Fortune 500 to government.
- FirmwareBurner 3y ago>As a project manager, that's the last thing you want. First, it'll show what you didn't manage well. Secondly, it costs money. Finally, negative findings will delay delivery and means you failed to deliver on time, which is your only priority. And yet FAANGMAULs and other tech-first companies like Mozilla, seem to be doing quite well on security with relatively very few oversights, caused by dev gross negligence. So it's definetly possible to deliver airtight products if that's your goal and part of your dev culture, instead of just "ship it by Christmas at any cost".
- Schiendelman 3y agoSure, they have product managers.
- ziddoap 3y agoIt's too early to play guess the acronym for me. What is the MAUL part of your FAANGMAUL acronym.
- james-skemp 3y agoMicrosoft, Uber, Lyft, and AirBnB is what I eventually found. FAANGMULA in the above case.
- hbn 3y agoWhy are Uber, Lyft, and AirBnB being added only now, after their infinite-VC-money heyday is drying up, and when the general public is starting to hate them and are returning to taxis and hotels?
- trantrungtin 3y agoMicrosoft, Airbnb, Uber, Lyft. When will we stop adding companies' acronyms?
- karmakaze 3y agoI'll stick with the ~1T market cap software/service ones: Facebook, Apple, Amazon, Microsoft, Google/Alphabet: FAAMG; But in discussions I'll include any company that has similar tech/business requirements or behavior.
- _jcrossley 3y agoI think I’ve heard MAGMA for this :)
- karmakaze 3y agoIf we're using (M)eta for FB, shouldn't we use (A)lphabet rather than G? MAAMA
- camgunz 3y ago
- kasey_junk 3y agoThose companies spend a bananas amount of money on security and pay a huge price in delivery times. They can afford to. New enterprises can’t. And if you go back to those companies growth phases you’ll see security decisions that seem bananas now.
- pas 3y agoWhat? Mozilla basically abandoned Servo, because of costs. And spent some money on CEO pay and on ridiculous preach-to-the-choir outreach campaigns and whatnot. And they regularly say no to security features. (eg. TLSA/DANE support https://bugzilla.mozilla.org/show_bug.cgi?id=672600 https://bugzilla.mozilla.org/show_bug.cgi?id=672600 )
- figassis 3y agoAt some point their engineers are just better. I've been part of teams where every one was highly skilled, maybe a few juniors. And teams where everyone was junior and because they were very skilled on one specific thing, they assumed they were senior. The difference in those teams are that skilled engineers: - Code review holistically bc they understand that part of the codebase, and other parts it interacts with, and they ask thoughtful questions. So things like logging sensitive info in plain text are not even a question. - They understand how multiple components of a system work, like the tcp/ip stack, http, and other parts. Specifically not just how they eg. send messages, but how connections are setup/managed/torn down. Often that's where the security issues are (like which parts of a connection are insecure and when/how the upgrade happens). - They have this deep understanding because they put effort and time to diagnose issues that happen do them and enjoy sharing. Unskilled devs just say "it's not working, someone else fix it please". I had a mobile dev once lose his mind because he was unable to upload a file to the api. Turned out his app was using a library that was messing up the multipart upload boundaries and content length headers (tracked it to a bug with multiple gh issues). He was unable to use this info to proceed. - Participate in the hiring process, for they're a good filter for the company - They abstract away a lot of the implementation details from product managers and eat a lot of the complexity to the point that the product manager only sees 60% or less of the actual work in Jira. - A security autidor would need to really be worth his pay to find vulnerabilities, scanning for OWASP top 10 is not enough. Note, these engineers do not need to be 10x, they just need to...be engineers. Companies like Sunbird would not know how to tell one from the other, and product managers don't know what a secure app looks like. They could actually add that as a requirement and not know how to verify it. Often it's the developers that tell QA how to verify something. If your engineers are crap, you end up with apps like Nothing Chat. They aren't to blame, the company had no standards to begin with.
- macNchz 3y ago> There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more. A glance at LinkedIn suggests you’re correct: the Sunbird app team seems to include a bunch of business people, a project manager, and no software engineers.
- FirmwareBurner 3y agoSounds like the usual scammy juicero-like vaporware unicorns: 1. Pitch some grandiose idea to clueless execs 2. win over big money contracts 3. farm out the actual work to the cheapest body-shop and pocket the rest
- jjav 3y ago> Because they talk well and they've delivered before. Have they delivered something good and secure? Nobody cares, deadlines were met and functionality was shipped. This is exactly it. These product managers are judged on delivering on time, delivering UI glitz and UI functionality. Rarely anything else. Actual product security is not even in the top-25 factors they are rated on. One of these PMs once told me "We will put up some text on our website stating how we are extremely secure against all including nation state attackers, and that's the extent we're investing in security. We will not invest any time in implementation work related to this." Eventually we did get this PM removed, but about a year of damage was done. (LinkedIn tells me this PM is now at a FAANG) This is why I assert that silicon valley was ruined by the rise of the PMs. In the 90s I had never met a PM, now I can't throw a twinkie in any direction without hitting at least three.