Live data from Hacker News

Goodbye Auth0

joshcanhelp.com

151–160 of 281 posts

Re: Goodbye Auth0

#151

Earlier quoted context omitted.

At my second job, the company terminated an employee for poor performance and intended to let them stay on a short term to wrap things up and then start their severance. The first evening (or maybe the first Friday evening), that dev stayed late in the office and deleted the source trees from as many machines as he could get access to (this was 1996, so most machines didn't have logins) and wiped the hard drive on th…

Is that the lesson to learn here, really? An employee makes a stupid thing and the leadership didn't look into its security practices to avoid this type of attack?

> and the leadership didn't look into its security practices to avoid this type of attack?

It sounds like they very much did, starting with physical security. Especially in that time period, physical access was probably the biggest component even.

Re: Goodbye Auth0

#152
> I was being exposed to engineering concepts that just weren't a thing in agency work: unit testing, CI/CD, git hygiene, release management.

As someone who’s worked at an agency that’s grown from twenty engineers to hundreds over the last five years, what? Even when we were small and scrappy we still wrote unit tests…

Re: Goodbye Auth0

#153

Earlier quoted context omitted.

So because the company hired a criminal sociopath, every other person laid off until the end of times must be treated the same way? Certainly there are better ways to handle even this crazy scenario you mentioned. That feels so inhumane to me. If you don't see your employees as humans, instead as mere resources and, as soon as they are laid off, threats, then we can say it makes sense.

Similar things have happened in my ~12 year career which leads me to believe it is not as uncommon as your comment would portray it. The first instance I can recall, a developer was terminated and his access was revoked. He goes home, waits until midnight, then tries logging into as many systems as he can. He apparently had saved a WordPress password on his Google Drive. He logs into WordPress and defaces a bunch of…

I can definitely understand that assuming everyone is not a sociopath is very naive. But the reason I say this is inhumane is not about the security implications.

There's a whole plethora of issues around layoffs that are often ignored. I recall looking at Slack's people list constantly to see which accounts were suddenly marked as "deactivated". People I had great relationships with but never exchanged personal emails simply gone. That dread of "what the fuck is happening" and "am I next?" overcoming you. Some people scramble to create sheets with contact information from those who were laid off.

That's absolutely inhumane.

I survived 3 layoffs in the past few years and I can still distinctly remember the awful feeling each of those left me with. I can only imagine how much worse that is for those affected.

We can separate the security parts from the human parts. Companies choose not to do that, for whatever reason that I simply cannot understand. Especially companies with so called "human resources" should be extremely prepared for situations like this, to make sure everyone is actually treated well.

Recently we had that viral video of a person that recorded themselves getting fired with zero reasoning of why. That's the kind of shit that happens with these layoffs. Bad management at its worst.

In short, I agree with you with regards to security implications. But those can be solved with proper access controls and planning. What I don't agree with is everything else around it. Not once I have seen companies laying off people handle this in any manner that I would describe as humane.

We can do better, I don't know why we don't.

Re: Goodbye Auth0

#154
post #4

I don’t get it why the US company layoff culture is so different from what I’m familiar with, the European one. What are they afraid of that people need to be locked out? That one brings a gun to work? Here you get laid off, get a notice, are expected to continue working for a while (but depending on your work ethic you’ll take it easy), consume your remaining PTO, complain to your coworkers about what happened durin…

Not sure which part of Europe you are referencing, but from the layoffs I've seen and heard of (DACH) the procedure was always to lock the person out immediately after the layoff call/meeting. If that's good or bad is rather subjective, personally I would rather walk out the door right after. One might have enough time to send their farewells, but that's about it - you are still getting payed until the end of the not…

At least in Norway the guiding principle in law is that the employee can and must work out the grace period, and locking an employee out is illegal. It's possible to mutually agree to exceptions or be granted an exception - but the latter is rare.

Re: Goodbye Auth0

#155
post #32
post #14

Earlier quoted context omitted.

I had that experience with a US mother company of a European subsidiary (of a subsidiary). CEO swings by, as he does once per year, and fires the whole dev team, including the local branch manager, because they'll take over in the US (they couldn't, and then bought a competitor instead; the original product is still running, 15 years later), and we were told to leave the building. I had a program building something f…

What country was this? If it was a European subsidiary, then would you have not have been subject to the employment protection of the country's laws?

Depends a bit on specific laws for every country, but you usually have to go trough proper process and announcement, and follow special rules if you're firing a big quantity of employees. Musk skipped that in the massive Twitter layoffs and it bit him in the back (for example, when firing the whole Spanish staff [0]).

