Ask HN: What is the thing you've built that you regret the most?
Thanks in advance.
Thanks in advance.
I'm a lot more paranoid about privacy these days.
1. Almost all software can be abused or co-opted for surveillance purposes.
2. Some software comes already designed for surveillance purposes up front.
2a. This includes plenty of well-known mass appeal software; importantly, the customer-facing marketing copy and the investor pitch can present a completely different value proposition.
3. Software doesn't become used for surveillance or abuse by accident; there are actual human beings who make a decision to use it in this fashion, or commission it for this purpose.
3a. The "misguided programmers harming people by trying to solve social problems with technology" meme is dumb for many reasons, but it's also distracting (possibly purposefully so) from the fact that it's not software, or people who coded up the software, that are the primary culprits. The coders that were too naive or too self-interested to refuse work or blow the whistle may have some responsibility, but we should start talking about the people who made the decisions to commission or repurpose technology for bad purposes.
which is why it's less of a technical problem and more of a social problem
people need to realize that with how the technology is today we can't afford to rely on marked self regulation for a lot of things especially wrt. privacy protection it just fundamentally does not work
(Or in other words, such usage of employee surveillance should be just plain out forbidden by law not just to be used but to be deployed)
I tend to believe it, "will be."
All tech will eventually be used to try to gain an advantage in war and surveillance. I don't think there's a way to prevent it.
There's probably more illegally unpaid overtime than there's unauthorized (boss doesn't like) breaks. The data can likely prove that, too.
I am sick and tired of how often extremely pertinent information has to be neutered in this way. And I am utterly disgusted at how the legal system is used to protect scummy corporations like this unnamed hotel chain.
I wish we had strong laws that prevented employers from even thinking about threatening employees for talking about their work. Or collective bargaining to make sure employers don't have the leverage to impose such one-sided contracts.
My apartment building has lights in the hallways that are only on when needed, but they just use a basic infrared sensor.
* Minimize installation cost. They just wanted to plug into a light socket, not run network cabling.
* Push data logs to a central server. They didn't want to send a tech physically to each lightbulb to get data for e.g. energy usage certifications.
plus other obvious requirements.
All of that made it really easy to just stick a beacon tag inside employee badges and measure the RSSI from the mesh lightbulbs (since they already tracked that to discover who their physical neighbors were). Instant employee monitoring.
For location tracking they specifically called out things like equipment carts, but it was implied that it could track other bluetooth devices.
that's the rule I've always followed.
i have never worked in an office environment where people didn’t routinely unwind for a couple minutes. the way we’re treated in an office setting vs those outside an office is in a lot of ways disturbing. a couple years ago my friends dad lost his job of 25 years because he was caught sneaking around a corner, out of eyesight of his foreman, to eat a candy bar. he had been warned about these “unauthorized” snack breaks in the past.
this idea is entirely foreign to any of us who sit at a computer coding or doing whatever desk job that sometimes we don’t stop to think of how ludicrous some workers are treated—my entire post college career, if i wanted to eat a candy bar, i just ate it.
were a decision to come down in just about any office full of engineers which said “unless authorized, you cannot drink or eat anything. if any unauthorized stoppage of typing occurs, there will be consequences.” people would be justifiably outraged.
but they’d be “catching” “unauthorized” non-typers.
the idea that someone somewhere decided to put trackers on human beings is wild.
Even without intending to, everyone would go from a ticket or two per decade to dozens of tickets on every commute.
"But the law is still the same!?!"
Of course it is, but changing from poorly scalable human-required surveillance to always-on, fully-scaled electronic surveillance, changes it from completely reasonable to massively oppressive.
If everyone's productivity is fine, and people take unauthorized breaks, no one will notice, all is cool. If one or two people are noticeably unproductive, the manager will likely investigate and fix the unauthorized breaks, which is also fine.
But with constant electronic surveillance, it's no longer about meaningful productivity differences, it is about oppression.
(I know I’m jumping right to where the slippery slope ends.)
Your profile indicates that you've commented on HN on a weekday.
Don't worry - this behavior has already been reported to the authorities.
1. Logs of the CDN were sent in real time to the ministry of technology -- there was about a 15 minute delay if I remember correctly, and they could impose fines if they were delayed. The log included the url visited, the IP address of the visitor, and a few other things. Perhaps the user agent? I forget.
