HN user

parkerhiggins

87 karma

meet.hn/city/us-Salt-Lake-City

Posts1
Comments51
View on HN
BeyondCorp (2014) 2 years ago

It is and today, it’s relatively straight-forward to implement. Get a good Zero Trust vendor.

I've found that there isn't a lot of discussion or research around this subject. Shoutout to engprax, a compliance company, for clearly approaching the issue.

Is it actually an issue though? Software engineers by design (?) are not capital "P" professionals. There's no certification or board underwriting our work. Software engineering/developers have had the latitude to "move fast" and represent the only "professional" trade that has the ability to "try again" (with a deployment) versus a structural engineer for example.

Dr Junade Ali CEng FIET, the Principal Investigator of the study, said: “Recent developments demonstrate the fundamental importance of software engineers being free to raise the alarm when they become aware of potential wrongdoing; unfortunately our research has highlighted that software engineers are not sufficiently protected when they need to do so. From software engineers facing mass retaliation for speaking up and banned gagging clauses still being used, to ‘industry-standard’ software development metrics not considering the public’s risk appetite; this investigation has highlighted systematic and profound issues with society-wide impact, given how integral computers are to all our lives.

With the ubiquitous nature of software in modern society are we at the point were we need certification? The development and certification of "industry-standards"? This theme, balancing innovation with responsibility, is throughout the the Biden Administration's Executive Order on the Safe, Secure, Trustworthy Development and Use of Artificial Intelligence (Order).

Who is really responsible though? The developers who wrote the code? Or the executive who ordered the change?

There's are plenty of examples of this in recent history. Where engineers/developers released code they knew was harmful/fraudulent but did so anyway under fear of retaliation.

FTX (Nishad Singh) https://www.reuters.com/technology/how-secret-software-chang...

Pollen https://blog.pragmaticengineer.com/pollen/#:~:text=Later%2C%....

I wonder where this is going to go.

I agree, the author is conflating the ability to report and block a user due to their content and the ability to report specific content of that user.

All they had to do is add a link to report the specific contentId that user created.

The author was blinded by frustration and didn’t read.

Not a silly ask. I’ve seen B2B Success Teams be very successful setting up a private channel for clients and using Atlassian Assist.

This feature isn’t marketed by Atlassian. It Jira Service Desk provides the “backend” to the support experience, providing private comments, threads, the ability to merge multiple conversations that pop up in Slack, and link up support requests to active development in Jira.

The only downside is I believe JSM is limited to 5000 external users. Not a huge issue for B2B Success. Considering a external user is only created when a support request via the :ticket: emoji is used.

This cause exists not for product testing and QA but rather to prevent payment details for being abused in the name of “testing”.

Everyone runs 1-3 “real transactions” as a “real customer” when getting ready for a launch with QA.

This cause exists for Stripe to point to for excuses people make when attempting to wash transaction or test stolen CC info in a prod environment (which doesn’t work with a test api key)

.gov/anime 4 years ago

Not the OP, but xor is a doppelgänger of mine. We met in person decades ago. xor is always poking around the internet finding interesting stuff.

It's an interesting search pattern. I would be interested to see other kind of "topic/domain" searching done across all .gov properties.