That wild Ask a Manager story
jacobian.org
jacobian.org
The new hire who showed up is not the same person we interviewed - https://news.ycombinator.com/item?id=30150343 - Jan 2022 (600 comments)
Eventually after some incidents they introduced “special instructions” for customers who we had to gather extra troubleshooting data for because of some complex issues they had.
Then a few more customers had special instructions… and a few more.
Eventually these involved things like “Send the account manager an email for each call, this customer is very sensitive.”
After just a year EVERY account had special instructions.
Many people oriented instructions were impossible to follow “Page Jim.” Jim didn’t carry a pager anymore and when he did he would never respond so you couldn’t do step 2.
Some involved gathering loads of memory dumps for issues long solved. Others would have you follow program pointers to memory that didn’t exist so you would start over and over until you gave up and decided failing to do your job was preferable to losing your mind at 4am….
Some instructions were multi page word documents expected to be read every time the customer called. After reading it a dozen times a week it almost became impossible to notice if it had a slight change or not.
One clever account manager trying to make sure tech support “noticed” his special instructions tried using a <blink> tag… entirely ignoring the issue that upon noticing the instructions they would be hard to read. Thankfully the tag failed to work.
As you can imagine eventually there were exasperated executive meetings about how nobody follows the special instructions.
This is the world of protecting against corner cases.
Computers don’t have emotions; I don’t need to worry insulting the vast majority of S3 objects when I defensively check integrity every time. But humans are different; when we design a human system around uncommon cases, we do need to consider the ramifications on the majority.
We can hide the complexity in computer systems even engineer the risks of it out, this is not the case in human centric systems. That complexity will endanger everyone involved.
KISS is a good principle generally, but it's the most important principle in humans systems, sometimes even ahead of completeness.
> when we design a human system around uncommon cases, we do need to consider the ramifications on the majority
This is how I feel every time some new service asks me which pronouns I prefer. I'm happy that some people get to choose the pronouns they feel represent them (or avoid the pronouns they feel disservice them), but it seems like it is both pushing an agenda and adding additional friction to the process. Just leave the option setCustomerPronoun() available without making it a necessary step.I've chosen a contentious example, but there are dozens of others. Just for another example, if I was born in 1977 (above age of consent), what does the forum software care my exact date of birth and err when I don't want to provide it?
Same with the Last Name field. I happen to know someone who doesn't have one. Why isn't he accommodated?
How about colour blindness? Why isn't there a colour-blind accessibility option in the sign up form? Is making colour-blind people's options the same level in the UI as regularly-sighted people a bad thing?
I think that my point is made.
Having a separate first-last name is often brought up as a UX failure for exactly this reason, and UX designers often design websites so that colourblindness doesn't hamper usability (in my experience working with designers at big companies). The Christmas one isn't as much of an issue because AFAIK very few people are meaningfully put out by seeing Christmas decorations on websites from majority-Christian countries. In other countries these things often /are/ turned off depending on cultural sensitivities.
We should be trying to design our processes to fit the world around us, not rejecting the parts of the world we don't like.
The obvious solution is to just not use pronouns - it's a messy part of the language that is currently in flux, so why wade in?
Obviously, some sites are dedicated to these issues, so they can justifiably ask on sign up, but if you don't _need_ to care about people's personal details, better not to ask at all.
Forms of address --- Mr., Mrs., Miss., Ms., and often professional titles (Dr., in German Ing. (engineer), esquire (lawyers), Reverand, etc.) is at least fairly common if not entirely standard practice.
I suspect, again, some motivation on the part of a requestor. A magazine's circulation department, for example, might want to know the number of lawyers and doctors among its subscribers as a proxy for advertising value.
Many business information request forms provide detailed rosters of who you are, what you do, and your company title. For similar reasons, I suspect.
(I also feed those bogus information as a matter of course.)
The New York Times formally adopted use of "Ms." as a title, distinct from "Mrs." (a married woman, often referred to by her husband's full name, e.g., "Mrs. John Q. Smith"), or "Miss" (an unmarried woman or girl, addressed by her given and maiden names, "Miss Jane Q. Jones"). Ms. Magazine was a direct and deliberate challenge to that practice, and was launched in 1971 by Gloria Steinem. Interestingly, all three words, "miss, "missus", and "mizz" originate from "mistress", which was at one time the single title applied to any woman, adult or child, married or not.
(For men, the terms "Master" (unmarried child) and "Mister" were both represented as "Mr.".)
And then as now, "Ms." resulted in much gnashing of teeth, changing of forms, and updating of databases.
https://en.m.wikipedia.org/wiki/Ms.
https://www.nytimes.com/2009/10/25/magazine/25FOB-onlanguage...
There's virtually always the option to leave the option blank, or to make up a garbage or meaningless value. The first system on which I recall the option being offered was Google+. My response was "trans-krell", playing of my pseudonym's character.
For age, I usually try to find the earliest possible birth year acceptable to the system. For Google this seems to be about 140 years prior to the present date. Again, I avoid providing this information if possilbe (most of my various little-used Google accounts have either no value provided or a ridiculously early age).
I'm of the view that we don't need to be formulated, sprawling on a pin, within some global surveillance database(s). If I can evade classification and feed garbage to the system, I will, for as long as that is viable, and probably for some time after that point.
The gendering or nongendering agenda concerns me far less than the Total Information Awareness agenda. Services demanding anything from me other than some random username and password (I tend to use password generators to create both values), and possibly a contact email address ... tend not to get used.
As I just commented to a friend a few days ago, I can't remember the last time I did create an account, with the exception of some recent Mastodon and Diaspora* migrations in the past year or two.
For my most recent Android device (the Android aspect of it being among the least attractive characteristics), I bailed out of Google Play Store registration, which requires creating a Google account. (Even if not formally associated with other identities I have, those could all but certainly be trivially linked.) Instead I'm relying on F-Droid, APK-Mirror, and the Aurora Store. I've kept actual app installations to a bare minimum, and most of those through F-Droid. There are I think three apps with actual accounts associated to them, though only one has been so configured.
My use of the Internet dates to the 1980s. I've seen a lot. And am disliking increasing amounts of it. Read Dan Geer if you haven't recently.
> There's virtually always the option to leave the option blank, or to make up a garbage or meaningless value.
Right, but it's an uncommon option that relates to a controversial subject. That's why I mentioned to leave the option setCustomerPronoun() available without making it a necessary step: show it in the UI options but it doesn't have to be front and center in the sign-up form. > The gendering or nongendering agenda concerns me far less than the Total Information Awareness agenda.
Sure, without a doubt. I may have inadvertently picked a flamebait example! > Read Dan Geer if you haven't recently.
Thanks, added to the list.As a human, can you please tell all of us what these abbreviations are?!
...TFA: The Featured Article
a.k.a. (also known as) OP (original post(er))
This is one “human corner case” I have no shame working around. Wouldn’t want to convey hostility where none exists.
I prefer "TFA" to "OP" as the latter may be ambiguous as to whether it refers to the article or, more typically in my experience, commentary on it. Even here, "OP" might reference either a thread root or the parent of the post immediately being replied to.
In the second case, if I were to say "OP" here, I'd be referring to your comments parent, by tchalla, https://news.ycombinator.com/item?id=30345056
It refers specifically to the submitted article, and carries an overtone, sometimes tongue-in-cheek, sometimes subtle, sometimes more blunt, that the person being referred to ought to read the specific submitted work more closely. Perhaps at all. And without crossing HN's guidelines against specific accusations.
