Get Coffee

As we navigate the aftermath of the layoffs, there is (as can be predicted) a certain amount of uncertainty (or, to get Rumsfeldian, a lot of known unknowns) — what gets picked up, what gets redistributed, what we do in the interim. “Interim” is doing a lot of work here – there is nothing more permanent than a temporary solution, and the desire to have certainty — at the expense of a more solid plan that takes longer to navigate — is understandable.

It’s overwhelming.

If you are a person who has to-do lists and likes to check things off with a satisfying finality, this stage of corporate life is not for you. It’s a bit like having a super-long list of to-do’s, identifying that, “Wow, that’s a long list”, and then writing “get coffee” on the list because at least that is a box you can check with certainty and finality. Although with coffee is there ever really finality?

I was talking through the recent changes with a coworker, and we were discussing what we do to decompress — there’s the extended workouts, there’s “setting boundaries” (though for one tethered to one’s laptop, boundaries are fuzzy). (Side note: Any tech company you work for will take from you everything you give to it: if you want to work 80 hour weeks and compromise your home life, they will not stop you).

At any rate, as we talked through coping mechanisms, I shared one of my deepest, darkest secrets: I have been playing one of those farming games. You know, the kind where you start out with a little barn and like four squares of field and you grow wheat, and then after a bit you get to grow corn, and then after a bit you get to have a cow and make “cow feed” from the corn and wheat to feed the cow which then gives you milk, okay so now you have milk so you can make cheese, and with the cheese you make a burger, which you can then sell at the market and put on a train, etc…

It is *addictive*. It offers certainty – Wheat takes five minutes to grow in the game, and two wheats and one corn equals one cow feed, which takes 15 minutes to make. Things happen at a predictable rate, with a designated formula, and it is a box-checker’s dream.

In this game, you can throw money — real money– at it. There’s “town cash” which is purchasable or earnable, and of course all the good stuff — stuff that helps you grow faster — is for sale. I, however, am stubborn, and am refusing to give this game any real money – so I have to patiently wait for the trains, or boats, or what have you. I have a plethora of nails but not enough hammers to expand my barn, but I will NOT be giving this game any real money and instead force myself to wait to check the box. The advantage here is *I* get to control when the box is checked and if I really wanted to, I could throw money at the problem.

In the corporate reality one can throw money at the problem, too, but much as with me and my little farming game, there is a discipline not to do so. A forcing function of “do more with less” in which there is considerably more and considerably less, combined with an eye towards efficiency, means fewer boxes will be checked, and we will have to have patience to load the trains.

I’ll be writing “get coffee” on my to do list today.

Posted in Uncategorized

And so it goes…

Tuesday was perhaps the hardest day in my working professional life. I have worked in the corporate world for just about 32 years, and on Tuesday I had 13 conversations with people who had been informed, on Monday, that they no longer had a job. That it’s not them, it’s us; here’s a package, it’s a super nice package and by all accounts nicer than they’d get at another company, and best of luck. I didn’t get to have that conversation. The conversation I got to have is, “now that your world has been upended can you let me know just how much work is going to drop to the floor or have to be reprioritized and oh by the way is everything documented?” I got to have that conversation on Tuesday. With 13 people.

Thirteen of course is not the number of impacted people from last week’s layoffs. It’s more than 100 times that, and there promises to be more. Those that have left are given a package and luck; LinkedIn is awash with green “open to work” and badge pics. Those that are left are awash in ambiguity, apprehension, and more than a little agita. As one person put it, “The herd is spooked. The herd is spooked and feels like they have been lifted from grass to desert, and do not know where the grass is.”

This is valid.

Tuesday was hard for me, but it wasn’t nearly as hard as it was for some 1600 people on Monday. Some of those folks have small children at home. Some of those folks are taking care of parents and extended family. Some of those folks are in the prime of their career and if you need security professionals, compliance professionals, and technical program managers deeply familiar with AI please do hit me up as I have a roster.

Tuesday was hard for me, but it wasn’t nearly as hard as it will be for the remaining thousands of folks who have the unenviable task of identifying what work — work that is/was good, righteous, and important — has to drop, or somehow has to fit in; inasmuch as we would like to think “removal of bodies == removal of work” I have never seen it work that way. We are consistently encouraged to do more with less, although I am certain someone has a calculus formula that proves that isn’t a permanently tenable position.

Tuesday was hard for me, but it did serve to show me a few sides of the collective humanity of the working community: I had several people checking in on me (some at work, some not at work) to genuinely see if I was okay. (I’m okay). I had a few more that popped onto my LinkedIn to view my profile, in what I could charitably assume was a check-in (or uncharitably assume was an attempt at schadenfreude). The most gracious, empathetic, and optimistic people I encountered on Tuesday, *and since*, are the people I had those first conversations with. Riddle me that.

