Financial Institution Letters: Vacation Policies (1995)
fdic.gov
fdic.gov
Although the provenance of the control is to deter and detect fraud, it also helps to highlight key-person dependencies (where a process cannot run without a specific individual present). On the flip-side, humans are very innovative creatures and you can use this control to identify where someone has found a way to bypass parts of the process (the process time suddenly increases a lot when someone in the team is on their mandatory-vaykay, or the quality suddently drops).
I also see it used in smaller companies by bosses who want to simulate the effects of a person quitting, and how confident the rest of the team are to take over the running of a task.
Aka the Bus Factor. What if our lead engineer takes a bus out of town (or the darker version).
Even in large companies, work is done by teams and those teams are susceptible to this problem as well.
I default to, what if Bob wins the lottery?
I was working with an IoT company who proudly showed us, their biggest customer, how the signing keys to particular actions that could impact many, many people were held on a rather trick little Spyrus USB stick. Which they displayed. In the pocket of a person that had the requisite passphrases to access it all on her own.
I asked what would prevent the person from hopping a plane out of nearby SFO and having a pleasant CCP-funded retirement and they turned all sorts of colors. They invested in a proper storage mechanism (and key management processes) after that.
Eg make it so that 10 out of 15 people employees need to sign.
HA! I've never heard this version of it. I've only ever heard the dark version. I like this better.
disgusting food -> interesting and unique flavor profile
bad movie -> the director made decisions that challenge audience expectations
take your crazy pills -> I had not heard of that before
and of course the Southern classic
you idiot -> bless your heart (this one doesn't really work anymore because people know it)
Edit: I remembered another one:
Resting B*tch Face -> Resting Business Face.
I'd heard it through two different management consultancy sources, but that could easily have a common root, of course.
Emotional archetypes are limited. You have borrowed others ideas because that’s how it works; you memorized such emotional states from others. Awareness of such emotional state is not yours alone.
See. That’s how you put someone down. Directly. Not through passive aggressive southerner classics. You’re far too obvious to those who have diverse real world experience and just come off as a cliche. But we silently eye roll rather than validate such antics through feedback, good or bad.
I try to be like "ok, let's get back to the topic"
"what do you mean?"
"oh, in case I get hit by a bus"
Silence.
Someone in their company had been hit by a bus and died a couple weeks earlier. Not in their department - it wasn't a direct friend/colleague - but it was... awkward enough that I didn't use that phrase again for a long time. And even when I do, I tend to catch myself before and rephrase it.
I assume she eventually retired or something because it was transferred to one of the big benefits companies a few years back.
At the computer maker, where my pension is from, getting things done tended to be about reaching out to the right person who knew how to make such and such happen. Of course at the intervening smaller companies everyone knew everyone else. Where I am now, personal connections still matter of course. But when I joined, it was a bit of an adjustment to just "submit a ticket" rather than tracking down the right individual to ask a question or do something--at least with respect to company operations like payroll, benefits, or legal.
It’s fascinating seeing a company successfully grow from 30 to 300 in a couple of years, with effectiveness mostly increasing.
chaos did, in fact, ensue. pretty sure it was part of the reason some big clients left.
For example in one bank I worked for there is a 2 year limit on how long you can work there as a contractor. This is to make sure that all key personnel is actually employed by the bank and the assumption being that if somebody worked for 2 years they become key personnel by default and have to either be hired as an employee or fired as a contractor.
Note: There are other criteria that have to be met as well for the govt to consider someone an employee: - if work happens a the employer’s premises - if the employer owns all equipment needed for work - how is the work instructed - can denote a manager/employee dynamic)
This is covered in accounting and the CPA as well. Not that I'd necessarily recommend a CPA over an IT auditor in many cases.
Tangentially related: it's one of the reasons why government positions should be (randomly) rotated. In many ways, it's the same reason why we should choose our elected representatives randomly. (Also: I'm under the impression that random selection of representatives is one of the few ways to implement robust, fair representation.)
The major downside is a lack of accountability; however, at least in large parts of the US, factionalism & gerrymandering have almost completely removed accountability, so we're not really losing anything.
MP means Member of Parliament (or equivalent representative of a democratic government). Belgium has been a hot-spot for this kind of initiative.
This seems extremely unlikely just by virtue of the fact that the average person has an IQ of 100 and the average MP doesn’t. Practically guaranteed to be above 115. There are very large differences in education. The median voter in the US is over 50 and never went to, never mind graduate from, college.
For that reason, instead of picking people directly at random, pick ballots at random to fill up parliament.
In theory, you could pick random votes first, and then ask them about their choice. But there's all kinds of targeted influence possible at that stage. So let voters make their choice first, and then pick randomly.
