The most unethical thing I was asked to build while working at Twitter in 2015
twitter.com
twitter.com
This is something I've been repeating to some of my younger colleagues.
Engineers aren't really fungible resources, to the extent that these projects require. Ask any manager how easy it is to swap "allocated resources", and they'll probably sigh heavily.
People are afraid that if they don't follow their manager's every request, they will be fired. But remember that hiring is hard, and managers are loath to fire someone they've already spent so much effort finding, hiring, and onboarding. Finding someone else to do it can take weeks, months, or longer! Which in many cases risks killing the project altogether.
Even if you're at the bottom of the chain, as the person who does the actual implementation, you have a lot of power on what gets prioritized.
See also the oft-circulated OSS "Simple Sabotage Field Manual" http://svn.cacert.org/CAcert/CAcert_Inc/Board/oss/oss_sabota...
You don't need to do it, you don't even have to explicitly say no, you can just always find (or create) work that's more important to do than breaking your own morals. The worse that can happen is someone else gets the hot potato.
Later on when the engineering team was actually implementing it they thought Bird Mode sounded dumb and just called it Satellite View. And so it has been ever since.
There's a reason our satellites need station-keeping fuel. https://en.wikipedia.org/wiki/Orbital_station-keeping
Beyond LEO the drag is really negligible in the sense that other factors (e.g. gravitational abnormalities, the moon) have larger effects.
... and are therefore no longer satellites. https://www.nasa.gov/audience/forstudents/5-8/features/nasa-... https://www.nasa.gov/audience/forstudents/5-8/features/nasa-...
Some Lagrange points are stable and therefore will not decay toward the Earth outside of other factors. (Because these systems are never sufficiently isolated, in the eternal view, therefore, also still require energy, though much, much less.) Though, of course, an object at a Lagrange point may still not technically be a satellite of earth. https://solarsystem.nasa.gov/faq/88/what-are-lagrange-points (though by the NASA definition above I'd argue that they are)
As a practical matter, there's a differing relationship with atmosphere. Planes depend on air to produce lift and sustain flight, but satellites are either inconvenienced by air, or entirely unaffected by it.
Atmospheric correction however is really an issue and often results in distinct patches on the "satellite" view
The result is that satellite photographs are much more frequent and have much better coverage, while aerial photographs have much higher resolution. The dishonest naming of the Google Maps feature has given people extremely unrealistic expectations of what satellites can do, which results in difficulty in selling actual satellite photography products when they don't match what people have come to expect from GMaps.
Some of the pictures were from satellites, not airplanes.
Overlook
That's textbook bike shedding, and maybe it's why they seem to struggle with actual important things, like dealing with search spam.
I'm hearing Meta, Stripe, Google, Netflix, Lyft and Uber are hiring like crazy for amazing salaries. Not only that but one basically just needs to sort of show up half the time and surf the net 99% of the time there.
That was obviously sarcasm.
That is obviously not the case
Benchmarks are meant to be reproducible, meaning perfectly predictable. CPUs have things called branch predictors which try to predict what the software is going to do and try to do the calculation ahead of time resulting in (hopefully, if it predicted right) faster execution time. If you know which 'branches' a benchmark goes down, you can make a program which can coax the branch predictor to always make the right guesses for a given benchmark.
A program branches whenever you encounter some sort of conditional if-else statement.
Print '2' is lot less operations than (insert formula here) if you know the answer is already 2.
Caveat: this applies to perms. It doesn't apply nearly as much to contractors (as my many experiences with saying "No, but..." to managers and being canned can attest.)
Anecdata. One of my colleague got fired for not meeting expectations at his level for two consecutive halves. From what I've seen, he was competent and provided value to the project. Some companies have high turnover and are functioning with the idea that everyone is replaceable.
One of my proudest moments was about seven years ago. I was two years into my career as a junior software engineer with no academic background in programming. I was by any measure an impostor and I worked very hard to learn and impress and earn the luck I was given with that job.
A PM, one who I liked and wanted to impress all the time, came to me asking for help to get git commit history for each person on our wider team “to measure how productive everyone is being.”
Despite being anxious about “what-ifs” like being blacklisted or some other concepts I knew nothing of, I gently explained why it would be a bad metric. I remember even saying, “some of the best engineering someone can do is to write negative lines of code.” I felt so wise despite being so green.
He pressed the matter and I calmly said that I said my part and I’ll play no role in this.
I asked around weeks later and apparently he approached nobody else and the issue was dropped.
Maybe this is a mundane anecdote or I’m not telling it properly but I’m still so proud that I was even capable of seeing the ethical dilemma, let alone acting correctly on it. Those years were full of “I have no clue what normal looks like in this industry.”
I feel somewhat confident in saying that experience emboldened me to do the right thing even if it was scary. Sometimes I worry that I fly too close to the sun with my attitude of “you won’t fire me.” But so far it’s worked.
Why didn't you teach him to find people who were writing negative lines of code?
You want to aim for a plane with the right weight, but you only know what that is by working out the entire design. Similarly you want to aim for the right number of lines in your code base, but you can only know what that is by working out the entire design.
Maybe engineer A has a easy feature to do. Lots of lines of code but it's smooth sailing. Another engineer, B, has a tricky bug fix to do, which requires him to read documentation, navigate the fode, reproduce the issue, until he published a fix with a handful of lines of code.
Who's the better engineer, A or B?
Even if we consider the average over time, one may be getting more tricky features than other. Or spending time in tasks such as hiring, mentoring, etc, which is worth a lot to companies.
For example, I worked a .NET project with a central form that had close to 30K lines of code. This was 10x in comparison with anything else in the app. This is clearly a "whale" of a problem.
The lines-of-code comparison made it much easier for non-technical staff to now understand why this "one form" (really dozen of different functions contained in a single form) was troublesome in terms of fixes, enhancements etc. and also why no one wanted to touch it.
