Live data from Hacker News

Entropic Engineering DEFCON 32 Statement

entropicengineering.com

121–130 of 187 posts

Re: Entropic Engineering DEFCON 32 Statement

#121
post #116

> They expressed that they specifically wanted to work with us as a woman-owned, queer- and POC-driven engineering firm Why would someone's gender, sexual orientation or skin color be relevant to developing a badge? This is so weird.

You're right, it's not relevant to their abilities. It's relevant to the historical opportunities that such companies have had available to them. Likely, the thinking was, "We know that in the past such firms have experienced disadvantages. In years past, bias and discrimination against them may have hurt their chances of procuring a contract like this. Recognizing that historical disadvantage, we now want to give su…

Cutting edge, avant garde creative companies have for centuries been staffed by non-conforming people. We could give a similar description for the staff of our consulting company.

But we don't. We just use our work and our reputation.

There's no "historical disadvantage" for a company that supports the hacker community to be full off all sorts of eccentric, non-conforming people.

Re: Entropic Engineering DEFCON 32 Statement

#122
post #72

As per usual nobody comes out of these things looking good. To really understand who is right and who is wrong here we would need to read the letter of the agreements between these entities, and cross reference them with facts. Of course neither the contracts, nor the facts are available to us. As is, the best I can do here is to put all participants on my personal “do not work with” list. Who needs the drama. In par…

Exactly. Let's see the formal contract. The deliverables, the payment schedule, and any emails indicating DC agreement to subsequent requests for changes of terms.

The way EE phrases it, they were paid much less than they were owed, but owed according to what? Their internal accounting, or what they'd mutually agreed on with DC? Only the latter matters.

Emails saying "it's going to cost $X more", if any of EE's emails rose to that level of clarity and directness, are legally useless and meaningless without clear assent from DC.

Re: Entropic Engineering DEFCON 32 Statement

#123
post #72

As per usual nobody comes out of these things looking good. To really understand who is right and who is wrong here we would need to read the letter of the agreements between these entities, and cross reference them with facts. Of course neither the contracts, nor the facts are available to us. As is, the best I can do here is to put all participants on my personal “do not work with” list. Who needs the drama. In par…

> EE seems to say they thought the guy was not their subcontractor but someone working for DEFCON.

I didn’t see that in their statement.

Re: Entropic Engineering DEFCON 32 Statement

#124
post #116

Earlier quoted context omitted.

You're right, it's not relevant to their abilities. It's relevant to the historical opportunities that such companies have had available to them. Likely, the thinking was, "We know that in the past such firms have experienced disadvantages. In years past, bias and discrimination against them may have hurt their chances of procuring a contract like this. Recognizing that historical disadvantage, we now want to give su…

Cutting edge, avant garde creative companies have for centuries been staffed by non-conforming people. We could give a similar description for the staff of our consulting company. But we don't. We just use our work and our reputation. There's no "historical disadvantage" for a company that supports the hacker community to be full off all sorts of eccentric, non-conforming people.

Especially since this is JLCPCB type work. It should be fairly automated.

Re: Entropic Engineering DEFCON 32 Statement

#125

DEFCON’s response was posted on Reddit: https://www.reddit.com/r/Defcon/s/NVw5T4LXQR Unsurprisingly, it contradicts some of the claims Entropic has been making. Entropic admits to having exceeded agreed upon budgets by a significant amount, which DEFCON corroborates. There is some disagreement about what has been paid, though, as DEFCON believes they have paid for the hardware development. Some of the other claims al…

> As far as I can tell, the firmware was produced as part of the agreement between DEFCON and Entropic, in which case there shouldn’t be much question about the license as it’s a work for hire.

The default state of things is that the author owns the code, regardless of any contracts between Entropic and DEFCON. He may or may not have signed those rights away, but if his other assertions are true (that he wasn't anyone's employee or contractor) then I'd be mildly surprised if the right legal structures were in place to ensure DEFCON owned the code.

