A Dropbox account gave me stomach ulcers
reddit.com
reddit.com
A couple of years ago I inherited managing Dropbox for a company I was at. I’d never really used Dropbox in a more daily use company.
I discovered Dropbox wasn’t very IT admin friendly. If you share out a personal folder as your team folder, IT can’t find your folder to share it to new members of your team. The person who owns the folder has to share it out. So when new employees ask why IT can’t access and share the folder, we had to explain that’s how Dropbox works.
The other crappy thing I discovered about Dropbox from that time. I have no way to audit or tell who has what folder. If someone was sharing something illegal from their folder, I had to turn on the auditing capability and download logs as they were generated. It was confusing because if someone were sharing something and I was the admin of that account, I should have access to all files and accounts. Nope. So we dumped Dropbox before I left to avoid scrutiny down the road for any acquisitions of the company.
Dropbox is still a consumer product trying to be a workplace tool IMO. Maybe others have a different opinion.
This is a good story to tell on Monday.
> It was confusing because if someone were sharing something and I was the admin of that account, I should have access to all files and accounts. Nope.
In both cases, you should be able to assume the shared folder owner (via the admin console) and modify their permissions. Did this not work for you?
(note: I'm an ex-Dropbox eng that worked on a lot of the sharing/team management systems)
Have felt similar pain with G Suite Drive. Perhaps I simply didn’t find or didn’t have the proper permissions (I wasn’t the top level admin on the org) but at some point I wrote a Python script to output a list of users who had access to each file in our organization. I saw no way of generating this automatically.
e.g. when asked why they need so much space on their laptops, they were evasive.
To my mind this makes it much worse. Not only were they doing something dumb, but they knew it was dumb, and they hid it instead of fixing it.
It certainly invites speculation about the company culture in the acquired business.
It's a failure all round but i would say acquiring companies IT team are least to blame here.
- Are we using git or Leif Points for this project?
- eh, how about git?
This story sounds like they also used Leif Points, but for their database :O
Yes, that's a total fuck up on their side as well. That an incompetent company dies while doing stupid stunts like that is understandable and how the market filters out stupidity.
That another company looks at it and thinks "Oh that looks fine", that's a total failure at their work.
Then after NDA's and a few other docs if a company accepts being purchased they have to give access to their internal docs. Finance books, IT, etc.
If during this "due diligence" period the buyers find a major red flag they might pull out, revise the price down, etc.
Personally I've never seen one of these discovery phases bring back anything remotely close to real life. No random IT manager alive is going to throw his dirty laundry out to a potential buyer and potentially torpedo a deal.
Some of the things I've seen/found during my company buying spree since 2015 have been magical.
My company was acquired 18 months ago. We were the smaller company, about 1/4 the size, and as the founder/CTO, I expected the acquiring company to be all over us. I mean, we had a pretty tight operation but there was only so much 16 people could achieve. There were plenty of things we could improve, and I was looking forward to the resources and experience of this bigger company to help us.
Was I in for a shock!
While their software dev practices were OK (certainly no better than ours), what hit me hardest was their secops. It was a nightmare. And these guys service some brand name clients.
As an example, not only was the corporate wifi password memorable - not actually “P455w0rd” but similarly bad - but it was written on a whiteboard in view of the whole office! Service passwords are still stored in clear text in the corporate wiki, and few people understand why this is terrible. It’s like a 90s IT shop, where people used to ask me “why would anyone care about our password?”
Kicking the can down the road is fine for a while, but without strong technical leadership, kicking the can becomes how things get done, and that’s been my experience here.
I’m not long for this place.
I know this painfully well :(. Can you recommend some good solution? Ideally open source and self hosted, instead of cloud password manager.
Crossplatform, git versioning, gpg security (allows you to integrate with smartcards and tokens that you might already have in place for your employees).
Decent UX too, works with clipboard, supports totp.