Maybe it helps you understand if you think about how easy they are to game. You could just as well create useless lines of documentation as you could create useless lines of code.
Goodhart's law says:
"When a measure becomes a target, it ceases to be a good measure".
I'm not saying "LoC is a bad metric because it can be gamed". Most metrics can, if you work hard enough.
I'm saying "LoC is a bad metric because it can be gamed by a child within a couple of minutes".
It's the difference between lock made of a tin sheet and a proper heavy-duty steel lock. People like the lockpicking lawyer can still pick the latter, but the former is so weak that it should never be relied upon.
Avoiding LOC measurement for other (non-productivity) purposes is a mistake.
This should be posted absolutely everywhere with this as the hook. This type of request and the admittance that companies give even more than that all the time is headline news worthy.
Sure, if they were giving your IP to a telCo who can map your IP to a name if you're a customer - that's identifying you.
It's HIGHLY unlikely this happened at the usual suspects (FAANG).
They explicitly and unambiguously deny doing it; if that was incorrect, there would be a huge regulatory and public backlash. (Think of what happened with the Cambridge Analytica case, despite Facebook's hands being pretty clean on that). No disgruntled ex-employees blew the whistle on this but did on other issue), which suggests it probably didn't happen.
Selling ads is very profitable. Selling data directly risks that business for little gain. In addition to the backlash when that data selling were revealed, it risks somebody else using the data sold by Meta to outcompete them on ad targeting.
Companies typically don't admit to the public when they're engaged in unethical practices. Purdue Pharma is a good example.
Bingo. They're unlikely to be selling the data because those data are their secret sauce. They are as economically incentivized to build sociopathic models on you as they are to keep your data out of anyone else's hands.
There are a bunch who basically pay apps to use their api and then take the data.
Apple was right to kill that imho. IIRC that was foursquare's pivot
There is also lot/lon in programmatic bid requests, but I don't think they're super accurate or granular and lots of fraud. (could be wrong, just from my small experience buy side using DSPs seeing lots of lat/lons being smack in the middle of a city)
[1] https://www.safegraph.com/guides/mobile-location-data-provid...
[2] https://developers.google.com/authorized-buyers/rtb/geotarge...
[3] https://fixad.tech/wp-content/uploads/2019/02/3-bid-request-...
Can probably be related to email addresses too, and hence shared with every other mall with same ownership as well as the company that provides the free wifi.
e.g. Aruba, Meraki, ...
Have any journalists and/or leakers exposed exactly what these tech companies are sharing? As much as I've heard about data collection and sharing by big tech, I feel like I don't see much in the way of samples or example data. Even the forced GDPR data releases I've seen haven't been extraordinarily in-depth. Surely there must be some articles out there that I'm missing?
I think that the answer to this is "yes, multiple times, often multiple times on the same companies up and down every level of the stack".
And some of the companies brag about their abilities. There was some surveillance company which was showing how Covid spread after spring break in Florida by gleefully posting screenshots from their tool that tracks individual phone locations.
Do you have a link? It's always sort of discussed as if everyone knows exactly what's happening, but I'm specifically looking for links that break it down.
It's simple - an app asks for background location permissions, then uploads all the datapoints and timestamps the OS gives them to their servers, which is then resold with "anonymization" that just replaces any personal information with an impersonal unique identifier.
That's the reason Apple/Google have clamped down so hard on location permissions since then. But even a degraded dataset is still valuable - https://www.eff.org/deeplinks/2022/08/fog-revealed-guided-to...
* https://www.advanresearch.com/
It comes from the telcos directly (think Sprint phones with custom OS installs), it comes from popular mobile SDKs (e.g. why Yahoo bought Flurry), and it comes from apps who simply sell the data directly.
There is one journalist who actively covers this sort of PII/data-selling world: Joseph Cox at Vice [1]. The only US-based legislator who actively fights against this is Senator Wyden.
(As an aside, it seems cute that the guy thinks the change in ownership somehow makes it "safer" for him to share inside details, but I'm glad he did)
If the change in ownership means "I am never going back, time to set that bridge on fire" he's absolutely right it's "safer". Or simply if he thinks "It is now acceptable to future employers to do this", it is also safer.
Or maybe it was something that he now sees as a greater threat, and therefore is worth mentioning even if is not safer or even riskier.
But I focused on reputational risk.
https://www.cnet.com/tech/tech-industry/apple-unblocks-googl...
But Twitter had been tracking apps installed on a users iPhone until Apple restricted access to the API that they used.
https://www.cnet.com/tech/mobile/twitter-is-now-tracking-the...
The purpose of the API was for one app to send messages to another app. But it could be used to tell if an app was installed.
There is some obsession amongst a subset of techies with knowing everything, and that extends to the daily minutiae of the lives of others.
A data science company I used to work for got hired in 2017 by a large American telco to handle this exact same sort of data coming from antenna location to do better ad targeting.
The reason why Verizon or AT&T do not have the ad capabilities of Google or Meta is because they are giant incompetent corporations that are incapable of developing anything in any area that didn't exist in the 1980s.
- the location logs would be collected by a simple application, witch imply the phone/phone OS itself can do that;
- they do refuse, Legal teams do not, but nothing state they can't satisfy the request TECHNICALLY.
In other words when people tend to disagree with my consideration of smartphone as macro-spy devices bought and kept up by those who get spied as opposite of classic spying gears should think about not only that, but what they do with their (well, not really their, since they are just formal but powerless owners) phones, things like pay taxes, act on their banks accounts, pre-heat/cool their cars etc.
Because such activities have a FAR bigger impact than mere position logs.
Perhaps I am missing something, but I don't understand the intersection of why telco's are involved in serving subpoenas and the need to know the physical location of users. Are you referring to a log of networks / DHCP leases their customers were using at any given time?