2. The ministry of technology had a special API to block URLs on the CDN. Basically, they provided a list of URLs that would return a 451, and of course those logs also went to the government.
No other country had this kind of access at the time, but it was considered critical for the business to continue to operate in China. As I understand it, these are required to comply with chinese government regulations, and other CDNs like Cloudflare and Cloudfront have also built similar capabilities. Perhaps jgrahamc can comment on what cloudflare did?
I feel quite guilty about being involved with that project, but the business was set on building it, so I did what I could to limit the blast radius. I would not be surprised if someone got arrested or was killed because of it.
So, yes, I regret I couldn't do more, but I don't regret the choices I made with the information I had and the position I was in.
Other engineering disciplines have a strong focus on 'engineering ethics' and it may be more acceptable in different branches of engineering to refuse to build something that you consider unethical. I do not know if there are any professional bodies or laws which protect the employment rights of individual engineers who refuse certain work on ethical bases. But I feel that software engineers should be able to exercise their conscience, reference a standard of professional ethical principles, and refuse to work on such projects.
I'm very curious because many Chinese people including me are doing that daily.
(It would make me more sorry. Sorry.)
In that case, isn't it better for user privacy (not that anyone cares about it in China) to receive an ICP recordal but then wait for an actual request from law enforcement to turn over the logs?
Also, while you wouldn't see anyone from Amazon or Cloudflare comment on your thread, both have the ability to stream logs to a destination, and that is also exposed to customers, so I don't think they needed to build anything else.
At the time, Akamai also had the capability to stream logs, but the ministry of technology required a specific, custom interface to receive them, which required engineering work, especially to do it for an entire country without the customers configuring it themselves. I would be extremely surprised if it required no engineering work at Amazon or Cloudflare to deliver the logs in the way they requested.
As if that makes if any better?
One meeting in particular really stands out still, a social media giant that everyone knows was in town meeting the founders to sell additional personalization data. Before that meeting, I thought things the start-up were doing were a bit sketchy, maybe borderline unethical. During the meeting itself, it was more like sitting around a table with Dr. Evil and a few henchmen. They were actively, unambiguously picking vulnerable groups for ad re-targeting. And that's not even the worst of it, the meeting wraps up and one of the founders says "OK guys, let's go get some beers and bring some girls". Then this despicable excuse for a man promptly walked out into the office, points at a few female employees and says "You, you and you, come with us now".
I hope this is a message that gets through to young devs. If someone is hiring you, you'll be making them more money than you cost. When you interview with someone, you're interviewing them too. You get a choice in who you make rich the more we make cruel people wealthy the more power they have to damage our society
This fintech didn't exploit them, but it was very obvious how this data could have been used to exploit them and other addicts.
And did everyone clap?
But the partner corp was just a startup, trying to break into some markets, and now had some of those opportunities encumbered by patents and rightfully viewed our partnership as not in good faith (we didn't tell them about the patent work). The engineers at the partner firm were fairly pissed off at me, since I knew them well on a personal level and my name was on those patents. And naturally Big Corp promptly forgot about that business, never doing anything with the "IP".
I've thought about chucking those patent plaques in a fire, but I keep them in a box as reminder of that little snippet of my career, which I'd otherwise probably block out.
My understanding is their strong patent portfolio was a good part of why they are still around after the massive consolidation of DRAM manufacturers through the 80's and 90's.
The boxes were also sold to Syria and Burma, and were used to facilitate censorship and human right abuses
(I guess Bell Canada, which also sells TV services, lost too many customers over this policy to their unthrottled competitors)
https://www.cbc.ca/news/science/small-isps-fight-ruling-that...
Canadian telecom regulators are gutless.
Though I kinda liked it when my university throttled napster and torrents, because that meant my IRC downloads went very very fast!
In a corporate setting, mitm'ing TLS and blocking sites by category is routine practice (better ways to stop bad stuff but expensive firewals are a waste when most traffic is TLS).
I don't know about this. The difference with knives is that they are an old technology, basically they have always existed. If you are responsible for creating a new technology, especially one that is not certain to exist without your involvement, the calculus is different.
Sometimes, the moral calculus is done only retrospectively and that’s when it really becomes problematic.
