• Err(()).unwrap()@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    3 years ago

    Our business-critical internal software suite was written in Pascal as a temporary solution and has been unmaintained for almost 20 years. It transmits cleartext usernames and passwords as the URI components of GET requests. They also use a single decade-old Excel file to store vital statistics. A key part of the workflow involves an Excel file with a macro that processes an HTML document from the clipboard.

    I offered them a better solution, which was rejected because the downtime and the minimal training would be more costly than working around the current issues.

    • Tar_alcaran@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      3 years ago

      The library I worked for as a teen used to process off-site reservations by writing them to a text file, which was automatically e-faxed to all locations every odd day.

      If you worked at not-the-main-location, you couldn’t do an off-site reservation, so on even days, you would print your list and fax it to the main site, who would re-enter it into the system.

      This was 2005. And yes, it broke every month with an odd number of days.

    • SSTF@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      downtime

      minimal retraining

      I feel your pain. Many good ideas that cause this are rejected. I have had ideas requiring one big downtime chunk rejected even though it reduces short but constant downtimes and mathematically the fix will pay for itself in a month easily.

      Then the minimal retraining is frustrating when work environments and coworkers still pretend computers are some crazy device they’ve never seen before.

  • esadatari@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    3 years ago

    i worked for a hybrid hosting and cloud provider that was partnered with Electronic Arts for the SimCity reboot.

    well half way through they decided our cloud wasn’t worth it, and moved providers. but no one bothered to tell all the outsourced foreign developers that they were on a new provider architecture.

    all the shit storm fail launch of SimCity was because of extremely shitty code that was meant to work on one cloud and didn’t really work on another. but they assumed hurr hurr all server same.

    so you guys got that shit launch and i knew exactly why and couldn’t say a damn thing for YEARS

  • thrawn@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    3 years ago

    It’s pretty depressing, but the fact that soil and groundwater are almost certainly contaminated anywhere that humans have touched. I’ve seen all kinds of places from gas stations, to dry cleaners, to mines, to fire stations, to military bases, to schools, to hydroelectric plants, the list could go on, and every last one of them had poison in the ground.

    • pfannkuchen_gesicht@lemmy.one
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      Some places are insanely polluted to the point where you wonder how a whole company could be so braindead and essentially poison themselves.
      A place not far from where I live had a chemical plant which just dumped loads of chemicals on a meadow for years. Now there are ground water pumps installed there which need to run 24/7 so that the chemicals don’t contaminate nearby rivers and hence the rest of the country.
      When taking samples from the pumped up water you can smell gasoline.

  • Aceticon@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    3 years ago

    Over a decade ago I worked as a freelancer for an Investment Bank (the largest one that went bankrupt in the 2008 Crash, which was a few years later) were the head of the Proprietary Trading Desk (the team of Traders who invest for the profit of the bank) asked me if I could change the software so that they could see the investments of the Client Trading Desk (who invest for clients with client money) was making, with the assent of the latter team.

    Now if the guys investing money for the bank know what they guys investing customer money are doing they can do things like Front-Run the customer trades (or serve them at exactly the right price to barelly beat the competiotion) thus making more profits for the bank and hence get bigger bonuses. This is why Financial regulations say that there is supposed to be so-called Chinese Walls between the proprietary trading and the customer trading activities: they’re supposed to be segregated and not visible to each other.

    Note that the heads of both teams were mates and already regularly had chats, so they might already have been exchanging this info informally.

    I was quite fresh in there (less than 1 year) and the software system I worked in at the time was used by both teams, but when I started looking into it I saw that the separation was very explicitly coded in software and that got me thinking about what I had learned from the mandatory compliance training I had done when I first joined (so, yeah, that stuff is not totally useless!!!)

    So I asked for written confirmation from the heads of both teams, and just got some vague response e-mails, no clear “do such and such”.

    So I played the fool and took it to a seperate team called Compliance (responsible for compliance with financial regulations) saying I just wanted to make sure it was all prim and proper, “just in case”.

    Of course, it kinda blew up (locally) and I ended up called to a meeting with the heads of the Prop Desk and whatnot - all stern looks and barelly contained angry tones - were I kept playing the fool.

    Ultimatelly it ended up not being a problem for me at all, to the point that after that bank went bust and its component parts were sold to another bank, the technical team manager asked me to come back to work with the same IT group (remember, I was a freelancer) with even greater responsabilities, so this didn’t exactly damage my career.