Well I know that in the UK it is a legal requirement, but not sure about the US.
Telcos keep it because it helps them with network capacity planning and is incredibility financially lucrative when they want to sell the data. It's probably more to fill in their data product for malls and fine grained location than to do it for subpoenas, which if they had a choice would probably rather not have to do.
Not sure what country you are in, though that is untrue in USA. Businesses keep whatever business records they desire, and some required regulatory/personnel data. Even if they have the data a USA attorney can try to argue that the request is unduly burdensome or too broad and ask court to quash subpoena.
Also telcos only have data for their customers - this gets them access to competitors' customers.
Was not very precise. One of the "advantages" of 5G is a lot higher resolution for telcos. And I think even 4G was superior to "a few city blocks"
> telcos only have data for their customers - this gets them access to competitors' customers.
And this is the true reason for the request.
A mind-bending digital info screen, developed in partnership with Misapplied Sciences and dubbed Parallel Reality, will debut in beta form on June 29 near the Delta Sky Club in Concourse A of the McNamara Terminal.
According to a news release, numerous passengers can look at the same screen at once, and each passenger will see personalized flight information that the other people looking at the screen will not see, because they'll be looking at their own personalized flight info.
The Parallel Reality display conveys the same sort of stuff you find on traditional airport screens—about departure times, gate numbers, baggage carousel locations, and so on—but you don't have to scan lists of data because the screen semi-magically shows you only what you're looking for, while up to 100 other people are simultaneously looking at the same screen semi-magically showing them what they're looking for.
https://www.frommers.com/blogs/passportable/blog_posts/delta...
If they know that, they can target those areas and then heavily advertise that they have better service than their competitors in those areas lol.
Historically they could do that by old fashioned research and surveying. But that's expensive. I imagine getting this data from everyones' phones is a lot cheaper and easier.
If that's the case, I don't think their desire is necessarily _evil_, but very misguided lol.
Subpoenas are used to compel production of existing information. Speculatively creating info to comply with future theoretical request is not necessary. It's easier to not have the info and truthfully respond to subpoena with "no such data".
I am constantly, constantly bombarded with "this looks better in the app! please just run our app!!" as I browse. Still I refuse--with the web I at least know they can't harvest information about everything I'm doing. There are still some privacy concerns of course but it's much better to have the web as a firewall of sorts.
"This looks better in the app" because they sabotage the web experience so they can do this very thing.
We have 30 years of browser UX development, culminating in tabs and multitasking tools that allow you to open things to read later, wait while they load on a slow connection or form a queue of things to read.
Mobile apps for every social media site loose all of that. They are worse than useless. There is this internal fear at social media companies, they want to prevent their users leaving their little walled garden. That or the religious drive for managers to reach target metrics creates a net negative feedback loop for user satisfaction.
Social media apps have no multitasking features (at least last time I used them). It's absurd.
I've only used the twitter mobile website for the last three years. Will never install the app again.
(Aside: my (ridiculous) conspiracy theory is that React Native is an attempt to distract developers from the advantages of a WebView based app development process that would eventually lead to the success of PWAs, locking devs into the app stores as a distribution channel)
I remember the couple months or years where each Chrome tab was it's own app instance. I thought it was incredibly ambitious & interesting to make the OS try to deal with tabs, be a manager. And indeed Google backed it out. And so as usual, Android is in the background of daily life, hardly ever touched or used, and I just stay in Chrome almost all day letting it define every bit of my computing existence.
The web experience just has so many more hooks & so much more power, than these little self-defined bespoke inward experiences. Because so much part because browser gives us such basic & flexibility utility as we compute & surf.
Thanks for the good post, enjoyed reading very much, & two thumbs up!
Web apps have a lot of access to your data as well, especially your location data.
This is not the case in iOS, and I don't believe it's the case in android either, IIRC. You can also always audit app permissions via the settings app.
> how do I revoke it
Settings app. No idea how I'd do it in the browser, FWIW. Nor how I'd audit what permissions an app has.
> it still running in the background accessing my location at all times
Apple has a "allow location access only while running [in the foreground]" option as well. Not sure about Android.
> Furthermore, apps update silently, and are they giving themselves new permissions or not with each update?
They are absolutely not doing this. Security auditors would be screaming from the rafters if Apple or Google allowed app updates to change their permissions settings.
- use bluetooth, accelerometer data, or anything else not exposed to a browser
- spy on their user closely to generate valuable data (your app is the product, not the user)
- be discovered in the apple or google app stores. Relatively expensive, niche, high touch, business to business apps are not impulse buys for bored managing directors.
And their dev team is usually already over burdened just dealing with the web stuff.
But still they pour money into the two native apps bucket. Before they're even profitable...
I wonder how much this "IT LOOKS BETTER IN THE APP" propaganda is affecting their business sense. Twitter and Facebooks business model is a bit different from B2B SAAS SME.
Recently a coworker was struggling to change some personal details online and got stuck in a loop of no access due to multi-factor authentication. The phone helpdesk kept directing them back to the site to get stuck again. The solution? In this case the app's lack of support was a blessing. Personal details could be easily changed there because the app hadn't implemented multi-factor authentication.
Our phones are packed with sensors, and are more powerful than the computers that landed us on the moon. Apps can be so much more than dumb pipes for simple data upload and download from a server.
Not sure if this changes your calculus at all, but it can (theoretically) be used on chrome for android.
There is a lot that a website can do to profile you too.
Apps don't have access to device IDs other than IDFA, which can be reset at any time by the user.
> wake/sleep/network events, etc
Apps can't tell if the device has been woken up or put to sleep, apps only have access to their own application state events like didEnterForeground and didEnterBackground.
Apps can tell if the device's internet has been connected or disconnected, I didn't know that was not possible on websites.