You'd need some kind of resolution mechanism for when multiple random ballots have the same candidate on them. Eg give the guys vote in parliament a higher weight, or have people write down multiple candidates in order, or just pick another random vote etc. (Some resolution mechanisms might work better than others. I don't know.)
I've long thought that once a person attains a certain level of success, roughly including college degree, certain military rank, managerial position of certain scope at medium-large company, etc., they should be subject to random political service in state or federal legislature or executive branches. Perhaps after one term, they can stand for re-election for maximum of two terms, 10 years max, to take advantage of experience gained. Pay should be greater of a set level or 110% of their max earnings in previous 5yrs (so service is not punitive).
There would of course be some random evil and grifters, but their concentration and ability to embed for life would be very limited.
How we get from constitutional structure to there is another question.
Just pick randomly from all willing candidates to fill up parliament. Or even better: still have elections were people can vote for willing candidates, but instead of picking the winner by some kind of majority or proportionality scheme, you pick n ballots at random to fill up the n seats in parliament.
(You can come up with your favourite scheme to handle the case when a single candidate gets multiple votes for her selected. Eg give her extra weight in decisions?)
I would suggest using sortition only for instances where the law of large numbers helps you. Eg for filling up a parliament with a few hundred representatives, but not for picking a single president.
1.) Going to throw people into an unfamiliar role for, say, a couple years. So they're going to heavily lean of whatever permanent staff/civil service there is because their knowledge of the job is extremely limited
2.) You'd basically be asking/telling people to take two years off their job--for probably quite limited pay. (Sort of federal grand jury duty on steroids.) Which I can't believe would be very popular.
The government has the benefit of being able to eschew normal market pricing for things including job pay.
(1.A) Yes. As I said in another comment, though, it turns out that in the limited research that's been done, the average person is somewhat better at doing the job than the average career politician. The argument is that the sort of person who wants to be a career-politician is uniquely unsuited to actually running a government.
(1.B) The civil servants should be randomly rotated.
(2) There's normally a mechanism to preselect a pool of applicants. Universal sortition is interesting, but has drawbacks. I am drawn to a nomination mechanism: you have to get enough (unique) nominations before you're allowed in the sortition pool.
https://www.energy.senate.gov/members
The Republican party is somewhat better than the Democrats on this-- Committee reform was a major plank of the 1994 Contract With America and the GOP still has term limits for Committee Chairmen.
https://about.bgov.com/news/frustrated-democrats-mount-push-...
Institutional knowledge in civil service is the only reason our government functions even as well as it does. I'm not sure that's a great idea.
Also, it's a job like any other, and the more unpleasant you make it, the more workers with options will leave. And the workers with options will tend to be your best ones.
Source: have watched "The Think of It"
yes
> you have a dedicated civil service that does most of the work and then a politician that may or may not know whats going on setting direction?
this is the ministers and their private secretary.
> have watched "The Think of It"
you should also watch "Yes Minister" i find it a bit more charming if a little dated, but also quite real.
It has aged well and is arguably more relevant than it was when they released it.
Everyone in Japan, rotated, at least, every two years. Often, more frequently. This included very senior-level executives.
I'm not sure that it was to combat fraud, but I'm sure that was a knock-on effect.
I would work with engineers for many years, but they would be working on different projects, and might suddenly appear in the project I was on, many years after the last time I saw them.
They also had a lot of vacation/holiday time, but the company told them when they would take it. I think that more seniority gave you more discretion.
When I worked at IBM just out of college, my manager introduced me to someone who was getting promoted three levels up. It turned out that he had some months previously figured out how four people working together could evade the accounting controls and transfer $25 million out of the company on a Friday afternoon and be in Brazil or wherever (never to be seen again, presumably) before Monday. He reported the flaw in the controls and the promotion was the recognition of his acumen...
For the business:
* It's a real life test of what happens if an employee quits/resigns, with less impact (a team member will probably be able to reach them in an emergency).
* You can test your operational robustness (as mentioned by the parent comment).
* It exposes holes in processes and documentation that have been papered over by a human.
* The vacation may reveal tasks which can be delegated to others or not done at all (timeline depending, of course).
Here are my general thoughts on that: https://letterstoanewdeveloper.com/2021/09/13/always-be-repl...
tl;dr "...you should always be looking at ways to replace yourself. This will free you up to work on new tasks and learn new things."
Over time this made me really angry at the team. It really shut down my brain because I had so many things to juggle. I really wish I could have replaced myself. I wound up just leaving the team, I think they struggled for a while.
