I patched my Slack client to keep “oops” messages others delete
github.com
github.com
If this is an entirely corporate offering, with supporting EULA - you could accept it as simple monitoring requirements. But without that clear separation of corporate, and potential end user devices, this feels more to me perverse - like spying - than anything.
You are removing the right for someone to make a mistake.
That being said; the idea of a system to which a conversation is mutually engaged (“contract”), but to which a single party can immediately and entirely redact their contributions is flawed at best.
Feels like some kind of in-between is required - hopefully with clear end user understanding.
Being able to see the original message someone shot off in anger and then revised into something nice is really handy as a manager. Especially if the entire team is remote and you can't tell things by body language.
You aren't stopping them from making a mistake, and you aren't even stopping them from removing evidence from their PoV. You're merely retaining all communication on your side.
I understand OP's sentiment, and even share it to a degree.
It's 50% FOMO, and 50% a certain arrogance of "It made it to my client desktop, the bits are HERE, therefore they're mine now. How DARE you reach out remotely and remove them." Feels like a violation.
But these feelings are silly, and life is too short to worry about such things. There are better things to optimize for and spend time on.
This is a cool tech demo, but anyone who's thinking of using it PRACTICALLY should consider why they also don't root through their building's trash for nuggets others threw out.
We were both into computers so he acted like it was a funny/novel piece of tech but he used it in daily life. Felt like stalkerware. You don't stalk your friends, and you don't violate their consent in the same way that friends dont use a patched snapchat client that disables screenshot notifs/keeps photos. Thats creeper shit!!!
This is documented in this old FAQ https://github.com/Kjir/amsn/blob/master/amsn/FAQ
(Former aMSN developer)
I admit now this is creepy.
Early ICQ didn't even store the contact list on the server so you had different contacts on every PC.
i checked out that "open chat window once someone starts typing" once out of novelty value... but it felt to stalky to keep it active, and wasnt really handy at all. sometimes ppl misclick and open the wrong window and realize later, others are reading past discussions... really not that useful as a feature
(I will admit to an illicit thrill when I click no on the outlook pop-up that informs me someone wants to recall their message...)
A bit mean to systematically retain.
But if my password, or any other credentials, were leaked because someone in a trusted environment was scraping deleted messages, then storing it unsecurely, i wouldn't be impressed.
Worst ever is one of those apps where you do /funny cat and a meme pops up.
Did one once. And this crazy offensive thing popped up. Like sort that can get you fired. Learned that there was no way to delete it.
I hate when that happens.
It astounds me that people use notification sounds for messenger and e-mail clients. How do you get anything done when being repeatedly distracted all day?
You're confusing productivity with reachability.
I currently have my Slack set to be pretty sensitive to topics that concern me, but that's voluntary. In a previous workplace, Slack was noisy af and I felt pressured to keep it at maximum sensitivity. Of course that just made me more anxious.
I think as a developer it would be very different.
I even find them sometimes helpful, they provide short breaks.
If I want to focus hard on something I can just ignore them to check later
First time on medication was surreal oh how I just worked on one thing at a time.
When building a chat system with notifications, it's also important that you can recall notifications. Wouldn't want someone's accidentally pasted password to be retained in notifications.
I did end up catching him- the app he was working on enabled geolocation and he went from Chatanooga, Tennessee to Romania in an hour. I'm surprised he accepted geolocation! I also later confirmed IP addresses via Firebase deployments in the same region.
EDIT: since a lot of people are commenting saying that this is fine by IRS laws of subcontracting etc I should clarify:
1. This wasn't a legal matter, but a business matter. I needed to federate access to sensitive infrastructure for this project, and this person failed to disclose (or denied) any additional involvement.
2. The work was not up to spec which is why there was a problem.
3. The reason for using a 1099 as opposed to a w2 in this case had nothing to do with trying to flout benefit obligations. I don't think saying you need to know who's touching your codebase and hiring someone on a contract basis is trying to have your cake and eat it too. This type of contract is much more expensive for us than a full-time employee.
independent contractors are free to sub out work. this is the law. they also probably should not be on your slack unless you're considering the whole thing a consulting arrangement.
i understand where you're coming from, especially in trying to make use of upwork in some actually useful way for your business. but you should also be aware of the law.
https://www.irs.gov/businesses/small-businesses-self-employe...