The webbrowser limits their ability to spy on you dramatically.
In what way?
What information can a native app get from a user that a website couldn't?
They also can't collect any information in the background they couldn't in the foreground. Like apps can't tell which apps you open, can't tell what info you put into other apps, can't track you across other apps etc.
Like the app has to register as being allowed in background mode, upon which if a push notification is sent to it the OS wakes it up for ~30 seconds to make an API call or set data. But there's no UI shown, there's no ability to track which app is open, or even if the device is awake or asleep. It's not like the apps are able to run code in the background whenever they choose.
not including apps with Allow in Background location permission, like bicycle tracking apps etc. but those are done with explicit permission from the user.
Sadly, there are very few resources; textbooks and professors qualified in software engineering and ethics, and the adjacent political, social and economic realms to fill this.
I'm really, honestly doing my best with this problem.
The subject area is massive. The issues are horrendously complex. The targets keep moving (each day we seem to set a new bar for what shitfuckery is acceptable).
Also writing a book on Ethics For Hackers that is not prescriptive or too personal value-laden is extraordinarily hard (and it makes it worse that I am an opinionated bastard)
HN remains one of my best resources for "pragmatic" ethics, and so I thank you all.
Ethics and personal values are the same thing. It would be impossible to write a book on Ethics for [any audience] that didn't consist entirely of personal values. Similarly, since ethics are necessarily subjective, it is impossible to write about ethics in a non-prescriptive way.
That one's especially easy. They are exactly the same thing; mos is the Latin word, and ethos is the Greek one.
It troubles me when someone proclaims such glib ease. I read maybe 10 different sources, philosophy books, old and modern, and numerous debates on the subject precisely because some people think "oh that's easy" - a symptom of our deflationary society which itself is an interesting predicament.
What do those Greek and Latin words mean? Mos comes from "mores and customs" whereas ethics (from Ethikos) means character in the mind of an individual. That sets a distinction between normative and subjective standpoints. However "Western" sense this is reversed. We are comfortable talking about "your morals"my morality" as subjective, relative positions, but reserve the word ethics for something supposedly more objective, scientific, and therefore presumably more widely agreed.
And that's just the surface of it. Resolving the actual documented uses of "morality" versus "ethics" in case studies reveals a whole lot more. Some distinctions assign the qualities of rightness and wrongness to morality, but the terms goodness and badness to ethics. And then the are are the entirely subtle but profound distinctions Plato and Emmanuel Kant make about the mental/spiritual realm of ethics versus Aristotle's primary focus on how actual people might behave. Or a modern moral philosopher like Jonathan Haight's distinctions between morals and ethics.
The bottom line is it's not that important so long as you're consistent. However it is useful to have different concepts and to set them out as philosophical tools. So "especially easy" - I don't think so :)
I gave you the correct source. The -ic- in ethikos forms an adjective from the noun, just like the Latin form -alis that you see in "morals". There is of course zero semantic distinction between a noun and its own adjectival form.
If you look up "moralis" in Lewis and Short, you'll see a citation noting that the word was coined by Cicero as part of a protest against the idea that Latin was unsuited to the purpose of discussing philosophy (popular opinion at the time being that you had to use Greek for that purpose). It begins by noting that "mores [are what] the Greeks call ethe".
The Greek and Latin words are translations of each other, and both refer to habits and norms. It is true that in modern English norms are a distinct concept from ethics. (Not true in Greek!) But it is not true that in modern English morals and ethics are distinct from each other.
Make the end push to graduate require ethics classes to book end all the technical detail they spent the prior years absorbing.
But I think by the time of starting third level education, something like this is too late to change someone's moral decision making, so I don't really think it had any effect on anyone in that course.
That's an interesting reflection. It depends on whether you see ethics as rational and actively learned, or formative conditioning.
It's why such a project is harder than I imagined, and also why I tried (only somewhat successfully) to avoid prescriptive narratives. The overlap between psychology (behaviour, which can be changed) and moral feelings is complex.
I think the best we can do is lay bare some uncomfortable truths; how people have seen things historically, what the likely outcomes of our behaviours will be, and how we delude ourselves otherwise.
What I see in tech is that there's a lot of "moral armour" - comfortable things we tell ourselves, distorted rationalisations, fallacies, short-term economic justifications - that kind of thing can be improved, unlearned and replaced by a better framework by appeal to the rational adult mind.
My best guess as to why people are so willing to act as if ethical criticisms are not valid is that the commenters self interest sees themselves as a potential future benefactor of similar actions and so they see the rational behaviour as being to defend it in case they could benefit from doing the same.
I'm not saying that people cannot ever be convinced to change their outlook here, but that doing so for an adult is a way more involved, individual process that requires input from people the person in question respects, which is way more than a university ethics course can hope to achieve.
to, what, make sure it is forgotten by the time you graduate?
is there even any evidence that making somebody take a class on ethics will make them more ethical? most college courses are grading you on your ability to write about a subject, not on how much you care about it, or decide to alter your future behavior.
That seems a little dismissive. Did you forget everything you were ever taught? I doubt it. Maybe let's be charitable toward others.
> is there even any evidence that making somebody take a class on ethics will make them more ethical?
Yes of course. Same as there's evidence that teaching cookery makes better chefs and people who take a driving lesson crash their cars less. Education is a real, actual thing, as you well know.
> most college courses are grading you on your ability to write about a subject, not on how much you care about it, or decide to alter your future behaviour.
Most college courses are rubbish. They're training camps there to take your money and give you a piece of paper to boost your fragile ego. I know that because I'm a university professor. You can read what I think about the current state of education the Times HE.
Maybe one in five students actually take anything meaningful from school. They're the ones who care about stuff and focus on their future behaviour as successful individuals and members of society rather than on ephemeral "knowledge" or getting grades. Don't fall for the certificate scam and don't let schooling get in the way of your education.
