[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Story time, /g/. I'm a code monkey currently looking for

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 27
Thread images: 7

File: leakedkeys.jpg (31KB, 599x447px)
leakedkeys.jpg
31KB, 599x447px
Story time, /g/. I'm a code monkey currently looking for a new job, and one of my suitors sent me a technical challenge to do. I strongly prefer these to beating my head against a whiteboard in front of strangers, and have had success with them in the past, so I was excited to take a look at this one.

Holy shit, what an incredible shitshow I've stumbled into.

I'm 99% certain they sent me a snapshot of their production code/data, including client data and API keys. Besides including PII, they also sent me both their test AND live Stripe API keys, plus credit card tokens. At this point I'm still in shock and trying to decide the best course of action, but I'm curious what kind of suggestions you guys will come up with.

Pic somewhat related. Feel free to post similar experiences with the results of normies being allowed to handle sensitive data.
>>
Roll for a wisdom check against your morals. DC12, since it's sticky whether or not they intended it.
>>
>>55777644
lookie here, you're looking for a job, they may have given you these keys but it's pretty obvious what you should do with it.

if you want the job, just do the technical challenge and contact your recruiter about this issue, you might even get a better offer
>>
>>55777702
That's where it's sticky, quaddie.

If the situation is as such, this is either unlikely test or a sign of utter incompetence.

The latter is far more likely.
>>
Do you want to work for people who would make that type of mistake.
>>
>>55777702
It's not like I'm considering stealing their money, at a minimum the digital trail would easily land me in prison. But do I really want to work at a company with such shit security practices? Do I write something up on Medium and post it to HN? Do I email Stripe security informing them that one of their clients is just hanging out their API keys?
>>
>>55777719
*an
>>
>>55777732
You'd really be fucking them over, publicizing this. There's consequences for that, but go figure.

No point going black on this stuff, ought to just wash your hands of it and consider other employers.
>>
How long has it been since you'd gotten all this?

How long will it be until someone realizes what they've done?
>>
>>55777756
Yes, but how many other people have they sent this to? The zip is dated a week ago, am I the first? If I just tell them they fucked up and move on, will they actually do anything about it? Don't their clients deserve to know that their names, addresses, phone numbers, drivers license numbers, and other shit are being emailed around like it's nothing? It's not like they don't deserve to get fucked a bit.
>>
File: transcended common sense.png (334KB, 694x524px) Image search: [Google]
transcended common sense.png
334KB, 694x524px
>>55777644

They did that on purpose. They're testing your moral fortitude. It's all bullshit that they're pretending is real to see if you'd actually do something bad with it.
>>
Another point I should bring up is that this challenge is utter bullshit. It's one thing to ask me to write up some dinky little program with no practical use, it's another thing entirely to essentially ask me to implement a feature in your product. Fuck that.
>>
>>55777644
>inb4 its a test server with some randomized data that only works there
who da fuck would give away _production_ details to an outsider?
>>
>>55777819
Starting to seem a lot more like some oddball communication test.

If you're down for muscling past awkwardness, be a mensch and call somebody about it ASAP
>>
>>55777824
That's what I thought at first, and honestly keep hoping for. Some of the data is obviously fake, with names like Abe Lincoln, but unless they've created fake Facebook profiles for the rest of the client data, it would seem to be real. There's way more data here than there needs to be just for running tests.
>>
>>55777871
What time is it where you're at? You should call them.
>>
File: 1422449823525.jpg (27KB, 440x570px)
1422449823525.jpg
27KB, 440x570px
>>55777777
>>
You're an idiot if you don't abuse that. I wouldn't know where to begin looking, but I'm sure there's some fuck out there who would gladly pay for that kind of information.
>>
File: .png (419KB, 2527x2207px) Image search: [Google]
.png
419KB, 2527x2207px
@55777777
>no fun allowed
>>
File: chess.gif (26KB, 300x300px) Image search: [Google]
chess.gif
26KB, 300x300px
>>55777777
>>
Call'em, tell'em
>>
File: check these dubs.jpg (76KB, 1102x636px) Image search: [Google]
check these dubs.jpg
76KB, 1102x636px
>>55777777
impressive
>>
>>55777677
Underrated
>>
File: 1468290130183.jpg (38KB, 934x325px) Image search: [Google]
1468290130183.jpg
38KB, 934x325px
>>55777777
Nice integers senpai.
>>
>>55777777
this is a number
>>
>>55777777
Checked
>>
>>55777819
I suspect they don't want to hire you, they just want you to do this one implementation and then profit off in while not paying you or a contractor for it.
Thread posts: 27
Thread images: 7


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.