The piece the author is missing, and why zendesk likely ignored this is impact, and it's something I continually see submissions lacking. As a researcher, if you can't demonstrate impact of your vulnerability, then it looks like just another bug. A public program like zendesk is going to be swamped with reports, and they're using hackerone triagers to augment that volume. The triage system reads through a lot of reports - without clear impact, lots of vulnerabilities look like "just another bug". Notice that Zendesk took notice once mondev was able to escalate to an ATO[1]. That's impact, and that gets noticed!
> Why’d he quit? ... he told me this: at each stage of a company’s growth, they have different needs. Those needs generally require different skills. What he enjoyed, and what he had the skills to do, was to take a tiny company and make it medium sized. Once a company was at that stage of growth, he was less interested and less good at taking them from there.
This is an aspect that gets overlooked in many businesses & careers. I've heard it phrased that companies go through 3 stages: Startup, Scale Up, Optimize. The above quote is a sub-stage of Scale Up. Some people are built for just a single stage and knowing how and where your skillset fits in is crucial to career happiness. As well as knowing when to encourage employees to move on.
Great post and I wish @steveklabnik continued success in his career!
> Getting motivated to lift 2x a week is another issue...
Was in the same boat until I started doing group classes. Used that to build accountability, motivation, and a "vocabulary" of how the gym works. Now I could spend hours at the gym by myself and love it. Find what works for you, cuz lifting is a blast!
When devs are promoted into management or team lead positions they are not given adequate training on what it means to manage / lead. Thus devs don't learn what good management is, and the stereotype of the bad manager perpetuates.
> 'progressive' practices such as unlimited vacation
Unlimited vacation is not progressive and it is also unhealthy.
It causes feelings of guilt while on vacation. Often there's an unspoken obligated to check-in (email & chat) when on vacation. And leads to taking fewer vacation days not more. When leaving a company, they have no obligation to pay out accrued vacation days since there is none defined (this may be a Canadian thing). Additionally, it can also come with the unspoken culture of overtime, since it can easily be made up with "more time off".
Having worked with unlimited vacation, if I am ever offered it again, I will decline and negotiate defined vacation into my employment agreement.
Your solution of mapping to a grading system A,B,C,D; or terrible, crap, better, best was mentioned in another thread about this article. It's a common thought, however it's incorrect because you're still leaking substantial information about passwords. By storing entropy of any kind: whole number, graded, > threshold, etc you are weakening your password hash. This is completely unnecessary where better solutions exist: TFA
It's an assumption on my part, and anecdotally a correct one. Having included this entropy example in a number of talks and asking the audience what's wrong, the majority of the technical audience did not know, nor did they have an appropriate guess.
One friend is in a townhouse in North Vancouver. Rented for a while, then bought. Real-estate is stupid silly there. I've also heard talk of people moving to Victoria as an alternative.
I can speak a bit for western canada; Vancouver has seen many of the larger/top companies open offices: Microsoft, Facebook, Amazon, etc. so plenty of jobs to be had there. I live in Calgary and have seen many peers move to Vancouver for better job prospects.
Re: SRED credits - I've been a part of the application process twice. Documentation can be a bit cumbersome, but not much more than 5 minutes summarizing the weeks work in a spreadsheet (for each employee), and tracking their hours spent on related tasks. Add in source control and the numerous artifacts that software devs come up with, means low amount of effort for high payout. And by high payout, I'm talking 1-2 devs salary in a 10 dev shop. We also hired a consulting company that specialized in SRED applications which saved us a ton of overhead. Cost 10-20% of payout, but was worth not having to deal with the application and/or any audits had they occurred.