logoalt Hacker News

Scubabear68 • today at 2:54 PM • 4 replies • view on HN

Do you really think the engineering teams pour over those contracts when implementing new features?

Every single time? I sincerely doubt it.

Whatever logical business firewalls Google has between orgs for this kind of purpose seems pretty frail and thin from what I have seen reported.


Replies

sulam • today at 3:25 PM

This absolutely happens, there's a set of teams whose job it is to make sure it happens every time a system is going to be handling customer data. It's not left to the engineers to remember to do so.

redwall_hp • today at 4:20 PM

Yes, absolutely. Every microservice where I work is architecturally scrutinized by multiple groups over things like PCI, GDPR and SOX, with major features requiring review. And then third party auditors get to review stuff occasionally. PII is radioactive and PCI data is hard siloed.

If you work at a company that deals with education or HIPAA stuff, there's going to be even more of that.

Presumably Google aren't morons or criminals.

hn_go_brrrrr • today at 3:30 PM

Tell me you've never worked at Google without telling me you've never worked at Google.

There are a lot of complaints you can legitimately levy, but "Google doesn't have enough of a compliance org to ensure eng behaves." is not one of them.

altmanaltman • today at 3:29 PM

They don't even need to know how to read the contract. But its not like engineers can ship whatever they want at a company the size of google.

So my question is, what have you seen reported and what makes you doubt it?