Live data from Hacker News

Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

news.ycombinator.com

1–10 of 82 posts

Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#1
A big bank in Australia has outsourced its work to my consulting company and when I started work at this bank (One of the biggest in Australia) I noticed that my consulting company is illegally uploading bank software to github.

They do this because each consultant needs to have background verified by the bank security advisors which takes around 2-6 weeks and moving all the software to github allows all consultants to start working immediately (without waiting for background check to complete).

I pushed my code to github without my knowledge the first day and brought this matter to my higher ups in my company but they threatened to take me off the project if I "impeded the workflow of the team".

Now, my rest of the contract fees hasn't been paid out.

A software lawyer said I could be implicit in this activity (which he says is NOT criminal but civil liability) because I pushed my code to the company github on internet (Regardless of my intent or ignorance)

I am an independent contractor with the consulting company. The Financial Ombudsman said I do not qualify for lodging a complaint since I am not "technically an employee"

What's the way out? And will I be in legal trouble if I lawyer up?

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#2
What rights has the bank given to the consulting company regarding the software?

If the bank has stated that the software can't be on github and your company is putting it there then it sounds like a legal trouble between the bank and consulting company with you as the whistleblower, if you decide to lawyer up

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#3
Anonymously heads-up the country-level information security officer of the bank in question with a link to the Github repo. CC the country head.

Working on code without security background checking confirmed is an absolute no.

This will completely torpedo your employer, but that might not be so bad if this is their attitude to information security.

Edit: As anonymous as you can. Have a lawyer present. Don't take advice from the internet like it is legal opinion.

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#4
"Illegal" how? Against an actual Australian law, or do you think it's against the terms of the master services agreement the bank has with the consulting company. Have you seen that agreement or the specific statement of work they're operating under?

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#5

What rights has the bank given to the consulting company regarding the software? If the bank has stated that the software can't be on github and your company is putting it there then it sounds like a legal trouble between the bank and consulting company with you as the whistleblower, if you decide to lawyer up

There are strict security in place to prevent any "leaks" of software which means all USB ports are disabled in company devices, the company network has disable git/github/bitbucket and our security manual explicitly states that the code cannot leave the intranet.

The consultant bypasses this by running wireless hotspots

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#6

What rights has the bank given to the consulting company regarding the software? If the bank has stated that the software can't be on github and your company is putting it there then it sounds like a legal trouble between the bank and consulting company with you as the whistleblower, if you decide to lawyer up

There are strict security in place to prevent any "leaks" of software which means all USB ports are disabled in company devices, the company network has disable git/github/bitbucket and our security manual explicitly states that the code cannot leave the intranet. The consultant bypasses this by running wireless hotspots

Talk to a lawyer. Especially because you're asking about Oz advice on a primarily us site, so common understanding of the law may be different. And whatever you do, consider if you can afford getting both fired and sued right now - even if people tell you you're right.

Also I'm assuming that's 100% the public GitHub service and not an on-site, or specially negotiated GitHub enterprise system?

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#7
post #6

Earlier quoted context omitted.

There are strict security in place to prevent any "leaks" of software which means all USB ports are disabled in company devices, the company network has disable git/github/bitbucket and our security manual explicitly states that the code cannot leave the intranet. The consultant bypasses this by running wireless hotspots

Talk to a lawyer. Especially because you're asking about Oz advice on a primarily us site, so common understanding of the law may be different. And whatever you do, consider if you can afford getting both fired and sued right now - even if people tell you you're right. Also I'm assuming that's 100% the public GitHub service and not an on-site, or specially negotiated GitHub enterprise system?

100% public github because they want to give access to new employees who do not have access to enterprise system.

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#8
post #4

"Illegal" how? Against an actual Australian law, or do you think it's against the terms of the master services agreement the bank has with the consulting company. Have you seen that agreement or the specific statement of work they're operating under?

I have worked in Financial sector for a long time and know that copying bank software illegally is criminal in US and probably civil in Australia.

I program for the bank via the consulting company and my code is on the internet. Plus my contract is frozen with fees until I withdraw my complaint to IT of my consulting company.

Not sure who to talk to in the bank. HR said I have to resolve with my consulting company but I am pretty sure the HR doesn't understand the implication of copying software

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#9
post #3

Anonymously heads-up the country-level information security officer of the bank in question with a link to the Github repo. CC the country head. Working on code without security background checking confirmed is an absolute no. This will completely torpedo your employer, but that might not be so bad if this is their attitude to information security. Edit: As anonymous as you can. Have a lawyer present. Don't take advi…

The consultant is running wireless hotspots to copy the software. All I want is the contract money they agreed to pay me for this project. They froze the payment because I complained about this, at best unethical, behaviour.
Post reply on HN