• zazilicious@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    2 months ago

    I know this thread is old but: so many HIPPA violations, oh my God. I am a pediatric therapists/child psych, and the clinic I used to work at constantly stored client data in the most insecure ways, and therapists and staff would discuss client names, diagnosis’, address, EVERYTHING openly in the break room. I complained at one point, but it went nowhere. Turns out nobody cares, lol. They also frequently ignored the best interests of our clients to maximize profit from insurance (leaning towards fraud). I ultimately left the company when my boss blatantly violated the safety of one of my clients by refusing to send her home when she had a fever of 104 F. Sure, working with kids means everyone gets sick a lot, but when the child is THAT sick, they need to be in a hospital, not in a hot, cramped room with a therapist.

  • المنطقة عكف عفريت@lemmy.world
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    9 days ago

    Every time we notified anyone about a potential illegal breach of gdpr that could get us fined or sued, admin pretended they had never been informed because the changes would take too long and collide with their plans to “revamp everything, reinvent the platform, and rebrand”.

    I should have whistleblown them myself if it were not for the fact that doing so would probably get some previous employees fired rather than hurt the company.

  • netvor@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    1 year ago

    The building, used by several hundred employees, had a security systems with 4-digit codes. I’ve been part of group of people who liked to work late times, and the building would lock at midnight – the box by the door would start beeping and you would need to unlock it within a minute or so, or “proper alarm” would ensue.

    However, to unlock the alarm you did not need your card – all you needed to do was to enter any valid code. Guess what was the chance that, say, 1234 was someone’s valid code? Yes.

    We’ve been all using some poor guy’s code 1234, and after several years, when he left the company we just guessed some other obvious code (4321) and kept using that.

    By the way, after entering the code to the box by the door, it would shortly display name of the person whom the code “belonged” to. One of our colleagues took it as a personal secret project to slowly go through all 10000 possible codes and collect the names of the people, just for the kick of it.

    (By the way, I don’t work for that company anymore, and more importantly, the company does not use that building anymore, so don’t get any ideas! 🙃 )

    • Lurkinglemmy@lemmynsfw.com
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      One of our colleagues took it as a personal secret project to slowly go through all 1000 possible codes and collect the names of the people, just for the kick of it.

      Just an FYI it’s 10,000 codes, not 1,000. 0000-9999

  • shadesdk@lemmy.ml
    link
    fedilink
    arrow-up
    28
    ·
    edit-2
    1 year ago

    The company would bid on government contracts, knowing full well they promised features that didn’t exists and never would, but calculating that the fine for not meeting the specs was lower than the benefit of the contract and getting the buyers locked into our system. I raised this to my boss, nothing changed and I quit shortly after.

    • hactar42@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      1 year ago

      I’ve worked in IT consulting for over 10 years and have never once lied about the capabilities of a product. I have said, it doesn’t do that natively, but if that’s a requirement we can scope how much it would take to make it happen. Sadly my company is very much the exception.

      The worst I saw was years ago I was working on an infrastructure upgrade of a Hyper-V environment. The client purchased a backup solution I wasn’t familiar with but said it supported Hyper-V. It turns out their Hyper-V support was in “beta”. It wasn’t in beta. They were literally using this client as a development environment. It was a freaking joke. At one point I had to get on the phone with one of their developers and explain how high-availability and fail-over worked.

  • TerkErJerbs@lemm.ee
    link
    fedilink
    arrow-up
    15
    ·
    1 year ago

    I quit a well known ecomm tech company a few months ago ahead of (another) one of their layoff rounds because upper mgmt was turning into ultra-wall street corpo bullshit. With 30% of staff gone, and yet our userbase almost doubling over the same period, they wanted everyone to continue increasing output and quality. We were barely keeping up with our existing workload at that point, burnout was (and still is) rampant.

    Over the two weeks after I gave my notice I discovered that in the third-party app ecosystem many thousands of apps that had (approved) access to the Billing API weren’t even operating anymore. Some had quit operating years ago, but they were still billing end-users on a monthly basis. Many end-users install dozens of apps (just like people do with mobile phones) and then forget they ever did so. The monthly rates for these apps are anywhere from 3 to 20 dollars per month, many people never checked their bank statements or invoices (when they eventually did, they’d contact support to complain about paying for an app that doesn’t even load and may not have for months or years at this point).