If you are/were impacted by recent layoffs:

Posted in Uncategorized

The Audacity of Scope

When I was a kid, we had this little black and white TV that I got to have in my room — I was about 9 — that I was allowed to watch on Saturday mornings. My guess is that its purpose was a combination of peace and quiet for my parents and a place to store it. I’d watch cartoons, then drift into Gilligan’s Island. Life was definitely simpler (because I was a kid, and I didn’t read the paper apart from the funnies, and so I hadn’t yet heard about trickle-down economics).

The TV was old and this was a time where TVs had I think five or six channels, tops. Not all of the channels would actually have content, and so if you hand-cranked the dial to a channel that had no content, you got to see what we called “flyraces” — the black and white scatter screen with white noise, which in itself could be moderately entertaining if you were a bored kid and you decided you would try to “follow” a fly or two. When I was really imaginative, I’d try to predict, or even will, a given fly to go in a given direction. Keep in mind this was at a time where nearly every report card I got said, “Bobbie would do so much better in class if she just *applied* herself.” Bobbie was applying herself to flyraces.

Some decades later and the news and media input into this brain are… flyraces. Each and every little dot of black is a new attention-grabber and generally it’s not good. “If it bleeds, it leads” is true and there’s a lot of blood; even the most antiseptic, clinical assessment of things is depressing. The moderately entertaining flyraces of my sheltered youth have morphed into a cacophony of fear, hate, and what could only charitably be called idiocracy.

One is tempted to turn the TV off. After all, if you don’t read, or watch, then there’s nothing to depress you, right? A sheltered take – the only people who’d have the luxury of that are the ones who aren’t impacted by the various policies enacted. The parents trying to make their rent and pay their health insurance in a world where their transportation costs are skyrocketing (along with said health insurance) would not be comforted by not watching the news — the bills still come due. To look away is irresponsible; to continue watching is detrimental.

My current solution is scope – I am trying to pay attention to two to three flies, ones I can follow, and ones that I can (perhaps) do something about. The usual things – how one votes, where one’s money goes (for a vote with dollars is also a vote), where one puts one’s energy and time — apply here. I cannot track all the flies, so I try to choose which flies to follow and nudge. The cacophony of the other flies still abounds though; their visual impact still seeps through. Attempts to “scope it down” to just my flies often fail. I keep trying, though.

I am increasingly having difficulty with the differing opinions people have about living in a society. By definition, society is a collection of people living in some sort of organized pattern. I think the disparity of belief is in the next part that I take as a requirement of society: for the common good.

A basic reading of evolutionary genetics tells you that the chief principle of evolution is “fuck you, I’ve got mine”. As long as this gamete can use a zygote to make more gametes, game on. To make more progeny, at whatever cost, is what a “successful” evolutionary pattern wants: even if it costs the progenitor their life (mantis, octopus, etc.). Except that there is evidence for altruistic patterns wherein “fuck you, I’ve got mine” is NOT the way to go: that evolutionary altruism leads to the greater good for a given species… or society.

The tension here is what one considers “society”. Is society “my people” (so in terms of “fuck you, I’ve got mine”, is “mine” and “I” an assumed collection of like-minded individuals) or is society “the people” — ALL of the people. Not just the ones of your racial construct, or your religious affinity, or your immediate vicinity. There are some of the society that think of “mine”, and some of the society that think of “all”. And as long as we – the collective, larger we – differ in who we are talking about, we will continue to have these very big, very real, and very existential problems.

There are people who need to have a counterperson to compete against – the “yours” to the “mine”. They *need* to have “fuck you, I’ve got mine” because on some level in their head it makes things better — they cannot see benefit without seeing comparison. They need the “fuck you” part of the equation in order to operate. They are not scoping down to a couple of flies because they cannot keep up with all of them, they are scoping down to a couple of flies because they want their flies to be the only flies in the race. Therein lies the rub. As humans, we are limited in our ability to handle all of the things at once, and so must focus on a subset: how we choose to view the rest is the differential here. For some folks, the rest is “more to focus on once we get this part sorted”, and for some folks, the rest is to be fucked, for they’ve got theirs. Until we have a greater acceptance of the former, we will be stuck contending, cajoling, and combating with the latter.

Blocks

Four weeks ago*, at 6:30am on a cold Friday morning, I was on a ferryboat looking out at grey and fog over cold water, with the *bitterest* coffee I have ever had, on my way to an all-day nonprofit seminar, and if that isn’t the most Pacific Northwest thing I could do, I don’t know what is.