    That said, over the years there were various cases of IT guys in large investment banks who went along with “innocent” requests from the Traders and ended up as the fall-guys for subsequent breaking of Finance Regulations, serving jail time, so had I gone along with that request I would’ve actually risked ending up in jail.

    (Financial Regulators were and are a complete total joke when it comes to large banks, which actually makes it more likely that some poor techie guy will be made the fall guy to protected the bank and its heads).

  • Whitebrow@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    3 years ago

    The programming team that is working hard on your project is just one dude and he smells funny. The programming team you’ve met in your introductory meeting are just the two unpaid interns that will be fired or will quit within the next two months and don’t know what’s happening. We don’t do agile despite advertising it. Also your project being a priority means it’ll be slapped together from start to finish 24 hours prior to the deadline. Oh and there will be extra charges to fix anything that doesn’t work as it should.

  • shadesdk@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    3 years ago

    The company would bid on government contracts, knowing full well they promised features that didn’t exists and never would, but calculating that the fine for not meeting the specs was lower than the benefit of the contract and getting the buyers locked into our system. I raised this to my boss, nothing changed and I quit shortly after.

    • hactar42@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      I’ve worked in IT consulting for over 10 years and have never once lied about the capabilities of a product. I have said, it doesn’t do that natively, but if that’s a requirement we can scope how much it would take to make it happen. Sadly my company is very much the exception.

      The worst I saw was years ago I was working on an infrastructure upgrade of a Hyper-V environment. The client purchased a backup solution I wasn’t familiar with but said it supported Hyper-V. It turns out their Hyper-V support was in “beta”. It wasn’t in beta. They were literally using this client as a development environment. It was a freaking joke. At one point I had to get on the phone with one of their developers and explain how high-availability and fail-over worked.

      • bpm@lemmy.ml
        link
        fedilink
        arrow-up
        1
        ·
        3 years ago

        I could very well have been that developer. Usual story, sales promised the world, that our vmware-based system would run on anything and everything, and of course it’s all HA and load balanced, smash cut to me on Monday morning trying to figure out how to make it do that before it goes live on Wednesday.

    • esadatari@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      eh DHCP isn’t really important right? obviously if it hasn’t changed since the 80’s why would you need to reboot your server.

      what are vulnerabilities?

  • dudebro@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    3 years ago

    Why is everyone here afraid to name the companies?

    Unless you’re sharing something that only you would know and the company is aware that you’re the only one who knows it, there’s no way they can identify you.

    Something tells me the people posting here who had “NDAs” didn’t actually have any sort of a high level clearance to important information.

    • linearchaos@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      3 years ago

      It’s a bold assumption that you will never dox yourself or be doxed. The fediverse by nature not at all private.

      • Aes Sedai@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        3 years ago

        Yup. I was able to identify the employee running my company’s subreddit that was hosting a current/former employee hatefest and many, many leaks, fueling RTO protests and unionization. Took all of about 30 mins of digging through his comments to figure it out. I never acted on it because I support everything about what it would lead to, but if I could figure it out, so could someone smarter than me who works for the interests of my company. He was still at the company, last I checked about six months ago.

  • shittymorph@lemmy.world
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    3 years ago

    I used to work for a popular wrestling company, billionaire owner, very profitable, would write off any OSHA penalties as the ‘cost of doing business’ just as they did in 1998, when The Undertaker threw Mankind off Hell In A Cell, and plummeted 16 ft through an announcer’s table

  • SloppyPuppy@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    3 years ago

    I worked for an online payment company you all know. Many eployees have access to the main DB which holds all transactions and names and everything in clear text. You could basically find out all PII (personal identification information) of any celebrity you wanted given they had anaccount. Address, phone number, credit card and all. If you knew a bit of SQL you could basically find whoever person you wanted and get purchase history and all.

    Cant say I didnt use this to find stuff about my exes or various celebrities.

    • ramjambamalam@lemmy.ca
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      Cant say I didnt use this to find stuff about my exes

      And I can’t say that doesn’t sound creepy at all…

  • GrouchoMarxist@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    3 years ago

    At Disneyland, Mickey Mouse is always played by a woman, due to the small costume. So if you put your arm around him for a photo, try not to accidentally touch Mickey’s boobs.