• rtxn@lemmy.world
    link
    fedilink
    arrow-up
    5
    ·
    edit-2
    1 year ago

    Our business-critical internal software suite was written in Pascal as a temporary solution and has been unmaintained for almost 20 years. It transmits cleartext usernames and passwords as the URI components of GET requests. They also use a single decade-old Excel file to store vital statistics. A key part of the workflow involves an Excel file with a macro that processes an HTML document from the clipboard.

    I offered them a better solution, which was rejected because the downtime and the minimal training would be more costly than working around the current issues.

    • SSTF@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      1 year ago

      downtime

      minimal retraining

      I feel your pain. Many good ideas that cause this are rejected. I have had ideas requiring one big downtime chunk rejected even though it reduces short but constant downtimes and mathematically the fix will pay for itself in a month easily.

      Then the minimal retraining is frustrating when work environments and coworkers still pretend computers are some crazy device they’ve never seen before.

    • Tar_alcaran@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      1 year ago

      The library I worked for as a teen used to process off-site reservations by writing them to a text file, which was automatically e-faxed to all locations every odd day.

      If you worked at not-the-main-location, you couldn’t do an off-site reservation, so on even days, you would print your list and fax it to the main site, who would re-enter it into the system.

      This was 2005. And yes, it broke every month with an odd number of days.

    • V4uban@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      As weird as it may seem, this might be a good argument in favor of Pascal. I despised learning it at uni, as it seems worthless, but is seems that it can still handle business-critical software for 20 years.

    • bleistift2@feddit.de
      link
      fedilink
      arrow-up
      0
      ·
      1 year ago

      cleartext usernames and passwords as the URI components of GET requests

      I’m not an infrastructure person. If the receiving web server doesn’t log the URI, and supposing the communication is encrypted with TLS, which removes the credentials from the URI, are there security concerns?

      • nudelbiotop@feddit.de
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        1 year ago

        Anyone who has access to any involved network infrastructure can trace the cleartext communication and extract the credentials.

      • ItsMyFirstDay@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        1 year ago

        I’m not 100% on this but I think GET requests are logged by default.

        POST requests, normally used for passwords, don’t get logged by default.

        BUT the Uri would get logged would get logged on both, so if the URI contained @username:Password then it’s likely all there in the logs

        • bleistift2@feddit.de
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 year ago

          GET requests are logged

          That’s why I specified

          the receiving web server doesn’t log the URI

          in my question.

  • Boozilla@lemmy.world
    link
    fedilink
    arrow-up
    5
    ·
    1 year ago

    Health insurance company I worked for would automatically reject claims over a certain amount without reviewing them. Just to be dicks and make people have to resubmit. This was over 25 years ago, but it’s my understanding many health insurers still pull this shit. They don’t care if it’s legal or not. Enforcement is lazy and fines are cheaper than medical claims.

    Obviously this is in the USA.

  • shadesdk@lemmy.ml
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    1 year ago

    The company would bid on government contracts, knowing full well they promised features that didn’t exists and never would, but calculating that the fine for not meeting the specs was lower than the benefit of the contract and getting the buyers locked into our system. I raised this to my boss, nothing changed and I quit shortly after.

    • drphungky@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      I worked in government contracting (and government, for that matter) for years and that blows my mind. I can’t remember the details, but if you even had a bad reviews, much less being found noncompliant, it could disqualify you entirely from some contract vehicles for a matter of years. Wild that there’s some agency that somehow lets people get away with fraud.

      Also, if that cost the government money, there’s a chance you could report that after the fact and make some money.

    • Tar_alcaran@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      The contractor I worked for was run by a man who used to say “if the contract says they’ll blow up the contractor on delivery, we’re putting in a bid and solve the problem later”

    • esadatari@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      eh DHCP isn’t really important right? obviously if it hasn’t changed since the 80’s why would you need to reboot your server.

      what are vulnerabilities?