I’ve never seen a contracting agreement that didn’t specifically prohibit subcontracting without the explicit written consent of the client. It’s not that it wouldn’t be federally legal, it’s that it would violate the specific contract with the client.
Here in the UK, for example, if you wrote such a contract, it would be enforceable… but you would be considered (by the tax authority) to be trying to evade employment taxes, and hit with something starting in the range of a low 5-figure financial consequence (assuming the contract was a few months at current average rate for tech workers).
All of my contracts explicitly allow subcontracting in order to comply with tax law.
I realize this thread is full of armchair lawyers, but that is definitely not the case in the US.
Most importantly, there are plenty of valid business reasons to prevent subcontracting that don't have to do with "locus of control" issues that would warrant someone being a full-time employee.
There's also an issue of 'what you bought' - this isn't necessarily a contractual thing. I work for a consultancy, if we sell you a project based on the skills and knowledge of a few of our experts and then when the project starts we actually staff the project with a few grads, you'd be annoyed right? Very carefully our contracts don't name individuals to allow us flexibility (e.g. someone gets ill, goes on leave etc.) so we're fine legally but you'd be understandably upset and might want to end the contract. [this by the way, is exactly what Accenture does quite a lot]
3. RESPONSIBILITY FOR EMPLOYEES AND SUBCONTRACTORS, INCLUDING AGENCY MEMBERS If a User subcontracts with or employs third parties to perform Freelancer Services on behalf of the User for any Engagement, the User represents and warrants that it does so as a legally recognized entity or person and in compliance with all applicable laws and regulations. Further, at all times a User that agreed to perform services under a Services Contract remains responsible for the quality of the services and represents and warrants that User has entered into agreements with any such employees and subcontractors on confidentiality and intellectual property at least as strong as those in these Optional Service Terms.
it's a business to business agreement. a contractor is free to sub.
https://www.upwork.com/legal#optional-service-contract-terms
They can also include clauses that the company's code and other materials won't be shared with 3rd parties, aka an NDA. These are standard and well-accepted practice.
The contract will also be very clear that access to the systems is only granted to the person signing the contract. They don't get to grant access to other people just because they have contractor status.
Practically speaking, there is no way a software contractor can sub out work without violating a litany of contractual obligations in the contracting agreement. Even minimalistic contracting boilerplate agreements will have clauses that cover these situations.
For example, if you sign an NDA with a company covering the work and then turn around and send the codebase to a contractor in Romania to work on it, you've very clearly violated the terms of the NDA.
So no, the law doesn't automatically allow engineering contractors to do whatever they want with the work.
I find that unlikely. What if you were instead handing it to an employee?
(Also, different NDAs are... different, it's pretty tough to talk about them all in general and expect a statement to be true.)
> So no, the law doesn't automatically allow engineering contractors to do whatever they want with the work.
Yes, it does. Just because you might have terms in a contract prohibiting it doesn't mean the law prohibits it.
> (Also, different NDAs are... different, it's pretty tough to talk about them all in general and expect a statement to be true.)
If you sign a contract that says you're not going to share the company's code and then you share the company's code, you've violated the NDA. It's as simple as that.
Being a contractor doesn't grant someone magical immunity to the contracts they've signed. At most, the employee could argue that the contract made them a full-time employee and sue for benefits and such. They can't, however, simply ignore contractual obligations that they've agreed to.
If it were me, I would not renew a contract with someone who sub-contracted work out to someone I don't know and didn't approve without informing me. Whether it is or not, it certainly seems shady, and I don't want to work with people who have violated my trust.
When I was a contractor, our clients usually had a number of clauses in the contract that would have allowed them to end the engagement early for pulling something like that.
And, of course, in the end they could always just have said "go to hell, we're not working with you anymore," and it would come down to who wants to go to court the least.
At minimum, any NDA would have been violated by sharing the company's code and/or access with a third party.
Being a contractor doesn't give someone carte blanche authority to pull random people into confidential work. Any reasonable contracting agreement will make it clear that the materials are not to be shared with anyone outside of the contract.
The law, nor the linked resource, stipulates that any 1099 relationship can be subcontracted out by anyone, let alone without disclosure. If that were the case the explicit option to hire onshore vs offshore on sites like Upwork would be meaningless, or a matter of arbitrage.
The problem is that you can't just have what are effectively employees but on a contract basis under law. It opens you up to liabilities, as Uber has been experiencing.
