Live data from Hacker News

Ask HN: What is the most unethical thing you've done as a programmer?

news.ycombinator.com

361–370 of 520 posts

Re: Ask HN: What is the most unethical thing you've done as a programmer?

#361
post #219

I created software that was used by call center agents to bid on “bathroom” break time slots and kept track of who was on break and actively punished those who didn’t follow the rules. It rewarded those that had higher performance and who took less breaks with higher priority. If an agent didn’t come back from their break a security guard would automatically be dispatched to find them. For the same company I also mad…

I have to ask, why did you choose to take the contract? Financial pressures? Or did you not feel that such a system is morally reprehensible? Personally while I'm opposed to programmer certification, systems like these certainly make me wish such a thing existed.

I was just starting out in my career and was more pre-occupied with the task at hand to have enough mental headspace to contemplate the full picture of what was happening. The system itself was designed by traditional software means: trial and error, trying to see what worked and didn’t, usually trying to maximize some KPI at the company. There was also the thought that punishment and reward should be applied fairly and be “data driven”; take the bias and human factor out of decisions and implement performance management in a predicable, deterministic and transparent way.

The problems arose when people realized that the same controls and abilities to instill this equity and “fairness” provided the platform to enable wide scale exploitation in the other direction. Want more profit? Change a variable that was a single number whose action would cause great stress for many people, but would produce a desired result. The goals and metrics would always start out resonable but eventually would cross a certain point, and once they did, there was no going back to the way things were.

Draw your own conclusions to the similarities in this system to our modern day technical web triumphs.

Re: Ask HN: What is the most unethical thing you've done as a programmer?

#362

I created software that was used by call center agents to bid on “bathroom” break time slots and kept track of who was on break and actively punished those who didn’t follow the rules. It rewarded those that had higher performance and who took less breaks with higher priority. If an agent didn’t come back from their break a security guard would automatically be dispatched to find them. For the same company I also mad…

First i thought that this is scary but I've had many friends who told me that they they play games all day at their office and once boss called them in their cabin and they expected to be laid off but were given a small raise instead.

"I take lots of cigarette and bathroom breaks to fix my makeup/hair and Snapchat my friends. I can't see myself working hard. I am not a sheep". Those are the exact words.

This is a scene from a government organization in Romania.

Now, i am in the US and I've not witnessed it here but here i am in executive role so i hangout with different people.

I asked them why not do your job properly? They answered, if they are going to do their job then they'll most likely receive a promotion, raise and more responsibilities come with it. For them more money = more problem.

They told me that for them money does not matter and all they want is experiencing different cultures, traveling etc... and work has no place in it.

This is something I had never heard before!

They somehow managed to rationalize not performing their jobs.

Re: Ask HN: What is the most unethical thing you've done as a programmer?

#363
Throwaway account.

In high school (2010-ish), I was on the student council so I had insider access of sorts to a lot of the inner workings of the school administration. One day, during a short meeting with them, the principal told us on the council that the IT department was installing wifi for personal device use. Since we had difficulties with getting school bonds passed by voters at the time, the wifi was supposed to enable us students to bring our laptops from home and use them in the classroom (since most classrooms only had 3-4 computers, with older schools only having 1-2 computers per classroom for staff use only). Naturally, we were all on board since it would enable us to finish our schoolwork without fighting over computer space.

Fast forward two months and I notice that the wifi seemingly hasn't been installed yet. I ask the principal and was told that it was supposed to be installed and working perfectly. So I did some digging on one of the school computers. This is where I found out how the school district's IT department submitted updates.

The IT department ran an old Novell Netware server for account login, Faronics Deep Freeze on the end user machines to protect against student abuse, and a Windows network share for unattended updates. Since the Windows Netware client cannot assign local Windows permissions (or it wasn't configured properly in my case), everything inside Windows was ran with admin privileges (you were logged into Netware but ran under a local admin user account in Windows). Since Deep Freeze reverted changes to the file system on reboot, the assumption was that the students could completely wreck the install all they wanted with a simple reboot being all that was needed to effectively reset the machines to the default configuration.

