5 ms·
> "The fact that they are persisting the key just for the password hint functionality is compromising the security of that product completely." Ugh. How this g
by nmjohn 12y ago
> "The fact that they are persisting the key just for the password hint functionality is compromising the security of that product completely."
Ugh. How this gets through the hands of so many talented engineers boggles my mind. It's easy to just blame the project managers, but at some point don't we have a responsibility to say no, this is a terrible idea and completely compromises the premise of the product?
- nine_k 12y agoSaying a definite 'no' in Korean culture is often hard (as is saying a definite 'yes'). Saying a firm 'no' to your boss, which would make him say a firm 'no' to his boss, is harder still. /* Include a typical "that's why such things should be open-source" essay here. */
- PakG1 12y agoI attended a session at Simon Fraser University once earlier this year, hosted by Samsung. Those guys, including a product guy, made it pretty clear that the development work happened in their Greater Vancouver R&D lab, not in Korea. So....
- lockes5hadow 12y agoKorean culture could be heavily embedded in their Vancouver office.
- milkshakes 12y agoit certainly is in their san jose "research and development center"
- Loopsnut 12y agoYou would appear to be at least partially correct: http://www.techvibes.com/job/vancouver/company/samsung http://www.techvibes.com/job/vancouver/company/samsung
- deleted 12y ago[deleted]
- hiou 12y agoI work in the US and I can't remember working with someone from Korea or of Korean decent. I have had at least a handful of times where I was the only who spoke up about how irresponsible something was. I have yet to see another US developer speak up about the ethics of something like this. Actually, much worse stuff than this. Not once. I'm not sure this is a Korean problem.
- on_and_off 12y agoI routinely see dumb ass decisions that totally ignore design/UX/technical principles imposed by the product manager while most of the company are against them. It weakens the product first because they are bad decisions and secondly by having us spend time implementing them instead of actually improving it. Thankfully I have not yet encountered decisions like this where the user personal informations are affected but I can totally relate to this kind of situation..
- higherpurpose 12y agoForget about Samsung's software engineers - they've proven how "talented" they are one time too many already - but what about NSA? They've just approved Samsung's Knox devices for classified information. Unless of course they want these devices to be vulnerable to bugs only "they" know about (at least until today). http://www.pcworld.com/article/2836612/samsung-knox-devices-approved-for-government-use-by-nsa.html http://www.pcworld.com/article/2836612/samsung-knox-devices-...
- Tloewald 12y agoPerhaps the NSA hopes everyone else will use it (and not, say a stock Android phone or an iPhone).
- andrewfong 12y agoI question how talented the actual engineers are. I doubt there's some project manager insisting upon some particular implementation of a password hint function. More likely is that they're relying on some freshly minted CS grad with no experience who doesn't grok how hard crypto is.
- truncate 12y agoThis is actually true I think. One of my high school classmate graduated in EE or EC with no CS background/courses and much interest or knowledge in CS worked in Knox right after college. Of course, I can't generalize based on just one case, but it does make me skeptical about the product.
- hawleyal 12y agoAccepts no responsibility, gets paid, goes home.