The closest I think you could get is actually contracting a PEO that takes the individual under employee status and assigns them specifically to your company under contract. Being an employee of the PEO means that they can in fact control these aspects of the job, and you aren't contracting them, you are contracting the PEO who subs out to them.
This isn't actually even the root issue.
The contractor almost certainly violated their contract by sharing NDA-covered materials with an unauthorized third party.
The contractor also shared access credentials to the company's systems with someone else and then facilitated fraudulent interactions wherein one person claimed to be someone else.
Being a contractor doesn't give someone carte blanche authority to do whatever they want with the company's materials (codebase, design documents) and secured systems.
I don't see why software projects can't be the same.
> I don't see why software projects can't be the same.
Contractors can't automatically give subcontractors access to the plans, the construction site, and so on. The contracting agreement will have provisions about who can access the site, how they get approved, on what terms, and so on. Becoming a construction contractor doesn't give someone carte blanche to invite other people to a site without regard to the terms of the contract.
Likewise, a software contractor can't just decide to share your codebase and design documents with a subcontractor because it almost certainly violates many of the contractual clauses they agreed to.
I would definitely expect all of that to be handled by the primary contractor (i.e. the person who specializes in construction sites). No?
Being a contractor doesn't automatically grant someone the right to delegate access to sites and such.
I think a lot of people in this thread have misunderstand what the law is actually saying. The law doesn't say that if you're given contractor status you can do whatever you want. The law says that if the job is misclassified as a contracting position when it should be a full-time position, then the employee is owed benefits and such.
If you sign a contract with a company that says you will not share the code, design docs, system access credentials, physical building access, or other common stipulations, you can't automatically ignore those because you're a contractor.
If the work is good, I'd be fine with the above arrangement so long as I wasn't working in an industry that required regulation (PCI compliance, etc.)
Fraud would require a contract saying X is doing the work, which is controlling what will be done and how it will be done which means they would be classified as an employee.
Like, not giving out your password (or badge, or key, or whatever) to someone else is a pretty core job responsibility!
Employers should also not frown upon those that have this type of behavior unless they specifically call this out in a contract or the employee handbook.
Note that I've never attempted to outsource my work since I like writing code and I get paid an awesome enough salary as it is, but I don't blame those that do unless they are breaking the rules.
I actually got laid off from a job because the lead programmer on my team was doing this. He had 3 folks working in India full time. He told me about it prior to the layoffs over beers. 3 folks on my team were let go. Note that we all found jobs within a month. The last time I spoke with him, he was still doing it. The only time he does any work is when the company has meetings he is asked to attend.
1. Legal/compliance/tax problems
2. If Upwork were to allow this, it effectively allows bad actors to reset their reputation whenever they want
3. If you're willing to lie about this, do I really want you working for me?
4. Just because you approve of them and think they're safe doesn't mean I do, and you're sending my confidential company secrets and source code to them
None of these are problems if you're upfront about it, but lying and claiming you're doing the work when you're actually outsourcing it is very bad.
In other words, is it the misrepresentation that's the problem, is it your need to scrutinize the subcontractors, or is it simply that the prime contractor isn't personally toiling sufficiently for you?
Personally, I don't see what the big deal is. A client is paying some agreed amount of money for some agreed results in some agreed time period. What difference does it make if the contractor personally types in the code or if he finds 5 Indian guys to do it?
I put in some hours in the world of defense/government contracting, where in many cases, the prime contractor never does any work at all. His only job is to "be the prime contractor" but he subcontracts everything, and I mean everything out to others as soon as the ink is dried.
Yes, the misrepresentation is the key part. For example, if I grant you access to a server that doesn't mean that I want a bunch of randos I never meant having access to the same server as you — if nothing else, you'd want them to have had whatever you consider necessary security training and you'd want your ops people to know that a connection from Romania isn't an immediate sign that you've been hacked.
This is especially true when you're crossing country boundaries and things like IP law or similar concerns vary widely. Most contracting agreements cover things like handling corporate IP carefully and I'd expect at least a request to confirm that this is okay.
Now, there are cases where it might be more forgivable: for example, if I'm hiring you to work on a project which involves an open source component and you turn around and hire one of the developers on that project to add a feature we need, that seems entirely reasonable because it's a) not my IP and b) totally above board that J. Random Maintainer made those commits and shipped v1.2.3 which you're using. Similarly, if you found an artist to contribute assets but didn't give them access to my server or a copy of our code, that seems fine, too. None of that seems anything like the situation described, however.
