Live data from Hacker News

I didn't get paid, so I open-sourced my client’s project

github.com

261–270 of 272 posts

Re: I didn't get paid, so I open-sourced my client’s project

#261
post #27

As someone who occasionally does recruiting for developers and always do some quick searches for GitHub profiles. You'd be dropped as a potential candidate on our team if we stumbled upon this, "After he signed and I began building he decided to pivot and not pay me." Just screams unprofessionalism in my opinion.

> Just screams unprofessionalism in my opinion. Surely the guy not paying is the unprofessional one? Sure, since "he signed" , he could have probably taken legal action, but that's often a long and costly process. How is cutting your losses and walking away (but outsourcing the code you wrote) unprofessional?

> Surely the guy not paying is the unprofessional one?

Surely, both people in the relationship can behave unprofessionally.

> How is cutting your losses and walking away (but outsourcing the code you wrote) unprofessional?

That's not why people are suggesting the developer is unprofessional. It's because he's complaining about a client publicly.

Re: I didn't get paid, so I open-sourced my client’s project

#262
post #81

Don’t understand why someone would throw away their integrity by doing this. When a client refuses to pay, the standard procedure is to take them to court and then make them pay what is owed + attorney fees. Instead, this developer has put himself on industry blacklists by doing this. No way he’ll be trusted with sensitive projects. Don’t do this.

He's not on my blacklist. Perhaps he's aware that every action that anyone ever takes, is approved of by some people and disapproved of by others, and your only choice is between who approves of you and who disapproves of you. I for one, approve of this resolution a hell of a lot more than courts and suits. They are tools you may be forced to use sometimes. It's great that the system is there for when you need it. Bu…

There is an unhealthy desire amongst freelancers to burn clients.

Re: I didn't get paid, so I open-sourced my client’s project

#263

Earlier quoted context omitted.

I don't agree with that assessment, but I do wonder why mention the client or client non-payment at all. If he wants to bother to mention the breach of contract, he should go all in and publish the client's name. Otherwise, just publish it as code written on his own time. (Which it was, at the end.)

I have no interest in exposing other people and tarnishing their names. Hes welcome to continue screwing people over if he chooses

If I were to hire you, can I trust that you would not publicly complain about a disagreement? This needs to be asked because this simple act, even though your anger is justified, calls into question your ability to act professionally.

I would recommend removing or rewording the complaint about the client.

Never, never, never publicly complain about a client in a way that can be linked back to you and/or your client.

Re: I didn't get paid, so I open-sourced my client’s project

#264
post #48

Earlier quoted context omitted.

German online payment system called Sofort wants the same... ( https://www.klarna.com/sofort/ ) The instructions asked me to provide account, card number and OTP login code... then it’s just a matter of scraping all my past 10 years transactions and keep the session alive to snoop on exactly how many condoms I buy... Criminals

I am not sure how much information they get from your account. Could be just the balance and transaction confirmation. Also, you need a separate transaction authorization. The log-in information is not enough to initiate a transaction.

That’s correct... but I ran away screaming the second I realized how deep they could dig into my financial logs.

Luckily for the German merchant, they also provided an IBAN I could copy-paste into the transfer form.

Re: I didn't get paid, so I open-sourced my client’s project

#265
post #191

Earlier quoted context omitted.

Those questions are irrelevant, btw. It's the answers that matter, for safety. Someone could know your dog's name or mother's maiden name, but if your answers are "Doginator2000" and "Iron Maiden", you'll be safe and anyone trying to gain access will be locked out.

I just have a shitty memory, and if I game them, I won't remember what answer I gave. If I were to take that strategy I'd need to write them down, which is basically already a great sign of a terrible security policy.

I store them in the comments area in KeePass, both the crap question and my silly answers.

