Dear Stupid, I write with news I did not check the content of the [Name] field before sending this letter
- Reference: 1674462730
- News link: https://www.theregister.co.uk/2023/01/23/who_me/
- Source link:
This week meet a reader we'll Regomize as "Stan" who once worked as the subscriptions and IT manager (an odd combination of job functions if ever there was one) for a business magazine. Stan's chief responsibility in this dual role was to manage the FileMaker database containing the names and addresses of the magazine's ~20,000 subscribers.
As it was a business magazine, that database featured substantial overlap between the recipients of the magazine and the sales department's advertising contacts. The latter usually are often sent free copies of magazines.
[1]
Both types of subscriber were lumped together in a single table that included an an enormous number of fields, many of them obscure.
[2]
[3]
Stan didn't design this dastardly DB. He tells us it "had been managed by a succession of people with almost no knowledge of IT, including the CFO". He also learned that nobody was really sure why some of those obscure fields had been used, or what they contained.
So the only fields Stan worried about were "name, street, postcode, town and ID."
[4]Sysadmin infected bank with 'alien virus' that sucked CPUs dry
[5]Mixing an invisible laser and a fire alarm made for a disastrous demo
[6]When we asked how you crashed the system we wanted an explanation not a demonstration
[7]Programming error created billion-dollar mistake that made the coder ... a hero?
Then as now, magazine publishers are always looking for ways to increase circulation and revenue. One day, the boss was looking over Stan's shoulder while he prepared a run of letters to subscribers, and noticed a field he hadn't spotted before: Name2.
"Oh, do we have a second contact at some of these places?" the publisher asked.
[8]
Stan looked and, indeed, some five percent of the Name2 fields did indeed contain data.
He did not, unfortunately, check what that data was. But before long the publisher had decided the 1,000 or so folk in the Name2 field all deserved their own magazines.
"Just duplicate all the rows which have a Name2 and add them to the table," Stan was told.
[9]
Stan did what he was told and set about printing up ~21,000 subscriber letters to accompany the next distribution of the magazine. He worked long into the night, printing letters, restocking the paper trays, taking the printed letters out and stacking them in boxes to be taken to the fulfilment house.
In the morning, a sales person wandered into the area, picked up a printed letter, and read out loud the following greeting at the top of a letter:
"Dear don't let him get drunk or he'll bore you to tears, I am delighted to enclose the latest copy of …".
Another was addressed to "Dear get her drunk and she'll do anything".
Stan checked the address on the latter letter. It was going to the sponsor of that very issue of that magazine.
At this point – and not before – Stan inspected the content of that Name2 field. Among some actual names, some odd but benign comments could be found – and 23 highly derogatory comments.
All of the 23 nasty "names" were associated with important advertisers. Suffice to say it would be a very very bad idea for the intended recipients of those letters to open their mail.
Staff were therefore recruited to go through the 21,000 printed letters, find the offensive ones, and destroy them.
When the CFO arrived, he was informed of what had (almost) happened. "Ah," he said, "a while back I renamed the Comment field to Name2 as everyone was just using it to put in the name of a second contact."
Have you ever inherited a badly built system and suffered unforeseen consequences as result? Tell us all about it in [10]an email to Who, Me? and we'll share your pain with others.
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y85o1D2E3j9l7rE33myQ9AAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y85o1D2E3j9l7rE33myQ9AAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y85o1D2E3j9l7rE33myQ9AAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2023/01/16/who_me/
[5] https://www.theregister.com/2023/01/09/who_me/
[6] https://www.theregister.com/2022/12/19/who_me/
[7] https://www.theregister.com/2022/12/05/who_me/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y85o1D2E3j9l7rE33myQ9AAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y85o1D2E3j9l7rE33myQ9AAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] mailto:whome@theregister.com
[11] https://whitepapers.theregister.com/
Re: "a while back I renamed the Comment field to Name2"
I've told this story a couple of times, so apologies if you've read this, but..
A few years ago, we had a need for an equipment and inventory tracking system. None of the existing commercial solutions quite fitted out requirements, at least not for the prices our management was willing to pay. The problem was that we needed users to be able to book some of the equipment, and any equipment worth over £500 required the user to fill out a risk assessment, and get it approved by a manager outside our team. The booking system needed to be able to manage all communication with the approver and user. We did not know about any bookings until it was approved.