I am here for it (well, most of it. The coffee was admittedly a disappointment). I’m also keenly aware that I have, YET AGAIN, signed up for All the Things.

Being on a ship with no internet for 30 minutes meant I had time to figure out why I do this. As my husband and I looked out over our next couple of months we found there is no down time. None. There is always something to do/to be done, always a commitment. I think largely it’s a conflation of “living” with “busy”. Think about it – when you hear people use the phrase “living life to the fullest” you imagine — or at least I do — bungee jumping or some sort of extreme activity. I am grateful my meetings are not like bungee jumping.

This (the Do All the Things) is not happenstance; it is deliberate, even if I do not recognize it in the moment. If I keep myself very busy, I don’t have to pay attention to the things that bother me: I keep myself very busy because it is a measure of control, and also of comfort: as the world turns, churns, and burns, I can at least say I’m *doing something*. I cannot move mountains and I cannot move governments, but I can help people get housed and fed and educated. I can help people do what they need to do so they can do what they can control; and maybe if enough of us do that we can collectively steer the ship – or steer those steering a ship.

“Compartmentalization”. “Mindfulness”. “Deliberate Action”. These are all mantras as we go into intense or busy periods, and they mostly cover the how-to. To be clear, not all of the Things I am Doing are in service to others. There’s fun stuff in there too — like a series of running events, a vacation, hobbies, friends, family — but fun things require preparation and planning, too.

Which works really well until something catches up to you. The very next week after my ferry trip, I caught a bug and was laid out for a day – a day in which I had something like 10 meetings scheduled. I managed to attend six of them and divert four. Tell me why I felt guilty, even though I slept in until 7 and went to bed at 5.

There’s a specific comfort (to me) in the logistics of life. Do this thing here in preparation for that thing there, and then that thing will be better off by it. My current challenge is when you layer so many blocks of preparation, it becomes a very tight Tetris game. The music speeds up, the blocks speed up, and they pile up. Understand this: I was — and I think still am – very, very good at Tetris. I reliably got to the Space Shuttle when playing, and the faster the music went the better my “flow state” got. Until it didn’t. The fine thread I am and have been seeking is that state *before* game over, where I can Do All the Things but do not crash. In the videogame (and this was the old days, with an actual console and an actual cartridge you had to actually blow on) you hit “restart”, in life it tends to be your body (or your brain, or both) hitting “restart”.

So, the music is speeding up, and the blocks are speeding up, and so far, I’m able to keep up. I’m going to go for the Space Shuttle, again.


Things I’m Specifically Doing

*Posts aren’t infrequent because I don’t have time (well, not entirely because of that). It’s just there is so much in the world right now, and I feel like I can only occasionally dip in and say things, without adding (too much) to the cacophony.

Memory Lane: Syria & the Model UN

In 1992 or 3– memory is a little fuzzy — I was part of the Model United Nations and the country we were representing was Syria. I remember thinking “I know nothing about Syria” and having to cram as much information as I could to prepare. There was a delegation of us, I think… 8? 12? I just remember probably six of us crammed into a hotel room in New York, where the final event is held, toward the end of the school year. It was my first trip to New York, and I learned a lot.

West Point had, if I remember correctly, Burkina Faso. I do not know why I remember that. I just remember seeing what looked like two very white bro-dudes representing Burkina Faso and then looking at our delegation of mostly female persons representing a country that only superficially extended any rights to female persons.

To establish the zeitgeist of the moment: the US had just “won” the first Gulf War (fun fact, I was on an airplane to Australia for the student exchange when we declared war. The pilot shared that on the overhead. I and some 30 other exchange students didn’t know what to do with that), the “Middle East” was and had been for some time a scary place (inasmuch as all the news we got at the time was about scary things happening there). There was no internet (or none that was easily navigable to), and news was something you either got from a physical newspaper or from 6pm-8pm on TV. Heading to New York to effectively pretend to be Syrian — as a female person, in the company of *mostly female people*– was going to be an interesting prospect.

It was straightforward – act in “your own” interest. In the case of Syria, that was one of a wedged country – Syria participated in the Gulf War on the side of the US (because the alternative was siding with someone who would be interested in invading Syria) but also had a history of cracking down (murderously) on its own people. On one hand, Syria could be simply oversimplified into “bad guys in the Middle East that we had to work with against a worse guy” (plus assorted other stereotypes) and on the other hand how do you concentrate millennia of cultural history into context for play acting over 3 days? Not terribly well.