That is, the meanings are similar but different. "TFA" is more concise and specific. All of which make it the more fabulous ;-)
It turns out I do use both terms fairly frequently, as my comment history shows. The distinction is largely as I've described above. "The article" usually refers to some additional or other reference rather than the HN submission. "TFA" in the context if "you/I should have read that closely".
TFA: https://hn.algolia.com/?dateRange=all&page=1&prefix=true&que...
"the article" https://hn.algolia.com/?dateRange=all&page=1&prefix=true&que...
The real problem with crypto is that usually what is asked for is a ledger, and the crypto and distributed parts are just bloat.
Unlike code that triggers (hopefully) only when something weird happens, the cost of the special instructions and the dysfunction that followed was ultra high.
This sounds insane and I genuinely don't understand why anyone would work here or put up with this.
I understand the main point, I think, of 'make sure that people read instructions instead of ignoring them', but this is taken to bizarro levels which I don't understand why anyone would tolerate. The 'account managers' designing these 'special instructions' are either sadists or just assholes, and if management is not willing to protect its own staff from this bullshit, I see no reason for anyone to continue to work there. I don't really understand people staying in abusive job situations like this. There are many other job opportunities out there.
I'm working to get out of a job that turned into this once our (lovely) manager bailed and exposed our team to the incompetence of our current leadership.
I'm having to HEAVILY fight my gut instinct by leaving, because I was raised in poverty and grew up as a disabled lesbian back when those things created more issues than they do now. I'm also from a rural area and neither of my parents have college degrees.
I may logically know that I (as someone with credentials and a decent skill set) have every right to leave and it's in my best interest to do so, but it conflicts with literally decades of messaging I've got telling me I'm lucky to be allowed where I am at all and seeing those around me be punished for standing up for themselves.
I was also abused by my parents, and that's another angle: People who are used to abuse don't think it's that bad, and I'd wager there's a fair number of people who have just never had a decent work situation. If you're going to be abused, at least pick an abuser you know and can work around.
Humans are pattern recognition/social machines, and if you only expose humans to dysfunctional patterns, they'll assume the problem is them. If you design a society, it's pretty easy to get yourself a group of people who are open to being exploited.
I've had a lot problems myself struggling around guilt about the pay and general lifestyle in tech. But I'm now working in a tech company with lovely people, doing interesting work. For what it's worth from a stranger: I wish you luck in overcoming your inner critic and that you are worthy and deserving to get a job with people you like at a job you enjoy.
This is a large part of it, especially as someone whose community is likely to have those sorts of jobs. If everybody around you hates their job and you grow up in a culture where people actively despise their workplaces/management, you assume that's just how jobs are.
EVERYBODY I grew up around hated their jobs, so it's really hard for me to know what to put up with. To people like my stepdad, my displeasure at how I'm treated by leadership is complete stuck up whining: I personally make more than him + my mother and their households ever have, I'm not in physical danger (unlike him doing HVAC work, my mom doing warehouse work, my siblings' SOs who work landscaping, etc), etc. I was taught growing up that basically unless your boss put you in the hospital, you were lucky to not be homeless or starving and work just sucks.
This is a particularly hard mindset to get out of because in white-collar environments, you can't talk about how growing up blue collar or working class makes you anxious because a lot of 'professionalism' boils down to 'don't let the nice people know you're a peasant or you'll be kicked out for not being a culture fit'.
The pandemic has been very helpful, ironically! I'm more than willing to blame myself for all my life problems, but when I see OTHER people being treated like I was, it raises my heckles and pisses me off.
I'm so glad to hear that you found a job you like. I'm hoping to move from a small-shop/journeyman dev to working in a dev team and I'm trying to maintain optimism, so stories like that help!
Feeling safe let me leave bad employers in the past. Thankfully my current one is pretty awesome.
My personal experiences, outliers though they are, tell me that change is likely to screw me over. I would love to save my paychecks but when your meds cost 300k+ a year for your entire life, your life is dictated by health insurance and care. I lived like a college student and saved and was STILL fucked by change, so I'm very change and risk averse.
While the special instructions incidents were horrific, particularly to someone like me who wants to do the right thing and their brain seizes up with such insanity, they were eventually resolved.
Finally they instituted a policy where instructions were reviewed by a group of senior account managers every 90 days. Whomever wrote them had to justify them, or they were simply deleted. That actually turned out to be a great process as many out of date instructions were auto deleted without anyone doing anything.
As for the job, it was actually a great job. The support team was amazing, supportive, it paid great, and the company weathered a lot of economic downturns easily. If anything the special instructions incident demonstrated how even a great organization can go bonkers insane.
Try Auftragstaktik instead:
This sort of implementation inevitably becomes a mountain of technical debt that overfits to the current process and reduces operational agility when the current process changes. At some point with business applications you have to trust your people to do the work and view the technology as something that enables that rather than necessarily constrains every dimension of it.
Me: Kraken, I'd like to recover my old account I created years ago.
Kraken support: Sure, just login from the same computer and IP.
Me: I can't, I no longer have either of those things.
Kraken: How did our customer service go?
Me: It didn't.
Kraken: We can fix it, just login to zoom from the same computer and IP...
Ad nauseam, ad infinitum.Their financial incentives aren't aligned with customers.
I blundered my home address when initially setting up my cable internet installation. The installer called from the other house and I redirected him. He told me just to call customer service to have it corrected.
Multiple attempts, there is no way to change the billing/service address of an open account. Web says to call, customer service agent says to use web..
I've set to paperless billing and figure for any service visit, the tech will call me confused from 2 doors down and I will redirect them. Easy enough. Two year going now, so far so good.
I can see someone overlooking the need to support address corrections because that is probably a rare case, but customers moving within the company's service area and wanting to have service at the new address surely is common enough that they cannot have overlooked supporting that.
In my experience working working in tech support at a company that encouraged us to fix whatever we could do like as, service address and billing address changes occured everyday,multiple times a day.
At the time I was there that ISP had fewer than 200,000 customer, wasn't even one of the big players at the time.
Intenode in Australia, based in Adelaide, circa 2004 through 2010.
When I first started working at Intenode, tech support was still solely on the third floor of 132 Grenfell Street, and you would occasionally bump in to Simon Hackett in the lift.
I was still there when iiNet acquired the company, but left before TPG acquired iiNet.
Good times.
It's cheaper. If they don't let their customer service agents have any autonomy, then they don't have to hire for things like 'judgement' and can just throw warm bodies in a chair, which makes people easy to replace and cheap to employ. It also prevents your cheapness from causing issues; if you hire decent people and rely on them, then it causes issues if those people leave en masse or start siding with your customers over you. "Sure, Mrs. Johnson, I'll forgive last month's bill; they don't pay enough managers to check and I'm quitting tomorrow what do I care?"
I’ve seen a similar thing with integration tests, as on a team with decent unit test practices production bugs are often a result of bad assumptions about another team’s API. Eventually a mountain of brittle end-to-end tests cripples a team until they get managerial buy-in to rip them all out and the cycle starts over.
Yes, checklists and process standardisation will avoid numerous types of errors and issues. However one of your checklist processes must be to assess the checklist itself, weeding and refactoring the checklist itself from time to time. This includes recognising that the refactored checklist will itself have further issues and shakedown bugs.
Ultimately process is a compromise between what can be kept in working or near-at-hand memory, and what's both sufficient and required for the particular problem domain.
