TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Moving Fast and Securing Things

375 pointsby Chris911about 7 years ago

12 comments

wpietriabout 7 years ago
One of the things I think about when analyzing organizational behavior is where something falls on the supportive vs controlling spectrum. It&#x27;s really impressive how much they&#x27;re on the supportive end here.<p>When organizations scale up, and especially when they&#x27;re dealing with risks, it&#x27;s easy for them to shift toward the controlling end of things. This is especially true when internally people can score points by assigning or shifting blame.<p>Controlling and blaming are terrible for creative work, though. And they&#x27;re also terrible for increasing safety beyond a certain pretty low level. (For those interested, I strongly recommend Sidney Dekker&#x27;s &quot;Field Guide to Understanding Human Error&quot; [1], a great book on how to investigate airplane accidents, and how blame-focused approaches deeply harm real safety efforts.) So it&#x27;s great to see Slack finding a way to scale up without losing something that has allowed them to make such a lovely product.<p>[1] <a href="https:&#x2F;&#x2F;www.amazon.com&#x2F;Field-Guide-Understanding-Human-Error&#x2F;dp&#x2F;0754648257" rel="nofollow">https:&#x2F;&#x2F;www.amazon.com&#x2F;Field-Guide-Understanding-Human-Error...</a>
评论 #16995682 未加载
评论 #16996009 未加载
评论 #17001475 未加载
vasilakisfilabout 7 years ago
I am in favor of checklists for certain critical tasks, even if they are repetitive and&#x2F;or boring. I think checklists are underrated.
评论 #16995476 未加载
评论 #16995229 未加载
评论 #16995498 未加载
评论 #17001630 未加载
评论 #16999039 未加载
ejcxabout 7 years ago
I love this! If you&#x27;re a part of a security team and you are not automating your processes and procedures then your team is going to drown. You must automate.<p>It seems like some simple checklist app but having a non Jira process that takes only a few minutes is so valuable, and &quot;security reviews&quot; and &quot;threat models&quot; as part of your SDLC take insane amounts of time and honestly aren&#x27;t super helpful.
评论 #16995545 未加载
评论 #16995328 未加载
maccardabout 7 years ago
&gt; At the start of 2015, Slack had 100 employees. Today, we’re over 800 people!<p>That&#x27;s a lot of people...
评论 #17006101 未加载
punnerudabout 7 years ago
I like the addition question if you are using C&#x2F;C++: «We confirm that we really, really need to use a non-memory-safe language.&quot;. PHP&#x2F;Python&#x2F;C&#x2F;C++ get Medium Risk directly, Low Risk: WebApp&#x2F;API&#x2F;MessageServer&#x2F;iOS&#x2F;Android&#x2F;Electron&#x2F;WindowsPhone
spydumabout 7 years ago
So glad they finally published this, saw the OWASP AppSec talk, was eagerly awaiting it.<p>However - I would want to caution: I think this model works because Slack has a self-described &quot;culture of developer trust&quot;. I tend to think, they hire bright engineers and ensure they are equipped to do the right thing. I believe the vast majority of organizations are NOT ready for this. I direly want them to be, but simple fact is there are too many mediocre developers, and they can&#x27;t be trusted without guardrails (and some straight up need babysitters).
JepZabout 7 years ago
And I thought &#x27;security&#x27; itself is friction ;-)<p>No seriously, I was wondering if that tool has a CLI interface? Might make it more accessable for some devs.
mbidabout 7 years ago
A security app written in PHP. Nice touch.
hhaidarabout 7 years ago
The company I work for has been offering an enterprise level service like for about 8 years now: <a href="https:&#x2F;&#x2F;www.securitycompass.com&#x2F;sdelements&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.securitycompass.com&#x2F;sdelements&#x2F;</a>
mikekeyabout 7 years ago
Well written and timely for me. I would like to see this capable of something other than Jira though :&#x2F;
评论 #16996568 未加载
jrochkind1about 7 years ago
this is really cool.
boffinismabout 7 years ago
&gt; The process of deploying code to production is very simple, and takes about ten minutes total. This results in a life cycle in which we deploy code to production approximately 100 times per day.<p>What? They spend 1000 minutes out of every 1440 deploying to production? The deployment process is occurring over 16 hours out of every 24? Am I the only one who is nonplussed by this?<p>EDIT: Ok I get it, I get it. I guess I always worked in much smaller companies where CD meant deploying about 10 times a day tops. TIL big companies are big.
评论 #16994905 未加载
评论 #16994839 未加载
评论 #16994838 未加载
评论 #16994981 未加载
评论 #16994805 未加载
评论 #16995174 未加载
评论 #16994825 未加载
评论 #16994790 未加载