5 ms·
Here is the HN discussion on original accusations: https://news.ycombinator.com/item?id=38886915 https://news.ycombinator.com/item?id=38886915 Carta CEO's firs
by alsodumb 3y ago
Here is the HN discussion on original accusations: https://news.ycombinator.com/item?id=38886915 https://news.ycombinator.com/item?id=38886915
Carta CEO's first response saying it was a one time employee mistake that happened on Friday: https://x.com/henrysward/status/1743713154721554849?s=20 https://x.com/henrysward/status/1743713154721554849?s=20
Evidence by Karri that it happened well before Friday, and happened to multiple other companies too, questioning if it was indeed a one time incident: https://x.com/karrisaarinen/status/1743741496921383250?s=20 https://x.com/karrisaarinen/status/1743741496921383250?s=20
The linked tweet is Carta's CEO Henry Ward's comment ranting about how Karri should have reached out to them instead of publicly questioning the company, accusing him of using this incident to increase his twitter/linkedin exposure.
- alsodumb 3y agoHere is a detailed response from Karri about the call details: https://twitter.com/karrisaarinen/status/1743824345334714587 https://twitter.com/karrisaarinen/status/1743824345334714587 This particular detail stands out as to how the solicitation actually happened: "He (Carta's CEO) explains commonly Carta Marketplace looks for sellers and buyers in their platform who have opted in to it. But in this case the employee in question, again not employed by Carta but a separate business, Carta Marketplace, was able to access our cap table data by their “break the glass” system which requires approval to see customer data. He didn’t know how it was done, he offered that potentially the employee self approved the request. The employee in question was put on administrative leave." Lol, the employee (of technically a different business entity?) might have accessed the info through self approved request, but Carta's CEO is sure that this only happened this Friday to one company and is a one time incident. Yeah, I don't believe it.
- marcinzm 3y ago> “break the glass” system That begs the question, when is that system supposed to be used? In what sorts of situations would it be beneficial to Carta'a clients for another company (Carta Marketplace) to access their confidential information?
- mattzito 3y agoMy guess is that it’s a customer support system that has a mode where non-support agents like account managers can in emergencies access a companies carta account. Imagine a scenario where a founder is freaking out because it seems like the cap table in carta doesn’t match the spreadsheet they’ve been working on, and they’re in the middle of negotiating a funding. They might call their account manager in a panic asking for their help, and the AM might want to see their account setup so that they can more effectively communicate with support. Perfectly justified reason, and a reasonable feature. But I would bet that essentially everyone at “both” cartas who interact with founders or investors have access, and while theoretically every break glass is logged with a justification, and those justifications are audited, every single one says “helping company (company being accessed)”. That’s assuming anyone even looks at the audit trail (Narrator: they do not).
- deleted 3y ago[deleted]
- danielheath 3y agoHaving a “break glass” button is common for production access during an outage - the idea being that you should never touch prod manually (instead using code reviewed changes via normal deployment), except during incident response, where you can hit the button that lets you do so anyways.
- x0x0 3y agoI've built a break glass system. The trick is you need to actually audit the use. We reviewed every access, audited as part of our soc 2 commitments, at a +2 reporting level the next business day.
- gurchik 3y ago> After the call I’ve learned Henry has been trying to explain this as “isolated incident” over tier 1 VC email group and saying the only way this to happen is if the company has opted in to CartaX. How does Karri know this? Did someone in the email group tell him? Why would a VC leak information damaging to the company? And if this is true, isn't this an implication that Henry is lying to investors about the problem? Karri has already proven he hasn't opted in to CartaX.
- zht 3y agoSome VCs can be a very chatty bunch. Some very sensitive information and gossip can travel quite far across the VC community very quickly
- kevinmchugh 3y agoThey might still be annoyed with Ward after this incident: https://techcrunch.com/2023/10/25/cartas-ceo-reaches-out-to-customers-about-bad-press-alerting-them-to-bad-press/ https://techcrunch.com/2023/10/25/cartas-ceo-reaches-out-to-...