The purpose of keeping a record of past postmortems is that you can potentially go back and say “oh gosh, it isn’t actually rare, and so maybe the more elaborate countermeasures are justified”.
I’ve seen the opposite extreme happen, where a devops guy was adamantly against writing a postmortem at all, because “it wasn’t our fault” and “it probably won’t happen again”. Facepalm.
I’m a firm believer in learning from mistakes, and making the right trade offs between reliability and velocity. Postmortems are a fantastic tool for facilitating this. As you point out though, the implementation matters and you need to be conscious of the cost/benefit of the recommendations that come out of the exercise.
If that list of extra checks is automated, i.e. added to your deployment scripts rather than manually followed by a human, then that's great. Every bit of repetitive decision-making and tribal knowledge that you can eliminate from your team's day-to-day functioning is a win.
(Spoiler: NY was "Search by State", CA/TX was "Zip + radius")
Population density means zip codes are extremely concentrated in NYC, especially in Manhattan. Traveling down the length of Manhattan might have you cover ~25 zip codes in 13 miles. Basically, a zip code isn't a meaningful measure of distance like it might be elsewhere. A radius might also place you into NJ, which could be an issue depending on what you're trying to accomplish: Delivering something from Queens might be significantly easier than from NJ, even though Queens might be further.
That's my guess anyway, though it's odd because nowadays generally looking something up via zip code + radius is actually easier in Manhattan (with a map you can easily see whether it would require coming from Jersey, crossing the park, etc. etc.)
Contrast to FL, TX, CA, and we had to immediately support zip-code-ish search (a non-trivial technical and operational burden, as zip-codes are rough-approximates for GEO's, and change pretty frequently) b/c "Couch for Sale in TX" means something completely different from "Couch for Sale in MA".
Contrast to the midwest (eg: kansas, montana), and this random-population-density-map I found: http://ecpmlangues.u-strasbg.fr/civilization/geography/US-ce...
...you can see that "just tell me what state it's in" hits within ~1hr of a single city center up until you hit TX or FL. So in 2000 it was a reasonable shorthand for "east-coasters" to say: "MA == Boston of course", and "CO == Denver" b/c where else was the internet going to be? ...either relatively close-by, or at your states major population center.
This is totally non-scientific and anecdotal, but I worked for a P2P sales startup out of college, implemented the zip-code search, radius, and update code, and distinctly remember noticing that some competitors (and dating sites!) definitely didn't support zip + radius searching, and they were usually ones that were funded from NY. CA was probably a bit more technically advanced, geo-aware, and wouldn't usually launch w/o zip + radius capabilities... again b/c "Couch in NV/CA", or "Singles in NV/CA" is a completely different scale from "Couch in NY/NJ, or Singles in NY/NJ"
(edit: in the 2000-era!! barely dial-up, and computers in general were decidedly non-rural devices, no cellular networking, and a motorola "two-way" was peak connectivity).
That said, I’d take Suffern NY over south Jersey, so by state isn’t ideal either.
But if you were in that 1%, shit sucked, sorry.
Two examples:
1) You're a single parent working part-time as a legal secretary, and in receipt of some form of social welfare payment to ensure you and your children don't end up in hardship.
You are offered full-time hours! Yes! Except because you hit the boundaries/limits/edge cases in the legislation, your net income will only increase by $30 a week, because your income tested supplementary assistances will decrease as your earnings do.
Now, the legislation in play here, ensures social welfare and works okay for 99% of people (when I say "works okay", I mean, gives them money, and doesn't disincentivise work). But that income testing bites you as you approach the edge of the income curve.
2) You want to go hunting in a national park managed by the Dept of Conservation. The usual hunting permit requires that you only use centrefire rifles - rimfires and shotguns are totally banned (to prevent hunting of native birds, especially the tasty fruit fed kererū/kūkupa/wood pigeon[0]). However, you want to hunt red deer and chamois, with a crossbow.
The policies at the time don't account for crossbows (and this was before bow hunting was as common place as it is now). So the department defaults to "No".
In both situations, the broad rules work well for 99% of users. But for the 1% it sucks. The key to the 1% is human discretion and agency.
Good systems, whether legal, business process, or algorithmic, always allow for a human to override. Bad ones don't. "Computer says no" style.
(On the crossbows, a ranger (my Mum, I'll be honest) went into bat for the hunter in question, to determine what was needed for "no" to become "yes", and well, now there's a policy that determines the minimum draw weight for a crossbow to be considered humane - and no barbed or exploding bolts allowed! [1])
[0]: https://www.doc.govt.nz/nature/native-animals/birds/birds-a-...
[1]: https://www.doc.govt.nz/parks-and-recreation/things-to-do/hu...
But I suspect a) was the main driver :D
The UK introducted legislation stating that people on a specific type of visa would only be eligible for permanent residence if it was issued on or before April 2010. The same legislation said, if this type of visa was issued after April 2011, it oculd only be extended to a maximum of 6 years, and then the visa holder would have to go back to their home country.
Well, there were obviously a bunch of these visas that were issued in the interim period, where the holders wouldn't be eligible for permanent residence, but if the employer company was willing to do so, could keep extending these visas indefinitely.
This seemed so baffling to us that we spoke to multiple immigration solicitors and the Home Office/UK Visas & Immigration support reps (or whatever outsourced org they were then -- Capita? Sopra Steria?) and they confirmed that this was true -- the visa could be indefinitely extended unless the government changed the rules.
The government eventually patched this bug, but IIRC, not before most such visa holders used the extra time to sort their employment situation out. (Opinion, not facts, based only on forum discussion anecdata)
My mother at one point made $25/mo too much for her childcare assistance because she worked some overtime. She lost her assistance for months and ended up several thousand bucks in the hole. Plus joy for me, since when parents can't afford childcare, guess who gets to do it instead? If you guessed usually the oldest kid, here's a prize!
Very true.
I remember, back when I was still interested in helping companies succeed, one “interview” I had.
I mentioned that I had this ginormous portfolio, packed with dozens of highly relevant, finished, tested, well-documented, well-designed open-source projects, a decade of checkin history, of tens of thousands of lines of code, hundreds of pages of documentation, dozens of articles on various sites, where I walk through my design philosophies and processes, in detail, teaching modules, etc.
The “interviewer” told me that they were not going to look at it, because “I could have faked it.”
My jaw dropped.
If I could fake that, then you should hire me immediately, at three times your offered salary.
I’m pretty sure that the decision had already been made, not to consider me (because eld), and this was their way of chasing me off. They weren’t going to waste the half hour or so, that it would take to do a quick review of my work.
It worked a treat. I couldn’t hang up, fast enough. I won’t go where I’m not wanted.
The other explanation, is that they actually believed what they said, which would mean they were completely insane.
Hopefully I dont break the site rules for pointing this out, but interviews are a game to weed out people who are difficult to manage. And people who show any unusual flair are considered difficult to manage by lots of managers.
And yes, some eccentric people with whom I worked were awesome, but there were also lots of eccentric people who were not (combination of "exceptionalists" and "insufferable").
SRSLY? You are saying "big words," On HackerNews? This venue is the Home of The Big Word. I can't hold a candle to some of the eloquence that regularly appears here. I pretty much write in the vernacular.
BTW: I am "strange." You got it in one. I've become quite happy about that, and so has pretty much everyone I've worked with, over a long career, in many diverse teams.