> I put in some hours in the world of defense/government contracting, where in many cases, the prime contractor never does any work at all. His only job is to "be the prime contractor" but he subcontracts everything, and I mean everything out to others as soon as the ink is dried.
Yes but speaking from experience on the .gov side they do that with the full knowledge of the agency and a contractor will be terminated and banned from future work if they violate security policies such as having unauthorized people access a government system or sharing source code without authorization.
There seem to be quite a few comments specifically calling out the misrepresentation as the main problem. I guess we could speculate that the motivation is actually that they want the prime contractor to toil for them, but I dunno. Caring who exactly is toiling seems kind of weird and controlling, we should be generous to the community and not ascribe weird motivation to them if they've got some other perfectly reasonable reason to care.
> Personal performance of services: An independent contractor should have the freedom to hire assistants or subcontract work to other workers or firms at his or her expense (this is where profit or loss could enter the picture). If you require the worker to perform the work personally, that's a sign of control and therefore indicative of employee status.
Someone would be an employee rather than a contractor if they couldn't subcontract AND they had set hours AND they had to use your tools AND you set the work on a day to day basis. Many of those things need to be true, not just one to push someone from contractor to employee.
Or consider the ABC test:
A. The worker is free from the employer's control or direction in performing the work.
B. The work takes place outside the usual course of the business of the company and off the site of the business.
C. Customarily, the worker is engaged in an independent trade, occupation, profession, or business.
In this case, again, depending on the contract signed, A would cover subcontracting unless it was explicitly prohibited by the contract. And maybe it was. But I have signed plenty of contracts with my personal name not my fictitious or LLC name that would not have been violated by having someone else perform the work.
This whole thread got super litigious around my comment that there is a defendable reality where people subcontract what you contracted them to do. It all depends on the contract wording.
Good counter example to me defending be able to subcontract would be performance agreements (e.g. I pay Foo Fighters $1m for a concert they can't send Weird Al in their place).
Yes, but the contractor must still respect the other contractual obligations.
For example, they almost certainly signed a contract that they wouldn't share the codebase (NDA) or share access to the company's systems. The contractor would have clearly violated this by giving the code to someone else to work on and giving that person access to the company's Slack under someone else's name.
If he would have subcontracted an isolated task involving no trade secrets, no confidential information, and no access to the company's systems he would have been fine.
But you can't just hire someone in Romania and have them pretend to be you and log in with your credentials and have access to the company's proprietary materials. Being a contractor isn't an automatic license to ignore all of the things you've agreed to.
> Depends on the contract.
And you immediately jump to conclusions:
> they almost certainly signed a contract that they wouldn't share the codebase
We don't know what they signed.
Hired an “American” contractor named Jeff. Had a video meeting with him, everything started off great.
Then when we got him into slack, his English went way down hill.
I tried to get a phone number for him and he resisted and gave excuses why he couldn’t talk right now.
So… because I suspect this is getting to be very common… Get a phone number for your contractor and call them periodically. Insist to speak with them on the phone about something they have done recently.
Even if the work would have been good, I won’t pay a liar like that.
Combining this with my bot that makes me “is typing…” any time anyone begins typing at me will surely make my Slack experience even more passive aggressive.
A few minutes later I got an email from the producer, but obviously intended to be read by one of his colleagues, who I had CCd on my email. It said something to the effect of "you know, they kind of have a point, blah blah"
This was almost immediately followed by a plain-text email that said "recall" IIRC. I assumed this is how Outlook implements recalling an email internally, except that I was using some Linux email client that was blissfully unaware of this. I chuckled. Just seconds later yet another email begging me not to read the original email as it had been sent by mistake, apologies, etc.
I guess the moral of the story, if there is one, is that you can't really un-deliver a message once it has been delivered. Think twice before you send!
Somewhat relatedly, the Tweetdeck client for Twitter appears to be write-only, because I'll routinely see two or three instances of the same tweet where the author deleted to fix a typo, and other more embarrassing tweets, including at least one that was obviously meant to be a DM.
On the other hand, maybe it's best they can't be deleted, since that will force people to rotate them.
Also, honestly, if you are manually typing passwords and copy/pasting private keys, you can’t expect any security anyway.
Not everything is meant to be permanently recorded.
https://support.signal.org/hc/en-us/articles/360007320491-De...