  • esadatari@lemmy.world
    link
    fedilink
    arrow-up
    4
    ·
    1 year ago

    i worked for a hybrid hosting and cloud provider that was partnered with Electronic Arts for the SimCity reboot.

    well half way through they decided our cloud wasn’t worth it, and moved providers. but no one bothered to tell all the outsourced foreign developers that they were on a new provider architecture.

    all the shit storm fail launch of SimCity was because of extremely shitty code that was meant to work on one cloud and didn’t really work on another. but they assumed hurr hurr all server same.

    so you guys got that shit launch and i knew exactly why and couldn’t say a damn thing for YEARS

  • FireRetardant@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    edit-2
    1 year ago

    1-800-got-junk? doesn’t care at all about its environmental impact. No sorting what so ever happens to what goes on their trucks it all goes to landfills. All the ads will say they recycle and that they repurpose old furniture but I was threatened with being fired when I recommended donating antiques instead of dumping a load of furniture.

    More jobs and more profits comes before anything else in that company, including employee health and safety. Several times I was told to enter spaces we werent trained for (attics and crawl spaces) and carry waste I legally couldn’t transport (human/organic wastes and the laws states the driver is fined, not the company). One guy injured his shoulder during an attic job and was told to finish the shift or lose his job. Absoulte scum of a company with very sleazy management and possibly the labour board in their pocket as they kept “losing the files” when I tried to file a report with buddy’s shoulder (he was hesistant to report for fear of losing his job).

    • Mugmoor@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      I’ve had a few friends work for them out in Montreal, and their parent company (2 Men and a Truck). According to them it’s a mob-operated business.

      • Thwompthwomp@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Oh no! I had a great experience with 2 men and a truck when I he used them! No idea it was associated with the 1 800 junk folks

  • Whitebrow@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    1 year ago

    The programming team that is working hard on your project is just one dude and he smells funny. The programming team you’ve met in your introductory meeting are just the two unpaid interns that will be fired or will quit within the next two months and don’t know what’s happening. We don’t do agile despite advertising it. Also your project being a priority means it’ll be slapped together from start to finish 24 hours prior to the deadline. Oh and there will be extra charges to fix anything that doesn’t work as it should.

  • shittymorph@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    I used to work for a popular wrestling company, billionaire owner, very profitable, would write off any OSHA penalties as the ‘cost of doing business’ just as they did in 1998, when The Undertaker threw Mankind off Hell In A Cell, and plummeted 16 ft through an announcer’s table

    • Gearheart@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      1 year ago

      I want to believe… but the morph has always been exactly.

      “nineteen ninety eight when the undertaker threw mankind off hell in a cell and plummeted sixteen feet through an announcer’s table.”

      But I want to believe…

      Edit: looking back at previous shittymorph posts. Grammar, punctuation and delivery is at much higher standard… I’m sad 😢. I’m hoping that I’m way way wrong. Can anyone reach out to shittymorph on reddit to confirm?

      • shittymorph@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        That is quite an astute observation, in fact many folks would have overlooked such precise details. As you could imagine, with newness and changing situation such as a major platform shift, and as we enter a revolutionary technological time period in hopes of a prosperous fediverse, it’s easy for us to become a overzealous and infatuated with all the excitement, but we must remember, it pales in comparison to the crowd’s excitement in nineteen ninety eight when the undertaker threw mankind off hell in a cell and plummeted sixteen feet through an announcer’s table.

  • TerkErJerbs@lemm.ee
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    I quit a well known ecomm tech company a few months ago ahead of (another) one of their layoff rounds because upper mgmt was turning into ultra-wall street corpo bullshit. With 30% of staff gone, and yet our userbase almost doubling over the same period, they wanted everyone to continue increasing output and quality. We were barely keeping up with our existing workload at that point, burnout was (and still is) rampant.

    Over the two weeks after I gave my notice I discovered that in the third-party app ecosystem many thousands of apps that had (approved) access to the Billing API weren’t even operating anymore. Some had quit operating years ago, but they were still billing end-users on a monthly basis. Many end-users install dozens of apps (just like people do with mobile phones) and then forget they ever did so. The monthly rates for these apps are anywhere from 3 to 20 dollars per month, many people never checked their bank statements or invoices (when they eventually did, they’d contact support to complain about paying for an app that doesn’t even load and may not have for months or years at this point).

    I gathered evidence on at least three dozen of these zombie apps. Many of them had hundreds of active installs, and were billing users for in some cases the past three years. I extrapolated that there were probably in the high-hundreds or low-thousands of these zombie apps billing users on the platform, amounting to high-thousands to low-tens-of thousands of installs… amounting to likely millions per year in faulty and sketchy invoicing happening over our Billing API.