But you ... might want to browse around my work ... just a bit ... before deciding you know about me. I make it very easy to check my work. Unlike most folks around these parts, I'm extremely open about who I am, and how to find out about me. Helps me to stay away from the Dark Side of The Force. I'm also not particularly interested in working for anyone else, ever again, so I'm not really about trying to be diplomatic. If some chap in a crown is running about, starkers, I'm likely to point it out.
It's kind of amazing that we regularly resort to sending up insults, hereabouts, without taking just a couple of minutes to see if they have a landing pad, first.
It's not that insane? Like, how hard is it to clone some substantial, but lesser known, project and edit the committer to yourself? Edit the name too to something that you buy a domain for. It wouldn't hold in court, but a hiring manager in a rush won't ever be able to figure out if you did that or not.
It would be mighty hard to fake, and even a quick shufti will tell you that. My code and my writing has a very distinctive style.
It was -quite literally- the equivalent of a little kid, sticking their fingers in their ears, singing "lalalalaaaaaa-I-can't-hear-yoooouuu-lalalalaaaaaa."
Sadly, the StackOverflow Story will be going the way of the dodo, soon, so I'll have to rebuild it, manually. Pain in the ass. Since I'm no longer bothering to look for work, it won't be a priority.
I'm even worse at this - you'd be hard pressed to find anything of value attributed to my name since I left academia. I even don't host most of my code at Github. At least I won't be surprised by somebody not trusting my portfolio ;)
I’m not at all interested in competing with hungry kids. I wanted to keep busy, and make just enough to keep the lights on, and some insurance. I probably would have cost half as much as most folks.
I wasn’t expecting to be fawned over or flattered, but the flat-out, unapologetic disdain, made it clear that the industry is no longer a place I want to be.
I found some folks that wanted to do stuff that interested me, and I’ve been working with them, for free. They seem happy with my work, and I’m quite happy, working with them.
Also, and this is neither here, nor there, all my Git commits are GPG-signed.
> Computers don’t have emotions; I don’t need to worry insulting the vast majority of S3 objects when I defensively check integrity every time. But humans are different; when we design a human system around uncommon cases, we do need to consider the ramifications on the majority.
That's very true. It could be called "the tragedy of security": annoying and insulting everyone just to ward off a few bad actors.
For example, in Europe, online payments are becoming annoying to a degree that would have been unthinkable ten years ago. To use a VISA card online includes typing its 16-digits number, expiration date, "security code" (which is printed on the card), then receiving a code in a text message and typing it back, and now typing yet another personal code (or in some cases, the access code to one's online account!!) And after all that, it may still fail. It's insane.
I'm sure there are good reasons from the banks or regulators POV to act like this, but the consequences are incredibly painful for the vast majority of people, and probably economically detrimental as well (I sometimes give up from buying something online when the system doesn't accept a simpler payment method than VISA).
There has to be a better way.
Really? In my experience aside from typing the card numbers, all I have to do is approve the transaction with 3D secure which is one tap in my bank's app. It has never failed in my experience.
Maybe you need to switch banks? :)
Is some relatively local stores it's along the lines of:
- check out an item in the cart
- you're taken to a payment processor's page (gateway)
- there you pick your payment method, e.g. which of the supported banks you use
- then you enter your bank's user ID and personal identifier
- then a prompt pops up on your phone (though you can also use a "code calculator") with a reference ID
- you enter your PIN code to confirm the prompt on your phone, granting the gateway access to your bank account
- it then lists your payment accounts, from which you pick one that you'd like to pay with
- then you get yet another prompt on your phone, this time you have a separate longer PIN to enter for confirming the payment
- you do so, the payment is processed and you're taken back to the store page, with your order placed
Note: that app (SmartID) that's used for the codes and confirmations isn't actually maintained by the bank, but is a separate entity, so to make a payment you might have to rely on the shop being up, the payment gateway being up, the confirmation solution being up and the bank also being up. Despite all of those vectors for failure, i've actually had a pretty good track record with this solution (i've only seen the bank's service crash once and the occasional store have issues).Oh, and the app can also be used to confirm authentication for online banking: you enter your bank user ID and personal identifier, which makes a prompt pop up on your phone, so you also get 2FA there out of the box!
For anyone wondering: https://www.seb.lv/en/private/daily-banking/smart-id
Of course, the bank also has its own app where you can make payments to specific people, or request payments, as well as view your account balance and see how your investments are doing, which is pretty nice, though you cannot use it for confirming those purchases.
On global stores (e.g. the likes of Amazon, eBay, AliExpress etc.), however, the process is generally far less involved, you just check out an item that you want, shortly afterwards the money shows up as "reserved" on your account. If you don't recognize that order, you can dispute the charge. Of course, if you don't have card details saved, you would need to enter that information first (card number, name, expiration date, code), but the end result is the same there.
That said, despite the seemingly more cumbersome approach of integrating with the bank directly for payment processing instead of going with just the card approach, i'd say that it has some security advantages for sure! With this approach, even if my bank account is compromised, no one can make payments without having direct access to my phone AND knowing the codes (as long as the system works). Of course, many still choose to pay with their cards instead.
I recently gave up on becoming a Hetzner customer (to set up a Minecraft server for friends). After going through all the security checks it declined to provision the server, demanding a photo of me with my ID—even though it successfully made a transaction to validate my payment method, it matches my name and address on file, etc. I blame crypto miners playing chargebacks.
I imagine Germany has some laws about identifying who you host things for.
Now, now… calling extra security steps for online purchases ‘extremely painful’ and ‘economically detrimental’ seems a bit excessive.
In fact, I think these steps may be there just to make people feel more secure about buying online (this would totally work with my mom, who after many years of visiting me in the USA is still afraid of giving her card to the waiter in a restaurant to pay for dinner).
To be fair - her instincts aren't bad. It was always a shitty security model, it led to a lot of fraud, and it was one of the design principles of Chip and Pin to eliminate it.
And also, going to the store has its own rewards. You get to talk to real people, see and touch the things you want to buy, etc.
Now we're alone behind a screen, jumping through absurd and arbitrary hoops that keep getting harder and harder (tried to solve a captcha lately) and fighting "AI" systems fed with stupid data.
I'd just like to chime in here to say that this isn't universal across Europe. The dutch iDeal payment system only requires you to scan a QR code with your phone and enter your PIN also on your phone. I believe belgium at least uses a similar system, but I'm sure iDeal is not unique.
Not to discount your experience of course, sounds like a real hassle and an unnecessary one at that.
Why not just take a picture? If you're interviewing so many people that there's a genuine risk of forgetting who is who, a picture seems useful. I'm sure I'm not the only person who will forget your name in 3.5 seconds but never forgets a face.
Maybe this is my time at Pivotal speaking, but your first day on any team you get your picture taken with a polaroid. It goes on the pairing board. It's not weird.
"Thank you for interviewing with us! Mind if we take a picture so we can keep our who's who straight when the team is making the decision?"
All that jazz with IDs sounds unfriendly, sure. A snap isn't. Hell, make it a selfie with a team member.
Less so in smaller start-ups, but part of the process.
If you don't have ID cards, they could be part of, say, a company directory, wiki, or other system.
This isn't inherently adversarial and can be integrated into proceedures reasonably smoothly.
Again, this fits into workflows and isn't directly confrontational, but does preserve a record for comparison.
Very interesting insight! However I'm not fully behind some of the points.
Saying that fixing a bad hire is easy is a very USA-centric view of the world. In some European countries it would be very hard to get rid of such people, so the cost is hire.
