Live data from Hacker News

I will NEVER add such a privacy breaking a**hole feature

github.com

31–40 of 47 posts

Re: I will NEVER add such a privacy breaking a**hole feature

#31

He should have added it but with a shutter sound and a screen flash for every shot taken.

And any station that can be monitored by boss station, can monitor boss station too.

Sure here you go, screen shots, live monitor, recording, audio too...but everyone gets it the same.

Re: I will NEVER add such a privacy breaking a**hole feature

#32

Earlier quoted context omitted.

"Kimai is a free and open-source project time-tracker."

Yeah I noticed that, which is why I'm confused about this screenshot feature being invasive. Unless it's remotely managed, it would only be screenshots taken by you, and stored by you, in your time tracker.

Things don't need to be remotely managed for the user to lack control. The client software could take periodic screenshots during tracked time which are sent along when the user reports their tracked time.

Re: I will NEVER add such a privacy breaking a**hole feature

#33
post #24

Earlier quoted context omitted.

Doing the least you can at work is also called "meeting expectations." Why are you going above and beyond to create value you won't capture? If someone is willing to pay you a lot for not doing much and is happy with your output then what's the issue? People working multiple jobs is typically a sign of hard work. They could be playing Xbox instead but they chose more work. Spinning working on things that no one asked…

I am kinda tiring of seeing this rationalization. Don't you see, it's on the company to fire you if your productivity is low! Feel free to do nothing or as little as possible! That's such trash. If you're in software and are being honest you know we are not being paid for our output. Where are you working where the understanding is that if you get assigned a task for the week and finish it in one hour, it is common k…

Wanted to chime back in to say I agree with you here and on your previous reply.

I should’ve been clearer but I was talking about if the resting/vesting is endemic. Yes, there are always going to be people who will skate by as easily as possible. Hard to avoid completely in a gold rush, but I do believe that a company with better culture can suss it out better.

I do think there’s a limit to how much more work should be taken on once you finish planned tasks, but that doesn’t mean you shouldn’t do anything either. People saying that are, like you said, just rationalizing their own lazy/exploitative attitude.

It’s perfectly reasonable to expect someone to try to get ahead, and keep a company as competitive as possible, if they’re able to finish tasks faster and still staying within a healthy set of working hours. Nobody is asking for 80 hour weeks here. 20 is just unreasonable as 80 when you’re making a ”full time“ tech salary.

If you’re vesting, it’s in your best interests to stay competitive. Otherwise you’re riding on your coworkers’ coattails. All while probably complaining about the ultracapitalism of the C-suite. They’d step into their shoes in a heartbeat.

Re: I will NEVER add such a privacy breaking a**hole feature

#34

Earlier quoted context omitted.

Yeah I noticed that, which is why I'm confused about this screenshot feature being invasive. Unless it's remotely managed, it would only be screenshots taken by you, and stored by you, in your time tracker.

Things don't need to be remotely managed for the user to lack control. The client software could take periodic screenshots during tracked time which are sent along when the user reports their tracked time.

That would make it centrally managed. Unless the user can override this configuration, we're talking about remote administration. Either through this tool, or through some other tool that deploys it and ensures the user cannot change it.

Kudos to the developer for standing their ground, but if we're talking about a remotely managed client computer then I don't think there's much the user can do to protect their privacy.

Re: I will NEVER add such a privacy breaking a**hole feature

#35
post #27

I intentionally use screenshotting time-tracking software because it's nice to not have to worry about trusting my clients: screenshots add one more layer of legal proof that I'm actually working if they ever try to stiff me on payments.

Who controls the data? Are the screenshots sent automatically to the employer? How do you handle the sensitive information (api keys, user personal data) that can be displayed in the screenshots?

I used to use the Upwork tracker a lot which sends the screenshots to a third party (Upwork) where both parties could view (or remove) the screenshots. Having some kind of trusted third party or paper trail (if sending by e.g. email) seems necessary to prove any potentially-produced-later screenshots were in fact created at the time of work.

It might be different for others, but for most sensitive data I'm privy to on a job (api keys, their users' personal data), my employer could or should already have access to all of that. I've removed the occasional screenshot that had a personal dev tool key or similar though. Typically all this should be covered by a contract with a client though; they shouldn't just be stealing API keys and whatnot from your screenshots...

Re: I will NEVER add such a privacy breaking a**hole feature

#36
post #27

Earlier quoted context omitted.

Who controls the data? Are the screenshots sent automatically to the employer? How do you handle the sensitive information (api keys, user personal data) that can be displayed in the screenshots?

I used to use the Upwork tracker a lot which sends the screenshots to a third party (Upwork) where both parties could view (or remove) the screenshots. Having some kind of trusted third party or paper trail (if sending by e.g. email) seems necessary to prove any potentially-produced-later screenshots were in fact created at the time of work. It might be different for others, but for most sensitive data I'm privy to o…

> most sensitive data I'm privy to on a job (api keys, their users' personal data), my employer could or should already have access to all of that

It’s about storage though.