    Mgmt actually did put together a triage team to address my findings, but I can absolutely assure you the only reason they acted so quickly is because I was on the way out of the company. I’d spotted things like this in the wild previously and nothing had ever been done about it. The pat answer has always been well people are responsible for their own accounts and invoicing. I believe they acted on this one because I was being very vocal about how it would be ‘a shame’ if this situation ever became public, and all those end-users came after the company for those false invoices at one time. It would be a PR and Support nightmare.

    You have definitely interacted with this ecommerce platform if you shop online.

    • SreudianFlip@sh.itjust.works
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      4 months ago

      I’m unfortunately dependent upon said company, as a “partner”, which just means a hack indie developer who herds customers to the slaughter for the corp.

      The last round of layoffs was a brutal experience for the “Plus” customers. They lost crucial advisers and support, and now the guidance available is a bored and untrained chat support thrall on the other side of the world, or a stochastic parrot.

      You can smell the enshittification from here. The vendor lock-in is so intense it seemed inevitable.

      • TerkErJerbs@lemm.ee
        link
        fedilink
        arrow-up
        1
        ·
        4 months ago

        You’re absolutely right on all counts. And that’s why I quit (without waiting around to be laid off which frankly the severance package would’ve been nice). I got hired into the first (private) company I applied to, I’m thriving, and I don’t miss that stink of wall street/silicon valley money at all.

      • booty_flexx@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        1 year ago

        ✅️ is a shopping platform

        ✅️ has an app ecosystem with a billing api

        ✅️ high probability that someone who shops online has interacted with a store on the platform

        ✅️ multiple rounds of layoffs w/ staff stretched thin

        ✅️ unclear ambitions of being a megaplatform, beyond what it already is

        I guess we’ll never know, lol

  • pureness@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    Geek Squad, We were flying under the radar upgrading Macbook RAM, until one day we became officially Apple Authorized to fix iPhones, which means we were no longer allowed to upgrade Macbook RAM since the Macbooks were older and considered “obsolete” by apple, meaning we were unable to repair or upgrade the hardware the customer paid for, simply because apple said it was “too old”. it was at this point in my customer interaction, that we recommend a repair shop down the road that isn’t held at gunpoint by apple ;)

  • zazilicious@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    5 months ago

    I know this thread is old but: so many HIPPA violations, oh my God. I am a pediatric therapists/child psych, and the clinic I used to work at constantly stored client data in the most insecure ways, and therapists and staff would discuss client names, diagnosis’, address, EVERYTHING openly in the break room. I complained at one point, but it went nowhere. Turns out nobody cares, lol. They also frequently ignored the best interests of our clients to maximize profit from insurance (leaning towards fraud). I ultimately left the company when my boss blatantly violated the safety of one of my clients by refusing to send her home when she had a fever of 104 F. Sure, working with kids means everyone gets sick a lot, but when the child is THAT sick, they need to be in a hospital, not in a hot, cramped room with a therapist.

  • thrawn@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    It’s pretty depressing, but the fact that soil and groundwater are almost certainly contaminated anywhere that humans have touched. I’ve seen all kinds of places from gas stations, to dry cleaners, to mines, to fire stations, to military bases, to schools, to hydroelectric plants, the list could go on, and every last one of them had poison in the ground.

    • pfannkuchen_gesicht@lemmy.one
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      Some places are insanely polluted to the point where you wonder how a whole company could be so braindead and essentially poison themselves.
      A place not far from where I live had a chemical plant which just dumped loads of chemicals on a meadow for years. Now there are ground water pumps installed there which need to run 24/7 so that the chemicals don’t contaminate nearby rivers and hence the rest of the country.
      When taking samples from the pumped up water you can smell gasoline.

      • dammitBobby@lemm.ee
        link
        fedilink
        arrow-up
        2
        ·
        1 year ago

        We’re house shopping and there has been a house on a lake sitting on the market forever. I got curious and researched the lake and… It’s a literal superfund site. The company that was on the other side of the lake just dumped their waste chemicals right on the shore and it has polluted both the lake and ground water forever essentially because they don’t break down. I looked up the previous owner… Died of cancer. The shit that companies are and were allowed to get away with is just insane. Meanwhile right wing nut jobs want to get rid of the EPA (which was ironically created by Richard Nixon).

      • Flax@feddit.uk
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 months ago

        The largest lake in the UK by area got massively polluted and turned into a swamp of toxic green algae. It’s crazy how people just let stuff like that happen.