I think the S3 analogy is not apt either. Sure, the probability of an error for each individual object is negligible, but if you store billions or trillions of objects, it becomes certain.
A better tech analogy is this: imagine a service that creates a bunch of resources every time you create an entry. When you delete the entry, you want to get rid of each resource. Now you have to defensively program around the myriads of errors and possible inconsistencies that can arise from this. And of course everything can just go wrong anyway.
Instead you could do nothing, or an optimistic delete. Then have a cron job that periodically cleans up orphaned resources. This is a much simpler and resilient approach.
The right answer to this question can probably be semi-formalized by account for the volume of transactions (interviews), errors (cheating candidates), cost of error (bad hire), price of increased complexity (more cumbersome interview experience for all), and how effective it is at preventing errors (are we getting all the cheaters?).
EDIT: On an extra note, this reminds me of those anti-piracy measures that don't stop piracy but are a royal pain in the ass for legit buyers.
Most EU countries have laws around probationary periods at the beginning of an employment that can extend up to six months. Once that period has passed it can be difficult to get rid of an employee but until then it's easy.
The laws typically align with the values and sensibilities in the societies, but its a tiny bit easier in practice (if you really want to) to make happen. In the USA people think it is easy, especially at will states - even easier than they think. The UK people think it is moderately difficult; its actually pretty easy. France people think it is impossible, its moderately difficult at best, expsensive (like a couple of months salary) at worst, and within probations and first couple of years, pretty easy.
Culturally however, a) people dont like firing people and b) they want to believe that they are unfirable as well. So rather than pay an employee 3 months severance they linger on for years.
It's not too difficult, but it's not quick (and that's ok). Outside of gross misconduct, you have to go through multiple stages of explaining the issue, coming up with a performance improvement plan and then evidence that they haven't met it.
Pretty much the ONLY thing that is not a "go" during the probationary period is due to various things that fall in protected categories. I have a hard time thinking "I let someone else do my interview for me" falls under that, in almost every case.
The maximum amount that you can be awarded as compensation for constructive dismissal is presently the statutory cap of £89,493 or 52 weeks gross salary- whichever is the lower
I'm pretty sure it is very easy pretty much anywhere, because a contract based on deception not being valid is a pretty fundamental principle.
Basically, when the person who shows up is not the person you hired, well, you don't owe them anything.
Pay a day of salary and move on.
In my late 20s, I thought people-processes were the real hard problem.
Now, in my early 30s, I think leaders who build both of the above, but have the wisdom and flexibility to know when to make exceptions, are perhaps the most fundamental key to success.
I wonder how my perspective will change as I complete this decade of my life.
First because of the indifference of their way of life, for they make a cult of indifference and, like dogs, eat and make love in public, go barefoot, and sleep in tubs and at crossroads.
The second reason is that the dog is a shameless animal, and they make a cult of shamelessness, not as being beneath modesty, but as superior to it.
The third reason is that the dog is a good guard, and they guard the tenets of their philosophy.
The fourth reason is that the dog is a discriminating animal which can distinguish between its friends and enemies. So do they recognize as friends those who are suited to philosophy, and receive them kindly, while those unfitted they drive away, like dogs, by barking at them.”
Oh, sorry, real answer. Early 40s: So, I built and sold a consulting company starting in my early 30s. Business is hard. Computers are easy. Business is leadership and being able to build marketing, sales, etc as needed.
Which is a useful concept to grasp!
If you get it, maybe you learn to drop your ergo and focus.
Nothing really matters, but feelings are real in the moment. So maybe you learn to do the right thing and have the courage to be a decent person!
Or you get fat and complain about the kids of today!
Does a individual thread's identity count? May be it does may be it doesn't.
Arthur Dent: And are you?
Slartibartfast: Ah, no. Well, that's where it all falls down, of course.
reminds "the severity of Russian laws is alleviated by the lack of their enforcement."
First day, he refused to turn on his camera during any of the meetings, wouldn't speak up, when he did it was clear the voice wasn't the same, seemed very dodgy. Aside from that, he didn't know how to use Git or setup his dev environment. One of the devs setup a pair-programming session to help get him acclimated. He couldn't write a single line of code. In the interview the candidate was clearly very senior and had significant experience.
Manager called him up and said they needed to speak on camera, he kept making excuses but finally turned it on. Not even close to the same guy, interview candidate was clean-shave. This guy had a six-month beard.
HR took over from there, he never would admit to it and held firm that he was the same person who interviewed and stopped responding once we let him know he was being terminated.
Afterward we did some research and found it's becoming very common these days. You have one guy who basically gets paid to do interviews for others, the person gets hired and basically collects paychecks as long as they can.
This is why we now require photoId as part of interviews and first day. I also now have a habit of taking a screenshot during interviews.
The author of this article mentions the cost was low to the mishire was low. I think that is fundamentally false. We shipped equipment (we got it back but they could have kept it), we turned down other candidates (which we may not get another chance to hire), we removed postings, we had to get multiple HR members involved, legal had to get involved, he had access to our repos, all of that had to be audited.
There is SIGNIFICANT cost to things like this.
However, I wonder how the newly introduced DEI-oriented features in the various ATS will contribute to more similar cases or will make companies not use them at all.
We were expanding fast by hiring bunches of contractors, which was already giving pretty polar results. After a while, my team got one too.
They didn't have a computer ready for him yet, so my lead pairs me up with him to babysit basically. We go chill in a conference room and I basically just try to get to know him and explain what we do here. I can tell he's nervous, and since this was my first dev job I remembered that feeling all too well, and wanted to be nice to him.
Immediately, he barely speaks english. Weird, but okay. Then I try to just talk shop with him, and find that I can't get any answers about recent stuff he's built, what he's interested in, frameworks he's used, or even what his favorite language is. They guy clearly knew nothing about software. I laughed to myself in a "not my problem" kind of way.
After a while I finally hand him off and explain the situation to my lead.
Turns out, he had a totally different person do the interview and coding test. And he didn't know anything about software. When confronted with this reality, he simply repeated, "I can do the work, I'll get the work done, I promise." Presumably the plan was to either just try and collect the first paycheck or two, or maybe he even wanted to outsource the work to someone else.
So, maybe don't rework your whole hiring process around this possibility, but at least do a video chat.
(This was well before covid.)
What does the manager do when this happens? I have been there. The answer is simple, I did exactly what I would do if the exact candidate I interviewed showed up but fell short of expectations (say used google extensively, or the questions were theoretical and they were good talkers - happens with QA and Project Manager jobs). If they are borderline, give them a task, see if they are able to complete it. A Manager should do it anyway, interviews are hard. Most companies have probation periods for this reason.
Why does it happen/what’s in it for the candidate/contracting firm? For the candidate a few weeks or months of experience that they can add to their resume. Do it in 3 or 4 places and suddenly you are a mid level developer. Hopefully they also learn a bit of programming in the meantime. For the contracting firm any money is money. Sketchy IT contracting forms routinely do this and worse.
It’s pretty common. A contractor attends some degree mill back home and is basically a human terminal. They get some training on how to function and send most of their work to a smart guy who does the work of a dozen contractors.
If you allow remote, it’s 10x worse - the folks are almost certainly working multiple contracts.
One firm just decided to replace the trained contractors working on my BI team with a bunch of junior devs overnight, no explanation, no warning. The fact that BI management kept employing them says more for the suspected "hello money" I think was paid to get them in first.
