Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3 
hio77
12999 posts

Uber Geek

ID Verified
Trusted
Lizard Networks

  #1860713 8-Sep-2017 10:09
Send private message

timmmay:

freitasm:


As I said, performance and security should be in the development team's mind when they implement anything. There should have unit, system, integration and regression tests in every single step of the development lifecycle.


Release managers that authorise deployment without having a check mark against security items shouldn't be release managers.



Security testing can be challenging, particularly automated testing. Tinfoil Security that you recommended a while back is an interesting option.


Sometimes project / release managers will say "we need security testing", business owners will say "no get it live asap".



Frustrates me to no end when security concerns are not taken seriously by release managers.
At a previous role, i left the company due to this situation.




#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have.

 

 




antoniosk
2358 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1860726 8-Sep-2017 10:43
Send private message

Mr NBR is now reporting it....




________

 

Antoniosk


timmmay
20589 posts

Uber Geek

Trusted
Lifetime subscriber

  #1860727 8-Sep-2017 10:44
Send private message

antoniosk: Mr NBR is now reporting it....

 

Complete with a very serious looking picture of Big Daddy!




freitasm
BDFL - Memuneh
79309 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1860728 8-Sep-2017 10:46
Send private message

I asked them to add the link to CERT at the bottom of the article.





Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 


cadman
1014 posts

Uber Geek
Inactive user


  #1860729 8-Sep-2017 10:46
Send private message

timmmay:

 

 

 

Sometimes project / release managers will say "we need security testing", business owners will say "no get it live asap".

 

 

As long as they 'say' it in form where responsibility for the choice can be definitively traced, that's fine. Then when the proverbial hits the fan, the person signing off on the shortcuts can be clearly identified and dealt with appropriately.

 

I've had it few times over the years where blame for a decision outside my hands and against my recommendations has come back to bite someone (who really shouldn't even have been making the decision due to their obvious lack of knowledge) but not before they tried to blame me. But the trail always cleared me. One place I worked at in the mid-90s I had a decoy manilla folder clearly labelled "BLAME FILE" in my desk drawer which I went to great pains to make my superiors aware of, plus the real "BLAME FILE" in my bag which went home with me each day, due to my distrust of one particularly incompetent and deceitful manager and his demonstrated propensity to try and blame others for his decisions. One particular design which I recommended not be implemented soon failed exactly as I had expected and my decoy "BLAME FILE" disappeared from my desk drawer with the duplicate evidence that I'd told him that it would. When they tried to haul me over the coals under the guise of a "design review" you can imagine the expression on that PoS's face when I produced the evidence he denied existed from my real file. Fun times!

 

Naturally nothing came of his blatant lies but everyone then knew not to mess with me which steered the "confident but incompetent" (as I call them) away from me entirely. It really couldn't have worked out better!


freitasm
BDFL - Memuneh
79309 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1860730 8-Sep-2017 10:49
Send private message

@cadman:

 

I've had it few times over the years where blame for a decision outside my hands and against my recommendations has come back to bite someone (who really shouldn't even have been making the decision due to their obvious lack of knowledge) but not before they tried to blame me. But the trail always cleared me. One place I worked at in the mid-90s I had a decoy manilla folder clearly labelled "BLAME FILE" in my desk drawer which I went to great pains to make my superiors aware of, plus the real "BLAME FILE" in my bag which went home with me each day, due to my distrust of one particularly incompetent and deceitful manager and his demonstrated propensity to try and blame others for his decisions. One particular design which I recommended not be implemented soon failed exactly as I had expected and my decoy "BLAME FILE" disappeared from my desk drawer with the duplicate evidence that I'd told him that it would. When they tried to haul me over the coals under the guise of a "design review" you can imagine the expression on that PoS's face when I produced the evidence he denied existed from my real file. Fun times!

 

Naturally nothing came of his blatant lies but everyone then knew not to mess with me which steered the "confident but incompetent" (as I call them) away from me entirely. It really couldn't have worked out better!

 

 

You sound like some Russian oligarch with Kompromat material on politicians and adversaries. Sheesh.





Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 


hio77
12999 posts

Uber Geek

ID Verified
Trusted
Lizard Networks

  #1860770 8-Sep-2017 11:38
Send private message

timmmay:

 

antoniosk: Mr NBR is now reporting it....

 

Complete with a very serious looking picture of Big Daddy!

 

 

Yep, well done MF.





#include <std_disclaimer>

 

Any comments made are personal opinion and do not reflect directly on the position my current or past employers may have.

 

 


 
 
 

Trade NZ and US shares and funds with Sharesies (affiliate link).

Stu

Stu
Hammered
8346 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #1861020 8-Sep-2017 16:03
Send private message

Ahh Geekzone, you've done it again! https://futurefive.co.nz/story/vodafone-nz-customer-finds-major-loophone-my-vodafone-system/

Well done to the OP, et al.

ETA: The above isn't behind a paywall, unlike the NBR story




People often mistake me for an adult because of my age.

 

 

Keep calm, and carry on posting.

 

 

Referral Links: Sharesies - Backblaze

 

Are you happy with what you get from Geekzone? If so, please consider supporting us by subscribing.

 

No matter where you go, there you are.


cadman
1014 posts

Uber Geek
Inactive user


  #1861058 8-Sep-2017 17:55
Send private message

freitasm:

 

 

 

You sound like some Russian oligarch with Kompromat material on politicians and adversaries. Sheesh.

 

 

One must cover one's own arse.


nunz
1421 posts

Uber Geek
Inactive user


  #1862517 11-Sep-2017 20:15
Send private message

cadman:

 

freitasm:

 

 

 

You sound like some Russian oligarch with Kompromat material on politicians and adversaries. Sheesh.

 

 

One must cover one's own arse.

 

 

Having been on the wrong end of at least three witch hunts in the corporate / govt world of development I would have to say the CYA is obligatory, not paranoid. it saved my job and the job of two co-workers when we were able to bring out evidence and turn the smoking gun back on the accuser with ferreted away evidence. Sad but true reflection of corporate / govt development environments in many places. Toxic, toxic, toxic!!

 

I would recommend using email - confirming with a person giving a dumb order, that you have recevied their order, what the order is, and your objections to it - but showing compliance by following said order. make sure you cc it off site as well. Emails in third party servers like gmail stand as legal evidence, and cant be erased by the unethical.

 

 

 

 


1 | 2 | 3 
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.