Re: I didn't get paid, so I open-sourced my client’s project

#266
post #123
post #41

This thing wants the password for your bank account? WTF? That's way more than it needs. Enough info to authorize an ACH transfer, maybe. But the login password for your bank account? No way. That voids Bank of America's security guarantee.[1] If you provide info for an ACH transfer, and the other party abuses that info, it's reversible. If you provide login info and the other party abuses that info, it's not. [1] ht…

If you aren't comfortable with that you better not use any fintech apps like Cash App, Venmo, Wealthfront, Robinhood, any Intuit products, etc. These services use Plaid (like this app does) or similar APIs like Quovo, Yodlee, etc. Even financial institutions themselves like Citi Bank, American Express, Chime, PayPal, etc use these APIs to link your accounts. And to be clear, the app itself never has access to your cr…

Out of the app you mentioned only Intuit products, TurboTax specifically asks for bank account password. The rest just use account number is ACH for verification.

Re: I didn't get paid, so I open-sourced my client’s project

#268

Earlier quoted context omitted.

In Europe they solve it with laws. PSD2 forces banks to become open, and allow others to make services on top.

I work on PSD2 implementation for a local bank. Will solve is correct, not many banks implement it yet (but "final" deadline is approaching). Also there are rate limits for PSD2 APIs. And also the extremely costly license, which means that there will have to be middlemen reselling PSD2 access.

Costly license? Tell me more, I had no idea there was supposed to be license fees involved.

Re: I didn't get paid, so I open-sourced my client’s project

#269
post #56

Earlier quoted context omitted.

Have you ever seen mike monteiro’s “fuck you pay me” talk? Assuming that your contract leaves you with copyright until you’re paid you could always have dmca’d them when they deployed. But that’s the vindictive side of me :D

> Assuming that your contract leaves you with copyright until you’re paid Why would this matter? If he's not paid, what validity does the contract have?

My understanding is essentially people have contracts that essentially assign ownership of the copyright at point of completion rather that at the point payment.

In the monteiro talk he says that a lot of companies have default contracts for contractors, and say things to the effect of "it's just our standard contract there's nothing to worry about", IIRC he gives examples of contemporary contracts that require delivery on floppy disks. But also they try to have terms that essentially say all the work belongs to them, and you will be paid on completion.

e.g. if you don't finish the work - or they claim you did not (by applying feature creep offensively, etc). Then because you didn't finish they don't owe you money.

The other approach is that they fail to pay, you can't use (for example) the DMCA to pull down their site, or bring copyright violation suit against them because the IP already belongs to them. All you can do is sue for owed money but you don't have the leverage of stopping them using your IP, because it's not your IP anymore.

That is my understanding from his talk anyway - IANAL, and also I haven't done contract work myself (that's what my wife used to do, and she had a default contract produced by her own lawyer)

Re: I didn't get paid, so I open-sourced my client’s project

#270
post #208
post #98

Earlier quoted context omitted.

The bank has many reasons to specifically not provide that functionality. And if your value proposition as a company is to farm people's financial data for your own purposes, all I can say is tread carefully. It won't take much in terms of negative outcomes generated by increased attack surface to make bank/financial regulations even more strict. This practice is a clear violation of just about every bank I've seen's…

I don’t think it’s crazy for customers to be able to retrieve their own data.

I don't either. It is, however, crazy to expect a bank to tolerate you granting a third, unknown party access to their data systems by sharing your personal credentials with the third party.

Your business with the bank entitles you, and only you; barring certain exceptions at their discretion, access to that data.

They do this to minimize risk and culpability in the face of a large number of adversaries that could extract value from possession of data on your personal habits.

It isn't sexy, but that is just the way it works. I've banged my head against the financial industry looking for ways to improve it, but at the end of the day, a lot of the rules and restrictions they put in place actually do make a frustratingly good deal of sense.

Think about this.

Suppose you and 1000000 other people hand login credentials for financial service X to company Y.

Company Y is basically a shell company wrapping a money laundering operation. Your combined set of login credentials becomes an ideal way to wash money into the financial system until everyone else in the financial network catches on. Then that company disappears, and sets up under a different name.

This stuff happens; and even if only some people don't notice, that's all it takes.

Post reply on HN