Don't such short employment stints speak against a candidate?
Here they are more likely to result in punishing the already poor or underprivileged and at times seem to be the way we prop our economy up.
In general, people react with "The laws need to change! We need to ramp up surveillance/social care/police capability etc etc" or even the "What shall we do? Something needs to be done!" type response.
But I think that usually the answer is "Do nothing". It was just one edge-case disturbed individual. This is not a common event, and will not be a common event. We cannot generalize any learnings from this tragic event. We just keep on keeping on, and know that one time in a thousand a bad thing will happen but for the other 999 times everything is fine and will be worse with more rules and restrictions.
But I think it’s a valuable post nonetheless: it’s succinct, it’s a punchy reminder of something we should all try to remember, and as a colleague of mine says: “common sense is not always common practice.”
Trying to fortify some system against some failure mode overwhelmingly often makes it more vulnerable to some other one. This is what keeps terrorists in business.
EV[failure] = P(failure) * cost-of-failure.
As an employee, it is far more important for me to avoid blame than to be efficient as I will get no credit for marginal improvements/no hit for marginal harms, but will get blamed if there is a very noticeable bad incident.
I am far more likely to have an annoyed boss from the wrong person showing up to work than driving away 100 candidates as the interview seemed hostile.
So the calculation is heavily weighted towards fortification for me as an employee, as I benefit not from the enterprise value but do from the value of my boss not being annoyed with me.
But we can get more conceptual clarity by modeling it as a zero-sum game: one actor wins, one loses. In general the actor with the asymmetrical relationship to forecasts about future price action wins. Sometimes the smart guy loses because he's undercapitalized.
Watching PHDs in friggin "steering outcomes under low gravity conditions" running home to Gaussian assumptions, the Central Limit Theorem, Fourier math, and VAR would be amusing if it wasn't going to put actual hunger on people who no one ever sent the link to HN. In light of the outrageous concrete human suffering, I think I can stifle my amusement.
But god damn am I sick of rich kids. I thought I would get some catharsis from kicking them around like a soccer ball on the biggest field in consumer technology, but it didn't really make me feel any better.
One guy stomping the shit out of legacies at Ivies for a few years doesn't change anything. This year, next year, ten years from now: paper-failures like @sama will still know the right people.
"I didn't make anything anyone wanted, and I'm still rich as fuck."
For all the criticisms I could make about rich kids in the Bay Area, it is simply that they are _lame_. I'm nothing but a middle class public school educated child of immigrants myself, but I always keep in mind my mother's somewhat cynical advice -- "always remember you will work twice as hard for half as much in this country" followed by "and it will still give you a better life than where we immigrated from."
If I can give you a piece of advice (maybe advice is too strong a word, as this is really just a coping mechanism for me personally), it is to remember that the karmic gears of time tick slowly but inexorably. To be a paper-failure 10 years from now that didn't make anything anyone wanted and to still be "rich as fuck" is a certain kind of Dantean hell in and of itself. Your entire life is the real life version of the Chinese "heaven's ban" where you are surrounded by sycophants who always lie to you to get access to your resources, and anyone else worth knowing would never want to associate with you because they deem you a clown and a fraud. You never learned the skills during your formative years to stand on your own two feet, and now you are too old to do the work that brings at least its own intellectually stimulating and market validated reward, as well as the respect of people in the world who are most worth associating with -- never mind the respect of salt of the earth people!
Perhaps this is my NYC elitism creeping in, but I wouldn't switch lives with such a paper failure SV talking head if you paid me. They'll never have taste, or be able to truly enjoy the finer things in life, or stand on their own two feet, or live in a truly cosmopolitan manner; they'll never have the edge to be as good of an operator as me or the operators I respect. And they will always know that deep down inside they are inferior no matter how hard they posture -- in a sense, I am more free than they will ever be, and if the pinnacle of life is to "live free or die" then they are effectively the walking dead, while I am breathing my own air free and clear.
Where was I going with this rant? Ah yes. Perhaps you need a break from SV because it's only there where these sorts of folks receive any kind of societal acceptance. I'd recommend either the east coast (I love NYC and it's never been more fun), or southern Europe (Spain and especially Portugal have always been nice to me). If you stay long enough in the SV echo chamber, it will warp your thinking and make life seem a lot less sunny than it could be.
In my opinion (and this is having no idea about your personal situation), I view it as just a bubble where you happen to work to make your living, and you can always exit as you please when you need a break or you've had enough. Hope I haven't been too presumptuous with this post and that I've at least been a little helpful.
For context, I spent ~10 years in SV, then another ~3 in NYC (but for an SV company most of it), and now I'm back in San Diego where I'm from. I think you're right on the money that I'm a more than a little over-rotated on the SV worldview. I'm generally a bit more balanced and...diplomatic about it, but when a rough week brings out some weapons-grade snarkiness? I'm clearly at least somewhat wrapped around the axle about it.
It's not so much that other people worked less hard for way more money that grinds my gears: I've lived comfortably on each of 3-ish orders of magnitude in terms of income, net worth, etc, and if I pulled out all the stops I could probably grind a bunch more cash out of my career than the perfectly reasonable amount that obtains. I work way less hard for way more money than a lot of folks around the world and feel a bit guilty about it in fact. Maybe humbled is a better word than guilty.
I think that I spent way too much time around people who attributed success to intelligence, insight and hard work, when it was actually due to intelligence, insight, hard work, and a lot of luck. I know some absurdly rich people who acknowledge that there were at least a few dice rolls along the way, and those folks don't get under my skin. Coincidentally or not, those folks seem to not have a bunch of opinions about how other people should live and work and a megaphone.
Andreessen is not far off with the "software eating the world" stuff, in some sense caring about the culture of the tech scene is a bigger and bigger part of caring about society in general every year. And I think that ultimately what bums me out is that YC/HN was one of my key/formative inspirations when I was getting serious about math and technology. Things like the T-shirt that says "I made something people want" that you got by selling a startup to people who enjoyed the experience really spoke to me.
For all I know sama and seibel are really smart, really solid people, and I regret calling them out on hearsay. I know at least one person who I trust and respect who knows sama personally and thinks the world of him.
But optics matter, and I'm probably not the only person who stopped believing in Santa Clause right around the time that pg handed the reins to the guy who needed a bailout on Loopt, and got kinda morose around the time that the Loopt-bailout guy handed the reins to the Socialcam-bailout guy.
I think ultimately I'm obviously very touchy/sensitive/negative on the topic because YC/HN was a childhood hero that ended up being the same damned nepotism that it was supposed to replace. At least MIT is available to anyone with a YouTube account and some time. YC is the new MIT and much, much more exclusive on the basis of who you know.
That's enough of the pissy part: I've got it insanely good for a guy whose grandparents worked in coal mines and gratitude around that is probably the right thing to focus on. It was a rough week.
Thank you again for such a compassionate and thoughtful reply, you've given me plenty to think about. Cheers.
I.e. when investing in the stock market it's almost common knowledge that silently putting money in an ETF every month will outperform almost everyone, even professional traders.
Overreactions to day-to-day things like corrections or a 1-in-a-million hiring situation break the obvious macro strategy
When an asset class is going up and up and up, FOMO can get even serious professionals to go long at a (relatively) high price, and gloss over the risk management. When things correct a bit, a lot of folks realize they hadn't managed the risk and get short "before it gets any worse".
This is probably the most common way to buy high and sell low, and while retail investors probably do more of this than hedge fund managers, hedge fun managers also do it.