That's an issue when writing code for hire too (or, e.g., hiring a photographer). If you're not careful, you don't have very many rights with respect to the final product, even after paying somebody to write it for you.

Implied, limited, non-exclusive licenses are a thing, and I wouldn't be terribly shocked if (assuming a judge had to decide) all parties aren't at least allowed to continue distributing the badges (perhaps not to redistribute the firmware itself, modify the firmware, ...). Things get murky in a hurry though, and finding a resolution not requiring a court is probably better for all parties.

Re: Entropic Engineering DEFCON 32 Statement

#127

Earlier quoted context omitted.

It looks like a case of managerial miscommunication. Entropic seems to have expected that sending emails with higher budget estimates would give DEFCON the opportunity to say no if they did not agree, and took the lack of response as a sign of DEFCON’s agreement to the new budget. DEFCON seems to have either not read or ignored those emails and expected Entropic to work within the originally agreed-upon budget.

What higher budget estimates? According to the (admittadly biased) article, Entropic ate all of the cost overruns: > Once a month, we billed for our work and submitted an updated estimated per badge final cost - committing as costs built to discount our work as necessary in order to hit DEFCON’s per unit cost targets.

> According to the (admittadly biased) article, Entropic ate all of the cost overruns

I’m not sure of that. Entropic’s statement uses odd language: “…in order to hit DEFCON’s per unit cost targets.”

Why not just say “in order to hit DEFCON’s cost target”? Why “per unit”? It sounds like Entropic might have gone over budget on some other costs (for example, development) and only discounted hardware or manufacturing cost.

Re: Entropic Engineering DEFCON 32 Statement

#128
post #60

Earlier quoted context omitted.

Not sure about this event but in Europe you have to hire a professional security company. I've been involved in organising a computer event and we simply wouldn't get a permit without it. Volunteers doing security is a big NO. Parking assistance (guiding), first aid, entrance checks etc yes. But if someone doesn't comply you get the real guys. And it makes sense. At one camp we had a drugged up visitor going ballisti…

For US and especially Las Vegas events: usually the venue has their own professional security staff, some with law enforcement status of some kind, mostly with just security guard accreditation, some armed, some medically trained, etc. Venue also provides other paid employee or contractor staff for some things like cleaning, food service, etc. Especially in Las Vegas, this is highly unionized and regulated (to the po…

>I did this for a McAfee event at BSides which was super fun because his armed security were also high on methamphetamine and erratic)

Casually thrown in there at the end! Tell us more?

Re: Entropic Engineering DEFCON 32 Statement

#129
post #72

As per usual nobody comes out of these things looking good. To really understand who is right and who is wrong here we would need to read the letter of the agreements between these entities, and cross reference them with facts. Of course neither the contracts, nor the facts are available to us. As is, the best I can do here is to put all participants on my personal “do not work with” list. Who needs the drama. In par…

So how do you deal with the claim that they were sending regular cost updates and estimations throughout the development? (assuming they really did that). Shouldn't DEFCON stop it as soon as they realized some miscommunication about the price?

DEFCON isn't the entity doing the work. It's up to EE to get DC's clear agreement on changes of terms. Otherwise, EE must either:

a) acknowledge that they can't fulfill the contract under the existing terms, and follow the contract's termination procedures

b) keep working to try to complete the project, because the agreed upon payment is better, even considering the extra work, than whatever contract termination involved

When DC told EE to stop work, they did so rather than say "everything's fine, we're continuing as agreed"? That means they knew they couldn't deliver as contracted, or didn't want to because every day they kept working would lose them more money even if they fulfilled the contract.

This is why they should've had a reasonable contract that didn't require heroics in order to break even. Because, when things started to go bad, they needed a fallback besides taking a big loss for partial work, and taking a bigger loss for complete work.

Or alternatively, they could've reasonably contracted to do something nearly impossible, if they were okay with failing and getting nothing, at least for the r&d portion, turning it into an RP2350 learning opportunity. (Presumably, if they made it to production, the contract easily covered production costs.)

Post reply on HN