Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

i'm the one who set the password

security is not a requirement for many startups, velocity is



> i'm the one who set the password

You, personally, set the password to a public internet-facing database to 'abc123'?

And if you really did, how much do you estimate that increased your 'velocity'?


you built a internal project, co-hosted with a database, with a password 'abc123'

a month later, your manager decided to share it with other teams, the decision was made in a meeting which you're not invited

when the manager came to you, you asked:

- how about give me a week to make it a saas, with authn/authz

- no, we don't have the time, just tell them the endpoint and the password

another month later, something changed, your company built a partership with another company, your manager decided to share the project with teams in the other company

you asked:

- how about we do something like virtual network peering so that we can share a connected network with our parter

- it's complex, we can not change the network status of our partner, and we don't have a responsible role for this work, just give them the endpoint and the password

password 'abc123' is just a analogy, in this case, there's no password at all


And virtual network peering requires a license in China anyway.


I literally can hear Jimmy Yang as Jian Yang in Silicon Valley narrate this...!


I have no idea why people are downvoting first-hand information. Take an upvote!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: