Live data from Hacker News

Don't Talk to Corp Dev (2015)

paulgraham.com

41–50 of 127 posts

Re: Don't Talk to Corp Dev (2015)

#41
post #24

Earlier quoted context omitted.

Old HTML might be fine, but sending it over an insecure connection isn't.

These words "secure" and "insecure" when used as synonyms for "encrypted" and "plaintext" obscure more than they illuminate and have done a lot of damage to the world of software security. They stop thought. You would not believe how many times I've talked to a company with some complex webapp and asked for their security policy and they respond with some statement about using TLS. It's absurd. Then even in books or…

In the era of instant, free and stupidly easy to configure TLS certificates why not just serve it over HTTPS?

Re: Don't Talk to Corp Dev (2015)

#42
>If they can, corp dev people like to turn the tables on you. They like to get you to the point where you're trying to convince them to buy instead of them trying to convince you to sell.

I worked for an established company (not a startup) and had a run in with Wal-Mart. Wal-Mart managed to buy some stuff at an ultra low discount because ... someone thought maybe if we get in there we could sell tons to their IT team.

Meanwhile I'm working with their IT guys. They hate the product. They tell me in no uncertain terms and in every unprofessional way you can imagine (that part was pretty shocking). Of course what they're really doing is just buying the minimum and pounding the hell out of support with complaints as they pump 20 gallons into 10-gallon hat of our product.

What happens? We keep providing them free services, extra services. The folks at the top think they're at the tip of a big sale, big money despite myself and others telling them "These guys don't like our widget, they don't want it... and they're not capable of even making good use of it. All while giving it to them for free, why would they pay a dime more?"

By the end I hear we've made like our 5th pitch to them that is barely profitable for us... just on the face value of the product and support. Somehow Wal-Mart convinced these guys to take a 'big sale' moment and turn it into a loss if you consider all the time put into working with them. And they were happy to do it.

Finally we had a stroke of luck, we were acquired, and the new CEO had worked with Wal-Mart before as a customer and cut them lose. Finally all that effort and energy that went into this big deal that never happened (probably for 18+ months) could be put to use with better customers.

It's amazing how some folks can over time convince other people to actually propose a bad deal... for themselves.

Re: Don't Talk to Corp Dev (2015)

#43
post #35
post #24

Earlier quoted context omitted.

These words "secure" and "insecure" when used as synonyms for "encrypted" and "plaintext" obscure more than they illuminate and have done a lot of damage to the world of software security. They stop thought. You would not believe how many times I've talked to a company with some complex webapp and asked for their security policy and they respond with some statement about using TLS. It's absurd. Then even in books or…

In TLS context, “secure” and “insecure” don’t just mean (un)encrypted, but also whether the connection is authenticated, i.e. whether you can be fairly sure you’re looking at the “real” website. This is a far more important property of a site using https. Especially in a world full of disinformation, authenticity and integrity of information are often a much greater good than confidentiality.

I understand what TLS does, but an argument that "we live in a world of disinformation" is not a substitute for having a well defined threat model and for many websites, particularly sites that broadcast information or download binaries which might already be signed or have hashes distributed via alternate means, there does not need to be a threat that requires TLS to address it.

Like it or not, it is up to the information owner to determine their threat model and which mitigations are suitable for that threat model. If someone is broadcasting a message containing information that is public, they may not consider someone intercepting a response and altering it to be a threat that needs addressing, or they may consider alternate mitigations as sufficient -- e.g. the fact that many people can independently verify the information from different sources. For the vast majority of sites, this is a reasonable assumption. Just because you may be worried about this threat doesn't mean the information owner needs to be. Of course you as an information consumer have your own threat model, and if you are really worried about someone targeting you and altering http responses sent to your browser, then you may not want to visit unencrypted sites. That is also legitimate. The information owner can't force their threat model on you anymore than you can force yours on them. But words like "secure" and "insecure" make sense only with respect to a given threat model, they are not attributes of an http connection.

Re: Don't Talk to Corp Dev (2015)

#44
post #29

Earlier quoted context omitted.

