Live data from Hacker News

Asked to do something illegal at work? Here's what these software engineers did

blog.pragmaticengineer.com

361–369 of 369 posts

Re: Asked to do something illegal at work? Here's what these software engineers did

#361

Earlier quoted context omitted.

I think the risk is somewhat higher than just losing your job - you are potentially burning your whole referral network in the process (especially if you end up with your name in the press during any resulting prosecution). For a junior engineer it may not be that hard to fly under the radar, but senior/staff level folks tend to be well known by the execs. And execs talk, they call their friends to vet future hires..…

Probably for the best... Like, anyone who would work with some of my previous employers, are places I wouldn't want to work anyway. It's a big wide world out there.

> Probably for the best...

Quite. One of my first gigs was at a large real-estate aggregator. The people were great but the highest levels of the company did

- A pet “adoption” site, in quotes because to my knowledge the pets weren’t real and it was a subscription service with no means of cancellation outside of a voicemail box - A kind of Craigslist-esque site for selling home improvement services that was wildly vulnerable to XSS - I discovered that during an unannounced client demo when my own manager had said “you guys try to break it” - We were a PHP shop from the beginning. One day, engineering gets pulled into a meeting room and told that they’ve been developing 2.0 in an office downtown, with a separate team, in ColdFusion. They fired the lead engineer on the spot and most of us left or got fired shortly thereafter. They did offer to train us in CF, but the bad blood was too thick for my taste.

All that is to say, if I ever get wind of the owner or CEO being involved anywhere that I’m working, I’ll probably be walking.

Re: Asked to do something illegal at work? Here's what these software engineers did

#362

Earlier quoted context omitted.

> They've checked with their peers and lawyers, and decided it's a perfectly acceptable risk to have the founders and staff of a company they're already invested in do illegal things and potentially end up in jail ... No legitimate business person I have ever met holds this position, if for no other reason than criminal acts pierce the corporate veil[0]. > ... so long as the investors and their staff are all insulate…

> > ... so long as the investors and their staff are all insulated from the illegal behavior and jail time risks. > There is no such thing. Sure there is. You can never request an illegal act, never commit an illegal act, but create a culture where others become incentivized to do illegal acts. This can be done in sufficiently subtle ways that it's impossible to prove it was intentional. "Will no one rid me of this t…

> You can never request an illegal act, never commit an illegal act, but create a culture where others become incentivized to do illegal acts. This can be done in sufficiently subtle ways that it's impossible to prove it was intentional.

I disagree. So do many state and federal RICO[0] laws. They were enacted for precisely this situation.

But you do you.

0 - https://en.wikipedia.org/wiki/Racketeer_Influenced_and_Corru...

Re: Asked to do something illegal at work? Here's what these software engineers did

#363
post #272

Earlier quoted context omitted.

> They've checked with their peers and lawyers, and decided it's a perfectly acceptable risk to have the founders and staff of a company they're already invested in do illegal things and potentially end up in jail ... No legitimate business person I have ever met holds this position, if for no other reason than criminal acts pierce the corporate veil[0]. > ... so long as the investors and their staff are all insulate…

> No legitimate business person I have ever met holds this position Well, sure, that's true. But only because that's a no-true-scotsman fallacy in incubation. All these perps are "legitimate business people" until they aren't. And they cross that rubicon, almost to a person, still believing that they're legitimate business people and that this is all a clever hack. It looks obvious only in hindsight when you're looki…

>> No legitimate business person I have ever met holds this position

> Well, sure, that's true. But only because that's a no-true-scotsman fallacy in incubation.

Which, by your own admission, makes it not a no-true-scotsman fallacy since it does not exist.

> All these perps are "legitimate business people" until they aren't.

This is a strawman fallacy[0] when considering the assertion to which I replied, which reads thusly:

  They've checked with their peers and lawyers, and decided 
  it's a perfectly acceptable risk to have the founders and 
  staff of a company they're already invested in do illegal 
  things and potentially end up in jail ...
Note the explicit knowledge of illegality. This invalidates the premise of participants being "legitimate business people" as, by definition, they are engaging in illegitimate activities. Unfortunately, the rest of your argument is inapplicable due to the aforementioned strawman[0].

0 - https://en.wikipedia.org/wiki/Straw_man

Re: Asked to do something illegal at work? Here's what these software engineers did

#364

Earlier quoted context omitted.

> > ... so long as the investors and their staff are all insulated from the illegal behavior and jail time risks. > There is no such thing. Sure there is. You can never request an illegal act, never commit an illegal act, but create a culture where others become incentivized to do illegal acts. This can be done in sufficiently subtle ways that it's impossible to prove it was intentional. "Will no one rid me of this t…

> You can never request an illegal act, never commit an illegal act, but create a culture where others become incentivized to do illegal acts. This can be done in sufficiently subtle ways that it's impossible to prove it was intentional. I disagree. So do many state and federal RICO[0] laws. They were enacted for precisely this situation. But you do you. 0 - https://en.wikipedia.org/wiki/Racketeer_Influenced_and_Corr…

If you are familiar with RICO, surely you are also familiar with how notoriously difficult they are to prosecute. But in your words, "you do you" I guess.

Re: Asked to do something illegal at work? Here's what these software engineers did

#365

Earlier quoted context omitted.

> You can never request an illegal act, never commit an illegal act, but create a culture where others become incentivized to do illegal acts. This can be done in sufficiently subtle ways that it's impossible to prove it was intentional. I disagree. So do many state and federal RICO[0] laws. They were enacted for precisely this situation. But you do you. 0 - https://en.wikipedia.org/wiki/Racketeer_Influenced_and_Corr…

If you are familiar with RICO, surely you are also familiar with how notoriously difficult they are to prosecute. But in your words, "you do you" I guess.

