HNHacker News
TopNewBestAskShowJobs

akshatpradhan

369 karma · joined April 18, 2012

http://www.ComplianceChaos.com

Policy Writer for the Big 5 (i.e. ISO 27001, HIPAA, FEDRAMP, PCI-DSS, and now GDPR!)

I’m also familiar with SSAE-18 SOC 2 and SOX ITGC.

##CompSec on irc.freenode.org

/r/HIPAA /r/PCICompliance /r/ISO27001 /r/SOC2 /r/FEDRAMP

submissionscomments
akshatpradhan··on Advice for new software devs who've read all those other advice essays
The situation you described doesn’t sound like “Right Way Guys”. It actually sounds like “Bikeshedding” [1]. This means giving a disproportionate amount of attention or importance to the trivial details while neglecting or giving less attention to the significant issues.

Imagine a committee commissioned to approve plans for a Nuclear Power Plant. But the committee spends all their time discussing the color of the bike shed that they want built nearby.

In your case, their focus on separate VMs for QA/Production, systemd deployments, templating system for a few strings, and an ORM for a few SQL queries, especially for a project with a limited user base (10 people) really exemplifies Bike-shedding.

They’re emphasizing minor, arguably unnecessary details rather than the core functionality or purpose of the project [2]. This usually occurs because these trivial aspects are easier to understand and discuss, especially for junior devs, which leads to increased involvement on minor details while the more meaningful parts of a project (which might be more challenging to address), are overlooked or given less attention.

IMO, a good leader knows how to strike a balance between the “Right Way” and avoiding the pitfalls of “Bike-shedding”.

[1] https://en.wikipedia.org/wiki/Law_of_triviality

[2] I would argue complete documentation of the meaningful parts of the project is not bike-shedding.

akshatpradhan··on AirPods with Wireless Charging Case
>and the ability to have different tips on them to increase fit for more people and to provide the option of sealing out outside noise.

This is the single biggest reason why I won't upgrade to the AirPods. For me, the AirPods simply fall out of my ears. That's why I stick with the Etymotic Ear Phonnes: https://www.etymotic.com/consumer/earphones.html

For whatever reason, that flanged shape fits my ears so perfectly well and blocks out all other noises that I don't see myself using any other Ear Phones for a long while. If AirPods provided the option of a flange shape like the Etymotics, then I'd be compelled to buy an AirPod.

akshatpradhan··on Democrats to push to reinstate repealed 'net neutrality' rules
This is a really good point and I'm not sure why you're being downvoted. Think of it this way, who the heck approves of an Incident Response Policy or an Information Security Policy without reading it? Oh wait, your downvoters would approve an Incident Response Policy without reading it, /facepalm.
akshatpradhan··on Marriott Concedes 5M Passport Numbers Lost to Hackers Were Not Encrypted
Can GDPR be used as an audit mechanism for breached passport numbers? And if so, what would that process look like? Can hotels be fined if they’re found to not be GDPR compliant?
akshatpradhan··on Marriott Concedes 5M Passport Numbers Lost to Hackers Were Not Encrypted
How does GDPR play into the requirement to store passport numbers?
akshatpradhan··on Amazon is paying to tweet nice things about warehouse working conditions
Yeah but all of a sudden this new title seems waaay more interesting considering the recent journalist describing his experience working as an Amazon Flex Driver. Just saying.
akshatpradhan··on Launch HN: The Buttermilk Company (YC S18) – Homemade Indian Food in 5 Minutes
Nutrition Label upfront, in words and text. I know there is a picture but I missed it, some of the nutrition labels are like the 4th picture.

Some of the starter packs don’t have nutrition label on it either.

akshatpradhan··on Apple reportedly arguing headquarter buildings are worth $200 to reduce tax bill
Don’t encourage heavy handedness by the government, instead push for a better system of checks and balances.
akshatpradhan··on Demand for Ruby on Rails is Still Huge
Double Pasta, now that’s embarrassing.
akshatpradhan··on Demand for Ruby on Rails is Still Huge
>Coverage is a measure used to describe the degree to which the source code of a program is executed when a particular test suite runs. A program with high test coverage, measured as a percentage, has had more of its source code executed during testing, which suggests it has a lower chance of containing undetected software bugs compared to a program with low test coverage.

In case folks are wondering about what we mean by coverage...

PS. Love Rails.

akshatpradhan··on Demand for Ruby on Rails is Still Huge
>Coverage is a measure used to describe the degree to which the source code of a program is executed when a particular test suite runs. A program with high test coverage, measured as a percentage, has had more of its source code executed during testing, which suggests it has a lower chance of containing undetected software bugs compared to a program with low test coverage.