Deep packet inspection is a terrible practice in my opinion. It adds more security vulnerabilities than it typically helps avoid. I’ve seen one implementation use client software to extract keys from a machine to send to a centralized server. How some companies don’t see how this model can be easily exploited is beyond me. Me and a VP friend of an organization have had long debates about this topic and he insists it makes more sense for him because the employees have been more competent at the companies I’ve worked at than the company he managed (which could be true since his company had high turnover leading to many engineers being hired out of need rather than evaluated merit).
Selling deep packet inspection technology to the government of Syria is different as there is ample reason to believe that government would use it for human rights abuse.
Those people found another way to get paid.
Although I couldn't ever blame you for shutting it down. I'd probably do the same and try to forget about it for many years.
It turns out that the project was more of a demonstration of our ability to get dynamic languages to run efficiently on the CLR. To that end, I think we were successful. But once we achieved that there was not much of a path forward so the project was eventually shuttered.
We couldn't have made it user customizable without something like IronRuby, thank you so much for implementing it!
Maybe it didn't accomplish your original goal, but props for what you did accomplish. Quite impressive.
I remember a conversation ages ago about how you couldn't really get a (common?) lisp running properly, irrc due to limitations in the way CLR modeled classes amongst other things, but FFI came up there too.
It's a good thing that DLR is still there, though. While undeniably niche, sometimes it makes things so much easier. For example, I've used it to support dynamic reloading of C# code in a game, for rapid prototyping of mods.
As a former Microsoftie myself, it saddens me that the company seems to have forgotten this.
And the answer really depends on what you mean by "run on". .NET already supports two-way COM interop, and it does work with DLR to handle stuff like IDispatch. But the COM code in that scenario is still native (or, in case of VBScript, intepreted by its Active Scripting provider).
Implementing VBScript, or even VB6, as a language running entirely on top of .NET, is certainly possible, although it would be somewhat awkward because the object model in VB pre-.NET was specifically designed around COM. You can port the templating engine, as well. But the real hurdle is not the language - it's all the APIs. ASP itself was pretty basic, but most web apps would also need to talk to the database - so now you need ADO. And then there are all the third-party components, most of which were proprietary binary blobs compiled for 32-bit Windows.
And, well, why? There are many better languages running on top of .NET these days, starting with VB.NET.
You wrote me a house.
It feels surreal to come across someone who was responsible for something I hated so much back then. But now I’m just fascinated for some reason. I’d buy you a drink if I could :p
Except on mobile, which is what everybody preferred for obvious reasons.
I'm coming up on 3 years now with very minimal progress on returning media to users and getting the site fully operational.
There are a lot of places where in hindsight I could have made better decisions. At every point the best course seemed to stand out, only to sour with unexpected obstacles.
At first I thought I could stay in the warehouse, but then the returns became too much to complete before I had to vacate. COVID struck, and delayed the container move. Then I couldn't use my warehouse, and couldn't unload the containers. This is delayed efforts to return media and restore files that would have been easy to replace if I could unload the containers. Meanwhile Murphy customers have been 3 years without their discs or access to their media. I feel terrible about it. Some have died without getting their media.
I'm still fighting to do the right thing. I've filed a lawsuit against the city for refusing to issue permits, and I'm constantly looking for solutions, but I feel like I've failed a lot of people.
I think there were always some nay-sayers around in replies, but I appreciated what you were trying to do and despite the negative outcome am glad you at least gave it a shot.
Thanks for sharing your story on hn, I feel like I got to learn a lot vicariously.
There is a fantastic Australian film called “The Castle” (that you won’t regret watching!), but there’s a line from it where the main character is facing failure (and about to lose his entire neighbourhood)
“I don’t know what the opposite of letting someone down is. But you’ve done the opposite.” T Thanks for fighting to do the right thing. The world needs more people like you.
The whole product was positioned for process optimisation but I know for a fact that it was used to monitor and eventually reduce headcount at multiple customers. I still feel gross just thinking about it but the company is supposedly making good money off of it given that they just announced a new version.
I got deep into gathering all the data and ML analysis, to the point I started brushing with digital forensics. I got spooked and abandoned it when I've realized I can never release such tool without it being abused for surveillance ;(
I had a friend Josh who worked at Los Alamos National Labs, who wrote a script that automatically filled out his timesheet with plausible looking working hours and tasks, an emailed it in at the right time every month.
One month his boss was chatting with his assistant about how happy he was with how promptly and efficiently Josh always sent in his time sheets, saying what a good worker he was, and that he just received his timesheet on time that day.
The assistant explained to the boss that Josh was actually away on vacation that week.
