Live data from Hacker News

A software change allowed FTX to use client money

reuters.com

301–310 of 402 posts

Re: A software change allowed FTX to use client money

#301
post #297

Earlier quoted context omitted.

Probably because the whole Topf & Söhne debacle doesn't need repeating? Engineers are of course partly responsible for the things they implement.

> Engineers are of course partly responsible for the things they implement. That is outrageous. The company owners have limited liability protections. The employees should receive at least that unless they are in a position that requires specific legal training like an engineer legislatively appointed to be responsible for some safety function. Where they are appointed and remunerated specifically for their legal res…

> > Engineers are of course partly responsible for the things they implement.

> That is outrageous.

And this is why software engineering is a joke.

Re: A software change allowed FTX to use client money

#302
post #252

Earlier quoted context omitted.

Stay civil. This is not an argument against programmers, like other professionals, learning the aspects of the law which are relevant to their job. Why should programming be the one profession where this is not required?

Because to be criminally liable for something requires both a) actually doing something that is against the law and b) doing so with intent (i.e. you knew what you're doing is against the law and you did it anyway... because you thought you will not get caught or just didn't care). It is then up to the prosecution to prove, beyond reasonable doubt, that you actually intended to break the law. (With the exception of s…

"Mens rea" is a requirement for certain crimes, but not all, you definitely can be criminally liable for doing something without intent. The trivial example is murder vs manslaughter, the latter does not require intent but obviously can be and is criminally prosecuted.

Furthermore, even in cases where mens rea is required, it gets satisfied if you intended to achieve the prohibited result even if you thought that the result was permitted. "Intent" is not about intent to break the law, it's about the intent to do the thing that happens to be illegal. In this case, it matters if you knew what the thing you're making was going to be used for (e.g. hide some stuff from auditors) but your knowledge or ignorance of the relevant laws and regulations doesn't matter at all - as another poster noted, https://en.wikipedia.org/wiki/Ignorantia_juris_non_excusat .

Re: A software change allowed FTX to use client money

#303

Earlier quoted context omitted.

That's why be don't deserve the title of engineer in software and we should stick with coder or programmer. 'Hi mate. We just bought this rebar from Alibaba, saved as a ton of money. Could you sign here real quick? We need to finish that bridge!'

Engineer doesn't imply honesty. In those jurisdiction where it's a protected title, it just implies that you have some mix of STEM topics in your degree. Software engineers, in these jurisdictions, have that mix, and are as real as bioengineers (a.k.a hospital lab workers), chemical process engineers, construction engineers, etc. No one has had their engineer title taken away for being a crook, as far as I know. Unle…

It doesn't imply honesty. It does imply liability, so if something bad happens because you're dishonest, you will lose the title, and suffer other consequences.

Re: A software change allowed FTX to use client money

#304

Earlier quoted context omitted.

how would they know it's explicitly criminal though? i doubt most devs have enough understanding of their business domain, much less the regulatory frameworks to be able to confidently refuse to implement something because it's illegal.

At the very least they should be aware enough of potential wrongdoing to raise questions, and do so in written form. When you write exceptions that specifically only benefit one party and no others, there is always a reason to at least be suspicious.

What I’m struggling with is that what was done is not illegal in its self. It’s not necessarily suspicious in itself (from the perspective of a single dev working on tasks), unless you assume fraud. Of course we know fraud occurred so we can look back on it and have our perception of the request tainted.

If my boss came to me and said, “continue showing customer funds sent to our “sister” investment company in the staff dashboards” I wouldn’t find that suspicious. I would probably push back and say that might be confusing unless we separate out that amount and rename the total to something that denotes part of this value is with our sister company. But I would assume design incompetence and not fraud.

But then again if I was just one of a handful of devs that worked with the company I would probably find it suspicious, as I would confidently know that nowhere else in the codebase do we support a close integration with our sister investment company and should therefore know we shouldn’t treat them any differently.

Also the modification to exempt the investment company from risk rules does seem suspicious, unless again you believed there was an integration somewhere and believed investment risk mitigation rules were handled on the other platform or something.

Re: A software change allowed FTX to use client money

#305
post #297

Earlier quoted context omitted.

