* Would this product exist without the malicious use cases?
* Can the company sustain itself without the malicious use case?
* Are there ways to mitigate the malicious use cases, and could they be reasonably implemented?
* Is the true intent of the business - when you assess it honestly - for it to be used in the "good" scenario, or in the malicious scenario?
* Are the malicious scenarios being reinforced/rewarded?
* What portion of revenue is directly caused by the malicious use cases?
* Is the company marketing or appealing to the malicious use cases? Are they trying to actively warn against/discourage them?
* What are the worst case scenarios of the malicious use case? Are they theoretical or real?
* What are the best case scenarios of the "golden path" use case? Are they theoretical or real?
And we also need to pay attention as we answer the questions above, looking out for if/when we make shallow justifications rather than honestly assessing the answers to the questions above. Look out for situations where our response is hedged by an excuse that's irrelevant to your ethical duties as a software engineer, such as:
* "but we can't leave money on the table"
* "but people would lose their jobs if we didn't do this"
* "but this is what our competitors do"
* "but if we didn't do this, someone else would"
* "but it also causes [theoretical/unintended side effect that sounds good on paper]" (particularly important to watch out for when that unintended side effect is an oversimplified version of reality)
* "but it's not our choice how it is used" (particularly relevant in situations where the business model relies on the malicious use case, and/or there are opportunities to mitigate the harmful use case that are intentionally going unexplored... or situations where your product itself is using techniques such as behavioral conditioning to train a user's choices)
I would be worried that the platform is now used to silently steal the contacts list of millions of users without their informed consent.