Live data from Hacker News

Tell HN: Triplebyte reverses, emails apology

news.ycombinator.com

521–530 of 678 posts

Re: Tell HN: Triplebyte reverses, emails apology

#521
post #243

Earlier quoted context omitted.

We do not have a Chief Privacy Officer or Chief Information Security Officer. The issue was raised by our head of product and I dismissed it. I saw it as a minor concern (I'm ashamed to say).

Next time: pass it by your lawyers for a quick review if you can't trust your own judgment on things like this. Ditto for all the dark patterns you are still using today on your website, clean up your act. Note that you are firmly in the crosshairs of the EU data privacy watchdogs and that the fines are nothing to sneeze at, if you expect to establish and maintain a foothold in this market realize two things: - trust…

This is good advice, but I'll add to it. Your general counsel is an acceptable, but not great, substitute for a real VP-level privacy officer. Lawyers tend to look at privacy issues with an eye towards compliance, i.e. does this privacy issue subject us to regulatory scrutiny or open us up to lawsuits? They don't always look at these issues from the point of view of "What is our company's philosophy around the sharing of our users' data, around providing transparency and control for users, and does this feature align with that philosophy?" A dedicated privacy professional will explore that question deeply.

In my opinion, in 2020, any company that releases software and has more than like 20 engineers should have at least one VP-level privacy approver who has the power to block releases.

Re: Tell HN: Triplebyte reverses, emails apology

#522
post #209

Earlier quoted context omitted.

He certainly spent a great deal of time saying "I'm sorry you feel that way" (a classic non-apology... there's no better way to make a bad situation worse than by starting off with those words).

What I've come to observe is that you can never make everyone happy - a truism detached from this specific incident. So when you receive negative feedback on something - how should you respond? What if you're used to some certain baseline level of negativity? How should you respond then? I feel like there is feedback on the individual level and the aggregate level. Clearly in this case TripleByte saw that they would…

There are plenty of ways to respond. "I'm sorry you feel that way" is never one of them.

Re: Tell HN: Triplebyte reverses, emails apology

#523

I am not an active Triplebyte user, but I have an account and followed the thread(s). This e-mail (which I also got) seems like a heartfelt apology. They fucked up, realized it and turned the ship around. They listened and that's what counts for me. They listened to the negative feedback and responded to it. Some comments around here are extremely negative of the whole situation. More negative than I think they deser…

> They could've pushed through and ignored all the feedback they got. That’s a very charitable analysis of the situation. For all we know, this decision was motivated by internal KPIs that immediately reflected what a disaster this was. The whole situation reeks. Announcing on the Friday on a long weekend, the ceo defending it ardently in HN comments, the very deliberate decision to make it opt-in, the difficulty in…

What's left me confused is one thing: if the significance of "default public" was missed, then what was the motivation for the previous warning email? It seems bizarre to suddenly email everyone "Hey folks, we're changing your default privacy settings next week" while simultaneously believing that it's... an insignificant thing?

Re: Tell HN: Triplebyte reverses, emails apology

#524
post #78

One of two things happened: 1. Triplebyte attempted a big move against LinkedIn, tried to ease the blow to users by dumping on a Friday before memorial day weekend 2. Triplebyte, the company built around helping people find jobs, truthfully didn't understand that people might have concerns about their current companies knowing they are job-hunting It's pretty obvious it's #1, and that opt-out rather than opt-in was t…

I'd say it was both. I wanted to move against LinkedIn profiles, I thought that opt-out was the way to get critical mass, and I screwed up and did not realize how large a privacy violation this was.

> I screwed up and did not realize how large a privacy violation this was

Riiiight. You didn't realize how big it was because you didn't care, until it was clear it was going to have a serious negative impact on you. You didn't care about the privacy of others or otherwise you wouldn't have made the choices you did.

Re: Tell HN: Triplebyte reverses, emails apology

#525
post #396

Earlier quoted context omitted.

One continues to be taken advantage of, over and over again. Assuming good faith is not prudent when dealing with people who want your money or data. We have enough collective experience at this stage to say this conclusively. Edit: Being cynical is the new normal when dealing with companies. Especially if they have your data, or want it.

> Assuming good faith is not prudent when dealing with people who want your money or data. We have enough collective experience at this stage to say this conclusively. Well said. This ought to be taught in schools. Being slightly pedantic I'd change it to "when dealing with companies that want your money or data" rather than "people" (though I've pretty sure that's the general meaning you intended anyhow).

