> For anyone wondering why we don’t just lift the compliance restrictions, we don’t specify it. Their Compliance department does
after a year-long grace period:
> The machines came to end of life about 12 months ago, and the company being a multi-billion dollar operation managed to eke out another year of manufacturer support. Mostly symbolic as they’re not exactly going to release custom firmware for a handful of devices. They then put a set-in-stone tombstone date on support. 12pm today.
This was imposed internally by the company's compliance and legal departments, TFAA is the executioner but the execution would be contractually mandated:
> They require, and have specified, a zero-tolerance for device non-compliance.
This means an unapproved batched and drawn-out phaseout would be a breach of contract.
You could brownout or kill a few a few days before the real issue, though, potentially.
What one could try is to call the CEO directly. Or maybe try the legal backdoor: contact the general counsel, tell them that the contract says such-and-such, that you think the contract is well written and you intend to do what it says, but that the organization should be aware that it may cause a problem. If legal doesn’t know how to get the CEO’s attention, then something is very wrong.
> 4 meetings, 124 emails, and two phone calls a day for the last 14 days have warned them of this.
There's only so much you can do.
> If legal doesn’t know how to get the CEO’s attention, then something is very wrong.
From the thread legal (and / or compliance) is the setter of the issue, and was well aware that it would cause issues (for a minority), but they were not in charge of resolution. And from downthread posts, they likely extensively documented their warnings:
> oh I’m absolutely backing the horse with the 3 miles of email threads proving this
And methinks legal and compliance had very much planned for the issue coming to a head, because they were getting fed up with being blow off, and having to shoulder the legal or regulatory risk.
A year to make fixes and nothing was done?
Legal is like, "We warned you every way we possibly could have."
"two phone calls a day for 14 days" is far from insufficient notice, to say nothing of the rest.
There's value in face to face, but not when it's a wide reaching announcement like this.
You can always start early.
People here blaming management but discussing how to do things at the last day. You don't
You give them a new device before locking out their old one
Do it for 17 weeks before the out of support deadline? The users start screaming, we still have 17 weeks left before the deadline, how dare you disable us early! And they get enabled again.
Do it for 17 weeks after the deadline? The compliance people start screaming, you have 1600 devices out of compliance, we need them shut down now!
But at the end of the day, they did the job they were paid to do and were clear about the looming impact. It's not their job to also wipe their clients' metaphorical bottoms when they were ignored.
https://github.blog/changelog/2021-04-19-sunsetting-api-auth...
I don't know if that concept would work in this case, compliance is it's own beast, but I love that idea in general.