This strategy worked well, but there is a huge flaw. Because you had local admin rights, you had full access to whatever resources you wanted under Windows XP Professional (the OS of choice back then). This includes the ability to install software or games (we had some epic district-wide Halo CE LAN parties), see network information (MAC address, IP octet configuration, etc), and everything else you could do to a local computer. The only caveat is that whatever changes you made would be erased on reboot. I guess the assumption with this is that the average inner city high school student wouldn't have the technical expertise to know how to read this information, let alone access it. But, with me being gifted with tech skills at an early age, I could do some damage.

Back to the wifi story. I noticed in my digging that my Novell account credentials would let me into their update share. I was able to mount the share as a network drive and look through it. I saw everything from MS Office VLKs, the Faronics uninstaller, network diagrams, etc. I did have some ethics back then, so I didn't touch anything related to a license key. But I did find the wifi deployment timetable document.

It turns out that the IT department had already deployed the wifi to my school and was fully functional...for them only. They had made it as a hidden network only accessible to them for "maintenance purposes". (Keep in mind that most of the school and administration was under the impression that it was going to be for student use.) The timetable document also listed the wifi password for the hidden network. With that information and the MAC/IP pattern I swiped from one of the school machines, I was able to log onto the "maintenance" wifi with my own personal laptop. This made me the talk of the student body ironically, with even one of the assistant principals asking me for help because the IT department had stopped communicating with the administration regarding the rollout.

Anyways, I used my newfound wifi powers to do my work and prep for college. Never used any of the serials or anything, just wanted to stop fighting over computer use. Ended up keeping the timetable document on a thumb drive until graduation before sticking it in my desk for a few more years. When I moved to Seattle for work, I ended up tossing the drive into the ship canal under the Fremont Bridge. (If someone finds it, I'll buy them a beer.)

Anyways, that's my unethical story.

TL;DR: Hacked into a network share to get wifi access in high school because the IT department embezzled funds.

Re: Ask HN: What is the most unethical thing you've done as a programmer?

#364

Earlier quoted context omitted.

Most of the dark patterns lead to more profits, or sign ups, or something measurable. That's why they are everywhere, they really have a purpose.

I believe the key word is 'something measurable'. People remember their obtrusive ads more so they think mission accomplished even though they now try to avoid them as 'the guys with the obnoxious advertisements'. It might be ultimately detrimental to the company but their bosses think it is a good thing and they get rewarded for it. Metricitisis is a major management disease of our times and neither corporate, nor g…

Also, the question is, who did the measuring?

I worked once for a small company that had a social media marketing side (separate from what I did for them, but we sat in the same open space). From what I've observed, the social media marketing business mostly boiled down to our people writing reports which shown nicely growing metrics to customers who then happily paid. The metrics might or might not have been correlated with any real-world increase in profits, and really neither side understood any of that. But it looked believable, so customers paid.

I suspect a lot of that is happening in adtech these days - people with no understanding of statistics bullshitting each other with pretty charts.

Re: Ask HN: What is the most unethical thing you've done as a programmer?

#365

Earlier quoted context omitted.

People are not yet omniscient, I agree. But lately there's this wonderful new tool called the Internet which allows people to become omniscient as far as product discovery is concerned. If you have a product that solves problem X, make a website, blog posts, send samples to journalists for reviews, etc about how your product solves problem X, and let search engines & organic growth do the rest. > You're just arguing…

I'm definitely getting the impression that you're just asserting that outbound sales is "bad" in some general sense rather than specifically that its use means the business is a scam. Microsoft has one of the highest quality sales teams there is. Many of which are outbound focused. Do you consider Microsoft products to be scams? Most (all?) silicon Valley b2b startups utilise outbound sales heavily. /r/sales is full…

Well every “outbound sales” interaction I had was bad, so that’s my reasoning for not liking them.