> making somebody take a class
Now, that's a telling word you use. Not wishing to psychologise, but are you maybe afraid of someone making you take a class in this useless subject?
If so I agree with you. "Ethics" is widely abused as a stand-in for whimsical "policy" that can't be backed up rationally, or to conceal hidden political agendas. Many classes are tedious finger-wagging checklists and plenty of "ethics boards" are sham kangaroo-courts run by cardigan wearing Kevins and Karens [1] who sit down with tea and biscuits to decide the future of a department of PhD's based on how they "feel" about some keywords in a checklist (I've sat in those meetings).
You should be afraid of "ethics" when someone else co-opts it as way to tell you how to think.
That's not what my project is about. If you're sceptical about ethics in tech you'd probably like it. It's about ethics empowering you as a decision maker - to back that up with 8000 years of human wisdom - to be wholeheartedly motivated by projects that can make the world a better place, and confidently, courageously say no to tedious dehumanising schemes of extraction and surveillance that passes for computing these days.
[1] sorry actual Kevin and Karen
It was not a "why do good people end up performing unethical actions, and how you can prevent yourself from equivocating and rationalizing unethical actions as well" course.
Sexual harassment is bad. Victims have an ethical obligation to report the harassment. The result will be HR protecting themselves, likely via moving the harassed person to a new team or making their life suck in other ways. The only path forward after is to fight, likely in/with the threat of courts. Social fall out (because a manager or their skip level's life got harder) is almost guaranteed. A product deadline may be missed. The blame is often directed at the victim and not directed at the person who was harassing. I have watched this play out multiple times.
In this way, reporting someone for sexual harassment is a sacrifice. So while there may be a moral impetus to report, there is a cost to do so, and the end result is not an ethical question, but a cost benefit analysis.
The cost benefit analysis is then hampered by short term vs long term thinking. If nobody reports it, the abuse continues. If everyone reports it, then some of the abusers would likely be punished. The individual cost of reporting is high, and so a person would rather move on than fight. The abuser then continues to abuse.
The end result is that the ethics themselves are obvious and uninteresting, but it is the economic factors and game theory factors that bring all the meaning to any type of pragmatic discussion of ethics.
The ethics course itself is a very small piece of the puzzle. Even if every software engineer had to take an ethics course, there's still a huge power imbalance between the average engineer and their employer. Ethics are great and all, but without a legally backed standard of practice to protect those engineers, widespread violations are more or less inevitable. You can stand up and refuse to do work because it goes against what you learned in your ethics class, but your employer can just find someone who doesn't feel as strongly about that. That still happens in traditional engineering fields, but there's at least a legal/regulatory framework in place to discourage it.
Some jurisdictions "solve" this by lumping software engineering in with other disciplines and making the same licensing bodies deal with it. This is also a big mess. Those bodies are normally led by "traditional" engineers who barely understand software, their standards/legislation were written before software-specific issues (e.g. mass surveillance) were relevant, and their processes don't move fast enough to deal with a rapidly changing field like software engineering. It may be possible to fix all this or create similar organizations and legislation specific to software, but it's not trivial.
> The ethics course itself is a very small piece of the puzzle...
Do you have any recommended reading regarding this part of the puzzle?
I'm still waiting for ACM to audit the practices of Facebook, Google, Twitter, etc. and then apply penalties (conference and publication bans, membership revocations, digital library bans, etc.) as appropriate.
At the very least they should call out examples of unethical behavior - which currently includes many common practices in tech companies.
Spamming this submission with that hook (rather than the parts that the OP had actual direct knowledge of) is basically just spreading misinformation.
It's called a bluff.
> This should be posted absolutely everywhere with this as the hook. This type of request and the admittance that companies give even more than that all the time is headline news worthy.
It's pretty well know, but it should be even more well known. IIRC, what's left of foursquare basically does that, lots of "free" apps do it (like weather, calculators, flashlights, etc.). It's the whole reason the "only allow location access when using the app," was invented.
https://www.reuters.com/technology/investigation-finds-tim-h...
Let us know when you're in the drive through! Just say yes to this prompt.
[location prompt]
===
I've actually been curious about this for a bit, I need to dig in to some apps to see what they're doing. I've noticed, for example, the Chick-Fil-A app does that prompt, and then continues monitoring your location even after you've gotten your order and aren't near the restaurant anymore.
This almost annoys me more than the original intent. They could at least own their actions instead of treating everyone like a moron.
> Twitter was on its death bed and was desperate for money.
I worked at Twitter at the same time, and while the company definitely was going through a rough patch at that time, it was absolutely not anywhere close to 'shutting down' or 'on its death bed' financially.
So many of these stories are from someone who built the thing, profited, left, and then took up a new chapter of their career talking about how everything they did at <BAD COMPANY> was bad and that they should now receive funding, back pats, and NPR airtime for their new <GOOD COMPANY>.
My question is always: "So, are you going to give the money back?"
There really is a middle ground between just following orders and dedicating your life to sabotaging a company from the inside because someone there once thought about doing something that didn't 100% align with your personal mission.
You can refuse and you can quit.
More people need to read books on engineering ethics.
If you're not interested in visiting twitter directly.
Redirect: https://twitter.com/\*
to: https://nitter.net/$1
Hint: Twitter to Nitter
Example: https://twitter.com/yishan/status/1586955288061452289
Applies to: Main window (address bar)
I'm also using this for 'fixing' referral URLs but that's another story.He was kidding, but it really threw me off.
I've used nitter for a couple of years now instead of twitter because I have no intention of ever making an account.
Non-sequitur. The story is about middle management doing evil things for almost no incentive except a small pat on the back for padding a short-term revenue number, while the actual owner-leader who benefits the most shuts it down.
I don't think this is opinion that should be taken seriously - just tribal signaling.