  • MrBodyMassage@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    There is a million times more counterfeit/fake items at amazon than you think, and they dont care one bit to fix the problem

    • Sharkwellington@lemmy.one
      link
      fedilink
      arrow-up
      2
      ·
      1 year ago

      I recall watching a video about the nature of how things are stored at Amazon warehouses - basically if there are multiple sellers offering the same item it all goes in the same bin. Even if you are providing a genuine product, there’s a very good chance one of the other sellers is not, and that counterfeit gets sent out attached to your seller ID. Then you get a complaint for selling a counterfeit item someone else provided.

      Then when that seller is caught and booted, they just register another trademark with 5-10 random characters and do it again. This is causing a massive headache for the US Trademark Office as well.

    • SweetBilliam@midwest.social
      link
      fedilink
      arrow-up
      2
      ·
      1 year ago

      I wrote a review about a counterfeit item I received. They never approved that one. I haven’t bought cologne from them since.

      • limelight79@lemm.ee
        link
        fedilink
        arrow-up
        0
        ·
        1 year ago

        I bought a bicycle light set (front and rear) a few years ago. They work fine (in fact, I still use the headlight; the rear still works, but it was replaced by a radar light), and I wrote a review. More recently, I was looking back through my purchases, and I came across the review I’d written, but the lights they were now selling on that page were a completely different design than the ones I had.

        I edited my review to note that the current lights didn’t match the ones I had, not that it’ll do any good with a million other reviews of those lights. I know Amazon doesn’t really care, but I very often see “There is a newer version of this item available here” links, so I’m surprised that this was possible.

    • netvor@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      I always thought there’s exactly 0 counterfeit/fake items at amazon, so … 0 times million … phew…

      /s

    • drphungky@lemmy.world
      link
      fedilink
      arrow-up
      0
      arrow-down
      1
      ·
      1 year ago

      they dont care one bit to fix the problem

      Who is they? Warehouse workers? Because without getting into too many details, I know someone fairly high up at Amazon corporate, and if I recall correctly her colleague runs a whole…divison? I don’t know, largish multi-person unit…and their whole job is addressing the counterfeit problem. I think it’s just really hard to do.

  • TemporaryBoyfriend@lemmy.ca
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    I work in IT. Most systems have laughable security. Passwords are often saved in plain text in scripts or config files. I went to a site to help out a very large provincial governmental organization move some data out of one system and into another. They sat me down with a loaner laptop and the guy logged me into his user account on the server. When I asked for escalated privileges, he told me he’d go get someone who knew the service account passwords.

    After a few minutes, I started poking around on my own… And had administrative access within an hour. I could read the database (raw data), access documents, start and stop the software, plus, figured out how to get into the upstream system that fed data to this server… I was working on figuring out the software’s admin password when the guy came back. I’m sure that given some more time, I could have rooted the box because the OS hadn’t been updated in years.

  • tvbusy@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    I worked as software engineer and my boss tolerated me going to office at 2pm and leave at 9pm. It’s against company policy, certainly, but no one talked about it. It still is my most productive and happy time.

    • rmuk@feddit.uk
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      I’m changing jobs at the moment. I accepted a position at a UK office of an American company which I was a perfect fit for but they wouldn’t tolerate remote working or flexitime. A few days after, I was offered a job at a UK company offering 80% remote work and very generous flexi but for £5000/year less. I let the American company know I wouldn’t be starting with them after all. Honestly, it this day and age flexible hours and such aren’t a big ask for most information workers and work-life life balance is too important.

  • TechyDad@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    1 year ago

    I worked for a pretty popular magazine back in the late 90’s. One day near the beginning/middle of 2000, we were all called down to the bullpen for a last minute meeting by management and marketing. (That’s never a good sign.)

    We were told that we have a great product with amazing writing, but marketing doesn’t know how to sell it so they’re closing us down. Instead, we went online only. I was the web developer so I survived the firings.

    So then we figured that we were set because our website produced more content and had more traffic than any of the company’s other websites. However, in March of 2001, we had another emergency meeting. Again, we were told our content was great, but the company was going in another direction. Instead of producing our own content, the company was going to just repost other sites’ content. I and everyone else in my team were let go.

    Needless to say, the whole “we’ll just repost what other people posted” plan didn’t go so well. Last time I checked, the company wasn’t doing very well at all.