In pursuant years Syria remained a talking point on the nightly news as a Player In The Middle East and the older I got the more I understood (or thought I did) about how they moved in their local sphere (or internationally). Remembering my time in the Model UN meant I attached a little asterisk in my head to mentions of Syria; thinking back to “oh remember when you oversimplified their international stance over a 3-day period in an ironically mostly female representation?”

All is not wine and roses in Syria now; they still have crushing poverty and homelessness; they still need medical support and humanitarian aid. Yet this morning, I opened up the latest article in my inbox from the Economist to see that Syria is the Country of the Year – much improved and more democratic (yes, a subjective take), having shed itself of a dictatorship (and put in some measure of stability in the ensuing year). It had stiff competition — as noted in the article — but really, a transformative year. One that cannot, and should not, be oversimplified.

You can donate to UNICEF in support of Syria here.

If you’d rather donate closer to home, you can donate to Habitat for Humanity here.

You can learn more about the Model United Nations here. Most schools have to fundraise for their delegations and materials, so if you have an alma matter and if you have an interest, you can reach out to them and provide support.

It’s the Most Wonderful Time of the Year, Part II

Working on the premise that during these holidays you find yourself in situations where you are “the explainer” and/or see the need to be one, here’s a guide on what you can do about data.

Specifically, your data. Or encourage people to do with their data.

The very first part of this is a bummer so you may want to pull up a glass of eggnog while choking this down (if you aren’t already choking on the eggnog): your data is not 100% private no matter what you do. Not ever. The only thing you can control (somewhat) is the length to which it is shared and the compartmentalization of that sharing so as to reduce the amount of destruction that can happen with a Data Breach. The other bummer with Data Breaches is that they are not something YOU did wrong – some entity that was responsible for storing data was infiltrated by Bad Persons who now have your data. Even if you had a unique password, even if you had MFA. Usually what gets stolen are credentials (the ID part of them, hopefully not the actual passwords) because what is supposed to happen is that sensitive things like social security numbers, credit cards, etc. are supposed to be “hashed“. That said, there are clever hackers and there are dumb companies, and so you don’t want to trust that everything works “the way it is supposed to”.

The following are suggestions for discussion/implementation as you get called in as The Person Who Knows These Things. If you actually do get a data breach, the most immediate steps are:

  1. Change the password for the given site(s) that was(were) breached.
  2. Check your credit cards/bank accounts to see if there are any fishy charges.
  3. Make sure they have 2FA on them
  4. Pull a credit report and freeze your credit – and in the credit report look for anything fishy (new accounts, for example).

Otherwise, we’ll assume the time slots you have below are based on how much time you have — or are willing to have — to disseminate knowledge :).

15 Minutes

With 15 minutes you have a selection of things you can do/advise:

  • Unique passwords for each site (at least, at the very least, for anything tied to finance – bank cards, store cards, etc.) – this reduces what a potential attacker has access to if there is/was a data breach with that one site. With 15 minutes you probably can do like, 2, but you can include the explainer on why they should do this for the rest of their sites.
  • Provide an explainer on data breaches:
    • They are somewhat inevitable because no system is perfect,
    • This is why you don’t want to do things like store credit card information with retailers or on your browser,
    • This is why people should have two emails (or more) – one that all their finance stuff goes to vs. the “spamhole”,
    • This is why you activate 2FA or MFA on all your stuff (again, if data found in data breach is being leveraged by bad guys then at least make it a little harder for them).
    • Whenever you get a notice of one you change the password on that site – and any you think may be tied to it – immediately.

30 Minutes

  • Show them how to freeze, and temporarily unfreeze, their credit, and why.
  • Discuss options like Delete Me.
  • Take the free credit monitoring
    • Almost every data breach notification comes way too late after this particular horse is stolen from this particular barn, BUT, free credit monitoring is free credit monitoring.
      • When they sign up for that it should be with a unique password.
      • Put in a reminder for the couple of weeks before the monitoring is set to expire so they can/should decide if they want to continue it on their own payment or cancel it once it is no longer “Free”
        • (An unfortunate reality is with the frequency of data breaches you could probably stack these 😦 ).

45 Minutes or Longer

  • Get a Password Vault app (e.g., Bitwarden) and an Authenticator app installed
  • Set up that 2nd email and update accordingly to financial sites
  • Google yourself and see what comes up. If you don’t want whatever does come up, file a request with the owner of that site or leverage something like DeleteMe.

The last thing I’d point out is that there is an astonishing amount of information out there on you that is publicly available. County assessors include your information and real estate tax information publicly, county and state court websites have records, etc.