When you're on a team with someone who seems to know everything, some people are much less motivated to learn the system. Also, sometimes things just suck. Sometimes you just have a team of jaded short-timers about to leave. Sometimes you have a team of junior employees who can "make things work" but leave a trail of half baked decisions.
-Flavor text from Netrunner CCG (1996)
In every case that I was personally involved in uncovering/investigating, suspicions were initially raised when the employee went on compulsory block leave.
The reason block leave is important is that some of the coverup behaviour has ponzi-like characteristics. So say you have a hole in one account because you’ve lost a lot of money. You find a way to cover that up by booking fake trades say. Well trades have a settlement and some gnome in the back office is going to contact the counterparty on the fake trade when the trade fails to settle and your fraud will be discovered so you have to cover that up before the trade settles. So maybe you move some money from another account (by booking a trade) and cancel your first fake trade, then you need to book a fake trade in your second account which you will then need to cancel and cover hp in the same way.
Basically the perpetrator often ends up on the coverup merry go round which falls apart if the take time away.
I suspect this was intended to be utilized by poor people who struggle to afford to power their homes. The US Military is certainly well funded enough to pay its electric bills.
At a certain level, you can't fix stupid (note: the person in my anecdote wasn't the stupid person). Example: once upon a time I worked for a very large public utility and got to be friends with a cool guy who seemed to live in the underground server rooms below Utility HQ. He would offer us (infosec group) 'free' hardware from time to time, which was cool (bear in mind CAPEX is a very good thing in the regulated utility industry, so there were all kinds of things kicking around taking up space).
At one point I was wandering around the halls underground, he spotted me, and said "Hey Mark, can you use this?" while pointing to a check printing machine loaded with valid corporate check paper. My jaw dropped. The first thing I did was look around for 'tells' of a corporate security sting. Dollar signs rolled in front of my eyes.
I asked said subterranean server room dweller if he had any idea what he had, and what he could do with it (I have no doubt one could easily make off with zillions of dollars and have it written off as billing errors). He smiled and said "no," to which I replied that was a good thing for our shareholders, and that he should probably properly dispose of that thing toot sweet. All the processes in the world and yet there was a literal money-printing machine hanging out with no oversight at all, prey to anyone with an RS-232 connection.
This, and laziness in the name of avoiding friction and remaining competitive. In every size organization I have been in the customer code will be audited by third parties. I have never seen internal automation audited by third parties. Not in banks or financial institutions. I've worked for both big banks and small financial institutions that grew into big ones. People get spread thin and fight to maintain control of the systems and code they are responsible for and this is only getting worse with time in my experience. With time more command and control systems are spread out and inter-connected with on-prem and cloud solutions that delegate root privs to third parties running entirely closed source code with very little consequences for damages. Infosec and security orgs apply very outdated logic that would not even stop an amateur attacker.
If you were able to do that, someone (probably multiple people) weren't doing their jobs.
By design these jobs do not exist at least not in a meaningful manor. People validate change tickets. People validate that code does what it says it does but that's where they usually stop. Security organizations these days are being moved under the same orgs that manage code to reduce friction. This stops Security Theater which is indeed a real problem but it also curtails people going down rabbit holes. Close ticket, move onto other issues, don't block a team from getting work done. Don't like what someone is trying to implement? No problem, design a better solution. For 8000+ developers? Yeah nobody scales like that.
People review individual code snippets. People stopped looking at big pictures of implementations. Disasters like Solar Winds don't happen because of one piece of nefarious code. They happen because a broken framework of thousands of pieces of poorly thought out code are glued together. There comes a point where the junk-yard of automation gets so big and ugly that even if leaders wanted to overhaul it they could not and if something nefarious was occurring nobody would see it, probably not even for a long time after damages were done. It's next to impossible to reverse engineer junk-yard automation which is what most automation becomes with time.
There is truth in this but what I am referring to is happening with principal and senior developers and orgs that would never touch excel. In fact Microsoft products are forbidden by contract in the production datacenters I have worked with in the last couple of decades.
It's hard to see nefarious behavior when it depends on thousands of pieces of automation and frameworks that are poorly glued together. It's even happening albeit slowly in my favorite operating system that has no shortage of incredibly intelligent and talented developers. Ironically these folks won't see it because they did not experience all the vulnerable frameworks and bandages that Windows implemented early on and now history is rhyming with udev + systemd + debugfs + binfmt + firewalld + ebpf glued together but that is a long topic in and of itself.
Another related topic could be vehicle automation and inter-connectivity. I am intrigued and curious to see how that one plays out.
Such a policy is considered an important internal safeguard largely because of the fact that perpetration of an embezzlement of any substantial size usually requires the constant presence of the embezzler in order to manipulate records, respond to inquiries from customers or other employees, and otherwise prevent detection.