It’s one thing if your employer can access the data from an encrypted database with carefully managed access - and another to also keep it in a random screenshot in a third party time tracking tool.

There are also regulations and requirements, for example about deletion of personal data.

Re: I will NEVER add such a privacy breaking a**hole feature

#37
post #24

Earlier quoted context omitted.

Doing the least you can at work is also called "meeting expectations." Why are you going above and beyond to create value you won't capture? If someone is willing to pay you a lot for not doing much and is happy with your output then what's the issue? People working multiple jobs is typically a sign of hard work. They could be playing Xbox instead but they chose more work. Spinning working on things that no one asked…

I am kinda tiring of seeing this rationalization. Don't you see, it's on the company to fire you if your productivity is low! Feel free to do nothing or as little as possible! That's such trash. If you're in software and are being honest you know we are not being paid for our output. Where are you working where the understanding is that if you get assigned a task for the week and finish it in one hour, it is common k…

> it's on the company to fire you if your productivity is low

That's not what I'm saying at all, I'm saying that if your company is happy with your level of output and it's in line with the rest of your teammates then why would they fire you? On principal? I absolutely work 20-25 hour weeks most weeks and I just got the highest marks on my performance review, a bonus for it, and a promotion last year. Why in god's name would I work harder? What could I possibly gain by setting the bar higher for myself? My employer is extremely happy with the value/$ they get out of me and I'm extremely happy with the work life balance it affords me.

And my team doesn't look at me sideways, folks duck out early afternoon all the time. My department doesn't even schedule meetings after 3pm because people will be gone. And I can't speak for other teams but my direct manager has a rule to not even bother putting in PTO if it's less than two consecutive days off. And my work bestie does 2-3 hours of away-from-desk charity work during the day and he's our resident 10x developer. I realize where I work is essentially a unicorn of sanity that actually believes in work smarter not harder but it's hard to look at other workplaces and say we're the crazy ones.

You are nonetheless right that it's an informal policy that our CTO/CEO look the other way on but it's hard to argue that it isn't incredible for retention.

Re: I will NEVER add such a privacy breaking a**hole feature

#38

Earlier quoted context omitted.

Things don't need to be remotely managed for the user to lack control. The client software could take periodic screenshots during tracked time which are sent along when the user reports their tracked time.

That would make it centrally managed. Unless the user can override this configuration, we're talking about remote administration. Either through this tool, or through some other tool that deploys it and ensures the user cannot change it. Kudos to the developer for standing their ground, but if we're talking about a remotely managed client computer then I don't think there's much the user can do to protect their priva…

It sounds like adding this feature would turn the software into something you consider remotely administered.

Re: I will NEVER add such a privacy breaking a**hole feature

#39
post #36

Earlier quoted context omitted.

I used to use the Upwork tracker a lot which sends the screenshots to a third party (Upwork) where both parties could view (or remove) the screenshots. Having some kind of trusted third party or paper trail (if sending by e.g. email) seems necessary to prove any potentially-produced-later screenshots were in fact created at the time of work. It might be different for others, but for most sensitive data I'm privy to o…

> most sensitive data I'm privy to on a job (api keys, their users' personal data), my employer could or should already have access to all of that It’s about storage though. It’s one thing if your employer can access the data from an encrypted database with carefully managed access - and another to also keep it in a random screenshot in a third party time tracking tool. There are also regulations and requirements, fo…

IMO, storage is an implementation detail that should be handled up the chain (by your tool or third-party service), rather than by you.

In the Upwork example, screenshots are already encrypted and only accessible behind authenticated flows in their site/app; can be deleted manually (e.g. after you've been paid and don't need them for liability reasons); and automatically delete after some period of time otherwise (6mo or 1 year IIRC).

There are probably plenty of other time-tracking tools that give you more fine-tuned control over the privacy of your screenshots if you want that, but I can't imagine it's something most freelancers want to spend much time on.

Re: I will NEVER add such a privacy breaking a**hole feature

#40

Earlier quoted context omitted.

That would make it centrally managed. Unless the user can override this configuration, we're talking about remote administration. Either through this tool, or through some other tool that deploys it and ensures the user cannot change it. Kudos to the developer for standing their ground, but if we're talking about a remotely managed client computer then I don't think there's much the user can do to protect their priva…

It sounds like adding this feature would turn the software into something you consider remotely administered.

I'm interpreting it more like this is a standalone locally managed program, the user would like a screenshot feature in it.

But if you add remote management around it then this screenshot feature can be invasive, but then again so is the management software that prevents the end user from changing the config.

So the way I see it, the developer is getting upset over something they'd be unable to control.

Post reply on HN