The Real World

I will end with an example: recently, some folks I know were buying a house here in WA. Specifically in King County. They had seen a house, and they wanted to know more about it. Naturally, working with a realtor, they got some information. However, through about 15 minutes of searching, I could see: every permit that had been applied for, and accepted/rejected (and why) for that house, the previous homes the current owner lived in, how much they bought and sold those homes for, the current owner’s court records including their recent altercation at their house, a speeding ticket, their previous marriage, their previous divorce settlement, their current partner, their place of employment, their previous employment, the location of their families across the country, their voter registration, etc. etc. This is/was all publicly available data- I didn’t have to pay anything or even register anywhere to search it. Bonus: the folks I knew were checking with their own realtor about their own house to see how it was titled. and I was able to pull their title -an actual copy of their title – in 5 minutes.

This is what I mean when I say you will not be able to be 100% private. Certainly, there are ways to obfuscate this: you can get court records sealed, you can register your home in the name of a trust or a shell company, you can scrape your name off of as many sites as possible, etc. When you get the notice of the data breach, pay attention to what was breached – and respond accordingly.

It’s the Most Wonderful Time of the Year, Part I

As we sit in meetings and hear “yeah, so let’s circle back to that in the new year”, as we receive out of office emails, as we get quite literally bombarded with solicitations (to go buy things or donate money), we find ourselves yet again at the end of a calendar year, heading into “the holidays”.

It is “the holidays” because it incorporates a selection of them with a variety of observances and customs, and I can get behind any seasonality that involves getting together with the ones you love and eating things. Oh, and pretty lights.

This is also the time of year where you may be dragged into being tech support for a friend or family member and remember that it is an honor and a privilege: You Are the Techie Person. You get to say stuff like “it works on my machine” and “have you tried turning it off and turning it on again”. Practice holding your coffee mug in your non-dominant hand while gesturing at screens, it will help.

If, however, you do not want to spend all of your time at a gathering doing tech support, and you’ve allotted a specific amount of time to do the Good Work, here’s some suggestions. For all of these you should explain to the recipient what you are doing and why, so they understand when things change. It also means that they can’t wander off and leave you by yourself to play tech support (unless you, and they, want it that way).

15 Minutes

With 15 minutes, grab the phone(s) of the intended persons (WITH THEIR PERMISSION) and:

  • Ensure they are updated with the latest patches – this will help guard them against security issues and could help performance.
  • Adjust the text sizing/accessibility features as needed – sometimes these are hard or confusing to get to.
  • If the phone is a sea of apps, make sure they know how to search for apps and/or reconfigure their first page of apps to the ones they use the most.
  • Establish a family code word for human MFA – AI has gotten savvy and so if Grandma gets a call from her “Grandson” explaining he’s in jail / trapped in a town someplace else / needs money, Grandma can ask for the passphrase. The kid will know it, AI will not. (You may need to show Grandma some examples of AI real-time deepfakes, so she understands the abilities of the bad guys).
  • Depending on the state of the person and what kind of support you do, you may want to enable location sharing to you. If you do that explain why.

3o-45 Minutes

With this additional time,

  • Make sure they are storing passwords someplace safe. IF THAT IS A PIECE OF PAPER, make sure they understand that that piece of paper needs to be hidden and not just hanging out and visible to anyone who visits the house. Pitch solidly for a password manager — the one Apple has built in is fine; Bitwarden is good too.
  • Make sure they understand to NOT STORE THEIR CREDIT CARD INFORMATION IN THEIR BROWSER. If they are doing that, walk them through why it needs to be removed, and teach them how to use Apple Pay or Pay Pal. Yes, this may take more than 15 minutes.
  • Walk them through how MFA works (if they don’t already know it) and ensure it’s set up for any/every instrument tied to money (bank accounts, shop/store accounts, subscriptions, etc.)

An Hour or More

  • Check to see if the router ADMIN password is unique and not the one the router shipped with. If it is, change it, make sure they add it to whatever they’re using to manage their passwords, and explain to them why (I find it useful to use the “Garage Door Opener” example: there was a thing a few decades back where folks discovered that if you bought a garage door opener and drove through neighborhoods eventually you’d find one you could open).
  • Make sure their Wi-Fi is not open for all – it should be password gated and that password should be stored accordingly.
  • If you have crazy amounts of time and inclination – let’s say you’re visiting from out of town and staying at the house a few days? –
    • Consider setting up a guest Wi-Fi and/or IoT Wi-Fi network. Separate things-that-touch-money from “smart” things (e.g., smart fridge, smart thermostat, etc.), and also separate “visitors”.
    • Go through browser hygiene on all machines – how cookies work, what you do and don’t get for them (explain that this is how Facebook knows you were shopping for boots).
    • Make sure machines are on auto-update for patches.
    • Consider getting a separate authenticator, and walking them through how and why to use that.
    • Explain passkeys.