And if you are also familiar with RICO and think prosecution difficulty will save anyone from same...

EDIT:

Just so I am properly understanding your position, are you advocating for engaging in activities which would qualify as RICO crimes due to "how notoriously difficult they are to prosecute"?

Re: Asked to do something illegal at work? Here's what these software engineers did

#366

Earlier quoted context omitted.

If you are familiar with RICO, surely you are also familiar with how notoriously difficult they are to prosecute. But in your words, "you do you" I guess.

And if you are also familiar with RICO and think prosecution difficulty will save anyone from same... EDIT: Just so I am properly understanding your position, are you advocating for engaging in activities which would qualify as RICO crimes due to "how notoriously difficult they are to prosecute"?

Advocating? What? No, I'm not "advocating" for crime. I'm just pointing out that there are ways for crime to happen, to even be encouraged, without really risking the investors. Your "no such thing" comment, while maybe true in a nonexistant legally ideal reality, does not reflect how things play out in real life.

RICO is hard to prosecute on a good day. If an organization is usually law-abiding and occasionally structures things such that some lower manager has a near-impossible goal to hit that is made easier with crime, then one gets crime occasionally.

And that's also not counting all the crimes like environmental dumping, which consistently yield zero prosecution and slap the company with a fine that's 4% of what the company saved by dumping their waste in a river.

Here's a recent example https://www.wjhl.com/news/national/campbell-soup-admits-to-d...

Re: Asked to do something illegal at work? Here's what these software engineers did

#367

Earlier quoted context omitted.

And if you are also familiar with RICO and think prosecution difficulty will save anyone from same... EDIT: Just so I am properly understanding your position, are you advocating for engaging in activities which would qualify as RICO crimes due to "how notoriously difficult they are to prosecute"?

Advocating? What? No, I'm not "advocating" for crime. I'm just pointing out that there are ways for crime to happen, to even be encouraged, without really risking the investors. Your "no such thing" comment, while maybe true in a nonexistant legally ideal reality, does not reflect how things play out in real life. RICO is hard to prosecute on a good day. If an organization is usually law-abiding and occasionally stru…

> Advocating? What? No, I'm not "advocating" for crime.

I didn't think so, but had to ask in order to ensure we have a common baseline.

> I'm just pointing out that there are ways for crime to happen, to even be encouraged, without really risking the investors. Your "no such thing" comment, while maybe true in a nonexistant legally ideal reality, does not reflect how things play out in real life.

I agree, there is always a way for criminal acts to be perpetrated, sometimes for years on end. My disagreement is with the encouragement portion having no risk to investors. As mentioned previously, criminal activities pierce the corporate veil[0], which can and do ensnare investors as well.

The complete quote to which I made my "[t]here is no such thing" comment is (with my initial quotation being the post-hyphenation fragment):

  They've checked with their peers and lawyers, and decided 
  it's a perfectly acceptable risk to have the founders and 
  staff of a company they're already invested in do illegal 
  things and potentially end up in jail, if it makes the odds 
  of that company being a 100x exit - so long as the 
  investors and their staff are all insulated from the 
  illegal behavior and jail time risks.
Call me naive, but I do not consider my interpretation as being "a nonexistant legally ideal reality" that "does not reflect how things play out in real life."

Prosecutors are not stupid, nor are they robots incapable of reasoning and deduction. Quite to the contrary, they share many of the problem solving skills software engineers possess. And given a "big enough" problem, they will solve it via investigation and prosecutions.

As to what is chosen to prosecute and when, well, that is an entirely different discussion of which I am wholly unqualified to have.

0 - https://corpgov.law.harvard.edu/2014/03/27/the-three-justifi...

Re: Asked to do something illegal at work? Here's what these software engineers did

#368
post #114

In 2010 WellPoint was found to be automatically targeting insurance policies of women with breast cancer for cancellation, using any pretext. Angela Braly was the CEO at the time, now at ExxonMobile. WellPoint was the second largest health insurer in the US at the time. This required a lot of business analysis and software development - and people had to realize what this code was doing. I’m guessing bonuses were pai…

In the 2010s, we had a similar situation but it wasn’t illegal. I used to work for a large drug distributor both pre and during the opioid epidemic. At the time (pre-SUPPORT Act), distributors weren’t required to notify the DEA about anomalous ordering so we didn’t provide data to law enforcement unless they sent a subpoena. To increase profits, we identified our best customers of opioids and updated our inventory tr…

This is extremely common throughout the world for businesses that sell alcohol or variations on gambling - and while I don't necessarily think the advertising should be _illegal_ (in those cases with non-controlled substances at least), I've always been shaken that the many people involved in it don't seem to see how it could be immoral.

Re: Asked to do something illegal at work? Here's what these software engineers did

#369

Earlier quoted context omitted.

It really seems like you have effectively caused the deaths of many people through your actions. Does that have a lingering impact on you?

No. Patient took medication and were responsible for their health. Doctors wrote the scripts and have the ultimate responsibility to the patients. Pharmacies dispensed the medications as instructed by the scripts. Big Pharma (Sackler) makes and markets the drugs. Distribution is only responsible for making sure drugs arrive efficiently to their location. I would work for a drug distributor again if the pay were bette…

Americans are always looking for someone else to blame for their choices.

A bit of an ironic statement, given that this post is you blaming everyone except yourself for the role you played in deepening the opioid crisis to increase profits.

Post reply on HN