Rewards for loyal spenders are 'a honey pot for hackers'
nytimes.com
nytimes.com
* In terms of culture, it was primarily a marketing company, not a technology company. Marketroids made up much of upper management. During new-employee orientation, one of these marketroids would attempt to sell you on the company's mission by redefining the word "loyalty" in such a way that it doesn't involve trust, faithfulness, or any other human virtue.
* The office was aggressively open-plan. Engineers sat shoulder-to-shoulder at long benches, with about enough room for their MacBook and one or two monitors, and that's it. There were no "focus rooms" or other quiet places to get work done, only a few conference rooms (and of course offices for upper management). Engineering shared the same office space with sales, marketing, and the other divisions and the place was constantly loud. Even the receptionist's area was out in the open like this. It was like some of the worst boiler-room recruitment firms I'd seen, but scaled up, and you were supposed to get technical work done there.
* The pace was also aggressive. There was an expectation that new features would be implemented and go into production quickly, and this is also the sort of company where you "commit" to work for the next sprint, you do not "forecast". If what you pledged to do by end of sprint isn't done, you will be given the turd-burgling stink eye at best.
With rewards programs being implemented in that kind of environment, is it any surprise that proper care for things like security is not being done?
Once -- once! -- I was contacted by a domain expert looking for someone else to discuss some arcane tech issue (he was trying to decide if he should commit to a new display technology for their next gen design, or if it was too risky. I didn't make any decision for him or anything, just discussed the issues with him).
Typically the questions I get are from people who aren't really sure about the right question to even ask, typically in marketing or corporate strategy, and typically mid level (not new hires but not the VPs or senior directors either). They always have a particular question they want answered but don't even know enough to phrase it properly ("we're looking into strategic direction for our next level offering and our teams are recommending either writing it in C++ or using the blockchain" -- not an actual question!)
This actually makes sense. If they understood a bit about they domain they would already have contacts, hopefully ones they trusted, to help them decide. The kinds of people who pay (well, get their company to pay) to "speak to an expert" are not idiots, merely domain-ignorant and smart enough to know so. So what I end up giving is a kind of off-the-cuff interactive survey white paper to someone who hopes I don't know who they actually are (well, where they work).
Some things to note:
1) A lot of "tech companies" are really marketing companies.
2) These companies tend to experience weed-like growth, especially during the early stages, which causes other companies to adopt their practices (Dickensian-orphanage employee seating, emphasis on features and innovation rather than quality, short development cycles) in the belief that doing so will make them more innovative and hence competitive in the cloud era -- a form of cargo-cult management.
https://en.wikipedia.org/wiki/Honeypot_(computing)
A honeypot is a decoy used to attract malicious activity, keeping it from legitimate targets, and accurately identifying it.
Honeypots are deliberately promoted in such a way that legitimate users will not find them, but criminals will end up harvesting their addresses. For instance a honeypot e-mail address wouldn't be offered to legitimate users as a contact, but only buried in some content where only a spammer will harvest it. When the criminal uses the decoy identifier, their connection attempts are subject to time-wasting pauses (the honeypot is "sticky"!), and their IP address is put into a blacklist at the same time, so then the have a hard time accessing non-decoy resources.
What you're suggesting isn't "let's keep...", since at no point in time it exclusively meant that one thing.
Honey pot is defined as an enticing source of pleasure or reward.
So the title works for the non techy.
I agree that domain specific terminology, general language and another domain's language is confusing.
I'm sure a developer at a toy company and management could get confused by a conversation about models.
Doesn't mean either of them are right. Language is frequently ambiguous and we avoid it internally in our domains where possible.
Also it's been used to describe vaginas and male sex toys.
noun: honey-pot
1.
- a container for honey. "an earthenware honeypot"
- an enticing source of pleasure or reward. "massive increases in government -- purchases became a honeypot for the unscrupulous"
- a place to which many people are attracted. "the tourist honeypot of St Ives"
2. VULGAR SLANG - a woman's genitals
I guess the definition we are used to is the metaphor "an enticing source of pleasure or reward."But with the added nuance that you're intention is to trap the enticed in honey...
A company that holds my stocks and shares (which easily convert into US dollars) in an account is called a Broker or a Bank
So why is a company that holds my loyalty points (which also convert to US dollars) not also called a Bank (and regulated as such?)
Especially given that most companies take advantage of these programs and hurt customers, e.g. by diluting what you can do with a certain amount of previously earned points.
They have a USD/EU value equivalent because they need to for legal reasons but most companies will not honor requests to convert your points to dollars, and the fine print in their loyalty program T&C has language to that effect. They will only let you convert those points into their own goods or services.
(Credit card loyalty points are different, but they're also subject to regulation.)