Stocking Stuffers

  • Don’t plug your phone in to charge at any rando USB port. Instead, use a USB Condom. And with this, let the recipient know that they should never have to download an app just to charge their devices.
  • You can also get them a portable charger, especially if they travel a lot.
  • Bitwarden has a free tier but also for $1/mo or $3.33/mo you can get extras.
  • Ghostery is free but does accept donations.
  • Signal is free but does accept donations.
  • Credit Monitoring – even though we all get it “free” every time one of our accounts is compromised, it’s a good idea.
  • Authenticator Apps – Wirecutter and PC Mag have covered these.

Next post: why the Credit Monitoring is a good idea, and how to deal with the never-ending Data Breach issues.

One Foot in Front of the Other

One of the things I do to relax – particularly when I need the hands to be doing something (e.g., knitting project, cross stitch project, etc.) is “watch” YouTube. I have a handful of subscriptions but the ones I’ve enjoyed most of late are History Hit and the “Tech Support” series from Wired. The most recent one I watched was with a polar explorer, and I listened as he answered questions from a wide selection of forums.

In answering one of the questions, he started talking about a time he was on day 4 or 5 of a 50-day solo expedition – this guy legit goes out there with a tent and a stove and assorted gear and no one else — and he lost his iPod. (His white iPod, in the snow and ice, the irony of which was not lost on him). It meant that for 45 days then — if he was to continue — he was alone with his thoughts. No podcasts, no music, etc. This was disheartening and he had to park himself for a bit to work through a mental impasse; he ended up using his satellite phone to call a friend who in turn talked him through how to deal. Then he continued, for the remaining 45 days, with only his thoughts. As he put it: he started by putting one foot in front of the other, for a thousand feet, and just kept doing that.

I will not even pretend that anything I do in life is that hard. There’s not a chance. I can still take a lesson from it.

If you are at this moment a corporate worker bee of some sort, you are watching very likely as coworkers get Reduced in Force, as the job market dries up, as we are increasingly asked to do more with less in the name of Efficiency and Cost Savings. AI, whilst somewhat useful for the basics, hasn’t (yet, knock wood) really replaced human capability (barring the impression it has from some CEO’s). The more load you pile into a machine — think of increasing the number of pages you put through a shredder each time — the more bogged down it gets, the less productive it is, or feels.

It’s review season again where I work, meaning that each person sets aside a nominal period of time (some do this in 20 minutes, some do this over agonizing hours) to identify their *impact* over the last 6-ish months. Not delivery.

You can have a lot of delivery with little impact. If you ship a bunch of code and no one uses it, you had a lot of delivery, and not much impact. If you write a lot of docs and no one reads them, ditto. You can mop the floor six times a day 7 days a week but if no one is walking on it there’s not much impact. I’m not even going to pretend that this is in the sole control of the worker bee: oftentimes we are directed to Do the Thing and if your boss tells you to Do the Thing you Do the Thing because capitalism and rent and groceries.

Whereas you can *feel* like you’ve delivered relatively little but had serious impact. It’s a bit of “proving a negative” but if you are beating your head against a wall with a project and making only the slightest headway, *but still making headway*, that can be impact – because you’ve either found a way to NOT do it again (hey, document that so others can learn) or you’ve blazed the trail and figured out how it was supposed to go, so others can find it easier (and hey document that too). *Someone* had to do it first, and it wasn’t going to be easy. It’s also not what we normally think of when we think impact.

Dollars. Views. Customers. Reduced time to X. We tend to think about impact in objective numbers and quantitative measurement. There is also room for qualitative feedback and the value of pivoting. There is value in slogging through things but, and I want this to be copiously clear, there is no value in slog for slog’s sake, and having to repeat a slog. If you’re the first one to explore and slog, share that out so it’s less of a slog. If you find yourself slogging through the exact same stuff with the exact same people, it’s time to convert that into impact – pull back/up/out and figure out how to break the cycle (if you can).

I am equally not going to pretend that it’s that simple – there are and will be situations in which you’re told to do the thing because you were told to do the thing, in spite of objective evidence that there’s a better/different/impactful way. The best you can hope for there is a workplace that apparently rewards delivery, vs. impact. If you’re very very lucky, you have an environment, resources, and work community that lends itself to impact over delivery.

And in the meantime, you put one foot in front of the other for the next thousand feet.

Supply Chain Attack: an Explainer

I have told you to Do Your Updates, twice. A good example of why is the recent news about supply chain attacks in popular npm packages, which may mean nothing to you, and I figured I’d break it down.