So, my boss initiated a project where we would build our own. It wasn't a massive system (although it was much more heavily used than we anticipated, loaning more than 100,000 items and taking hundreds of bookings. Thankfully, we'd worked out our requirements for hardware resources, and doubled them, to enable the system to expand, so the system coped well, mostly. (there was one area where it was too slow initially, but we resolved that).
There were three of us on the team. One colleague designed the backend stuff. Basically a Java Web service connected to an SQL server based Database, and a small Java based application to manage it. I designed the booking website (for the users) and designed some administration pages that were accessed from a central Administration website, that managed various systems we used at the time.
I can do basic web design, but am not good graphically, so my other colleague did the graphic design for both sites, and I wrote the HTML/Javascript required to implement functionality for them.
It worked brilliantly (mostly, there were users who had bypassed the rules before that complained they were suddenly forced to follow them, and there was the aforementioned slow part we corrected eventually) until one day when our counter staff suddenly reported it wasn't allowing them to loan or return anything. Then I started to get notifications from our bookings website that it was failing (I'd built error checking into the code that emailed me any errors as and when they occured).
The emails told me that calls to the webservice were failing, and the webservice was reporting it could not find the transactions table. The way the system worked, every action we, or a user, performed generated a transaction. This was done deliberately, to ensure the system could be audited, and for debugging purposes..
The colleague who designed the webservice opened up SQL Manager. At this point, my colleague who designed the UI disappeared saying he had meetings all afternoon, so needed to go for lunch, and vanished.
It was then we discovered that somehow, he had renamed the transactions table as a full stop. Not sure how he did this, because I am certain SQL Manager does not allow that as a table name (although I don't currently have access to an SQL Server to try it).
My manager didn't take any action against him because all three of us had access to the database, and it could not be conclusively proved who did it, at least not the way that server was set up. So, after the manager give a stern talking to to all of us, our DBA removed both my access, and the access of the technician who had broken it. In fairness, we did not need direct access to the database anyway, so that worked out better, IMO. I'm quite happy at work to not have access to stuff I don't need access to. I can't be held responsible when something goes wrong..
" Dear don't let him get drunk or he'll bore you to tears, I am delighted to enclose the latest copy of … "
I am outraged that I never got the magazine as intended!
Us subscribers to "Telephone Pole Number Spotters Weekly" declare this to be the next *Me Too* moment.
These guys' newsletter?
https://www.telegraphpoleappreciationsociety.org/
It may not be entirely serious. However, the 2023 calendar appears to be entirely genuine.
To access or not to access
A CFO with database master access. That is a recipe for disaster.
Then again, a database with obscure layout and questionable content as a basis for your company is not the most healthy choice either.
Re: To access or not to access
> A CFO with database master access. That is a recipe for disaster.
In GDPR land that's 4% of turnover or €20 million...
(Of course, most regulators seem content to make themselves look toothless and fine organisations much less)
Re: To access or not to access
It's about incentives.
The regulators like the threat being available - makes the reprobates fight less, and results in less push back from politicos saying "you're endangering jobs in my region" or "you just fined my mate". They get to say "we know, so we low-balled the fine".
The CEO who just walked into the lariat of GDPR gets to say "yes we got hit, but due to my Leadership and Negotiation, we rolled with it" and that might save his job.
You know if anyone ever eats a big fine, that's someone who's got no important friends left.
(and for companies that haven't been hit yet, and don't know how bad it won't be - the unrealised threat is still there, hovering menacingly. I've seen plenty of internal discussions at my place end in "it can go up to 4% of turnover. We _cannot_ risk this.")
Re: To access or not to access
I've seen worse.
A database with several dozen tables, but no foreign keys. Table relations were managed in code, not enforced by the database. Some tables had in excess of a hundred fields, several of which were duplicates of each other, and which one of those duplicates actually got the data depended on which bit of code was filling it in.
There was actually a function in code called "check if column exists and if not create it", which might have gone some way to answer why there was a "color", "colour" and "coloour" field.
Even worse, significant bits of that database had been duplicated out to other systems.
Despite all of this, the company in question did pretty good business and their system worked pretty reliably.
Reminds me of a presentation I had to do.
