Once my team owned a service that did X. Among it's functionality, it had an API that, as a side effect, stored some data that could be retrieved. Sadly, this service had no validation that the data being input made any sense in the context of what this service did.
A developer on a neighboring team had a big promo project on the go. As a simple hack, and as a way to save time, his project used our service as a basic key value store database. They already called this service for the correct functionality, so they had access keys. The stuff he was storing could be argued to kind of make sense, but as the owners of this service we said "no fucking way, we aren't your database". He escalated to management who knew he was going to quit if he didn't get his promo. They overruled and last I heard that service was still being used as that asshole's database. He did promise to fix it right after the project launched, but the second he had his promo he changed orgs.
For some reason, Amazon is full of this sort of terrible tech debt and they can't figure out why everyone has to be on terrible on call rotations.
There are a lot of excellent ex-FAANG programmers I've worked with, and a lot of terrible ones, and my experience is that usually the ones with the most prestigious titles show up, do 3 months of junior level work which we end up having to rip out later, and then leave to their next high-paying gig.
i just don't understand this at all - why would someone who is working for you be a threat? They cannot take your job - it's not like them being a good programmer would somehow make them a good dev manager or "boss".
But the upside is that it’s a competitive advantage for startups that intentionally build different hiring pipelines.
I would say it is more of a fault of compensation structures.
Why would one stay for 3 years and get very meh comp increases every year, when they can switch to another company and instantly get a 30-40%+ increase (up to a point). It is also somewhat disheartening to see new hires get paid significantly more than you are for the same level.
And arguably this principle holds for most team members in any organization - since it’s only very few at the very top that actually get held accountable for overall team success.
When this terrible thing was done, we immediately realized we needed to add validation. We had thought that by limiting who could call through access controls, we'd never have a malicious user. So naive.
Sadly, at that point we couldn't add it because his awful project was running in production.
It's weird to have to say this, and some people probably think it's naive, but I stand by it.
No one suggests I am at fault if you break into my house and steal my stuff.
At least at Microsoft, there's a culture of where your title determines if you're a part of the "in group" or not. Not at least Senior? Forget about anyone outside your immediate working group taking you seriously, let alone deferring to your judgement on things. Not at least Principal? Put your ambitions aside, because you won't be allowed to make decisions that are actually important. There's exceptions to this, like if you're in charge of something nobody else thinks they understand.
As a result, this means that there's a lot of squabbling and weirdness around September. Especially in the Senior -> Principal jump, since that is also influenced a lot by department budget. There's also not any official acknowledgement of a good terminal level. Implicitly, that's the Senior band (and really the 2nd level within the band), because beyond that you're usually expected to do more than just be a wildly productive individual contributor. But everyone who's Senior eventually feels the pressure to somehow level up to Principal, because they have the expertise to make important decisions but their organization often won't allow them to be in the room where those decisions are made. Thus the backstabbing, jealousy, weirdness, and more.
It’s gotten better but there’s still limitations, and many people solve it by switching organizations- which has more costs than many realize.
Rewarding people is hard. But you can't shirk from it unless you want people to leave.
Thankfully, at a large company with plenty of hard problems to solve (and smart folks to work with), you can grow quite a lot whether or not the company chooses to recognize said growth.
Your hiring process should be good enough that firing is rare but nobody is perfect and if/when the situation arises (either due to a bad hiring decision or the situation changing) it's better to resolve it earlier rather than later.
Maybe it’s different now, but I doubt it. Any place that pays for performance has to differentiate rewards in some way.