> Engineers are of course partly responsible for the things they implement. That is outrageous. The company owners have limited liability protections. The employees should receive at least that unless they are in a position that requires specific legal training like an engineer legislatively appointed to be responsible for some safety function. Where they are appointed and remunerated specifically for their legal res…

> > Engineers are of course partly responsible for the things they implement. > That is outrageous. And this is why software engineering is a joke.

Engineers are responsible for strictly technical failures. When a piece of software does what a representative of company management asks for it hasn't failed.

Software engineers are not lawyers and they are bad at interpreting laws.

Re: A software change allowed FTX to use client money

#306
post #257

Earlier quoted context omitted.

Probably because the whole Topf & Söhne debacle doesn't need repeating? Engineers are of course partly responsible for the things they implement.

Why should be someone responsible for how the product of their labor is being used?

The tautological answer is that it's because we the people have made laws that in certain specific situations make people criminally responsible for how the product of their labor is being used.

The practical answer is that it's because we do want to discourage criminals from "splitting liability" by having most of a gang doing some illegal goal together stay "clean" and only delegating a single "fall guy" for the final touch; so criminal law is explicitly written to consider everyone who knowingly assists a crime to be partly liable as well.

Re: A software change allowed FTX to use client money

#307

> Only Singh, Bankman-Fried and a few other top FTX and Alameda executives knew about the exemption in the code, according to three former executives briefed on the matter. A digital dashboard used by staff to track FTX customer assets and liabilities was programmed so it would not take into account that Alameda had withdrawn the client funds, according to two of the people and a screenshot of the portal that Reuters…

> Singh will definitely get prison time as well Remember Alamada wasn’t a normal customer. It was acting as a market maker/counterparty of last resort to many other FTX customers. In that case there could be situations where ‘normal customer liquidation rules’ shouldn’t apply - it can go in the red temporarily to enable others to trade (and FTX to make commission). From the facts in the article (which are obviously n…

FTX and Alameda publicly represented that Alameda's relationship with the exchange was the same as any other market maker's, and any other market maker could sign contracts to become a counterparty of last resort by joining the Backstop Liquidity Provider program.

Re: A software change allowed FTX to use client money

#308
post #207

Brings up a question: what is the chance of blaming some of this on an "innocent" coding error? Can you get jail for not writing unit tests, swallowing an exception, a type conversion you did not expect?

Zero Chance. Singh already proved intent with his source code comment. Him claiming to be unaware of violating the law won't prevent him from getting almost certainly jailed.

Seeing all the crypto bros go to jail is the heart warming start to 2023 I needed.

Re: A software change allowed FTX to use client money

#309
post #151

Earlier quoted context omitted.

I assume this is a reference to other engineering disciplines, where an engineer signing off on something has real meaning.

People gatekeeping the word “engineer” is a bit annoying, since the word “engineer” dates to at least 1380 and originally just means someone who works on engines. “Engineer” as a legally super special class of job is a thing that came much later and only ever applied to certain jurisdictions anyway. “Software engineer” is just a synonym for “programmer”, in the actually existing practice of the English language.

And 'doctor' means someone with a PhD. I know a lot of doctors. However, when you talk about medicine, we mean 'Doctor' with an M.D. and they are literally held to higher standards of ethics and liability. They are licensed and people who practice professionally without a license are subject to legal ramifications.

Call yourself whatever you want, but that doesn't mean you get to define what 'Engineers' are and what ethics they are bound to. Just because you use the term in your title and say it is used properly in English, doesn't mean that you won't get treated any different than someone with a PhD demanding to be called Doctor and pretending there is no difference between them an and M.D.

Re: A software change allowed FTX to use client money

#310

Earlier quoted context omitted.

> Singh will definitely get prison time as well Remember Alamada wasn’t a normal customer. It was acting as a market maker/counterparty of last resort to many other FTX customers. In that case there could be situations where ‘normal customer liquidation rules’ shouldn’t apply - it can go in the red temporarily to enable others to trade (and FTX to make commission). From the facts in the article (which are obviously n…

Not an excuse. They had a programme for external liquidators giving some slack for trades taking the other side of liquidating positions, so Alameda should have used that. This looks worse. In any case it's not needed: liquidators get the 3% initial margin so are usually in profit. For the cases when the market moves faster than that, they should have done what the better-run exchanges do and close the most leveraged…

BLP fills were quite toxic, many trading firms turned this stuff on, found out that it was hugely money-losing, and turned it back off.
Post reply on HN