I used to work for a major telco and my job at the time was to give customers tours of a fancy showcasing setup where we talk about how wonderful the place was. When a salesperson has a customer group ready for a tour, we ask them to give us names for name badges, and whether each individual was an advocate, a detractor (of us, said telco), if they were a decision maker, an influencer or the like.
One day, I did a tour and the receptionist of the showcase was, as always sent this list. This particular customer group turned up with names including “Influencer” “Detractor” “lEconomic Buyer” “Big Boss” and “Subordinate”. I saw the “names” after I commenced the tour. By this stage it was too late.
I had to think of a way to sort this out. I texted a colleague and said “bring a six pack of beer, and a bunch of post it notes with “influencer” “detractor” “big boss” etc on it. At the end of the tour I showed the customers that we were having a lucky draw to win a six pack of beer, and if your “random title” gets drawn, you win. It was Detractor’s lucky day that day.
Re: Reminds me of a presentation I had to do.
"Lucky".
Great save. Hope you bought your colleague their own one of these --------------->
I worked on a system for a Housing Association which was set up to encourage tenants to pay their rent in time. If their account was up to date at 1st December they would be sent a prepaid Visa card loaded with £25 which they could then use in any shop at Christmas. I was tasked with setting up a mailmerge from their data to send out a letter to prompt them to clear any arrears and inform them of the scheme. I sense checked the data and found quite a few instances where the tenant had obviously died and they noted this by tacking the word "Deceased" onto the surname. I managed to warn the client before they got lots of complaints from people who got letters for their dead relatives.
I used to work at a pension company. One of the fields on the customer data screen was called "Alias", which was always left blank. One day, after a heated complaint from a Welsh customer, one of the call centre users decided to type something derogatory into the Alias field for that customer. He thought it was funny that when you looked up the customer details on the system it displayed that alias. What he didn't know was that the intended use of the field was for performers etc. You have to have their real name on the contact, but all their mail gets addressed to the alias. So a few days later, the customer got a letter addressed to "Dear Taffy Bastard".
When the gas bolier in our new-build home was commissioned, the fitter just put the builder's name in as the owner on the guarantee forms, as "Xxxxx Construction".
So, all the letters & paperwork come addressed to "Dear Mr. Construction".
A while back I had a heck of a time changing the name on one utility bill, as they wanted to speak to the current named individual, a "Mr The Occupier".
This would be the flip side...
...of the one where office admins see a bunch of "unused" fields in the database so decide they can keep notes in them. "I've been looking for somewhere to keep the reminder that this shithead always makes a fuss if we don't have the right kind of tea on hand whenever he comes in to give a lecture - hey look, this 'accessibility' field never has anything in it, I'll put it in there!"
Next thing you know the mailshot with this weeks events goes out and at the bottom there's a footer: "Students with accessibility issues, please note: Get twatface his stupid poncy tea."
Re: This would be the flip side...
Sounds like databases need a field explicitly labelled: "Offensive notes".
Many years ago, doctors used secret acronyms for things that it would be awkward to explain to patients. CAAC was "Crazy as a coot".
Several dictionaries and acronym finders seem to think [1]CGSM is real. I thought it was fiction. Anyone know for sure?
[1] https://www.quotes.net/mquote/956569
You're Special
I worked in a place with a call centre, taking calls from people with problems. Shortly after I joined, I noticed that customers could be flagged as "special". What it turned out to mean was that they are stroppy bastards but had they ever requested their data under the then DPA, they would've just seen "special".
'Stan didn't design this dastardly DB.'
I think it's pretty clear, neither did anyone else. 'Design' is not a thing that entered into its origin story.
Re: 'Stan didn't design this dastardly DB.'
Designed by Muttley? You did say Dastardly...
There's a dvd of "The Wacky Races" in one of these pockets
Dear Rich Bastard
Apparently [1]this sort of thing happens from time to time.
[1] https://www.snopes.com/fact-check/dear-rich-bastard/
How about
We give all C and D levels Root Access to Everything! Let's try it for a while! Then we can make boat loads of quatloos when they call us to fix their problems! Win-Win!
"a while back I renamed the Comment field to Name2"
No, that would be : Ah, a while back I decided to create a situation that could possibly destroy the company since I didn't think for a second about any possible consequences of my decisions.
It's called Data Management for a reason. And doofuses like that are the ones who enabled the book to be written on the subject.