And Elon Must is something even worse than a heretic - he is apostate. So he is obviously the worst/best person in the world for people that have no better things to do than to be passionate about the culture war that is going on.
Doing the ethical thing requires making less money (or losing money) for nearly all parties involved. Doing the right thing requires sacrifice.
In a happy world, the CEO has long term vision and sees the long term cost of loss of trust. The engineers see the ethical problem or betraying their peers and use their pocket veto to do the right thing. The user should be willing to pay a reasonable cost to receive the service they use. Politicians should see that the individual incentives harm the whole and create regulations that disincentivize the poor behavior.
Non-rhetorically: How do we ensure as a society that we live in the latter, and not the former?
Strong legislation and independent legislators are what’s needed
I guess the root question is: how should middle class people wage class warfare?
Incentive alignment. Nothing short of hardcore government regulation of personal data, and the remuneration for (opt-in) usage of said data, will change anything.
We need religious fervor. We need to decry bundling spyware and "analytics" with free alarm clock apps as evil. Finally, we need "know-it-when-I-see-it" type Software Decency laws that we can leverage to fine evildoers into oblivion (of course, those will follow automatically if we succeed in moralizing the issue).
Data aggregation/brokerage has little such baggage in the public consciousness.
If actual data privacy laws existed in the US, this situation would never have happened. In the linked twitter thread, he says that "legal" said it was ok. That right there is the safety valve that we can control to keep corporations in check.
Why doesn't my local supermarket price gouge us when there's a hurricane about to hit? That's an obvious way to increase profits. In fact, if it weren't illegal to do that, I'd argue that any CEO who didn't do that for "ethical reasons" should be fired and possibly even sued by shareholders.
These aren't intractable problems, and they don't just come from nowhere.
Just goes to show that governments can be effective in working for the citizens' interests.
As software engineers, we are just like medical experts talking about the toxicity of cigarettes while ourselves buying cigarettes and distributing them to our own children.
It's even worse than that. Most of the people working in adtech are actually producing cigarettes, and laughing all the way to the bank. Many of them are on this very site.
yeah, this is a major concern of mine now. while a few months ago i had some minor concerns with elon discussing taking it over, his behavior since this started has elevated those concerns to an absolute red alert level. the kind of data he has access to is terrifying.
i’m predicting whatever it is will make the facebook/cambridge analytica thing look tame in comparison.
This is how "Do No Evil" Google started mining data and buying up the nascent AdTech industry. They weren't mustache-twirling villains, they were desperate to save the company with antsy investors breathing down their necks. They had to do something to justify themselves to investors post-.com bust, and all that data was right there.
Weird that advertisers cut their money immediately.
Oh wait, it’s the government we need to be protected from.
I think the benefits of increased government regulation on digital privacy outweigh the potential abuses at this point. What more is there for the government to see? They have everything and more.
It doesn't matter if the current owners don't/won't do it, there is essentially nothing that prevents someone else from buying it up, and doing nefarious things with the existing install base.
And as far as "Terms of Service" go, there is essentially nothing to prevent a future owner from updating the Terms of Service, and then doing the above.
> I don’t know if this mindset will hold true with the new owner of Twitter though. I would assume Elon will do far worse things with the data.
When has Elon been against user privacy? Also, isn't Elon good friends with Jack? I feel like they would see eye to eye with this. In fact Elon seems like the type that would try to champion emerging fads like crypto, differential privacy, and zero knowledge proofs. Harvesting data is boring and easy.
Location based, privately identifiable, data is a bridge too far for me. But we also know for a fact other social media apps already do this if Twitter's app does not already do this currently.
The hype about Twitter being an unwise purchase is just noise from the peanut gallery. You should take such noise with a grain of salt.
Twitter was always under pressure to maximize value to shareholders. Same with every other tech company. Different companies sometimes make different trade-offs. I fail to see why Musk is somehow going to do any worse than what we've seen from social media companies over the past 15 years. But I do think there's a reasonable chance he'll do better.
When I say it was an “unwise purchase,” what I mean is this: the stock market did not think Twitter was worth that much. Even when Elon was legally committed to purchasing Twitter, the deal seemed so manifestly absurd to the market that the price did not rise to meet his offer (which is as close as you can get to free money in the market). Is that the peanut gallery? Sure, but in no larger a sense than that our entire economy and value drive is controlled by the same system.
The stock market did think Twitter was worth that much a year ago (Q2 2021 mcap was $51B). Of course the entire stock market shed trillions in market cap this year as the Fed relentlessly hiked rates. Musk clearly was trying to get a steeper discount factoring for the macro environment after the original offer, but it didn't work out. Can't say I blame him, if you can stall things in court to get an extra 10-20% discount from a $40B purchase like that, it's worth a shot.
When you offer to buy up an entire company and all the liquid shares on the market, you have to pay a premium. That's always the case for any buyout. For a while it looked like Musk was going to get away with walking away from the deal. That's why the market walked away from "free money".
The media's job is to dramatize everything. Especially when it's the drama machine itself, Twitter, at the center of it all. The media will do everything in its power to portray the Twitter purchase as chaotic, haphazard, unplanned, ill-considered, etc, because their own engagement metrics are driven by such takes.
At any rate I repeat my assertion that no worse can be done by Musk that has not already been done by Twitter, Facebook, TikTok, Google, et al. There's little to exploit there that hasn't already been exploited. Perhaps his subscription revenue ploy will work and he'll monetize with micropayments and other integrations. I hope so. I think there's a chance that version of Twitter is healthier than the ad and blue check insider peddling platform that has existed. Not guaranteed but it's a chance.
Musk's entire publicly stated justification for purchasing Twitter was doing better than the status quo. He harped for months about Twitter as a public service, the importance of transparency in moderation, made extraordinary claims about Twitter falsifying its ad and engagement numbers, and so forth.