So when Josh finally got back from vacation, his boss summoned him into his office for an awkward sit down talk.
And insisted that Josh set him up with the same system to automatically fill out and send in his time sheet, too!
You can optimise for many other things such as on-time delivery in production processes or duplicate/late/early payments of invoices just to name some straightforward examples. In the former case you're optimising the process with the goal of increasing customer satisfaction and in the latter you're optimising many things such as cash flow and working-capital while balancing early payment discounts and late payment penalties.
The first changes I made to the poc was making the ability to identify which employees did what and when so hard that if they asked us to do it, it would either not be possible or cost so much that it wouldn’t be feasible.
My company built the smart helmet used to track Qatar’s army of abused workers. The claim is GPS and accelerometer where used to track if a worker stopped moving or fell due to an accident; the geo fencing was supposedly for tracking if they had enough workers in an area for the job.
The reality is the helmets where/are used as mass surveillance tech to ensure workers are continuously active and never leave their assigned areas for petty things like going to the bathroom or finding shade to prevent heat stroke.
If this is real you should get in touch with investigative journalists, e.g. ProPublica.
("Get in touch with investigative journalists" probably applies to a bunch of the people posting in this thread.)
Next up was a table to help workers move large objects with hydraulic movement and pins to hold the material in place via compressed air activation, and all the associated limit switches electronic eyes etc. cool enough.
Then the big leagues, a 300k (17 years ago) A-B (Allen-Bradley) robotic arm in an auto parts plant. Day 3 inside / outside / on top of the cage, I become aware of a number of people standing behind the yellow line staring at me, later cursing me, one threw some crumpled paper at me… I’m asking the plant foreman wtf is with those guys. He says well as soon as your robot works they’re all laid off. I left that day and never went back. Someone finished programming and set up I’m sure, I could care less, I didn’t. I thought one day I’ll get stabbed in the parking lot.
I realize that my automation didn’t take jobs away from society, I didn’t do anything evil. Those jobs would just move and hopefully spawn better jobs in the community (medium to long term). But in that small short term microeconomic moment, there were real consequences, and I was the face of them. I was not happy, I changed careers that exact day.
It just seems obvious to me that society benefits when people don't have to do automate-able jobs anymore, and can retrain to do something more interesting/useful without simultaneously having to deal with crippling financial insecurity. My version of utopia is one where there's so much abundance and automation that no one has to work at all if they don't want to, but can still live incredibly comfortable -- extravagant, even -- lives.
Of course, some people will still fight tooth and nail to keep doing what they're doing, regardless of how obsolete it is, and regardless of what incentives and help they're given to learn to do something new. But the least we could do would be to help those who are more forward-thinking.
Anyway, I think automation and its consequences are much more complex these days and beyond the understanding of any non-technical / "not in the know" person. People used to know that "robots would take our jobs" but now that's not always true. The people writing completely "harmless" software are likely responsible for many, many bad things that would be difficult to even assign the blame for.
Then I started reading customer support emails, took a few phone calls from disgruntled customers, and it turns out the company was just cycling cash. Would charge 100 orders and float the cash as it trickled out refunds.
I ended up leaving, and the company sold for a couple million a year later. I was left with a bad taste for e-commerce that has only recently went away.
The lesson I learned is to make it easier to abort large projects. Even if it delayed me by 6 months, I should have found a rentable workshop.
I found out years later (this was in the mid 1980's), that his company was "The Company"; the US CIA.
So I don't think my shitty little pieces of C code written on a Windows box ever made it into any US Gov't system parsing Internet mails/chats/etc, but it could have.
After a couple of months of weekends we launched the site. Third partner was to take care of fulfillment because of their connections.
A couple of months after that, my mother in law contacts me and asks when her shipment will arrive. Turns out she liked what was on offer and wanted to be supportive.
My friend and I got the fish guy on the phone. He said he had to take a day job and was having trouble doing the fulfilling. I said ok, refund my MIL and I’m going to turn all the “add to cart” buttons into “email us” buttons and when you let me know you’ve got a plan to fulfill orders, even if just once a week, let me know and we’ll put the site back online.
My MIL never got her refund. Neither of us have heard from the fish guy again.
Sorry man, but that one's on you.
Think about dual-use. You may never really know quite how your creations pan out. Not quite in the league of Mikhail Kalashnikov, but it piqued my now intense interest in tech ethics.