Firstly, most folks understand that a supply chain is… a chain… of supplies. Tautology aside, it specifically means the chain of manufacturers, people, places, and companies through which various stuff flows through to an endpoint. Let’s take my fake coffee shop, Bobbucks, as an example. Bobbucks sells fancy coffee and (of course) pastries. Bobbucks does not want to have to have individual bakeries in every city/county/country that it owns, because Bobbucks’ primary focus offering is *coffee*, not pastries. Therefore, Bobbucks contracts with local corporate bakeries across the world.

Those bakeries make pastries according to Bobbucks standards, but key ingredients are fairly universal: for example, flour. All of those bakeries need to get flour, and they probably don’t all get it from the same place across the world, but there’s a good bet they get it from the same place in a geographic region. We’ll take that part of the chain. Now we have Bobbucks, which contracts with Starbakers for pastries, which in turn contracts with Queen Guenevere Flour company. Queen Guenevere Flour company in turn gets the wheat from Alan’s Wheat Farm.

Those products don’t magically flow, though, so for this supply chain we need trucks, and trucking companies. The trucking companies that are used in each part of the chain are contracted between the two links, e.g., Bobbucks and Starbakers have one trucking company (probably more, but we’ll say one to make it easy) between the two of them; Starbakers and Queen Guenevere Flour may have a different one.

If someone wanted to attack this supply chain, they could do it at different spots, with different results. For example: if someone were to put some laxatives in the pastries at Starbakers, then Bobbucks is unknowingly buying laxative danishes and selling them to people, who will then get sick. Bobbucks will need to do some investigating to figure out where it’s coming from, would probably quickly find the culprit in the danishes, and push back to Starbakers. Now Starbakers has to figure out if it’s one of their staff, or one of their ingredients.

Maybe it *wasn’t* some gremlin at Starbakers, maybe it was a gremlin at Queen Guenevere Flour company putting laxatives in the flour. Or maybe one of the trucking companies. Each company has to spend time and money to figure out where it happened, to rectify it. In the meantime, people need to be notified to get their pastries elsewhere and to take Imodium.

Specious examples aside, you also see this not so much in supply chain *attacks* but general “oopsie” like when a farm has questionable fertilization practice and ships a bunch of lettuce with ecoli– which then gets washed and chopped up in a processing plant (but maybe not washed enough) — which then gets packaged up with authentic Pirate Frank’s packaging for all the Pirate Frank stores — which then ends up in your cart. How many food recalls have you seen lately?

“But Bobbie”, you say. “Bobbie, that is concrete hard things that move from place to place. How do you attack a software supply chain?”

By poisoning a package. Or several.

As we’ve discussed previously, it is not efficient for you, the developer, to create a formula every time you want to say, convert Celcius to Fahrenheit. Someone else has done it and they’ve put it available for others to use, up in a registry. If you, a developer, need to create a shiny new website for your Ancient History Studies college courses, you would go searching for a package that already exists on the registry that, say, converts Julian dates to Gregorian dates (or vice-versa). You wouldn’t hand-code it yourself because you value your time and also your sanity.

That registry is visible and more importantly, open source. That means that if Person A has built that Julian to Gregorian date converter, and Person B has a Mayan Calendar conversion they want to add, they can publicly add to that package to make it more useful for them and others. That add is visible, and can be checked both by the registry and subsequent editors/adders/changers. There are all kinds of places and ways the content can get scrutinized.

For each fine cat, a fine rat. A particularly fine set of rats have gone to the very most popular packages – packages that handle string pattern matching, or prettifying things, or cleaning up things, or converting things – and put some poison in them. Sometimes the poison is to capture credentials (e.g., your logins or suchlike). Sometimes the poison is to silently watch what you do on your machine for ages to see if you go to any crypto sites (so it can grab your wallet) or banking or whatever. The little code injection captures what it needs and sends it faithfully off to the architect of this chaos, and sometimes you find out right away and sometimes you don’t.

The thing about supply chain attacks is that it isn’t just you, or a handful of yous. Much like with our flour analogy, those packages get used by Company A to build a thing which Company B buys, and uses in their thing that they in turn sell to Company C. Each of those companies have customers who use their products and it’s possible a customer is a customer of all 3 and so tracing back to “where did this come from and what is it doing” can take an appalling amount of time. Also, it’s not just one package. They use more than just one package. They may use dozens, or even hundreds, throughout a large product offering. And sometimes it’s a combinate poison: part 1 of the poison is in package Foo, but part 2 of the poison is in package Bar, and engineers tend to use both Foo and Bar packages.

