Hacker News new | past | comments | ask | show | jobs | submit login

>I was fired from MS for posting an image of myself online where my badge was clear enough to copy.

I won't ask you to go into any detail that you don't feel comfortable with, but is there more to this? Special circumstances? The above, out-of-context, sounds very... draconian. I'm really just curious.




I really wouldn't be surprised if this really was the primary reason for firing a security engineer. A person who carelessly compromises sensitive information is someone you want as far away as possible from having access to your security systems, not to mention building them.


How is someone's badge security information? Anyone can walk up to the building entrance and see several people's badges on the way, surely security can't depend on keeping those secret.


By that same logic, passwords wouldn't be security information either because anyone could videotape someone typing theirs in at a coffee shop from afar. But, I suspect that's rare because it's really difficult in practice. The purpose of many security policies is to increase the amount of effort an attacker must go through.


I don't know of any company that encourages the display of passwords around their employees' necks.


well, depends if you're concerned with security or appearance of security. Security engineers need to do both.


Sounds unbelievable to me. How is a picture of a card going to mean that you can copy the RFID/chip needed to actually access anything? It would be a first warning/stern telling off event at most.


You don't need to copy the RFID to enter the buildings, you can always tailgate.


I don't need to copy ANYTHING to tailgate.


There is a policy against it. Its kind of lame since the design is well known and lots of photos existed beforehand.

The actual reasons were likely that I didn't ignore problems the company had previously ignored and a falling out with a freshly ex-roommate who went and harassed my company's management until something happened (I was a vendor). I had gotten a TRO on this guy and my company ignored it and ignored the advice of Microsoft management.

In the end everyone agreed to forget the matter and move on. I have since not had issues with working at Microsoft.




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: