Live data from Hacker News

Tell HN: Triplebyte reverses, emails apology

news.ycombinator.com

301–310 of 678 posts

Re: Tell HN: Triplebyte reverses, emails apology

#301

Earlier quoted context omitted.

Triplebyte is not for EU users. You're forgetting that Triplebyte is an American company, they're not subject to European nanny laws.

Any European citizen is covered by GDPR no matter where they are located.

First of all, this isn’t popular with the EU crowd here, but there’s no method of enforcement for GDPR for American companies without a presence in Europe. Good luck trying to collect a fine from some tiny business in the US

Second, you really think GDPR is going to be applied to some tiny American startup because they said they might do something and then didn’t?

Third, my understanding is that if you don’t target EU customers, GDPR doesn’t apply. It’s not enough that an EU customer happens to wander into your store. You have to have some accommodation targeting the EU (like translated pages, international shipping, different currencies, etc)

Re: Tell HN: Triplebyte reverses, emails apology

#302
post #243

Earlier quoted context omitted.

Do you have a Chief Privacy Officer? Or Chief Information Security Officer? Was the issue raised and the privacy impact miscalculated (not ideal, but mistakes happen) or were the potential privacy implications overlooked entirely?

We do not have a Chief Privacy Officer or Chief Information Security Officer. The issue was raised by our head of product and I dismissed it. I saw it as a minor concern (I'm ashamed to say).

[deleted]

Re: Tell HN: Triplebyte reverses, emails apology

#303

Too late. I deleted my account today. Though of course it apparently takes 30 days to process an account deletion. Why? Do you guys need to recruit a DBA?

30 days is the maximum time allowed under GDPR. Quite typical to tell people it might take up to 30 days (though it practice I've found it rarely does).

Re: Tell HN: Triplebyte reverses, emails apology

#304
post #50

Earlier quoted context omitted.

> Some comments around here are extremely negative of the whole situation. More negative than I think they deserve People would have gotten laid-off to this. The dark patterns are just cherry on top. The negativity is well deserved.

Are workers in a competitive industry such as tech really at risk for getting fired for possibly looking for new work? Having a TripleByte profile would say as much as having a LinkedIn profile. It doesn't necessarily mean you're looking for a job. And when it's extremely difficult and expensive to replace an engineer, it seems like a bad business decision to fire a worker for this reason.

This gets into all sorts of dynamics and who controls them:

-- Layoffs are happening around COVID, now who do you think a manager will feel more OK picking?

-- For luckier companies, bonuses/refreshers/promotions happen at different times, a candidate may want their manager thinking about their work vs. them exploring greener pastures

That's sensitive stuff! Some candidate may like being exposed (it's a threat!), some won't (shows disinterest! distracts!). Crucially, the question is of agency: folks entrusted TripleByte, expected privacy based on TripleByte's marketing and industry norms, and instead of having the decision, got into a world of dark patterns (opt-out, weak notification, difficult avoidance, long time delays, ...).

Edit: People are down-voting this. Consumer tech companies have been going through layoffs, generally one or more rounds of 20%. Many B2B's are on a delay, and are starting to see numbers around their b2c customers plummet: easy for more to happen as ripples continue. What could have been an opt-in feature to help folks maybe get better new positions was instead setup to add easily-avoidable risk.

Re: Tell HN: Triplebyte reverses, emails apology

#305

Earlier quoted context omitted.

> This e-mail (which I also got) seems like a heartfelt apology. Even if it is heartfelt, I'd argue that if no alarm bells went off internally when they were discussing this feature, they are not the group of people to entrust with information such as this.

There was a study about surgical fuckups. In almost every case, multiple people in the OR admitted they recognized the problem but were too scared to speak up because the surgeon said things were going fine.

Many engineers complained about the risks before the Challenger disaster. Management suppressed the concerns and championed incorrect risk math in order to justify it.

Re: Tell HN: Triplebyte reverses, emails apology

#306

I am not an active Triplebyte user, but I have an account and followed the thread(s). This e-mail (which I also got) seems like a heartfelt apology. They fucked up, realized it and turned the ship around. They listened and that's what counts for me. They listened to the negative feedback and responded to it. Some comments around here are extremely negative of the whole situation. More negative than I think they deser…

> This e-mail (which I also got) seems like a heartfelt apology. Even if it is heartfelt, I'd argue that if no alarm bells went off internally when they were discussing this feature, they are not the group of people to entrust with information such as this.

Given the prevalence of comments like this, I wonder why any company would ever bother offering an apology or retraction.

As soon as a company does something that a chunk of people on the internet don’t agree with, there’s really no way out. They’re going to get bad press regardless of whether they retract, whether they apologize, and whether they say they’re taking actions to avoid the sequence that led to the action in question.

But alongside that, for every time the internet mob has risen up over a company’s action, very few companies seem to have experienced major long term effects. I bet everybody knows a few people who have quit Facebook/GitHub, or who rage about Oracle business practices or MongoDB stability, but these companies still manage to keep trucking along.

In light of this, I’m mostly surprised that Triplebyte bothered apologizing; it seems unlikely to do them any good, and it’s unclear to me whether continuing course would have actually done as much harm to their bottom line as the prior Hackernews thread appeared to indicate.

Re: Tell HN: Triplebyte reverses, emails apology

#307
post #283

Earlier quoted context omitted.

They gave their user base only one week's notice of the upcoming change[1], and according to the discussion in the original thread, had dark patterns in their UI that made it hard to opt out of the feature (it would only allow you opt out for 24 months)[2] or cancel your account. [1] https://news.ycombinator.com/item?id=23279837 [2] https://news.ycombinator.com/item?id=23283237

I got the email. Your characterization is inaccurate.

I also got the email. I think the characterization is entirely accurate. (The bit about needing to opt out was badly phrased at best, and buried in the middle of a paragraph. I skimmed the email and thought it was a neat feature, and made a note to turn it on before my next job hunt.)

Re: Tell HN: Triplebyte reverses, emails apology

#308

Earlier quoted context omitted.

Any European citizen is covered by GDPR no matter where they are located.

I’m curious how that’ll work in practice. The sovereignty of a nation is a big thing. The US isn’t going to just prosecute TripleByte because Europe said they should. Sure, if @ammon visits the EU, he could be arrested, but a nation’s laws (generally) don’t extend past their border.

It’s a total pipe dream. I don’t know what fantasy land people are living in where they think the EU is going to successfully collect a dollar in fines from some random small company elsewhere in the world, no matter how messed up their privacy practices are.

Re: Tell HN: Triplebyte reverses, emails apology

#309
post #287

Earlier quoted context omitted.

I'm in a different industry, but I read the HN thread about it a few days ago. In the CEO's comments, I saw a lot of 'I'm sorry you feel that way' type of apologies. I wrote that he should take responsibility for his own actions. Perhaps he read that and took it to heart. Perhaps he read that and realized it would sound better if it seemed like he took it to heart. Perhaps after the monumental PR screw-up, they hired…

They scrapped the feature so that's an action backing up his words.

Question is why was it there in the first place , so hideous, so late on Friday, one week time to update the profile. Why not more time when it concerns privacy.

Re: Tell HN: Triplebyte reverses, emails apology

#310

Earlier quoted context omitted.

I also read a story on HN where a devops engineer made a $80k mistake and got fired. He got hired at a new startup and the founder thought "of course he won't make the same mistake twice". He did.

Anyyyy chance you happen to have that link handy? Terrible misfortune but sounds like a good read.

https://news.ycombinator.com/item?id=22719573
Post reply on HN