Once the real origin is figured out though, time is still of the essence. Companies and developers have to update to the last known good or the newest known good version of those packages, push those updates out to *their* customers, and *also* have to sanitize all their stuff, change their passwords, their 2FA/multi FA, etc. It’s not enough to take Imodium, you’ll also want a probiotic and lots of Gatorade. And you may stop getting pastries from Bobbucks.

So do your updates.

PS – “how were attackers able to poison the packages in the first place?” – Phishing. They sent official looking (down to the return address) scary mails to package owners telling them they had to update their 2FA credentials and used that data to gain access to multiple packages and locations. They sent the same kind of official mail, with lots of urgency in it, to lots of package owners, and lots of package owners fell for it.

DO NOT click links in official sounding scary emails. All of those that purport to come from your bank, or important places like this, have actual websites you can actually go to directly without clicking on specious links. Same thing goes for phone calls from “the bank”, “social security”, “the IRS”, etc. Thank them for calling, tell them you will hang up and call them back. Then call back on the phone number from the *website*, not the number they called you from. (The IRS doesn’t call – they don’t have anywhere near the human capacity for that).

Do Your Updates, Part II

Firstly: a new Apple iOS update is out for phones/pads/Macs, and you want to take it *as soon as possible*. Not only does it have a zero day in it, that zero day is under active exploit. This means that a problem is/was identified before a fix was identified (zero days to fix) and professionals are already abusing it (under active exploit). Granted, the typical target of these things are journalists, government officials, etc., but also folks working at corporate offices. Maybe even you.

One of the questions I have fielded since Do Your Updates is best distilled as “why can’t developers do it perfectly the first time”. Aside from the unrealistic expectation that an engineer not be human, there’s a few reasons for this.

  1. The biggest vulnerability in any system *is the humans* and it’s not just the humans building the system, it’s the humans *using* the system. Phishing and social engineering – those emails asking you to click a link urgently or telling you “here’s your PayPal receipt” for a transaction of several hundred dollars (designed to make you panic) are phishing. Social Engineering is more like the person calling you on the phone saying they’re calling from Chase to verify a recent fraudulent activity and asking you for things like your passcode, to verify a 2FA, etc. These methods rely on the target feeling *vulnerable* and have a sense of urgency.
  2. Code evolves and so does technology. There was a time where a very strong password was sufficient to guard your stuff — but then we had data breaches. So then we added 2FA (second-factor authentication, e.g., when you get a text with a code to support your log in) — but then we had SIM swapping. So then we added MFA (multi-factor authentication), physical YubiKeys, etc. etc. — for each fine cat, a fine rat: engineers on the malicious side are not resting, so engineers on the corporate side cannot, either.
  3. We talked about packages and post-deployment vulnerabilities in Do Your Updates. That is still a thing.
  4. There are *a lot* of ways an attacker can poke at the platform or the code:
    • They can insert things into text boxes for forms that interrupt the inbound form contents (e.g., the text box in which you give your feedback on a thing) to try to get into the database in which those contents exist (this can go by a variety of terms and also has a variety of methods, one of which is called SQL Injection and is/was the first thing I learned about cybersecurity, aside from “never share your password”, back in 2002).
    • They can do something called a “brute force” attack which is just like it sounds: employing a variety of clients to just pound the ever-loving crap out of any intake on a site to either force it to give up/let you in and/or just take the site down (Ddos: Deliberate denial of service). 2FA helps with this but so does throttling (making it so that only so many requests are allowed before it locks you out), or Captcha/Re-Captcha. Except now AI can pick out all the parts that are a “motorcycle” in the image, even if you can’t. And so now engineers have to figure out the difference between a less tech savvy person reaching for their paper-written passwords and typing those carefully but incorrectly into the little box, vs. an AI acting as such.
    • They can code up sites that *look* like the site you want to go to and the URL even looks like the site you want to go to — except maybe instead of a “O” it’s a “0” in the site name. You go to the site that looks legit, that the engineer has scraped/copied the design from a legitimate site, and you type. your login as always. Because it’s not the real site, it tells you “oh gosh we need to verify it’s you, please type in the 2FA code” and instead of you sending that code to the real site and doing a real authentication, you are providing that code to the attacker so they can go log in as you.

AI is also not going to solve our security problems — it will make them harder to (as malicious folks have access to AI, too)– but it can help. AI can be used to detect anomalies faster (in most cases you don’t have to tell your bank you are traveling as it employs AI to figure out whether or not that was you booking a 7 night trip to Cancun or not), or even predict patterns for exploits. When it does, it will not be replacing the engineer or even making what the engineer does perfect. This dance does not end.

So do your updates.