    I gathered evidence on at least three dozen of these zombie apps. Many of them had hundreds of active installs, and were billing users for in some cases the past three years. I extrapolated that there were probably in the high-hundreds or low-thousands of these zombie apps billing users on the platform, amounting to high-thousands to low-tens-of thousands of installs… amounting to likely millions per year in faulty and sketchy invoicing happening over our Billing API.

    Mgmt actually did put together a triage team to address my findings, but I can absolutely assure you the only reason they acted so quickly is because I was on the way out of the company. I’d spotted things like this in the wild previously and nothing had ever been done about it. The pat answer has always been well people are responsible for their own accounts and invoicing. I believe they acted on this one because I was being very vocal about how it would be ‘a shame’ if this situation ever became public, and all those end-users came after the company for those false invoices at one time. It would be a PR and Support nightmare.

    You have definitely interacted with this ecommerce platform if you shop online.

    • SreudianFlip@sh.itjust.works
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      2 months ago

      I’m unfortunately dependent upon said company, as a “partner”, which just means a hack indie developer who herds customers to the slaughter for the corp.

      The last round of layoffs was a brutal experience for the “Plus” customers. They lost crucial advisers and support, and now the guidance available is a bored and untrained chat support thrall on the other side of the world, or a stochastic parrot.

      You can smell the enshittification from here. The vendor lock-in is so intense it seemed inevitable.

      • TerkErJerbs@lemm.ee
        link
        fedilink
        arrow-up
        1
        ·
        2 months ago

        You’re absolutely right on all counts. And that’s why I quit (without waiting around to be laid off which frankly the severance package would’ve been nice). I got hired into the first (private) company I applied to, I’m thriving, and I don’t miss that stink of wall street/silicon valley money at all.

      • booty_flexx@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        1 year ago

        ✅️ is a shopping platform

        ✅️ has an app ecosystem with a billing api

        ✅️ high probability that someone who shops online has interacted with a store on the platform

        ✅️ multiple rounds of layoffs w/ staff stretched thin

        ✅️ unclear ambitions of being a megaplatform, beyond what it already is

        I guess we’ll never know, lol

  • rtxn@lemmy.world
    link
    fedilink
    arrow-up
    13
    ·
    edit-2
    1 year ago

    Our business-critical internal software suite was written in Pascal as a temporary solution and has been unmaintained for almost 20 years. It transmits cleartext usernames and passwords as the URI components of GET requests. They also use a single decade-old Excel file to store vital statistics. A key part of the workflow involves an Excel file with a macro that processes an HTML document from the clipboard.

    I offered them a better solution, which was rejected because the downtime and the minimal training would be more costly than working around the current issues.

    • Tar_alcaran@lemmy.world
      link
      fedilink
      arrow-up
      6
      ·
      1 year ago

      The library I worked for as a teen used to process off-site reservations by writing them to a text file, which was automatically e-faxed to all locations every odd day.

      If you worked at not-the-main-location, you couldn’t do an off-site reservation, so on even days, you would print your list and fax it to the main site, who would re-enter it into the system.

      This was 2005. And yes, it broke every month with an odd number of days.

    • SSTF@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      1 year ago

      downtime

      minimal retraining

      I feel your pain. Many good ideas that cause this are rejected. I have had ideas requiring one big downtime chunk rejected even though it reduces short but constant downtimes and mathematically the fix will pay for itself in a month easily.

      Then the minimal retraining is frustrating when work environments and coworkers still pretend computers are some crazy device they’ve never seen before.

    • bleistift2@feddit.de
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      cleartext usernames and passwords as the URI components of GET requests

      I’m not an infrastructure person. If the receiving web server doesn’t log the URI, and supposing the communication is encrypted with TLS, which removes the credentials from the URI, are there security concerns?

      • nudelbiotop@feddit.de
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        1 year ago

        Anyone who has access to any involved network infrastructure can trace the cleartext communication and extract the credentials.

  • Abrslam @sh.itjust.works
    link
    fedilink
    arrow-up
    12
    ·
    1 year ago

    I worked for for the railroad. Nothing is fixed ever. I witnessed hundreds of code violations every day for years. Doesn’t matter if a rail car or locomotive meets code as long as it “can travel” its good to go.

    When an employee inspector finds a defective rail car management determines if it will get fixed. If the supervisor “feels” like “it’s not that bad” then the rail car is “let go”.

    • oatscoop@midwest.social
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      1 year ago

      Oh, so like ambulances in the USA.