In case folks are wondering about what we mean by coverage...

akshatpradhan··on Why Crystal is the most promising programming language of 2018
I think issues left open > 12 months is antithetical to the idea of lean/agile and could be a sign of suboptimal project management.

But don’t get me wrong, I <3 Ruby and am excited about Crystal.

akshatpradhan··on GDPR: Removing Monal from the EU
I started ComplianceChaos.com to sell my Policy Writing Services. I specialize in ISO 27001, HIPAA, and PCI-DSS.

I’d love the opportunity to add GDPR to my current list of specialities.

akshatpradhan··on Will GDPR Make Machine Learning Illegal?
It's in your best interest to reduce your risk by going through a De-identification process for data collected:

>De-identification is adopted as one of the main approaches of data privacy protection. It is commonly used in fields of communications, multimedia, biometrics, big data, cloud computing, data mining, internet, social networks and audio–video surveillance.

https://en.wikipedia.org/wiki/De-identification

akshatpradhan··on The Nightmare Letter: A Subject Access Request Under GDPR
If you want to collect and process data on individuals, then start implementing Security 101 basics:

* Data Classifications

* Privacy Impact Assessments

* Log Reviews

* Incident Reponse

akshatpradhan··on The Nightmare Letter: A Subject Access Request Under GDPR
You’re saying the following from GDPR doesn’t help?

* Data Classifications

* Privacy Impact Assessmemts

* Breach Escalations

* Access Controls

That’s more like Security 101 Basics to me.

akshatpradhan··on The Nightmare Letter: A Subject Access Request Under GDPR
>I know from direct personal experience to be real threats

Access Controls, Data Classifications, and Privacy Impact Assessments requested by GDPR are not a threat.

That’s just security 101 basics.

akshatpradhan··on The Nightmare Letter: A Subject Access Request Under GDPR
Exactly, GDPR is only asking for Security 101 Basics.

* Data Classifications

* Privacy Impact Assessments

* Log Reviews

* Incident Reponse

akshatpradhan··on The Nightmare Letter: A Subject Access Request Under GDPR
>The GDPR is trying to do a good thing, but it goes too far

By asking for:

* Data Classifications?

* Privacy Impact Assessments?

* Access Controls?

* Breach Escalations?

If your business is collecting and processing data on individuals, you should already have these Security 101 basics in place.

akshatpradhan··on The Nightmare Letter: A Subject Access Request Under GDPR
Then refrain from collecting and processing data on individuals.
akshatpradhan··on The Nightmare Letter: A Subject Access Request Under GDPR
>The parent comment

I wasn’t finished writing.

>we should write up 8 different formal policies?

Yes. That’s obvious.

akshatpradhan··on The Nightmare Letter: A Subject Access Request Under GDPR
>Please confirm to me whether or not my personal data is being processed. If it is, please provide me with the categories of personal data you have about me in your files and databases.

Data Classification

>a. In particular, please tell me what you know about me in your information systems, whether or not contained in databases, and including e-mail, documents on your networks, or voice or other media that you may store.

Data Classification

>b. Additionally, please advise me in which countries my personal data is stored, or accessible from. In case you make use of cloud services to store or process my data, please include the countries in which the servers are located where my data are or were (in the past 12 months) stored.

Asset Inventory

>2. Please provide me with a detailed accounting of the specific uses that you have made, are making, or will be making of my personal data.

Privacy Impact Assessment

>3. Please provide a list of all third parties with whom you have (or may have) shared my personal data.

Privacy Impact Assessment

>a. If you cannot identify with certainty the specific third parties to whom you have disclosed my personal data, please provide a list of third parties to whom you may have disclosed my personal data.

Privacy Impact Assessment

>b. Please also identify which jurisdictions that you have identified in 1(b) above that these third parties with whom you have or may have shared my personal data, from which these third parties have stored or can access my personal data. Please also provide insight in the legal grounds for transferring my personal data to these jurisdictions. Where you have done so, or are doing so, on the basis of appropriate safeguards, please provide a copy.

Asset Inventory

>c. Additionally, I would like to know what safeguards have been put in place in relation to these third parties that you have identified in relation to the transfer of my personal data.

Access Control

>4. Please advise how long you store my personal data, and if retention is based upon the category of personal data, please identify how long each category is retained.

Data Retention

>5. If you are additionally collecting personal data about me from any source other than me, please provide me with all information about their source, as referred to in Article 14 of the GDPR.

Data Collection

>6. If you are making automated decisions about me, including profiling, whether or not on the basis of Article 22 of the GDPR, please provide me with information concerning the basis for the logic in making such automated decisions, and the significance and consequences of such processing.