Dollar cost averaging into a diverse set of ETFs is the simplest and cheapest thing that gets you highly competitive returns (at least to date). But I think that this is more to do with how much it takes emotion out of the picture than that SPY is like, ideal. Buffet, and Michael Burry, and others have demonstrated that if you're willing to spend years to decades of 16-hour days reading public filings in a drab office, it's not "hard" to beat the S&P. But those people are a lot more dispassionate about their trades than I am, and I suspect than most people are.
Weird edge case escalation happens, engineering team spends a couple days handling it.
In sprint planning/retro – "we have to make sure we never waste time over this again".
Team spends weeks coming up with an optimal solution to address this very specific case.
Original problem was rare enough that it doesn't happen again.
A different edge case happens. Rinse and repeat.
Q: “Why did nobody notice the baby is sick?” A: Babies are weighed in every interaction, which is humiliating to parents.
Q: “Why didn’t you stop Sally from enrolling for benefits in 2 counties?” A: Fingerprint indigent beneficiaries, at their expense.
Q: “Why should people on drugs get welfare?” A: A family loses crucial benefits because mom smoked weed.
Bureaucracy builds walls out of process to remove individual agency. But politicians design programs to meet different goals, and social services law was no different.
Why is this humiliating?
Netherland recently had the long-running scandal of the "toeslagenaffaire", where the tax service had a tendency to assume people from foreign ethnicity or double nationality might be committing fraud, and gave them additional checks and hoops to jump through, leading to a lot of people to be treated as criminals and have to pay back money that they did have every right to. Was incredibly poorly handled, government fell over the scandal, but the new government consists of exactly the same parties, with the same PM, and I have no faith at all that this won't happen again.
A-fricking-men.
Is their a variant of this that I could use on product managers who make knee jerk demands for feature/changes based on bizarro interactions with high profile customers?
For me, a certain aspect of the pathological process here is one that ties to correct the pathalogical symptom. I don’t think any process that plays whack-a-mole at symptoms will ever have much success.
The quote that springs to mind is Henry David Thoreau
“There are a thousand hacking at the branches of evil to one who is striking at the root.”
So I’m ok with the assertion that well founded process can/should guide behavior, but if we just throw exceptional process corrections at exceptional behavior as mentioned in the article, we get gridlock and the classic story of “why we can’t have nice things.”
That's not how I had been thinking about it but rings true for me. I have approached it more from "the mitigation should be proportional to the potential harm" angle. But I like your model, it gives a little more guidance on what sort of changes will be successful.
Anyway yes I believe we are aligned.
The idea of turning the tables and being counter-pathological hadn't occurred to me... until now. :D
The Leetcode interview is surely one of these? Designed to catch out that guy who can't reverse a linked list, the kind of thing that pretty much never comes up as a real job requirement?
If you want your process to be effective, you need to account for this e.g. the famous 'stop the production line button' that people can't be blamed for pressing.
The best defense against this sort of fraud is clearly to have a human, humanised work environment where people are seen and appreciated, where candidates are interviewed by their team mates, etc.
I've been in an interview process where we played a game with my future team mates: everybody tells 2 truths and 1 lie about themselves, and the others have to guess which is which. It's fun, you get to know each other, it's memorable, and any fraudster like this will be immediately spotted on their first day.
I believe the "Ask for ID" is a strawman that wouldn't be helpful, but there are likely non-invasive steps we can take if we spend more time thinking about it. If nothing else, it may result in a less hostile experience for all involved.
As an employee, it is far more important for me to avoid blame than to be efficient as I will get no credit for marginal improvements/no hit for marginal harms, but will get blamed if there is a very noticeable bad incident.
I am far more likely to have an annoyed boss from the wrong person showing up to work than driving away 100 candidates as the interview seemed hostile.
Every time there’s a fire, they want to build a new fire engine.
So I asked my cousin how he handled it, and he said he hired the one guy, and the cheque would be made out to the first guy, income taxes filed in his name, and he could square up with his relatives, or not.
In fact, as a freelance contractor, I have the legal right to send a replacement software developer if I'm not available. Of course I won't, because I know very well that in software development this is never going to work, but technically I'm a company with a contract to send someone to do the job, which means my responsibility is to send someone capable of doing it, not to do it myself. In practice of course it's always me, but contracts often specify explicitly that I could send a replacement, in order to make very clear to the tax service that I'm not an employee but a contractor.
So in practice, policies are in place such that firing people is actually somewhat difficult or lengthy, even though yeah, legally Google could fire almost anyone instantly. So if they hire someone who sucks, getting rid of them would be somewhat challenging just because of those self-imposed policies.
I really, really wish this writer had been the guy in charge of the TSA back when the “shoe bomber” incident had gone down.
Part of why the answer for hiring fakes is 'do nothing' is because the downside there just isn't that bad, it's several orders of magnitude less destructive than "plane with dozens of people on board explodes".
Is it because someone tried in an airplane once? Tried and failed? Would you change your mind about Starbucks if someone tried and succeeded?
The whole point of that article is that you can’t design around extreme edge cases. If we used shoe bomb security theater logic around all aspects of flying, there would be no airline industry.
Likewise the "no liquids" thing because of a risk of "binary explosives".
Now weight the potential impact of the downside by the cost to society/taxpayers.
The answer, of course, was: "the same way you stop them reading a pron magazine at their desk".
But because it was all new, and there was technology involved, there were lots of people who felt there should be some technological answer to this.
So, yeah, I agree with the article: Adding process to solve a management problem from a pathological minority case is never the right answer.
How would you solve this situation if the interview process wasn't remote? Being remote changes almost nothing about the situation, after all.
> We could ask candidates on video (or in person) to see a photo ID and match the ID against the resume. But this would seem very weird. It starts an interview off in a hostile manner, and send the a strong message of distrust. Honest candidates – which are, remember, the vast majority – will wonder why the heck this company is acting so weird, and will rightly see this as a red flag about the company culture. There will be negative consequences for your hiring practices.
This sort of verification is already being used for some KYC processes by financial institutions (i.e., take a live video of yourself holding your ID that’s uploaded for verification). It’s probably a matter of time until this is so normalized with virtual KYC that people wouldn’t care much when asked to do the same by a potential employer. The process already excludes certain people (like the transphobic process mentioned in the article).
There is always a cost to the company for an incorrect hire, regardless of the underlying reason. So I would expect company HR teams to read that (widely shared) post and formulate strict identity checking and recording mechanisms so that they can absolve themselves from what may seem like an oversight or error. It also fits well with the typical HR style that’s more about controlling employees than about enabling/helping them (apologies to any good HR folks who are out there who struggle against the weight of the systems).
Though as it becomes more common, it's probably also a matter of time before software is available that lets someone hold up a green card and it's replaced with the document of their choice on the video feed.
Seems like it'd be better if chip card readers became ubiquitous on home computers and mobile devices, then we can scan our drivers license or other government ID to prove that we have possession of the physical card (and when making online purchases we can scan a credit card instead of typing in a number that can be stolen).
They don’t. But some days they are complete arseholes and you do begin to wonder.
Person A shows up for interviews, is offered job.
Person A shows up, signs contract.
Person B shows up, claims they're hired?
Person B didn't sign anything, person A is guilty of fraud, so I don't think there's anything to design around here, "you didn't sign the contract, you don't work here, good day."
Person B hires person A to the interview for him
Person A shows up for interviews, claiming to be Person B, including B's postal address.
