• 3 Posts
  • 344 Comments
Joined 3 years ago
cake
Cake day: June 16th, 2023

help-circle
  • People can work around a horrifying amount of mess for a dizzying amount of time before it all comes crumbling down due the wrong thing occurring at the right time.


    All of these examples are from finance companies, mostly banks. Not all my stories, these include stuff from friends in the field.

    I know a place that had no documentation on access revocation for >30 third party systems.

    Another with no Identity and Access Management policy until the pandemic. Service accounts with god level access? Go ahead and set an 8 character password with no expiration date, and never change it after 20+ employees who know it leave.

    One place with software that sits installed on computers within reach of the public where every client copy includes a password decryption function in a file that you can copy out of the client install and then just call it from whatever program you write. Yeah, you still need read access to the user database’s password field, but this was software that employees used to interact with bank accounts. With trivially reversible decryption.

    That last software was slated to retire over a decade ago, and last I heard was being kept alive by the finance company paying for source code access and maintaining their own edited version themselves. The last time my friend talked about it a year or two ago, the software was just shedding its reliance on Internet Explorer and shifting to Edge.

    Some federal processes and laws still require fax communications for various financial shit behind the scenes.


    Do what you can to steer out and away, keep your hands off it/don’t perpetuate it, have a threshold for “fuck it, not my problem to fix”, have another threshold for “fuck it, let it burn or they won’t learn”, have a third for “fuck it, I’m running before this eats me”, and always always always cover your ass. In writing, hard copy somewhere you control and work doesn’t.

    Ultimately, remember that companies don’t reward heroics. Unless you can quantify your improvements in manager-speak, it won’t even register to them. They don’t give awards out for burning yourself alive to keep the engines running for another day. They give out penalties when your changes result in temporary setbacks during adjustments to the new normal.

    There are many, many, many people in management and elsewhere that do not learn until they’ve been bit in the ass (if they are capable of learning at all). If you eliminate the friction before they feel it, they won’t know you’ve done anything at all. You want to look good, that’s how you move up. Let some things fall. Let some things break, especially when you know the fix is relatively easy and no one wants to take responsibility to ok it before SHTF.


    A ton of this job is managing people, at least as much as it is managing complex systems. Not to be sociopathic, never forget the people are people, but start looking at corporate interactions and politics like you might look at a complicated system with no or little documentation.












  • Anarchist ones are also blacklisted in a lot of places.

    Nope, they’re actually some of the larger servers (which is still pretty small all things considered, lol).

    For lemmy, there’s the instance/server I’m commenting from: lemmy.dbzer0.com

    It was built by the former head mod db0 of reddit’s /r/piracy, so piracy discussion is cool here too. They’ve also made a decent bunch of software for lemmy servers, like a database/review system for lemmy instances, and a CSAM detection tool.

    The instance also tries to handle as many big instance/server decisions as they can democratically (donators/supporters and community members vouched for get to vote, and the rest of the server’s users act as tie-breaker).






  • Garry nuked the Facepunch forums

    How in the FUCK is this the first time I’m hearing about this? It’s been over a decade since I browsed them last, but those were a massively important component of the whole Garry’s Mod community.

    I think a big part of the failure, beyond the absolutely massive amount of mismanagement, is that a lot of the stuff that made GM awesome has had it’s “lunch ate” by other development engines and sandbox game systems. Facepunch was never going to be big enough to fully challenge Second Life, or Roblox, or Unity, etc. They had a niche that they should have focused on.

    On top of that, there’s a problem that commonly happens with games that have deep modding communities that get “sequels”: All of the awesome stuff that the community spent years building on the last game won’t work with the new one, so there’s not any real reason to switch until the amount of content in the new game (from the devs or the community) passes a critical threshold.

    And then changing the underlying creation tools so drastically from the last game by jumping from Lua to C#? Yeah, let’s just throw away most of the skills the community built up!

    What a shitshow.



  • YDI.

    Would have been better to post in an out of the loop community, because it definitely reads like shit-stirring. Especially “neo-nazi” admins of dbzer0. Like holy shit that’s so far off the mark I have trouble taking it in good faith.

    Anyway, I don’t have context about the world admin being a zionist or not. But this comment lays out the rest of the events pretty clearly.

    In short: an anarchist.nexus (piefed sister site to dbzer0 being on lemmy) admin set their display name to something intentionally shit stirring like “death to all zionists”. A lemmy.world admin took it personally for some reason, and instead of reaching out to other admins on anarchist.nexus or dbzer0, reporting it, publicly announcing what was going on, or even running it by the other lemmy.world admins first, they just decided on their own to defederate from anarchist.nexus entirely.

    As soon as dbzer0/anarchist.nexus admins learned what was going on, the admin with the shit stirring display name stepped down. Lemmy.world has refederated with anarchist.nexus, but the admin that took it personally is still holding onto the threat of defederating from them again.

    dbzer0 is currently gathering allies from smaller lemmy and piefed instances to agree to collectively defed from lemmy.world if they follow through on defederating anarchist.nexus again, because this should have been something discussed, not done in the dark at the whim of a single person.