Posted by zdw 11/4/2025
you can't even change the culture in a restaurant without replacing every single person.
1. who is Drew DeVault?
2. what change did he bring to Linode?
I lost the context after 'the same title "Developer"'
If it's not part of my job, and neither is my own company, it's not my problem.
It's just basic due diligence, and it's worth reviewing details when these topics come up. Maybe the new ideas aren't always fully baked, but they may have a point. Regular discussion is just part of the job.
I agree that hostility is not acceptable, but there are some people who take everything the wrong way when asked to perform. I get why it's threatening, but it is what it is.
I didn't take anything away that led me to believe the author was being hostile. He was asking for more effort than some might expect and they couldn't handle it. I don't really know who is right in that situation. What I do know is there are a lot of people who don't take work seriously enough and hide behind HR.
Many of those situations where it is OK are down at the foundational level of the internet itself, which is what linode and Drew DeVault were concerned with back in the day.
An example today I’m wrestling with is TLS interception (valid) vs protecting against TLS man in the middle attacks. It’s tough to get people to see it’s an either or situation, they truly are mutually exclusive.
Unless, we walk together through every painstaking detail to reach the necessary conclusion together.
And then whether your trust in the browser vendor coalition to push back against and punish even accidental CA malfeasance are reasonable.
Security, like every human, believes they’re the good guys.
Platform teams cannot enforce the principle of least privilege.
Truly a paradox.