Business sends contract to Person B.
Person B signs, returns contract.
- You provide a service in this domain and are aware from the news that this is getting more common
- You provide a service in this domain and your customers tell you this is annoying them, and the story has amplified that issue, making things uncomfortable for you
- You perceive that you can provide specific value in this kind of situation, as someone who can change the dynamics of the issue with an intervention- or diagnostic-type product or service
- You see this news as a way to highlight the additional value of your offering, for example your industry group or union provides additional leverage by vetting or screening
Just some thoughts & questions as to interest, scope, and leverage outside that particular office.
Abstraction allows one to theorize and stay big-picture more effectively, so if a different but still relevant individual or position comes into play later, the rules aren't instantly outdated.
I wouldn't limit a message or rule to a position like "recruiter" if I wasn't sure that's exactly who I wanted to speak to, because that just leaks leverage all over the place.
And also, I'm thinking of many different positions, possibly hundreds, not just the poor recruiter... They do get a lot of flak :D
If you have a question about new information, and if it's out of legit interest, it's better to stay away from "just" unless you are firmly on the side of life being mansplainably simple in any given case.
At this point it's too weird to go into the rest though, as if to convince you that I have great ideas. I'm not exactly some kind of employment wizard and I'm not writing for an audience. "Leaking leverage" ought to be metaphorically simple enough to puzzle out with some interest in the problem...
You don't seem to be writing to be understood, which is of course your right, but I feel foolish for trying to understand now.
Okay, that's quite a projection. I think it's better to admit that this is your assumption, maybe even informationally based on someone saying they aren't writing for an audience. This layer of interpretation carrying some emotive personal confirmation is getting in your own way. You feel pain, emotional suffering, look I'm doing my best but this whole topic was derailed by trying to take the original comment off into a single, assumptive concrete example way too fast.
IMO you are also writing for yourself here whether you know it or not. Read it over. Better to embrace that aspect. It may be a new and frustrating type of discussion for you, I get that. If you stay with the abstractions, build up from there without assumptions, I don't think this would be an issue.
There were a number of incidents in which attackers gained access to office towers with deadly effect. One that comes to mind is the 101 California shooting in San Francisco in 1993.
https://www.sfgate.com/news/article/10-YEARS-AFTER-101-Calif...
At any rate, the article is right, this probably causes problems for some candidates (especially, but not exclusively, trans people). But if it's common practice in NYC it's likely most local candidates are used to navigating it. That's less likely elsewhere.
I am not so sure that it is rare enough that you don’t need to think about it.
We do know that it also happened with the SAT and ACT college admission tests
https://www.nytimes.com/2019/04/12/us/college-admissions-sca...
Where parents hired a person to take tests on behalf of their children.
Now that word is out about this technique, if you don’t do anything to try to prevent it, it will happen more.
The author is arguing that prevention in the interview process would do more harm than good, particularly because there are already processes in place to deal with this issue.
I think the SAT/ACT example is different. With a new hire in a technical field, it would just be so obvious if someone interviewed with a fake.
That being said, Facebook was (as expected) particularly creepy since you need to use your real FB account for a lot of their tooling. Just by entering their (busy) lobby and without ever telling anyone who I was, they already knew my name and what I was doing.
What if this was based on telephone interview?
What if remote, and one would be none the wiser?
As long as results happen, things move forward, are we not all happy?
What if the remote role was ostensibly being done by one person, but in fact they delegated to a team of people? A team of people that themselves come and go but all get managed into the same bodyshop? Does that matter as long as the work's getting done? What if, to mitigate potential loss of IP, a third-party information security policy needed to be agreed? Is it then turtles all the way down?
Honesty and integrity do matter. Trust matters.
Processes are modeled as having "normal" and "special" causes of variance. In managing processes, there are risks involved in overmanagement of either, though the Wikipedia article linked below doesn't seem to mention these.
For special causes, building too many special-case checks can create an ossified process. For normal causes, a problem may arise that in attempting to manage what is essentially normal random variation, additional variance is added to the system, or management processes themselves inject further variation or failure modes.
For an example I only just ran across, the Fermi 1 nuclear reactor meltdown incident near Detroit in 1966, and event which gave rise to a book We Almost Lost Detroit, and a Gil Scott-Heron song of the same title. The cause of the meltdown was determined to be "zirconium metal plate that was installed in the reactor as a safety measure", according to a Detroit Free Press article on the incident. Not the first or last time safety equipment has contributed to an accident --- think of the 737 Max and its MCAS system failures, or the thermal insulation cladding of the Grenfall Tower which precipitated a disasterous fire.
I may be mis-recalling or mis-understanding Demming's points on process control, and if anyone could help nudge this the right way I'd appreciate it. I'm pretty certain there is a connection however.
https://en.wikipedia.org/wiki/Statistical_process_control
https://en.wikipedia.org/wiki/Enrico_Fermi_Nuclear_Generatin...
https://www.freep.com/story/news/local/michigan/2016/10/09/d...
You just cancel the contract and be done with it. The fraudster is probably not going to sue, because it would just put them at risk of being found out.
If the fraudster does sue, it could turn into a lengthy process, but with multiple witnesses who can confirm there was someone else on the interview I doubt it would go very far.
Hiring someone is pretty much a choice the section heads can make. Firing someone, pretty much no matter why, is a choice the top level boss, 4 layers up, has to make, and they(government) are required to inform the unions a month in advance.
"For example, anyone who goes by a name that doesn’t match their government ID could be forced into an uncomfortable explanation"
I've seen this happen more than a few times, and the explanations are seldom anything you'd have sympathy for when discovered during a background check. People with good reasons will tell you up front.
Seems a simple enough solution, it’s expected and it’s something the company needs in order to pay me. It’s not a start of interview hostile question, it’s usually something we sort out in the formalities, along with what equipment I’ll need or be using, sorting out ID photos.
It's also a hot-button political issue in any number of directions (i.e. requiring photo IDs to vote, or allowing trans folks to change their name/gender on government-issued IDs).
I know there's a segment of society in the US that associates robust IDs with government overreach and dictatorship, but I see it as fallacious. Yes, communist dictatorships did have a "papers please" system, and you can still easily encounter an ID check in Russia for instance. As somebody who lives in a free and well-functioning country though, I consider a robust ID system to be both a boost to my freedoms and a great convenience.
It's essentially an authentication and signing system. It allows me to positively authenticate myself in any interaction with the government, and thus protects me from impersonation by others. It allows me to sign documents in a way that establishes a chain of trust between the document and my ID, which protects me from fraud. And since interactions with the government are relatively rare, the best part of the system is that it acts as a trust authority between me and third parties. If I want to enter into a contract with some other private entity, the government ID system provides us both with authentication mechanisms that we trust.
And with sensitive or valuable data, a week is a long time to let an unqualified or unidentified person have access to your system.
You only know the process worked when the person was caught. How do you know this isn't more rampant?
Like, certainly there's a gut level "but that's wrong!" reaction but is there actual, meaningful, unique harm caused that is not addressed the same way as all new-hire harm is: via a probationary period.
It is not amazon that will lose the object, but someone else in your team. As such the probability of it ever happening might be 1%
Once you're storing a few million objects at standard durability it's par for the course.
All principles have operating zones, from Bernoulli's to Godwin's.
Hook, line, and sinker.
Case in point: The Constitution of the United States of America.
Not a very popular viewpoint nowadays...