If this is true, I find it shocking in light of all of the recent allegations especially.
Not sure if you can share more, but this seems way to easy and auditing is, well, to late.
I never worked in a role that required me to go further, but the penalty of losing my job deterred me just fine.
No-one is going to check up on Zuck. So as long as he doesn't leak it himself, no-one is really going to know if he checks your nudes. I don't even really blame him. It's just human nature to be curious.
Except an engineer with a grudge, or a moral objection. Or an investigative reporter. Or a hacker.
A system where access control policy is capricious is a system that is fundamentally broken. I have been in jobs where I had the authority to hire and fire people, and make significant decisions that impact important things and spend lots of money. But guess what? I don’t have access to employee applications with PII. I don’t have access to the accounts for the business. Don’t know about employee healthcare or retirement.
If I tried to use my position to get access to that data, I would expect that issue to be escalated, even if I were the CEO. A data driven company with casual disrespect of basic principles is a problem waiting to happen.
I know that I've seen situations where departments critical to this access control policy system were chronically understaffed, because they are cost centers. They don't generate value. In the same way I've heard security and access control dissuaded from software development, because "we just need to get this out".
What all of these situations end up with is "performative" access control. You have to act as though you need the data, but beyond that it's a free for all. This lets the company pretend like it's fulfilling it's obligations, while saving money.
Where does the magical privilege end? Who is responsible when the all-seeing CEO is compromised personally and data or cash is exfiltrated?
A common fraud committed against public institutions like school districts or small businesses is compromise of a business manager’s account, which allows an attacker to empty the checking account.
In a public company, that sort of fraud for finance is mostly controlled by regulatory compliance. But as we know, information or data has value. Value as a commodity, value as a competitive advantage, etc.
“Perception is reality” was an internal slogan at the time. So if users (at the time) believed it was evil maybe they leave or maybe a possible new users chooses not to sign up.
The other thing too is employees abusing such a tool with other employees. When you use super you assume the user id of the user of your choice. That’s pretty dangerous and there are way better ways of helping a user fix an account issue than signing in as them. If employees can’t trust each other not to snoop then how can users trust the company not to snoop? It had to be addressed internally at the time of the intern that was creeping on someone and that’s when things started getting locked down and more auditing applied. But I think it boils down to PR. If you run a company online trust is everything. I’m sure this crowd understands that nothing online is secure but Facebook was built for the masses and they need to have that blind trust that they’re personal lives are private.
I don't think this line really conveys the weight of the slogan. That slogan is applicable in so many fields and pretty much all the time. Even just in small social circles, not just politics, whether corporate or government.