Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • About Bonfire
mhoye
mhoye
@[email protected]  ·  activity timestamp 9 hours ago

“Somebody got promoted for this”, boss battle edition.

https://infosec.exchange/@harrysintonen/116136789969194649

3
  • Copy link
  • Flag this post
  • Block
Chris Siebenmann
Chris Siebenmann
@[email protected] replied  ·  activity timestamp 2 hours ago

@mhoye I also wonder if this is a sign of internal dysfunction inside Google, where the Gemini team couldn't get a new API key type created and plumbed through Google's infrastructure so 'lol we'll (ab)use the existing keys, we can actually get that done'.

  • Copy link
  • Flag this comment
  • Block
Michael Newton
Michael Newton
@mavnn replied  ·  activity timestamp 8 hours ago

@[email protected] "I feel a great disturbance in the Force, as if a million security researches all face palmed at once..." ​

  • Copy link
  • Flag this comment
  • Block
Chris Adams
Chris Adams
@[email protected] replied  ·  activity timestamp 9 hours ago

@mhoye @harrysintonen imagine how different the business world would be if bonuses had clawback provisions. The only way some security engineer didn’t flag this is if they were completely bypassed in the rush to ship.

1
  • Copy link
  • Flag this comment
  • Block
mhoye
mhoye
@[email protected] replied  ·  activity timestamp 9 hours ago

@acdha @harrysintonen not sure it would help - “your bonus is being clawed back because it was based on a false premise” is the same as saying “this company’s internal controls are an unreliable shambles” and no company would admit to that, particularly at the executive level.

1
  • Copy link
  • Flag this comment
  • Block
Blackoverflow DECT:HUGz(4849)
Blackoverflow DECT:HUGz(4849)
@[email protected] replied  ·  activity timestamp 1 hour ago

@mhoye
@acdha @harrysintonen
Or a company could try to establish such a policy to flex:
"The policy does not matter, because our internal controls are reliable! The other companies do not dare to implement this, because they know how bad their controls are!"

  • Copy link
  • Flag this comment
  • Block

bonfire.mavnn.eu

News and community around mavnn.eu projects.

bonfire.mavnn.eu: About · Code of conduct · Privacy ·
Bonfire social · 1.0.1 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Public Groups
  • Code of Conduct