If I need something, I will search for it, read your website/marketing material and decide for myself. It is an automatic turn off if you call me first because you’d be taking my time, possibly interrupting me, and putting pressure on me to buy now that I otherwise wouldn’t have if I was evaluating the products myself.

> Microsoft has one of the highest quality sales teams there is. Many of which are outbound focused. Do you consider Microsoft products to be scams?

Define “high quality”. Is it high quality by conversion rate or is it by customer satisfaction, churn rate, etc? Because I too can build a “high quality” sales team by holding my future customers at gunpoint and achieving a 100% conversion rate.

While I don’t consider all Microsoft products to be scams, I definitely know a few that wouldn’t exist if it wasn’t for clueless people being conned into buying it by salespeople or consultants.

> Most (all?) silicon Valley b2b startups utilise outbound sales heavily

And I guess this is why Oracle, IBM and similar shitty companies are still in business, because they rely on clueless people falling for their sales tactics instead of actually making great products.

> If so, what is a scam to you?

A scam is something I would fall for that I wouldn’t normally fall for if it wasn’t for pressure/ideas from an uninvited salesman/scam artist. So like if I evaluate your product and decide it’s not for me, and then fall for it because of a salesman playing with my emotions (technically that wouldn’t work on me, but a lot of life insurance telemarketers will for example use the “think of your family” aspect to get a sale) or similar, then I would consider it a scam. A legal scam, but a scam nonetheless.

Re: Ask HN: What is the most unethical thing you've done as a programmer?

#367

Earlier quoted context omitted.

I disagree. You wouldn’t need “outbound sales” if you had a product that people wanted. They would be calling you with their wallets open if it was the case. You only need outbound sales/scammers if you have a product that you think that people need even though they’ve been living without just fine for ages. > Some of it is scams, plenty isn't. Please give me some examples of how some are scams but plenty are not. Fr…

How is it an innocent victim? Every company that I’ve worked for that sold B2B software had salespeople that had “regions” they sold into to get contracts. How are they anything but glorified telemarketers? I doubt any of our customers were “scammed” into buying services that cost tens of thousands a year. While I’ve never bought anything from a telemarketer, it doesn’t mean that thier product is not legit.

If the customer comes first to you and gives you their contact then it’s no longer telemarketing IMO - at the very least not the usual definition of telemarketing which is “asshole spamming your phone to sell their snake oil”. But if you just call out of the blue, I don’t care whether what you sell is legit, it’s just not okay to waste my time - frankly the fact that your company uses these practices damages my opinion of your product already. I don’t do that to your company - don’t do it to mine.

Now I’m not sure how prevalent scams are in the B2B industry (although I would expect there are still a lot of salespeople preying on clueless people that would fall for marketing BS instead of actually evaluating the product), but in B2C, every telemarketing call I’ve received was a really bad deal at best (that a quick Google search would beat), and an outright scam at worst.

Re: Ask HN: What is the most unethical thing you've done as a programmer?

#368
Not going to incriminate myself with any of my own stories, but a friend did work for a phishing take down company that was paid per site they removed. Of course the people who sign off on these things are never that technical, so the company was paid a non-trivial amount (say $1,000) for taking down each subdomain.

Think, contact.bankna.me, support.bankna.me, aus.bankna.me, customer-support.bankna.me, login.bankna.me etc etc.

They would often take down the subdomain and leave the parent name intact so they could keep cutting off the individual heads of hydra, if you will.

Re: Ask HN: What is the most unethical thing you've done as a programmer?

#370
I lied to the C-levels at a previous company about how hard it would be to monitor and log the instant messaging traffic of everyone at the office. Everyone was using AIM and there was no encryption, so it would have been trivially easy (I verified this, which was scary).

I then lied and told the CFO and CEO that it would be prohibitively hard to do and they dropped it. :P

Post reply on HN