Simplified a lot, and in general conditions, on Spain:

  - You have to announce it at least 15 days before ( unless it's a disciplinary dismissal ) or pay for those 15 days of salary
  - Pay for any unused vacation days and pending salaries
  - An "objective reason" is needed for the firing [1]
  - If there's no proper "objective reason", you have to reinstate the worker or pay 33 days of salary per year worked by the user [2]
  - If the layoffs involve certain number or percentage of the workers, you have to go through certain legal process and get government authorization [3]
Twitter didn't go through the process in Spain, to avoid paying the stocm options that were going to vest very soon, but then the firings were declared illegal and they had to pay proper severance and for the stock options too... [4]

  0: (EN) https://www.theolivepress.es/spain-news/2022/11/10/elon-musks-email-late-on-friday-to-sack-his-spanish-workforce-declared-null-and-void-by-unions/
  1: (ES) https://www.laboralix.com/despido-objetivo/
  2: (ES) https://www.laboralix.com/despido-improcedente/
  3: (ES) https://www.laboralix.com/despido-colectivo/
  4: (ES) https://www.elconfidencial.com/tecnologia/2023-01-24/twitter-confirma-el-despido-del-80-de-su-plantilla-en-espana_3563189/

Re: Goodbye Auth0

#156
post #135

Earlier quoted context omitted.

Because losing your job is really a bummer everywhere, but in Europe you've got a lot of things covered by the welfare state (how well, it's a different discussion), so it's less stressful, which reduces the probability of people being really pissed . In the US, you're probably out of healthcare in the blink of an eye, may have no severance, no coverage, no unemployment benefits, and in some cases it'd mean deportati…

Tying healthcare to employment is a uniquely stupid idea.

It is the case in much of EU also: In Germany most of the healthcare is covered by the employer. In Denmark, where I reside, you get an extra coverage with most (tech-)employments that provides access you wouldn't have otherwise.

Re: Goodbye Auth0

#157

Earlier quoted context omitted.

Similar things have happened in my ~12 year career which leads me to believe it is not as uncommon as your comment would portray it. The first instance I can recall, a developer was terminated and his access was revoked. He goes home, waits until midnight, then tries logging into as many systems as he can. He apparently had saved a WordPress password on his Google Drive. He logs into WordPress and defaces a bunch of…

I can definitely understand that assuming everyone is not a sociopath is very naive. But the reason I say this is inhumane is not about the security implications. There's a whole plethora of issues around layoffs that are often ignored. I recall looking at Slack's people list constantly to see which accounts were suddenly marked as "deactivated". People I had great relationships with but never exchanged personal emai…

> Especially companies with so called "human resources"

Never forget that "human" is an adjective in that phrase, not a noun. HR's duty and focus is on serving and protecting the company, not the employees.

Re: Goodbye Auth0

#158

Earlier quoted context omitted.

> Companies don't have to send fired employees home immediately, they only do this because they don't trust the individual to act appropriately. Companies don't have agency or feelings. If company leaders expect people to do their jobs properly only because they are getting paid, it's already an institutional failure, because it's not taking into account that individuals are fallible. If the company does not have an…

I could have been more clear here. When I mentioned companies there I was referring to the people running the companies. Of course a company has no feelings or agency, companies are just a legal structure around a collection of people. Don't get me started on the absurdity of arguing that companies are people, that ruling was terrible. I don't think its reasonable to assume that a company could ever have full safegua…

> Companies must trust their employees at some level, generally the level of trust grows in relation to the employee's responsibilities.

Hard disagree. People should be trusted with the things they need to perform their role, and no more than that. You would not give access of a production database to a CTO just because they have more responsibilities than a sysadmin, and any CTO that tries to bludgeon their way into getting access to it should be considered unfit for work.

Re: Goodbye Auth0

#159

Earlier quoted context omitted.

Tying healthcare to employment is a uniquely stupid idea.

It is the case in much of EU also: In Germany most of the healthcare is covered by the employer. In Denmark, where I reside, you get an extra coverage with most (tech-)employments that provides access you wouldn't have otherwise.

Yes, the employers pay, but you do not lose your healthcare immediately after being fired. The state provides it for you as part of the social security net. I don't know specifically about Germany or Denmark, but I suppose it's the same across the EU.

Re: Goodbye Auth0

#160

Earlier quoted context omitted.

At my second job, the company terminated an employee for poor performance and intended to let them stay on a short term to wrap things up and then start their severance. The first evening (or maybe the first Friday evening), that dev stayed late in the office and deleted the source trees from as many machines as he could get access to (this was 1996, so most machines didn't have logins) and wiped the hard drive on th…

So because the company hired a criminal sociopath, every other person laid off until the end of times must be treated the same way? Certainly there are better ways to handle even this crazy scenario you mentioned. That feels so inhumane to me. If you don't see your employees as humans, instead as mere resources and, as soon as they are laid off, threats, then we can say it makes sense.

I had a coworker who wasn’t even laid off and did something along these lines* on his last day because he felt hard done by.

*Deleted the configuration from the core network switch.

Post reply on HN