>7. I would like to know whether or not my personal data has been disclosed inadvertently by your company in the past, or as a result of a security or privacy breach.

Breach Escalation

>a. Please inform me whether you have backed up my personal data to tape, disk or other media, and where it is stored and how it is secured, including what steps you have taken to protect my personal data from loss or theft, and whether this includes encryption.

Backup

>a. What technologies or business procedures do you have to ensure that individuals within your organization will be monitored to ensure that they do not deliberately or inadvertently disclose personal data outside your company, through e-mail, web-mail or instant messaging, or otherwise.

Log Review

>c. Please advise as to what training and awareness measures you have taken in order to ensure that employees and contractors are accessing and processing my personal data in conformity with the General Data Protection Regulation.

Security Awareness Training

>8. I would like to know your information policies and standards that you follow in relation to the safeguarding of my personal data, such as whether you adhere to ISO27001 for information security.

Get an ISO audit.

akshatpradhan··on The Nightmare Letter: A Subject Access Request Under GDPR
All you’re telling me is that your Agile Startup doesnt have:

1) an updated Asset Inventory

2) a Data Classification Scheme

3) Data Labeling Policy & Procedure

Those are basic components of an InfoSec 101 course taught by Community Colleges and the top basic items GDPR is wanting.

akshatpradhan··on The US has forgotten how to do infrastructure
>As it stands now, some unforeseen circumstance in the field will necessitate a minor modification to the design. The contractor knows perfectly well what needs to be done, but instead of simply doing it, they will ask the designers to tell them to do it, so they aren't the ones responsible for it.

You always want peer review, even for a minor modifications. We have a similar process called code review.

akshatpradhan··on The US has forgotten how to do infrastructure
>This means every time there's a question, it has to be submitted through a formal process, tracked, answered, documented.

I don't know why you think proper change control is a bad thing. In both software and systems engineering you submit change requests that are tracked, reviewed, assessed for risk, approved and documented. You do this to create an audit trail to identify "how we got here". Any concerns? It's documented in the ticket.

Now when it comes to civil engineering projects, where bridges can collapse, you should WANT that kind of rigorous change control of tracking, approving, and documenting.

Yes, documenting change control requires more work, but it also saves lives and creates an audit trail in case of a grave error.

akshatpradhan··on Ask HN: What is the most common security mistake you see?
Most common security mistake: Lack of a Patch Management Policy that is actually followed.

Just look at WannaCry. The Patch was released March 14th and the worm was released May 12th.

That shows everybody who was compromised simply didn't have a regularly scheduled Patch Management Process in place.

From WannaCry Wikipedia page:

>A "critical" patch had been issued by Microsoft on 14 March 2017 to remove the underlying vulnerability for supported systems, nearly two months before the attack, but many organizations had not yet applied it.

>Almost all victims are running Windows 7 or newer.

Same with web apps, have a regularly scheduled Patch Management Policy in place for the Libraries, Gems, Modules, Packages, etc you use.

akshatpradhan··on Vue HN 2.0
Not to hijack this post, but there was another HN skin that was created a while ago. It was posted on HN about a year ago or something and it came in at 300+ points. What the skin/website did was sort the day's HN post by number of points. Does anybody know where I can find that?
akshatpradhan··on Ask HN: What're the best-designed things you've ever used?
I'm not affiliated in any way with this website, but I've been purchasing products recommended by www.ConsumerSearch.com since 2007 and I've been extremely pleased with all of their recommendations.

Some of those recommendations have been with me for 10 years and the designs are still easy on my brain.

akshatpradhan··on Mac-dev-playbook – Mac setup and configuration via Ansible
Have you seen Strap?

Strap is a script to bootstrap a minimal OS X development system. This does not assume you're doing Ruby/Rails/web development but installs the minimal set of software every OS X developer will want.

http://mikemcquaid.com/2016/06/15/replacing-boxen/

https://github.com/MikeMcQuaid/strap

akshatpradhan··on The U.S. Will Surpass China as the No. 1 Country for Manufacturing by 2020
>it's worth remembering that automation is going to result in that manufacturing resulting in less jobs. What's going to happen when people expect the jobs to come back but then they don't?

/u/Brightball posted this on HN and I felt it was a good response to your concern.

"One of the big perks to manufacturing is that it draws the entire supply chain around it naturally. Even if the manufacturing job itself isn't as abundant, the peripheral jobs that comes with it from shipping materials, producing materials, distribution, sales agreements, logistics, building construction and maintenance...they all provide benefits."

Page 1 of 8Next →