I think it's assumed that your recipient is not malicious. I swear at some point there was a warning saying that if you enable disappearing messages it wouldn't prevent your recipient (or you) from simply taking a screenshot of the messages.
There will always be outliers. Life isn’t a binary system.
I thought this was a novelty, but now it sounds like a lot of people are really waiting on a gotcha moment. Are you all in such bad circumstances that you actually want this?
I'm generally of the opinion people are free to say (almost) whatever they like to me, and deal with the consequences. Virtually though, I guess it's a little different. People type things they wouldn't say face to face, so maybe being able to delete them before they're read is the fix for that.
What? History should always be immutable; let's keep it that way.
If someone sends you a nasty message which they immediately delete: then isn't the world a better place?
No, I think it's better to just apologise for your past actions.
It's a somewhat philosophical and moral question...
Agreed.
I feel like you're agreeing with my point. Capturing a deleted message that you would never have seen is effectively changing history.
No, if it's sent then it's sent.
Then comes along computers and all that is out the window!
I wonder if it's a difference in culture/expectations. For me, once a message is sent, I expect it to be immutable, much like basically all forms of communication have been in the past. Email, IRC, etc. all work like that. If I intend to amend or otherwise change it, I'll simply send another one or use "correction asterisks". To do otherwise feels like a taboo, almost like trying to rewrite history.
Edit: seriously, immediate downvotes? What nerve did I strike this time...?
And yet, you edited your comment. How irritating :)
...with an appendix, without changing what I had previously written.
But I suppose that's another difference; it seems that editing is far more acceptable on forums and the like, unlike IM.
We were already not in good terms, and it was a small company so there was little to be done. But having seen the message and knowing the intention, and not being able to prove it felt horrible.
I since left (after discussing with the boss).
My workplace administrators have disabled deleting messages on Slack perhaps with the intent of preventing this sort of thing. Usually if someone sends an "oops" message they'll edit it to ".".
Great example, justified too. The message was read and had impact. Retracting it removes accountability and proof. Not something you want in a professional setting.
One can achieve the same with Snapchat.
In the end you can hexedit something like this as there is a statement involved "if message received is remove_message_id and is_owner_of_message are true or remove_message_id and is_admin are true its deleted. With something like Java (Android) decompiling yields pretty much something akin to the source. And everything has a native Android 'app' these days.
OTOH perhaps a good thing laymen cannot achieve this. We don't know the exact impact of the pros and cons of the feature.
Would be better if it showed me that the person tried to delete the message.
According to the readme, it does (via a notification)
“On paid plans, workspace owners can customize their retention policies. They can choose to set a custom time frame to keep messages and files, and they can also choose to retain all versions of an edited or deleted message.”
Whether or not the company toggles the setting is another matter of course.
The other one that gives me a chuckle is read receipts and typing notifications. Chat apps put them in (I can't stand them so I turn them off, I don't want to see them or send them) and then they make both the setting to receive them and to send them tied together, like some sort of mommy telling you how to properly behave. "If you don't want to send them then you shouldn't be able to see them, its only fair." But it is handled in the client, a lot of the time a FOSS client, which can be patched. It's kind of ridiculous.
Because I can't tell you how many times I've pasted a pretty critical, strong password into a chat window in hit send - accidentally.
Let's say someone sent me a message, immediately regretted it and tried to delete it. They will think the message got deleted on both ends ("delete for everyone"), but using this patch my client will keep the message anyway and notify me that someone tried to delete it
The backstory is kind of funny - not so long ago my friend had a rant about his former boss. He told me a story of how his former boss accidently sent him a nasty message and then immediately deleted it. My friend wanted to confront him but had no proof because the message was gone too quickly..
You should send it over Slack -- just make sure HR knows they also fall under your contract, at least that way they'll be laughing when they call you in for a chat.
Maybe they never saw an official Facebook blog post with 100,000 comments all copy-pasting the same text about not consenting to their data being used. Or maybe they've seen too many, posted in earnest.
https://www.reddit.com/r/copypasta/comments/87mi5v/i_dont_gi...
*Reading of this comment requires the READING PARTY, to agree to the terms and conditions of the comment. If you do not agree to these terms, you must delete the comment from your memory.
Terms: You are the READING PARTY
Conditions: The READING PARTY will agree with the comment.
Bulletproof legal argument.