logoalt Hacker News

purplemoonxyesterday at 2:31 PM6 repliesview on HN

It's hilarious how these companies handle security breaches.

I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.

I had just started working there and found it in the first week.

Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.

Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).

-----

I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.


Replies

jjiceyesterday at 2:51 PM

I was at a much smaller YC company when I found that AWS root credentials were checked into the repo, purely for S3 file uploads for logos. When other engineers and I brought it to the CEO (he required infrastructure stuff get brought up to him first), he handled it with zero urgency and didn't see why it was a big deal.

I explained to him how the EC2 instances would assume the role that already had the permission and it took so long to convince him.

Needless to say, we had to explain lots of basic security and networking concepts to him, which he wouldn't believe until given live demos of basic things like public versus private IP addresses in AWS.

show 1 reply
suzzer99yesterday at 3:28 PM

At a few companies I've worked at, they squelch this kind of bug/security breach reporting by immediately making it the discoverer's job to fix the problem and champion it through the system to production, taking on all responsibility if something breaks of course. You only have to go through that once to get the message.

show 1 reply
mettamageyesterday at 5:05 PM

Many SWE teams don't care about security. Even talking about security annoys them. I get it though. I've had offensive security training at uni (VUSEC Amsterdam). It's a way different type of thinking.

show 1 reply
ThrowawayTestryesterday at 3:03 PM

More proof that software engineering isn't real engineering. If a civil engineer made a mistake that bad in my country, he'd likely lose his engineering licence.

show 6 replies
mschuster91yesterday at 2:38 PM

> I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.

The main problem is that the IT industry for a loooooooong time "self-regulated" itself, the only areas that did have regulation had it come in externally (i.e. automotive, aeronautic, astronauts and maritime). Only in the last years, GDPR + insurances forced a bit of change and accountability, but still, it's far removed from the standards that company owners, workers and planners are held to in construction (licensed engineers), legal or medical practice. Mess up there and everything can happen from fines over a license suspension to a permanent removal, or even jail time.

In contrast, mess stuff up as a CTO and you'll probably be "asked" to voluntarily depart in exchange for a nice golden parachute.

show 1 reply
tonyhart7yesterday at 4:01 PM

unfortunately, that just how organization was