ec changed the topic of #elliottcable to: a 𝕯𝖊𝖓 𝖔𝖋 𝕯𝖊𝖙𝖊𝖗𝖒𝖎𝖓𝖊𝖉 𝕯𝖆𝖒𝖘𝖊𝖑𝖘 slash s͔̞u͕͙p͙͓e̜̺r̼̦i̼̜o̖̬r̙̙ c̝͉ụ̧͘ḷ̡͙ţ͓̀ || #ELLIOTTCABLE is not about ELLIOTTCABLE
Rurik has joined #elliottcable
Rurik has quit [Quit: Rurik]
_whitelogger has joined #elliottcable
Rurik has joined #elliottcable
Rurik has quit [Quit: Rurik]
Rurik has joined #elliottcable
Rurik has quit [Read error: Connection reset by peer]
Rurik has joined #elliottcable
Rurik has quit [Quit: Rurik]
Sgeo_ has quit [Ping timeout: 240 seconds]
Sgeo has joined #elliottcable
Sgeo has quit [Ping timeout: 264 seconds]
Sgeo has joined #elliottcable
Rurik has joined #elliottcable
<ELLIOTTCABLE> sigh.
<jfhbrook> tell me about it
<ljharb> why for sigh, specifically
<ELLIOTTCABLE> generalized anxiety, feelings of worthlessness, and stress
<ELLIOTTCABLE> but today’s was because money-related security is _always_ paradoxically the most poorly executed
<ELLIOTTCABLE> i had to do a bunch of financial stuff today and in the process for whatever reason i was mired in *four* different financial systems, and each had uniquely terrible security for differing reasons
<ELLIOTTCABLE> let’s see, a few of the more interesting ones, besides the almost-a-given-nowadays ‘dumb requirements’ and ‘short password-length limits’,
<ELLIOTTCABLE> - one account e-mailed me my username and password, not in plaintext, but in something even worse (which is not a phrase I’d ever thought I’d be typing) …
<ELLIOTTCABLE> in a fucking Microsoft Word .doc file.
<ljharb> hahaha
<ljharb> one of my domain names, i pay for my emailing a word doc with my credit card in it once a year
<ELLIOTTCABLE> fuck the second didn’t send
<ELLIOTTCABLE> goddamn coverage in my hospital is so bad
<ELLIOTTCABLE> ugh don’t want to type it up again. just, enter this static password we e-nailed you in plaintext years ago oh btw you can’t change it … and then we’ll show you the “message from your advisor”
<ELLIOTTCABLE> like. all over http. and the “message from my advisor” is literally a status http page i can retrieve without any cookies, so the whole song-and-dance of indirecting the e-mail thru a website is totally pointless …
<jfhbrook> the one that drives me nuts is that Fidelity normalizes passwords to be the digits 0-9 plus a *
<jfhbrook> so that you can punch it in over the phone
<jfhbrook> and they don't actually message that very well, like I think that's a kinda beefy security issue
<jfhbrook> in other news I'm getting just enough pushback on one of my more important proposals that I'm Freaking Exhausted
<jfhbrook> I'm trying to get someone else to take and run with it and am also trying to duck a meeting on it so I don't have to get frustrated about defending my ideas against people hostile towards them
<ELLIOTTCABLE> what is ur idea
<ELLIOTTCABLE> are you telling them to add a goose to the homepage that honks when you click it
<ELLIOTTCABLE> i support your idea how do i help
<ELLIOTTCABLE> i will call and do all your yelling for you <3
<jfhbrook> no
<jfhbrook> I'm telling them to refactor reporting so that we can ship report updates decoupled from ingestion updates
<jfhbrook> some of the issues are totally reasonable things to go over - should this be in a new repo, if so how to manage dependencies in the existing repo, yadda yadda
<jfhbrook> so the core issue, the reason for all of this stuff
<jfhbrook> like, ignoring the slightly improved security, ignoring the decreased likelihood of pushing a bad report, etc etc etc
<jfhbrook> is that it takes two engineers three hard days to deploy our current system
<jfhbrook> which means we do one deploy a month
<jfhbrook> meaning our lead time is a month
<jfhbrook> and people will be like, oh but if you're dealing with a release that *only* touches reports than you can skip a bunch of these steps!
<jfhbrook> and I'm like, yeah ok if that's true then why can't you guys ship? :) :)
<jfhbrook> but like having to actively argue this to people uninterested in listening is
<jfhbrook> fucking exhausting
<jfhbrook> to the point where I'm thinking about what I'm gonna do if I release the big "why we can't ship" doc and nobody that matters finds it convincing
<jfhbrook> like, save a copy for my portfolio and split? maybe
<jfhbrook> I love this domain though and some of my coworkers are fantastic
<jfhbrook> also thinking about taking a random day off to headphone up and work on that doc