Because: in this scenario you need to drive adoption first,if it is any complicated the humans will not use it. so you need the easiest tool possible.
when everybody is using it, THEN go for the real security move.
(you can try to find a non-cloud one that is super easy, but...)
Be careful: that sort of behaviour can get you fired and potentially land your company in hot water from a legal and/or compliance standpoint, as well as lose them customers.
Compliance is often as much, or more, about having and following documented processes, as it is about having good processes. This can include an approved list of software and services. If you step outside this you are likely breaching your compliance regime.
In the specific case of passwords you may have policies and procedures around secret management that would be violated by storing this information in the cloud, even with a service specifically designed for this. As stupid as it is, the quality (or lack thereof) of your current solution is not the key point here.
If you decide to get all subversive and start using a cloud service then, at the very least, if discovered you're going to get into trouble. At worst, if customers become aware they might leave, and as I've already said, the company might find themselves in legal difficulties.
The developer refuses to acknowledge it as a security risk, and actually caps the max iterations you can configure, both on the client and the server.
https://github.com/bitwarden/jslib/issues/52
https://github.com/bitwarden/server/issues/589
“It was audited” is meaningless if the audit missed this, or reported this and the dev dismissed it. Either way, it is unsafe.
https://crypto.stackexchange.com/a/61306
Django, uses PBKDF2-SHA256 with 216000 iterations, for example https://github.com/django/django/blob/master/django/contrib/...
Given Bitwarden allows almost 10x that, not sure I see the issue.
PBKDF-SHA256 is far too fast, even with the HMAC step.
I'd rather they use Argon2id to be as safe as can be.
However, I've not yet seen a fully cross-platform javascript-only implementation of Argon2 at all, which is problematic for an extension.. :-/
UPDATE: There actually exist an Argon2 implementation that's used by another vault, https://www.npmjs.com/package/argon2-browser
The point of PBKDF-SHA256 is to protect the secrecy of passwords if the server is compromised and its password hash db is dumped.
This is not some random webapp. It is a password manager.
Think about it.
Also, I avoided situps, cos the muscle pains felt like ulcer attacks.
There's this specific food that I love. It's eaten RAW but often prepared in a not too hygienic manner. Since I banned myself from eating it, I've slowly become able to stay a few hours without food and can handle more stress.
If not, you’ve made a series of lifestyle changes of questionable value based on terrible (or no) evidence. Avoiding hunger, sit-ups, and raw food has no long-term benefit to your general health; becoming overweight and (maybe) exercising less than before may actually be somewhat deleterious. (Unhygienic food, raw or not, of course may be to avoid... but that’s not related to ulcer formation.)
Ulcers are totally curable via a short course of proton-pump inhibitors +/- antibiotics to eradicate H.Pylori. These are cheap (generic) drugs with a low risk of side effects. Go see a doctor and get yourself fixed up. Chronic gastric inflammation definitely isn’t good.
And when my doctors have no idea what these are? And gave me the, "Avoid these food groups, exercise..."
Get off your high horse. Not everyone in the world has the same level of health care you do.
However, I do struggle to accept/believe that a relevantly qualified doctor, anywhere in the world, wouldn’t know what a PPI is. They aren’t new, they aren’t expensive, and they’re available worldwide. Honestly, every medical student would probably know about them.
Anyway, look for the medications named omeprazole, or lansoprazole, or pantoprazole. They’re PPIs. In many countries they’re even available over the counter. And (was together with a course of the correct antibiotics, where necessary) they cure ulcers.
Currently using Ab Roller for my stomach https://www.youtube.com/watch?v=dzE3Q03KXuY
As said before, please try to see a good qualified doctor about this (ideally a gastroenterologist, assuming this is possible - apologies if this is again an insensitive assumption). The reasons being:
a) If you do have an ulcer, then there are other things (beyond prescribing PPIs) a doctor might help with - such as a test for H.Pylori +/- antibiotics to then eradicate it, if you have it
b) There are other conditions that can present with similar symptoms to ulcers (they can sometimes be very hard to tell apart) which may require investigation to make a correct diagnosis, and which would then need to be treated differently.
c) There are other risks attached to chronic oesophageal/gastric inflammation; if you've had such inflammation for a prolonged period of time, it might be worth being checked out further.
https://www.mayoclinic.org/diseases-conditions/peptic-ulcer/...
