12 comments

  • moribvndvs a day ago ago

    I’d like to see these comments copied over to the “reason for termination” field in their personnel file.

    • ryandrake a day ago ago

      They'll be copy/pasted into their promotion and bonus letters instead.

    • cyanydeez a day ago ago

      Culpability for police see also. ...

      LMAO

  • tangotaylor a day ago ago

    And this is why I donate monthly to EFF. Nice find.

  • jauntywundrkind a day ago ago

    This is why police unions are starting to talk about shutting down Flock: because it's a hazard to police. Because the normalized abuse of power that pervades policing is actually visible here.

    • sublinear a day ago ago

      I agree that it is to some extent about optics for the cops, but access controls and properly scoped authorization are always problems everywhere in software.

      That's not to say we should let any of this slide, but that we should realize it is time we take this aspect of security more seriously. We are living in that future now. Yes, your shitty janky auth scheme is causing real problems right now and yes it sometimes is life or death.

      We're missing an entire category of software that manages permissions in more dynamic ways... Meanwhile, about a third of devs out there don't even know or care about the difference between authn and authz.

      • jauntywundrkind 17 hours ago ago

        certainly something we've seen an epic-facepalm on with the huggingface hack. oh your mongo all just uses one static username/password. oh your cross-cluster connection is all one password.

        reciprocally though i think the top down securitization of systems with only proper access control has taken out a lot of the grease that used to greatly ease how companies related to the world in really good ways. even when you do get through to support on the phone, there's often such a grim expectation that they will be in no way able to help you, that they don't really have access to information or corporate processes that are going to do anything for you.

        we (engineers) look at defined behavior & constraints as secure, safe, good. but i think the informal processes and laxity from the pre-coded world allowed companies to better actually help people and to be good, in important ways. we have to recognize that mechanization is not always a good force too, while also starting to take more seriously too that we often do need more oversight/guards/access-control too. it's paradox, it's duality, but we have to recognize both ends as dangerous.

        • sublinear 7 hours ago ago

          Yes, I'm saying if we are going to "mechanize" as you say, there are a ton of missing integrations to provide that authorization context. These abuse stories sound like we're far too dependent on a backlog of audits that grows faster than they can be executed (if ever).

          We need more dynamic systems that can match the real-world pace that these investigations occur. This doesn't even necessarily mean "automation", and it's not clear whether that would make things worse.

          It makes me wonder what other processes are being overlooked, even going way back long before computers. Anyone who has received a simple citation for speeding can attest that it was probably blank or damn near. Apart from the cop not showing up in court, this is a common reason to get it dismissed. We've been normalizing these kinds of failures for much longer than we've had computers involved.

          There's a deeper problem here, but we can't keep placing all the blame solely on cops or devs. There has to be a way to fix this. There just have to be other disciplines with similar problems that were resolved without any drama simply because there's less noise and politics in the way.

  • swed420 a day ago ago
  • sznio 16 hours ago ago

    actual cops or script kiddies that found a way to impersonate them?

  • writtenone a day ago ago
  • jamesnorden a day ago ago

    Waiting for the "think of the children" bots.