The only reason Corp Dev is establishing a partnership is because they want to buy you but they aren't sure yet, so it's like a trial. It's also a good way to convince you to sell to them while also locking out competitors. If you have a partnership with Google, it makes a lot harder for Amazon to buy you because first they have to unwind the partnership.

Re that last para. Amazon and Google could choose to share the pie: it's want to, not have to, surely?

It was just a contrived example. Imagine instead you have a partnership with Amazon and then Walmart wants to buy you. Both companies have made it clear they will never work with each other.

Either way, every deal, every partnership, every contract, complicates an acquisition. The fewer you have the more likely a deal is. By establishing a relationship, one company can discourage others from wanting to put in the effort of acquiring you.

Re: Don't Talk to Corp Dev (2015)

#45
post #6

He actually didn't even cover one of the worst parts about the whole process - fake buyers who just want to steal your tech. I was working at a startup with a ground breaking product no one had released before, we had shipped hundreds of prototypes and gotten good reviews and had plenty of orders, but board redesigns and setting up a factory assembly line for the production models was eating into our cash and runway.…

Wouldn't acquisition talks be covered in NDAs to prevent precisely this?

Absolutely.

Now...can your more or less thinly financed startup litigate against, say, Apple to enforce your rights? Because there's no magical moment where you say "But NDA!" and the other side says "Aw, you got us...here's your bags of money".

That'd be Nope.

Re: Don't Talk to Corp Dev (2015)

#46

>"What happened to Don't be Evil?" I asked. "I don't think corp dev got the memo," he replied. Why is it that every company that starts with good intentions eventually succumbs and becomes that which they claimed to not like?

Evolution and survival of the fittest. On a long enough time scale, all the companies which don't behave psychopathically are outcompeted and replaced by the ones which do.

Re: Don't Talk to Corp Dev (2015)

#47
I wonder how analogous this is to “don’t talk to VC associates” advice. Corp dev is interested in buying a company, any company, at a low price but even once corp dev is sold they’ll have to sell the deal to someone who matters. People confuse “this corp dev person is interested” with “this company is interested”.

If you’re not actively looking to sell, _definitely_ don’t bother taking the meeting unless there’s a champion high up who is personally interested.

Come to think of it, recruiters aren’t all that far off this either…

Re: Don't Talk to Corp Dev (2015)

#48
post #6

He actually didn't even cover one of the worst parts about the whole process - fake buyers who just want to steal your tech. I was working at a startup with a ground breaking product no one had released before, we had shipped hundreds of prototypes and gotten good reviews and had plenty of orders, but board redesigns and setting up a factory assembly line for the production models was eating into our cash and runway.…

> A year later they announced they would be developing a knock off.

This normally doesn't worry me.

What I normally see is:

1) company we're selling to gets snotty that we're charging too much.

2) company sets up internal group to do what we do

3) company spends 3 years doing it--and then shuts it down because it was soaking up money (gee ... ya think?)

4) company now comes back to us and we increase their prices relative to what they had and their competitors

If 3 guys and a dog can clone my work that easily, I'm doing something trivial, and I'm about to be out of business anyway.

Re: Don't Talk to Corp Dev (2015)

#49
post #42

>If they can, corp dev people like to turn the tables on you. They like to get you to the point where you're trying to convince them to buy instead of them trying to convince you to sell. I worked for an established company (not a startup) and had a run in with Wal-Mart. Wal-Mart managed to buy some stuff at an ultra low discount because ... someone thought maybe if we get in there we could sell tons to their IT team…

Sometimes it isn't about the "big sale" but having the big company on your list of customers. It can give your company a lot of credibility.

Re: Don't Talk to Corp Dev (2015)

#50

>"What happened to Don't be Evil?" I asked. "I don't think corp dev got the memo," he replied. Why is it that every company that starts with good intentions eventually succumbs and becomes that which they claimed to not like?

If you're genuinely asking: when companies get controlled by greedy people then morals take a back seat compared to financial gain (for those people). The greedy people have the money, they can structure society using the power they have because of it, they can corrupt others (who are also greedy) to support them. The people whose ancestors weren't as greedy, or lacked the violent capabilities to satisfy their greed,…

Gates' Cloak
Post reply on HN