      “The ambulance had issues making it unsafe (or even illegal) to drive? But it can still drive down the road? Doesn’t seem too bad: keep an eye on it.”

  • shittymorph@lemmy.world
    link
    fedilink
    arrow-up
    11
    ·
    1 year ago

    I used to work for a popular wrestling company, billionaire owner, very profitable, would write off any OSHA penalties as the ‘cost of doing business’ just as they did in 1998, when The Undertaker threw Mankind off Hell In A Cell, and plummeted 16 ft through an announcer’s table

    • Gearheart@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      1 year ago

      I want to believe… but the morph has always been exactly.

      “nineteen ninety eight when the undertaker threw mankind off hell in a cell and plummeted sixteen feet through an announcer’s table.”

      But I want to believe…

      Edit: looking back at previous shittymorph posts. Grammar, punctuation and delivery is at much higher standard… I’m sad 😢. I’m hoping that I’m way way wrong. Can anyone reach out to shittymorph on reddit to confirm?

      • shittymorph@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        That is quite an astute observation, in fact many folks would have overlooked such precise details. As you could imagine, with newness and changing situation such as a major platform shift, and as we enter a revolutionary technological time period in hopes of a prosperous fediverse, it’s easy for us to become a overzealous and infatuated with all the excitement, but we must remember, it pales in comparison to the crowd’s excitement in nineteen ninety eight when the undertaker threw mankind off hell in a cell and plummeted sixteen feet through an announcer’s table.

            • ThtCrzyBstrd@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              1 year ago

              Back on the site-that-must-not-be-named, u/shittymorph would occasionally come out of nowhere with the one story about Hell in a Cell. It was his thing. Shortly before the place went to absolute hell, he posted saying he was stepping away for personal reasons.

              We believe this is an imposter.

    • ikidd@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      1 year ago

      You son of a bitch, I don’t know if you’re the og shittymorph, but I missed that bastard.

  • esadatari@lemmy.world
    link
    fedilink
    arrow-up
    11
    ·
    1 year ago

    i worked for a hybrid hosting and cloud provider that was partnered with Electronic Arts for the SimCity reboot.

    well half way through they decided our cloud wasn’t worth it, and moved providers. but no one bothered to tell all the outsourced foreign developers that they were on a new provider architecture.

    all the shit storm fail launch of SimCity was because of extremely shitty code that was meant to work on one cloud and didn’t really work on another. but they assumed hurr hurr all server same.

    so you guys got that shit launch and i knew exactly why and couldn’t say a damn thing for YEARS

  • Teppichbrand@feddit.de
    link
    fedilink
    arrow-up
    11
    ·
    1 year ago

    Big german TV production company with succesful primetime action series used rented cars for their stunts. Different people from the team rented them with full insurance, returned them crashed. They did this until every car rent in the city stopped offering insurance without retention.

  • thrawn@lemmy.world
    link
    fedilink
    arrow-up
    10
    ·
    1 year ago

    It’s pretty depressing, but the fact that soil and groundwater are almost certainly contaminated anywhere that humans have touched. I’ve seen all kinds of places from gas stations, to dry cleaners, to mines, to fire stations, to military bases, to schools, to hydroelectric plants, the list could go on, and every last one of them had poison in the ground.

    • pfannkuchen_gesicht@lemmy.one
      link
      fedilink
      arrow-up
      7
      ·
      1 year ago

      Some places are insanely polluted to the point where you wonder how a whole company could be so braindead and essentially poison themselves.
      A place not far from where I live had a chemical plant which just dumped loads of chemicals on a meadow for years. Now there are ground water pumps installed there which need to run 24/7 so that the chemicals don’t contaminate nearby rivers and hence the rest of the country.
      When taking samples from the pumped up water you can smell gasoline.

      • dammitBobby@lemm.ee
        link
        fedilink
        arrow-up
        7
        ·
        1 year ago

        We’re house shopping and there has been a house on a lake sitting on the market forever. I got curious and researched the lake and… It’s a literal superfund site. The company that was on the other side of the lake just dumped their waste chemicals right on the shore and it has polluted both the lake and ground water forever essentially because they don’t break down. I looked up the previous owner… Died of cancer. The shit that companies are and were allowed to get away with is just insane. Meanwhile right wing nut jobs want to get rid of the EPA (which was ironically created by Richard Nixon).