Just saw this. I'll do that when I can afford it. For now, it's over the counter for me.
https://en.wikipedia.org/wiki/Garri#Health_implications
> Garri is made from cassava which contains hydrocyanic acid .../... can lead to .../... worsening of ulcers.
The ground cassava is left to ferment for some days which removes MOST of the cyanide. There's little to no health control for food in these parts. I've read that over 50% of food stuff exported from West Africa to Europe and US get culled at the border.
See: http://europepmc.org/article/PMC/3074370
See the abstract at: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6526674/
When it's prepared with hot water, it forms a solid called Eba. And it's consumed with soup. The heating makes it safe from my own observation.
That didn't work out.
And we all know what happened then.
When the board and ceo want's to aquired a business, IT is just something they believe can follow along easily.
Most developers are straight up lazy and uprofessional to do a job, and mixing in security is just scary as hell.
Can't run an application? Can't afford a license? Use the network share. No network share? Use dropbox.
Seems like an acquisition is a lot less hassle and risk. And can be done quickly. Most 'problems' can be made to go away by throwing money and fixers at them.
Every couple weeks an employee would mistake the synced folder for their local disk and rearrange files or delete files and then the files would disappear for the rest of the company.
Then we’d have to go into the backups and restore the files and send a message out to everyone to hold the files they were working on before saving them to the drive again.
I can tolerate some bad grammar, but somehow the combination of incorrect articles, words auto-spellchecked to something completely different, run-on sentences, and lack of punctuation, made it a real chore to read through without getting lost...
I hope the OP writes a book with zero changes to his writing style.
OP, please write that book / collection of stories. Loved reading this, it makes me appreciate the culture and quality of work we have in our company.
The patterns sound like native English speech.
I suspect dyslexia.
Btw, it sounded like the "version control" mentioned wasn't git.
Maybe they're doing full copies of the application + data into a timestamped directory or similar.
That kind of thing chews disk space. :/
Can tech just stop the dropbox bit n just set up sparkleshare for everyone if git is holding up? If git is less than efficient..then syncthing, seafile would all work for their file sharing needs n r trivial to setup?
They know just enough to be dangerous and frustratingly useless getting useful information from. So your integration team has to do all the planning with only the foggiest idea of what they are getting into. They then spend the entire first day on the ground just getting the lay of the land. No time to schedule local cable contractors for the really needed cable runs. Let's hope that the existing CAT5 runs work fine on gigabit for the next few weeks till we can get those contractors in to replace all the wiring. Worse case, we'll have to limit the port speeds to 100Mbps at the new switch if retransmits become an issue.
Even more fun when the next project is even less detail but the entity you are acquiring is on another continent instead of a few states over.
https://www.nytimes.com/2012/12/01/business/hps-autonomy-blu...
I just remember two of our engineers had a gig, spent 6 months at $150/hr wading through VHDL and C++ code of some company that was being acquired. They also had to work closely with a patent attorney who was billing probably $500/hr.
Also - they are NOT paying down the tech debt. The programmers and sysadmin staff doing overtime mentioned are.
Would just increasing the size of the dropbox to keep things muddling along and then trying to figure out a migration strategy come Monday morning be impossible for legal reasons?
They didn’t find out until today that a number of senior staff were laid off during the acquisition. Lots of room there for bad feelings. That opens them up to all kinds of vulnerabilities from disgruntled ex employees.
Imagine the repercussions come post-holidays if something bad happens during the next few weeks before everyone is back on board and there’s a security breach over the meanwhile.