Hacker News new | ask | show | jobs
by dboat 2572 days ago
Presumably you were able to explain your case and have the reprimand expunged from your record. As long as they are reasonable in that way I don't think occasionally testing the people handling sensitive data is a bad idea.
2 comments

Should it be expunged though? They've indicated they were aware it was quite clearly a phishing attempt, but they still accessed the link. If the test was to see if a user would try accessing the link, then this user failed the test. Why should that be expunged?

Curiosity shouldn't preclude security, and intent shouldn't preclude policy if the operator operated knowingly.

This isn't to attack maxk42, but to engage the question head on.

The goal is "don't be phished", right? Measuring http requests is a proxy for that, and not a completely accurate one.
> intent shouldn't preclude policy

Oh boy, I hope I never work in this kind of organization.

I was hoping implicit in this statement, along with other contexts offered that this would have been read with "information security" in mind, on me to communicate that better next time.
I think a better idea for the person involved is to work at a company that isn't run by self-serious bureaucrats.