Until companies are run by AI, it's people.

Re: Tell HN: Triplebyte reverses, emails apology

#526
post #500
post #420

Earlier quoted context omitted.

Check out the original HN topic. It would be one thing if he apologized immediately after people pointed out the flaws in their plan. But he didn’t. He ignored all the objections, and defended his decision over and over again. He clearly didn’t care. There is huge difference between “whoops, we didn’t think things through, sorry about that” and “after seeing tons of people cancel their account, let’s pretend that I’m…

Yeah it kind of feels like the reversal came only after hundreds? of people deleted their accounts.

> hundreds? of people deleted their accounts

Two thousand: https://news.ycombinator.com/item?id=23304097

Re: Tell HN: Triplebyte reverses, emails apology

#527

Earlier quoted context omitted.

Hi Ammon, 1. There is an opportunity. 2. You did lose a lot of trust. 3. You didn't have enough trust in the first place to really take advantage of this opportunity. I would encourage you to think about how you can earn that trust. This comes back to transparency and checks-and-balances. If you want to go that route, you will need to build hard constraints: legal and technological constraints which would have preven…

> Your team has a fiduciary duty to maximize shareholder value That’s actually not true. Also, your comment comes off as needlessly offensive: > 3. You didn't have enough trust in the first place to really take advantage of this opportunity. > I would encourage you to think about how you can earn that trust You’re attacking him when he’s come back, owned up, and apologized for the mistake.

I apologize if they come off as offensive. That was not the intent. I wasn't trying to attack him -- it's not personal. I'm criticizing a system he has in place, which this incident highlighted.

I'm also suggesting an alternative which I /think/ would have more privacy and more business value. I'm not an insider, so I could be wrong about either of those, but that's the point of a conversation. This way, he knows what would work for me, as a potential user. He can take it and run with it, take it as a problem statement and run with a different solution, or take me as 0.0001% of the market and ignore it. In his shoes, I've done all three at different times.

Re: Tell HN: Triplebyte reverses, emails apology

#528

Earlier quoted context omitted.

> This e-mail (which I also got) seems like a heartfelt apology. Even if it is heartfelt, I'd argue that if no alarm bells went off internally when they were discussing this feature, they are not the group of people to entrust with information such as this.

He dropped it on the Friday before the biggest holiday weekend of the year. He knows what he's doing. He's done it before, and he's still doing it. Just pulling power moves. Move fast and fuck shit up. The dude has personally tried to pull fast ones on me. This is a fucked company since day one. I brushed it off, but when you keep up these patterns for years...jog on.

> biggest holiday weekend of the year.

What holiday was that? I wasn't aware of any. In any case, I'd say Christmas is probably the biggest holiday, although it doesn't always fall on a weekend.

Re: Tell HN: Triplebyte reverses, emails apology

#529
post #515
post #409

How did you manage to submit this? I tried to submit it myself about the same time you did but got an error that the text could not be more than 2000 characters. How did you get past this limit?

They originally put a prefix in the root text and the rest here: https://news.ycombinator.com/item?id=23303045 . I inlined it. You can get around the limit by using 'edit' after a post is up.

Heh, that'll teach me to try to follow the rules. All that karma, gone! Gone, I tell you!!!!

;-)

Re: Tell HN: Triplebyte reverses, emails apology

#530
post #70

Earlier quoted context omitted.

Hi Ammon, 1. There is an opportunity. 2. You did lose a lot of trust. 3. You didn't have enough trust in the first place to really take advantage of this opportunity. I would encourage you to think about how you can earn that trust. This comes back to transparency and checks-and-balances. If you want to go that route, you will need to build hard constraints: legal and technological constraints which would have preven…

We are thinking about how we can make a stronger (and specific) privacy guarantee so it's not just a matter of our future intentions. I had a long conversation with my co-founder about this yesterday. We did not get anything together in time to include it in this email. But we're planning to.

I'm late to the party, and haven't done an extensive search to see if anyone has suggested this, so I'll offer my opinion anyway.

If you want to build a LinkedIn competitor it should be a completely different product to what you offer now with private employeremployee hookups.

The two services should be physically separate in every sense, so there's no possibility of someone flipping a bit and accidentally making public someones private job search intentions.

Post reply on HN