EDIT: damnit seems like everybody here is in the same boat. So mine was a gesture detection for medical robotics control that was repurposed for look-and-lock air combat (fire and forget a2a missile. An important caveat is I'm not even a "pacifist" and went in eye's wide open with a defence firm. I just wish they'd told me more up front that this was "generic tech" I was developing.
I'm intrigued by how missiles work. I bought this [0] book to learn about them but I've forgotten math.
[0] https://www.amazon.co.uk/Tactical-Strategic-Missile-Guidance...
As we scrambled to create something of value and keep the lights on, I (unintentionally) built and highly optimized a free-trial funnel for a Saas service according to a "gym-membership" model; ie, our entire revenue stream depended upon tricking people into submitting their credit cards and charging them for months when they forget to cancel (or couldn't due to the complicated cancellation funnel). Once someone hit gym-membership status, we would pause all emails, reminders, etc (on CEOs design) so they would forget about us and let their card be charged for years. People at our company would fight against these tactics, but leadership's only focus was AB testing the hell out of the funnel to continually increase subscriptions and impede cancellations.
To combat the inevitable high charge back rates we eventually encountered, our staff would purchase pre-paid gift cards at corner markets and we programmatically submitted multitudes of tiny transactions through out the day to skew the chargeback rate to an acceptable place; this was the CEOs idea again, rejecting our ideas of selling things people actually wanted.
It was a house of cards, but the success of monetization was leveraged to land further contracts with governments (that we could never fulfill) until it all came crashing down. I left long before then on principle.
The entire venture was revealed to be a complete mess from day 0. From the start, this outfit threw its entire batch seed into google ads to drive "users" and feign growth to pump up the valuation on demo day, landing a couple million in investment for something that had no real value. Hm. It seems that a system was crafted here to pick winners and losers, and the company responded by gaming it in every way they could.
Instead they covered LA Live and surrounding area with them and then just sold that data to… well I’m not sure who since I left shortly after they did that.
The justification was “but we put it in the TOS and Privacy Policy”.
It worked well enough, then quickly got to a state of overwhelming the agency responsible for following up. That's depressing enough, but it was then repurposed and unleashed as a way to find copyrighted content for major studios, which meant it went from something doing good to something just annoying people with cease and desist notices.
Btw, they got an early version that had a memory leak, and when I went to warn them, they just said: "It's okay! It's just going to run for about 20 seconds!"
https://news.ycombinator.com/item?id=14233542
The Google Groups page is currently in a redirect loop, but if that gets sorted out, you may find the story that you're remembering.
If any software needed a memory leak it's this.
Not to mention the nightmare of early GitHub for Education used in the first semester (all forks mutually visible, what were they thinking!?), a genuinely shocking percentage of the class tried to cheat their way around it, thinking that I wasn't looking. Cheating felt like it had significantly increased the moment they thought we weren't looking. I expected some cheating, sure, but it really felt like it went higher and stayed higher than before.
The course has moved to others (who I have nothing but respect for), but I hear it is "notorious" for cheating. I was so proud of this system, and the distribution/collection systems are still used by a department, but the experience has really left me with a bad taste in my mouth wrt anything related to automated grading.
Now that's all fine and good as such. I had no qualms about working on that stuff. But then somebody introduced the idea of capturing frequent screen-grabs (essentially video, albeit at a fairly low frame rate) of the user's desktop as they used the system. We worked out a way to do some weird windows network driver shenanigans to make sure the recording started when an outgoing connection was made to certain destinations, and then streamed the video to a server where it was stored.
The nominal purpose for this was advertised as "training" with a side-dish of "compliance enforcement", and probably in some highly regulated industries people will (and do?) accept this sort of thing. But it never sat well with me, and I felt a bit queasy about working on that aspect of the product.
I regret building it, but not for any ethical reasons, except for maybe that it's become nothing but corporate ads.
My real reason for regret is just the entire process that happened after it became successful. It took off and was over 50k DAUs ~5 months after I launched it. I tried supporting it the best I could, and had aspirations for the future of it, but I was young and dumb. I got caught up on feedback, took it too personally and started having trouble in my personal life due to it.
I ended up selling it to another company for far less than what it was worth, even while I had 2 competing bids because I let one of them get to me emotionally at the time. I also agreed to continue working with them on it, at what I found out later was vastly underpaid, to the tune of being ~10k below the CA minimum for a salaried SWE. Our time together lasted less than 9 months for a myriad of reasons.