      • PoliticalAgitator@lemm.ee
        link
        fedilink
        arrow-up
        2
        ·
        1 year ago

        A place not far from where I live had a chemical plant which just dumped loads of chemicals on a meadow for years.

        Sounds cheap.

    • Buffaloaf@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      I work in air quality and it’s a similar story. It’s crazy to me seeing how much is unregulated, grandfathered in, or simply not enforced.

    • Tar_alcaran@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      1 year ago

      It’s just as depressing when something counts as “clean”. My saddest example was a former sand pit, they spent 30 years digging out 15 meters of sand, then another 30 years filling it with anything from industrial to veterinary waste, “capped” it with rubble in the late 40s and called it clean enough.

      Had a bigass job digging out the top 3 meters of random waste, including several thousand of barrels of whatever the fuck. And definitely no unexploded ordnance (spoiler, after finding several ww2 rifle stocks and helmets, the first mortarshells were dug up too). After makimg room, it was covered in sand, clay, bentonite and a protective grid.

      So naturally, 3 months after that finished, some cockhead decided to throw an anchor and hit go all ahead flank on his assholes boat and tore the whole thing up. No need to fix anything though, just shovel some more sand it, that’ll stop the anthrax!

      This was all in open connection with a major river, of course. One people swim in.

  • MrBodyMassage@lemmy.world
    link
    fedilink
    arrow-up
    9
    ·
    1 year ago

    There is a million times more counterfeit/fake items at amazon than you think, and they dont care one bit to fix the problem

    • Sharkwellington@lemmy.one
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      I recall watching a video about the nature of how things are stored at Amazon warehouses - basically if there are multiple sellers offering the same item it all goes in the same bin. Even if you are providing a genuine product, there’s a very good chance one of the other sellers is not, and that counterfeit gets sent out attached to your seller ID. Then you get a complaint for selling a counterfeit item someone else provided.

      Then when that seller is caught and booted, they just register another trademark with 5-10 random characters and do it again. This is causing a massive headache for the US Trademark Office as well.

    • wildebeesties@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      7 months ago

      One of the major issues is counterfeit baby products, specifically sleep products. In the US, sleep spaces for babies are highly regulated. The terms “bassinet, crib, and playard” are terms that can only be used for products that pass rigorous ASTM testing. If something doesn’t complete that testing then they are not allowed to use one of those terms in ads or on their manual. This is why you’ll see many products listed as “loungers” because they’re not safe for sleep. There are hundreds of products online that are horribly made and steal manuals of actual approved products. Amazon is notified (groups I’m in notify them) and they don’t care. There are also products that aren’t knock-off versions of things but just flat out lie and say a product is safe for sleep when it isn’t and will use one of the protected terms - which makes the sale of them illegal.

  • FireRetardant@lemmy.world
    link
    fedilink
    arrow-up
    8
    ·
    edit-2
    1 year ago

    1-800-got-junk? doesn’t care at all about its environmental impact. No sorting what so ever happens to what goes on their trucks it all goes to landfills. All the ads will say they recycle and that they repurpose old furniture but I was threatened with being fired when I recommended donating antiques instead of dumping a load of furniture.

    More jobs and more profits comes before anything else in that company, including employee health and safety. Several times I was told to enter spaces we werent trained for (attics and crawl spaces) and carry waste I legally couldn’t transport (human/organic wastes and the laws states the driver is fined, not the company). One guy injured his shoulder during an attic job and was told to finish the shift or lose his job. Absoulte scum of a company with very sleazy management and possibly the labour board in their pocket as they kept “losing the files” when I tried to file a report with buddy’s shoulder (he was hesistant to report for fear of losing his job).

    • Mugmoor@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      2
      ·
      1 year ago

      I’ve had a few friends work for them out in Montreal, and their parent company (2 Men and a Truck). According to them it’s a mob-operated business.

      • Thwompthwomp@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Oh no! I had a great experience with 2 men and a truck when I he used them! No idea it was associated with the 1 800 junk folks

  • Boozilla@lemmy.world
    link
    fedilink
    arrow-up
    7
    ·
    1 year ago

    Health insurance company I worked for would automatically reject claims over a certain amount without reviewing them. Just to be dicks and make people have to resubmit. This was over 25 years ago, but it’s my understanding many health insurers still pull this shit. They don’t care if it’s legal or not. Enforcement is lazy and fines are cheaper than medical claims.

    Obviously this is in the USA.