"He can't be worse" is simply not the point. His stated goal was to be better; we've seen no earnest attempt to do so (and plenty of earnest attempts at value extraction).
Sure, we have. We've seen him charge an earnest fee for a premium service that Twitter previously withheld behind a mysterious bureaucracy that arbitrarily decided who did and did not get a blue check mark. We found that employees at Twitter were charging as much as $15K to pull strings for people for that blue check.
That's already objectively better. $8 a month to verify you are who you represent yourself to be and to get less ads, more access to revenue generation features from your audience, etc? Sounds fine. It's absurd to have some mysterious service that no one really knows the rules or thresholds for. It creates the very pay for play schemes that were the status quo.
- If he's charging for the service now then he'll clearly do anything to maximize profits.
- If the service remains free then he clearly needs to sell granular user data to stay above water.
Perhaps I'm missing the point you're trying to make but I don't think you can conclude anything from this.
He can make people pay, or not, or jack up tracking, or not. It doesn’t matter to me! The point is solely that he needs to do something.
Twitter needs to earn a profit, sure. That has always been true though. One way to make the company profitable is to increase revenue, which the $8/month blue check fee aims to do. The other way to make the company profitable is to cut overhead, which the mass layoffs aim to do.
I still don't get the concern trolling about data mining Twitter data: it's been done since the platform began.
The only unethical thing about the original article is selling location and movement data that is individually trackable, which is what this article is talking about from years ago when they worked at Twitter, which upper management was in favor of until Dorsey allegedly stepped in to halt.
Nevermind that there are other social media apps likely doing this already and selling better, more fine-grained data than Twitter can. Twitter is not as personal or intimate as other social media apps are with regards to insight into personal, private data. Everything shared on Twitter is understood to be public. They don't have access to private TikTok videos, 'destructible' Snapchat messages, text message data between couples, personal health search engine queries, etc.
Companies such as Facebook didn't need to sell super private mineable data to data mining firms to manipulate public opinion on election day, they were maximally profitable when they did, but they did it anyway. Twitter didn't need to shadow or outright ban doctors and politicians, or inject state-sponsored context alignment messaging (propaganda) into the newsfeed that disagreed with their internal company political alignment, but they did it anyways.
Nothing at this point, could be worse than the status quo for social media companies.
Elon/Twitter isn't even in the ballpark of maximizing profits yet. They are just trying to make the 1-1.5B debt payment that's going to come due. That's going to require huge cuts we just saw, plus advertisers to stay on board, plus Twitter blue, plus whatever else he can cook up. And, it still might not be enough.
They are reducing ads for subscribers: https://techcrunch.com/2022/11/05/twitter-begins-rolling-out...
EDIT: can someone explain the downvotes? Is the TechCrunch story not accurate, or did I misunderstand the above claim regarding ads?
I’m interested to see the degree to which they reduce ads for paying users: having a split ad/payment model is famous for producing “self-consuming” incentives, since the users who demonstrate the most purchasing power are the ones you promise not to advertise to.
Boring, easy, yet highly profitable. And sometimes the only boring and easy way to be profitable.
So I agree, and feel like the default assumption is that he's going to try to get users to directly pay for content, which is what he's doing with Twitter Blue. We'll see if it works.
You can see them advertising selling ads on their website here: https://loopinput.com/this-is-what-elon-musks-first-website-...
Here's an article from '99 that even quotes Musk on it: https://www.clickz.com/zip2-launches-ad-program-to-aid-newsp...
>“In today’s market, traditional local businesses need to be online to participate in the electronic commerce revolution,” said Elon Musk, founder and executive vice president of Zip2. “With Zip2’s Internet Start Program, our newspaper partners can offer their print advertisers an easy, low-cost way to take that first critical step.”
And now he's spent $44 billion buying a company that he knew primarily made its money from advertising and then spent his first week as owner complaining about advertisers leaving -- not something one who doesn't want to be in the advertising business normally does.
I don't feel like this massively weakens my argument.
Now Musk is on the hook for over $1B in interest payments after buying Twitter and overpaying for it. Do you really think you can trust him to do what’s in the best interest of users?
That would be highly risky for Twitter to do and would seriously harm their reputation and therefore their business. So I'm personally doubtful.
This isn't as simple as make more money or not by pulling a lever.
Get into a car accident, and want some blackbox data from your Tesla? Good luck - get ready for a lot of legal costs.
Get into a car accident, and it makes Tesla look bad? Tesla will hold press conferences and release your telemetry data to the media, whether you want them to or not. Exceptionally misleading data in some cases - one fatality collision where autopilot was being blamed, Tesla said "Woah, hold up. Not true. Driver was distracted. In fact, the car warned him to put his hands on the steering wheel before the collision!"
In reality, the car had issued -one- warning about the steering wheel, and none after that, and that one warning was -eighteen minutes- before the collision.
Generally not true/safe. Any NDA still in effect would be transferred to the new owner. If the author genuinely believes this, they may want to delete this tweet asap. If it's just rhetorical, well ok then.
And hence why almost every app on my phone has location access 'never' and only the ones that really need it have it 'while using app'.
Of course, I never even got the Twitter app, I've always just used it in Safari on my phone.
Sales. Sales at Twitter sells user data to Twitter's customers [who aren't necessarily even advertisers].
Got it.
> Legal said the request was fine – none of it violated the user ToS.
Almost as if was watching an episode of some dystopian show happening somewhere in the future. It's sad to learn it's already happened.
Maybe other things too
> I wound up meeting with a Director who came in huffing and puffing.
> The Director said “We should know when users leave their house, their commute to work, and everywhere they go throughout the day. Anything less is useless. We get a lot more than that from other tech companies.”