I regret it, mainly because I always look back and think of what could have become if I had the strength to continue it solo, or had spent the time to look for a better partner to carry my vision forward. Instead now, you can get your latest [insert corporate media here] watchface from it for a mere $4.99/mo.
You've learned from it, and it shouldn't be a continued weight on your shoulders. You did nothing wrong.
Project management consisted of the founder telling us what to implement. One day he told me to build something that would help us track the (many) exceptions in the app.
I went on to build a terrible alternative to SaaS bug trackers, which already existed at that time, but no one knew about/had the skills to find out.
It dawned on me 10-20 hours into the gig that these customers were professional spammers, and that I was helping them avoid being blacklisted.
I scrapped everything I’d made and eventually paid back my fee.
* Respectable email marketing = you have a pre-existing relationship (e.g. account on their website); spam = they found your address somewhere
* Respectable email marketing = there's an unsubscribe link that works; spam = no unsubscribe link or it doesn't work
(Could very well be that the people you're working with were actually spammers)
A non-expert trying to use Windows on the internet in three early 2000s had a near 100% chance of filling it with malware.
Received a lot of requests for this from my existing SaaS customers then started out as a corner-only slide-in modal.
Eventually I caved and added a centered modal… It’s currently in active use on at least 30.000 websites.
I’m sorry for making browsing the web suck a little more instead of less.
Most of my big regrets were bad technical decisions that worsened the quality. I'm sure every dev has stories like that but for a long time my mistakes followed a pattern.
Often because I didn't follow best practices and reinvented a wheel, without being aware of how much time the project would take up.
A lot of my biggest regrets were personal projects, they almost all were major time drains that I would say worsened my life. My expectations were too high and the disappointment was far larger than any enjoyment.
I am still working on selling things on eBay and decluttering stuff bought for DIY projects.
Now I constantly advocate for best practices. A lot of my biggest contributions come from finding ways to make things work without adding more custom software.
There's just so much good software out there, often that already does exactly what you want.
It was commissioned by tobacco firms who had sponsored those teams.
Later on some regulators decided that this could potentially market tobacco to children and it was going to be shut down. My boss joked that we should just remake the site but never mention the names of the teams, only just use their colors. The sponsors thought this was an ingenious idea and we actually did it.
A lot of denial from people working on this project. I heard my product manager and the CEO talking to each other privately about whether this increased tobacco use and they both strongly agreed that it couldn’t, they repeated the common lie told by tobacco companies at the time that it just encouraged people to switch brands.
It was for a programming language that I developed at the time called OwU[0]. It was supposed to be a sort of mashup between Lisp and K (an ASCII-friendly dialect of APL). I took a lot of design decisions from oK[1], a K dialect with a code design that I admired.
The biggest mistake that I made during my decisions is to seperate between verbs and user-defined functions. This is because in K, verbs behaves like operators, while functions behave like, well, functions. But in Lisp, both built-in and user-defined functions should be fundamentally the same in data type.
Because of this seperation, it was very hard for me to implement functional programming stuff, like fold and reduce, because I have to handle two different data types at the same time.
Not to even mention the fact that I chose to go with objects in the entire language to be dictionaries, and not classes (I implement this in Python). This makes code just generally very messy to me, as I have to figure out how would I access the data to perform operators on them, and this cause me to make a good few bugs.
Overall, OwU is a language that is better than any previous attempt, but there's still a lot of it that I regret.
[0]: https://github.com/HoangTuan110/owu [1]: https://github.com/JohnEarnest/ok
But the odd dream of creating an awesome retro gui for.. well, whatever reason, will likely pop up again soon.
There were lots of open questions, not only tech-wise, but also business-wise that made me really anxious (in both senses) to get to work on them. So I pushed the stakeholders to discover what they wanted. I asked for definitions of terms, clarification on business language, workshops to figure out what it is my software was supposed to improve, what problems it was supposed to solve.
I sat down with them and explained Agile from A to Z while also writing code, reviewing code, writing CI/CD pipelines, talking to other teams about architecture, and generally putting in work wherever it was useful - and that was everywhere.
Then a week before my 3 month trial period was up, I was told to clear my desk until the end of the day because that was not what the company was looking for. End of story.
I don't regret doing everything I did, but I do regret not playing it smart politically and doing it out in the open.
