Hacker Newsnew | past | comments | ask | show | jobs | submit | BlackNitrogen's commentslogin

The OP Hudson Rock writes something that I understand is saying: This was more than a breach of one customer's credentials, they got some employee creds and they weren't protected by 2 factor so they got into other customer accounts using that engineer's creds.

The snowflake writeup reads to me as if a customer's account creds got compromised - and it implied to me that was the end of it, no central or other account access on thoes creds. Nothing about this use of some employee account info that didn't have 2 factor auth on it.

1. I'm sure snowflake wants all access creds of any kind for their internal employees to use 2fa.

2. It used to be at least as a customer you could create a name/password without 2fa to log in to your own info there if you wanted to, like say as a customer you create a db or table and want to access it.


For 1. Those accounts would be set up by customers, so if they didn’t require 2FA, it didn’t happen.


That's just such an example of how it works. "Our employees are in high cost of living areas, missing earnings will be demoralizing". If you worked in a large corp for a while, you notice this happening. Everyone is incentivized to hit short term goals.


These days, I work for (some part of) a large corporation. In my anecdotal experience, the people who get upset about missing earnings are managers, not regular employees nor even tech leads. And even that is at the annual level or longer-term; quarterly results are considered quite ephemeral.


Regular employees definitely notice when they don’t get raises or bonuses. Whether they draw the line to quarterly results…


1. "noticing" and "caring" is not the same thing. They notice it like they notice the rain.

2. Our (*) raises are only very partially affected by company results, and probably not by the quarterly ones.

3. Our bonuses are affected by annual results, nor quarterly ones. Also, they're not so large as to corrupt professional-ethical motivation ("if we cripple the product then the company would make money and we'd get a larger bonus"). AFAICT of course, I'm not a mind reader and only know a small part of the thousands and thousands of employees.

4. There are no result targets with some kind of discontinuous effect on bonuses and raises. At least not that employees know about.

Of course, this could be very different at Google.

-----------

(*) - I actually work for a subcontractor so I should probably not even use the first person plural, but let's not complicate the anecdote even further.


At google, a substantial amount of employee comp is in equity so any drop in share price would lower morale.


Usually corporate is more than happy to draw the connection, hah.


This is basically the entire industry now. Even firms that aren't public operate as if they are.


That's terrible. Everyone's experience varies, my Pixel 3A has been great, no problems, no noticeable scratches. The killer feature of the 3A for me has been ability to take night time sky photos and show something. I got a usable picture of the comet.

I really don't want to ever buy a phone without a headphone jack. At least the 4A still has one. Only reason to buy a 4A now would be to get 128 gig storage.


Yeah two of my daughters are very happy with the cameras on their Pixel 3As, enough that they're willing to put up with the badly cracked screens.


It's incredibly stupid to drop them and yet here we are, with only a few phones with headphone jacks.


There's a lot more going on that pseudo glorification of slavery and plantation life. It's pushing the mythos of that life, how the black people behaved like children, there were many hollywood movies of the time that perpetuated those stereotypes. The story of the maid and her reactions and behavior, like she wasn't quite an adult or real person.


I think working in the financialization industry is a form of destructive waste. That's the gist of the idea. But that judgement is a very subjective thing, because why is my software helping society any better? I'm making new and better ways to program robots. Sooo, could better autonomous systems lead to job loss? Potentially, sure.


Yeah, why not, post away.


The per year deficit greatly increased though during that time. we reduced taxes, the economy grew a little more but the deficit really increased. the net is we borrowed from the future to make those tax cut (cause we'll have to back back the extra deficit over time).


There are a lot of different jobs. Some of them are easier to get when you are starting. Some jobs take some background to get you in the door. But there are a vast number of companies and different jobs. Figure out what you are interested in, look at job boards and apply. The monthly hacker news job thread lets you look for jobs in certain locations, easily in the browser.


If I understand your description, you reset your account. They delete the messages for safety when you reset. An attacker could reset by getting ahold of your phone number by sim jacking or the govt getting your text. It's a safety method so no one can take you texts. Of course many people want to carry their texts along, but this is a safety risk if you lost control over your number. So that's what signal is doing. If I recall when I had to reset my own number they did say they were deleting my old messages.


Signal allows backing up messages (though the UI and workflow for it is still rather clunky), so you should be able to restore them even if you switch to a different phone number entirely.


seems like unnecessary hassle


No, I had removed the app from my mobile previously, not deleted my account. When I resynced, they had removed my account and the messages saved on my desktop disappeared.


That is the same thing. The messages were stored on your phone never on any "account". The desktop was only ever a mirror of the phone. This is explicitly how Signal works. WhatsApp works the same way.

If you did not delete the Signal directory on your phone then there should be some old backups with your messages there. These will be encrypted so you will need to original password to unencrypt them.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: