Live data from Hacker News

Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

news.ycombinator.com

51–60 of 82 posts

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#52

Earlier quoted context omitted.

No. They said it's on the public GitHub, as opposed to private GitHub enterprise installation. Not that the repo itself is public.

This is correct. It's a "public github" as in it's on *.github.com with access to all employees of the consulting company regardless of the background check (That's the whole idea of them moving to their github repo)

I think there's a small misunderstanding here that I'd like to clear up explicitly.

Public GitHub repos are viewable by anyone with or without an account. You can view and clone the repo if you know the correct URL.

Private GitHub repos are only accessible to those given access.

Within the scope of this terminology, my understanding is that this repo is private. I think I'm right based on https://news.ycombinator.com/item?id=13682657 and https://news.ycombinator.com/item?id=13682501. Am I right?

Within the scope of corporate security, I understand that the code is being moved out of the local intranet onto a non-corporate-managed Web service. However, GitHub manage private repos for some fairly high-level groups (or at least I assume they do), so their data protection policies are clearly very decent. (I at least know that individual floors on the building are keycarded, which is nice. I learned this from a story posted here by a guy who got fired.) So, even though this is an impressive level of stupid, I'm relieved that no leaking can/will happen (particularly for your sake now you've posted this here).

OP, please note that several people have reached out to you from top-level comments. If you could add a new comment listing an email address (IANAL but a new gmail one would probably be okay), or even better yet put it in your profile, that would probably result in some nice leads for you.

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#53

Earlier quoted context omitted.

Thanks. I tried to avoid getting too specific since I knew Australian law would be different, i.e. in the US the normal form of protection would be an LLC or an S-corp (tax pass through closely held entity) and a consulting firm in the US would very rarely be a C-corp (taxable income at both corporate and individual levels). What employment means is also different. A person consulting to a consulting company that con…

Off topic: It would be good to have C-Corp and be taxable at both corporate and individual levels because companies pay a flat tax while individuals are tiered. This way we can choose our salary and leave the rest in company. This however severely complicates cases like mine which has three pass-thru contracts

In the US, there is a cap on the wages to which social security tax applies. That tax amounts to approximately 15.5% of gross salary when the company portion and the individual portion are combined, the effective tax rate for an individual is much less progressive than portrayed in popular political opinion. It is also the case that control of a C-corp offers much less personal liquidity than is possible with an LLC. In addition, the layer of complexity for a C-Corp is likely to require more meaningful (from an individual perspective) expenses on legal and accounting services.

All things being equal, it makes sense to optimize on taxes. Most of the time, all things aren't equal.

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#54
Now, my rest of the contract fees hasn't been paid out.

A software lawyer said I could be implicit in this activity ...

...

What's the way out? And will I be in legal trouble if I lawyer up?

I'm not sure why you are asking for advice on Hacker News if you've already spoken to a lawyer. Has the lawyer advised you to lawyer up?

There's nothing wrong with whistleblowing, or even venting on HN if you feel you were robbed by the consulting company of contracting fees, but I don't see the point of seeking legal advice here, under these circumstances.

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#56
post #52

Earlier quoted context omitted.

This is correct. It's a "public github" as in it's on *.github.com with access to all employees of the consulting company regardless of the background check (That's the whole idea of them moving to their github repo)

I think there's a small misunderstanding here that I'd like to clear up explicitly. Public GitHub repos are viewable by anyone with or without an account. You can view and clone the repo if you know the correct URL. Private GitHub repos are only accessible to those given access. Within the scope of this terminology, my understanding is that this repo is private. I think I'm right based on https://news.ycombinator.com…

> I understand that the code is being moved out of the local intranet onto a non-corporate-managed Web service

Spot on and this is what I meant. By "public github" I meant code on the internet but accessible to anyone in the consulting company. There are multiple modules and they are moved to github,bitbucket and stash.

This also means people without background checks or ANYONE in the organization has access to ALL the code of the bank. In the bank ONLY people in specific departments have access to specific code (As is customary for all IT industry)

I am not trying to be a whistle-blower and mr goody two shoes. I am very angry that my refusal to upload code to the internet is resulting in non-payment of fees and threats that I will never get a contract in this city. And as an independent contractor I am truly terrified of uploading bank code to the internet; I don't want to end up in jail for stupid reasons.

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#58
Just a clarification that I posted here:

By "public github" I meant code on the internet (from the bank intranet) and accessible to anyone in the consulting company (public as in public network). There are multiple modules and they are moved to github,bitbucket and stash. This also means people without background checks or ANYONE in the organization has access to ALL the code of the bank. In the bank ONLY people in specific departments have access to specific code (As is customary for all IT industry) This in turn means all contractors that git sync have all code on their machines regardless of their access.

The consulting company is not breaking rules just for the sake of it but to speed up development although what they doing is illegal.

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#59
post #52

Earlier quoted context omitted.

I think there's a small misunderstanding here that I'd like to clear up explicitly. Public GitHub repos are viewable by anyone with or without an account. You can view and clone the repo if you know the correct URL. Private GitHub repos are only accessible to those given access. Within the scope of this terminology, my understanding is that this repo is private. I think I'm right based on https://news.ycombinator.com…

> I understand that the code is being moved out of the local intranet onto a non-corporate-managed Web service Spot on and this is what I meant. By "public github" I meant code on the internet but accessible to anyone in the consulting company. There are multiple modules and they are moved to github,bitbucket and stash. This also means people without background checks or ANYONE in the organization has access to ALL t…

Gotcha.

Hmm, so this is violating standard access controls. I can appreciate your freaked-out-ness...

I understand you're not trying to make a scene (especially considering the circumstances!) and are simply trying to resolve what is effectively a legally-tangled paycheck bug.

Have you made any practical headway with figuring out how to resolve this? https://news.ycombinator.com/item?id=13682560 looks interesting, and https://news.ycombinator.com/item?id=13682806 sounds helpful also.

PS. FWIW, I'm in Sydney myself :) although I'm not working at the moment.

Re: Ask HN: I work for consulting firm that's illegally moving bank code to GitHub

#60

I would use the consulting company's open door policy and go up the chain... right to the country lead partner and mention this to them in writing. Believe it or not ethics is extremely important to consulting companies as trust and future work depends on this - and bring up any fears of being dismissed for bringing this up to their attention.

>consulting company's open door policy

Just a heads up (regardless of my case):

Company open door policy exists to protect the company. Even the HR is there to protect the company. Even in US, whistle-blowing or rocking the boat will result you in being fired faster than you can say Oklahoma backwards.

Post reply on HN