If they have so much data on us, why is the ad targeting so laughably bad? Facebook has recently been pushing me to watch Hocus Pocus 2. -_-
A reminder: use the mobile web version of any services you use, not the app, and use NextDNS to block all the tracker hosts at DNS level.
Here's a comment I made a month ago, or so: https://news.ycombinator.com/item?id=33001139
I was asked to do an unethical thing, just after being promoted.
I declined, but everything turned out OK.
"All other social media companies give us more than is"
An app logging signal strength can pin point your location, which is then commonly sold to companies such as telcos as alleged in this story.
Owning a phone without GPS turned on, any app can track and sell your every movement without violation of any T&C or local laws.
That is beyond distressing.
If I use the website I'm browsing on my terms: adblocking enabled, no location data, a lot less surface area for tracking.
When you use the app then you're browsing on their terms: geolocation, tracking, ads, everything.
Can't figure out which from the thread
Anyone who has a "Rules for thee, but not for me" ideology doesn't seem like they'd have too much problem selling people out.
Your referring to Twitter pre Musk, and not Musk, right?
Just like Rogan, the dilbert guy, and many others he seems to have gone from mostly reasonable to corrupted and self contradictory and it's not really clear how or why that happens. It's hard to know if he was always the way he appears to be now or if there was some kind of transformation.
I read a thoughtful (but long) discussion of this phenomenon at https://rebelwisdom.substack.com/p/what-happened-to-jordan-p...
Were I to own a car, I’d probably in the same boat as you.
[0] https://www.caranddriver.com/features/a32035408/dmv-selling-...
[1] https://techcrunch.com/2019/01/09/us-cell-carriers-still-sel...
Seems like we have lost something along the way.
The Elon Musk burn in that sense is distracting. He hasn't done anything in this direction yet. He very well may, but he hasn't. So it's a false accusation/speculation.
Counter to that, there is the fact that Twitter's legal and sales departments (pre-Musk) were totally cool with sending fine-grained location data to whoever pays for it.
Controversy should focus on actual events, not imaginary ones. As such, old Twitter has some explaining to do and it's worrying that no actual Telco is named. Finally, a quote like "other tech companies give us far more" should launch a swarm of journalists to dig as deep as possible.
First thing today I did, was uninstalling the Twitter app. Even if it's not in (who knows). Totally forgot about the big apps deals with the global spying business.
Use a VPN? Don’t give Twitter access to location?
How #1: You have a smartphone, your smartphone has GPS, you have Twitter installed in your smartphone. Twitter requests your location, you approve that request = done
How #2: You have a smartphone, your smartphone has WiFi enabled. Your WiFi interface can see certain WiFi SSIDs. A Google car wardrived through your neighborhood saving all SSIDs of every Wifi and where they were last seen. Now location services has your location even with GPS disabled.
This is why I don't install apps
He's of a libertarian bent, so it could well be a real part of the story that he wants more free speech, and less censorship of similar folks.
However, I do believe he is playing that up to try and avoid any discussion of the monumental tranche of data he is sitting on top of and the potential value of it. I recall in the early days, the entire Twitter database was made available to researchers, who found they could predict overall market movement (up, down, some basic idea how much) about 3 days ahead of time by looking at sentiment trends.
All of that is worth "Take over the World" kind of money, where as the free speech stuff is, well. Worth percentage points at best.
I notice here the casual dismissal of actual, observed harm for the sake of fantasies of future harm. I wish that the similar casual dismissal of government censorship laundered through private media monopolies came with some similar sort of fear of how President Trump or President DeSantis will handle their brand-new tools in a couple of years.
That being said, Democrats saw what Bush did with his unchecked executive powers, and didn't roll a thing back when they later had the Presidency and both houses of Congress. Instead, they continued doing politics by executive order, and cemented AUMF as a declaration of a permanent state of emergency.
Som may say that
So in the Good Timeline there's no Twitter _and_ no President Trump?
The story is interesting, but this line is petty. It's also more than a bit ironic, given that the OP just spent N tweets describing how the previous management wasn't exactly setting high ethical bars.
The worst aspect of "Twitter culture" is the tendency -- illustrated here, perfectly -- to slander people, just to make the mob shake their pitchforks harder.
I sincerely hope Musk finds a way to fix that.
He's currently slandering people on the daily, so I doubt it.
Examples? If it's daily, you should be able to quickly point to 3 from the past 3 days.
That's a month supply of being a jerk right there.
From the head of Trust & Safety:
"First, impersonation has always been banned on Twitter. Misleading profiles make Twitter worse for everyone. Last year, we banned more than half a million accounts for impersonating people and brands."
Musk notably called someone he disagreed with a pedo guy solely because he was white and lived in Thailand and then paid a private detective 50k to try and prove his claim. He's spent the past few days doing similar and spreading falsities and generally posting in bad faith.
What makes you think he will suddenly change his ways?
Let me try to summarize what author actually said in the end: "I left, I sent email to then CEO of twitter and PER MY KNOWLEDGE the project was canned, I don't know if it actually was. But new guy still could do worse things".
If you're so moral, why not blow whistle to public when you left previously, and not write unsubstantiated claims about new owner now.
It is likely that the third-party partners who were interested in collecting that data remain interested. The leadership who formerly blocked access to that data has left, and the new ownership finds himself in need of new revenue streams. It seems like a reasonable time to call attention to the issue, though I agree with others in the thread that it should be a larger story not specific to a single platform.
The first tweet in that thread:
> With Twitter's change in ownership last week, I'm probably in the clear to talk about the most unethical thing I was asked to build while working at Twitter.
IMO this guy demonstrated an incredible amount of personal integrity here. He likely could have made a lot of money by building this out, but decided not to because he knew it was wrong.
This is why we need more laws and government regulation: people that do the right thing like this are very rare. Typical incentive structures don't optimize for these types of people, so legal ones need to exist to limit the damage that the inevitable bad apples will do.