ec changed the topic of #elliottcable to: a 𝕯𝖊𝖓 𝖔𝖋 𝕯𝖊𝖙𝖊𝖗𝖒𝖎𝖓𝖊𝖉 𝕯𝖆𝖒𝖘𝖊𝖑𝖘 slash s͔̞u͕͙p͙͓e̜̺r̼̦i̼̜o̖̬r̙̙ c̝͉ụ̧͘ḷ̡͙ţ͓̀ || #ELLIOTTCABLE is not about ELLIOTTCABLE
Rurik has joined #elliottcable
Rurik has quit [Quit: Rurik]
_whitelogger has joined #elliottcable
Rurik has joined #elliottcable
Rurik has quit [Quit: Rurik]
Rurik has joined #elliottcable
Rurik has quit [Read error: Connection reset by peer]
Rurik has joined #elliottcable
Rurik has quit [Quit: Rurik]
Sgeo_ has quit [Ping timeout: 240 seconds]
Sgeo has joined #elliottcable
Sgeo has quit [Ping timeout: 264 seconds]
Sgeo has joined #elliottcable
Rurik has joined #elliottcable
<ELLIOTTCABLE>
sigh.
<jfhbrook>
tell me about it
<ljharb>
why for sigh, specifically
<ELLIOTTCABLE>
generalized anxiety, feelings of worthlessness, and stress
<ELLIOTTCABLE>
but today’s was because money-related security is _always_ paradoxically the most poorly executed
<ELLIOTTCABLE>
i had to do a bunch of financial stuff today and in the process for whatever reason i was mired in *four* different financial systems, and each had uniquely terrible security for differing reasons
<ELLIOTTCABLE>
let’s see, a few of the more interesting ones, besides the almost-a-given-nowadays ‘dumb requirements’ and ‘short password-length limits’,
<ELLIOTTCABLE>
- one account e-mailed me my username and password, not in plaintext, but in something even worse (which is not a phrase I’d ever thought I’d be typing) …
<ELLIOTTCABLE>
in a fucking Microsoft Word .doc file.
<ljharb>
hahaha
<ljharb>
one of my domain names, i pay for my emailing a word doc with my credit card in it once a year
<ELLIOTTCABLE>
fuck the second didn’t send
<ELLIOTTCABLE>
goddamn coverage in my hospital is so bad
<ELLIOTTCABLE>
ugh don’t want to type it up again. just, enter this static password we e-nailed you in plaintext years ago oh btw you can’t change it … and then we’ll show you the “message from your advisor”
<ELLIOTTCABLE>
like. all over http. and the “message from my advisor” is literally a status http page i can retrieve without any cookies, so the whole song-and-dance of indirecting the e-mail thru a website is totally pointless …
<jfhbrook>
the one that drives me nuts is that Fidelity normalizes passwords to be the digits 0-9 plus a *
<jfhbrook>
so that you can punch it in over the phone
<jfhbrook>
and they don't actually message that very well, like I think that's a kinda beefy security issue
<jfhbrook>
in other news I'm getting just enough pushback on one of my more important proposals that I'm Freaking Exhausted
<jfhbrook>
I'm trying to get someone else to take and run with it and am also trying to duck a meeting on it so I don't have to get frustrated about defending my ideas against people hostile towards them
<ELLIOTTCABLE>
what is ur idea
<ELLIOTTCABLE>
are you telling them to add a goose to the homepage that honks when you click it
<ELLIOTTCABLE>
i support your idea how do i help
<ELLIOTTCABLE>
i will call and do all your yelling for you <3
<jfhbrook>
no
<jfhbrook>
I'm telling them to refactor reporting so that we can ship report updates decoupled from ingestion updates
<jfhbrook>
some of the issues are totally reasonable things to go over - should this be in a new repo, if so how to manage dependencies in the existing repo, yadda yadda
<jfhbrook>
so the core issue, the reason for all of this stuff
<jfhbrook>
like, ignoring the slightly improved security, ignoring the decreased likelihood of pushing a bad report, etc etc etc
<jfhbrook>
is that it takes two engineers three hard days to deploy our current system
<jfhbrook>
which means we do one deploy a month
<jfhbrook>
meaning our lead time is a month
<jfhbrook>
and people will be like, oh but if you're dealing with a release that *only* touches reports than you can skip a bunch of these steps!
<jfhbrook>
and I'm like, yeah ok if that's true then why can't you guys ship? :) :)
<jfhbrook>
but like having to actively argue this to people uninterested in listening is
<jfhbrook>
fucking exhausting
<jfhbrook>
to the point where I'm thinking about what I'm gonna do if I release the big "why we can't ship" doc and nobody that matters finds it convincing
<jfhbrook>
like, save a copy for my portfolio and split? maybe
<jfhbrook>
I love this domain though and some of my coworkers are fantastic
<jfhbrook>
also thinking about taking a random day off to headphone up and work on that doc