Rendered at 14:58:44 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
moribvndvs 21 hours ago [-]
I’d like to see these comments copied over to the “reason for termination” field in their personnel file.
ryandrake 20 hours ago [-]
They'll be copy/pasted into their promotion and bonus letters instead.
cyanydeez 19 hours ago [-]
Culpability for police see also.
...
LMAO
cdrnsf 18 hours ago [-]
[flagged]
tangotaylor 19 hours ago [-]
And this is why I donate monthly to EFF. Nice find.
jauntywundrkind 19 hours ago [-]
This is why police unions are starting to talk about shutting down Flock: because it's a hazard to police. Because the normalized abuse of power that pervades policing is actually visible here.
sublinear 17 hours ago [-]
I agree that it is to some extent about optics for the cops, but access controls and properly scoped authorization are always problems everywhere in software.
That's not to say we should let any of this slide, but that we should realize it is time we take this aspect of security more seriously. We are living in that future now. Yes, your shitty janky auth scheme is causing real problems right now and yes it sometimes is life or death.
We're missing an entire category of software that manages permissions in more dynamic ways... Meanwhile, about a third of devs out there don't even know or care about the difference between authn and authz.
jauntywundrkind 8 hours ago [-]
certainly something we've seen an epic-facepalm on with the huggingface hack. oh your mongo all just uses one static username/password. oh your cross-cluster connection is all one password.
reciprocally though i think the top down securitization of systems with only proper access control has taken out a lot of the grease that used to greatly ease how companies related to the world in really good ways. even when you do get through to support on the phone, there's often such a grim expectation that they will be in no way able to help you, that they don't really have access to information or corporate processes that are going to do anything for you.
we (engineers) look at defined behavior & constraints as secure, safe, good. but i think the informal processes and laxity from the pre-coded world allowed companies to better actually help people and to be good, in important ways. we have to recognize that mechanization is not always a good force too, while also starting to take more seriously too that we often do need more oversight/guards/access-control too. it's paradox, it's duality, but we have to recognize both ends as dangerous.
LMAO
That's not to say we should let any of this slide, but that we should realize it is time we take this aspect of security more seriously. We are living in that future now. Yes, your shitty janky auth scheme is causing real problems right now and yes it sometimes is life or death.
We're missing an entire category of software that manages permissions in more dynamic ways... Meanwhile, about a third of devs out there don't even know or care about the difference between authn and authz.
reciprocally though i think the top down securitization of systems with only proper access control has taken out a lot of the grease that used to greatly ease how companies related to the world in really good ways. even when you do get through to support on the phone, there's often such a grim expectation that they will be in no way able to help you, that they don't really have access to information or corporate processes that are going to do anything for you.
we (engineers) look at defined behavior & constraints as secure, safe, good. but i think the informal processes and laxity from the pre-coded world allowed companies to better actually help people and to be good, in important ways. we have to recognize that mechanization is not always a good force too, while also starting to take more seriously too that we often do need more oversight/guards/access-control too. it's paradox, it's duality, but we have to recognize both ends as dangerous.
https://news.ycombinator.com/item?id=49699308