Also, systems knowledge and critical thinking skills have brought me anguish and made me cynical. I see problems and logical contradictions everywhere and it makes everything and everyone unbearably frustrating.
I should have been a lawyer and done software as a hobby. I don't think law rewires your brain like decades of coding does... You're still human. There's something about being constantly corrected by a compiler for over a decade which changes the way your mind works in a fundamental way.
If software made you cynical and miserable I don’t think you’d have survived law.
I have heard the line "If I don't build it somebody else will." from an engineer working on multi-million dollar weapons (think F-16).
I can only decide what I do with my time on this earth. Everyone makes that decision for themselves.
It was abused at a large scale in some large enterprises in India to monitor it's employees network communication.
Thought I was doing a good work for govt. agencies, but in turned out otherwise due to the abuse and affected a lot of privacy. Since then, I've made myself away from any and all mass techs as much possible and stuck with manual methods, cash and privacy friendly alternatives.
It's like creating a double edged sword. All the newer age, continuous monitoring and etc, etc., are doing more harm then what it solves...
Like in medical community, but an opposite... Risks outweigh the benefits!! Enough said! Peace!
it was technically well made tho, everything integrated into a single executable file that had an web interface:/
It is not inherently bad. Some of the real life uses are practical and beneficial, but it can also be weaponized.
I also regret building some things in C# or Java a long time ago.
The biggest regret money wise is I built a crypto forecasting company that became somewhat profitable BitBank.nz but I built it without enough foresight for cloud costs, was running a forecaster constantly on compute engine as well as filling up a postgres database without offlining data, turned out harder to scale down a database than scale up the memory. Basically things like that and I never had time for it after having kids meant it long term costed more than it made even with paying customers so I shut it down.
Now I run https://text-generator.io still machine learning related but I run it very lean from two GPUs I own at home which is a bit easier
My system was built entirely from scratch because the existing system was antiquated, poorly structured, and really not conducive to future expansions.
After testing and implementing my system, a handful of traders lost their jobs as a result. One criteria often looked at was their number and reasons for failure to delivers (FTD's).
Other than that, it's mostly automating things that I almost sort of regret. A lot of folks in the bank were fired after I wrote a series of apps that could do the work they do. Mostly repetitive tasks. Still feel bad about that but if I didn't do it, they would have hired someone else and at the time I was really, really in dire need for a paycheck.
I quickly found the source of the crashes: misconfigured ethernet switch MAC address limits applied to VMware ESXi. I also cleansed the environment by finding the one working server in each cluster and then cloning it out to replace the faulty ones. These were all "pets" on life support, and I tried to make them more like identical "cattle".
I went back a year later and half of the IT support team was gone. I asked what happened and the answer was: me.
Apparently after I fixed up the platform the number of support requests plummeted, and a bunch of the helpdesk staff were made redundant.
Oops.
It's the little * on the report, when someone manually entered a barcode instead of scanning it, that I felt a bit squeamish about.
\s
Why did reddit use such a shitty design, anyway? To maximize clicks / number of pages visited?
old.reddit.com is the only sensible reddit interface, the mobile app sucks. Even the old m.reddit.com was pretty great..
Even the bad technical decisions tended to be correctable learning experiences.
I've recently gotten re-involved with an open source project that I used to work on in the mid-00s, and it's really satisfying to see code I wrote so long ago, still in use, and get to work on it again.
Then I found out about nbdime, which did nearly everything I wanted. I ended up just making a simple Python script to make using nbdime more convenient, and soon I'm planning to make a vs code extension to make it 1-click.
After doing lots of post mortem analysis, the paper system was far more capable and had a better audit trail and most of the objections that were formed were entirely spot on. But we steamrolled them because we were under the six sigma project flag.
After seeing the shit show and reflection, I quit and got a shit job throwing web sites together.
I guess there have also been a few previous companies I worked on sites for that weren't exactly the most ethical operations overall.
But I don't think I can recall ever working on anything that was used for surveillance, or that itself was built for unethical ends. It's usually things associated with questionable companies that I didn't really know were questionable.
I've seen (and caused/fixed) so many horrific things that I feel compelled to improve my expression skills... so that I can write them up more formally.
Most recently, I moved some of our Ubuntu systems away from network-scripts to systemd-networkd
I didn't realize the gravity of this change. Be warned, systemd-networkd will significantly change how forwarding works.
Due to things outside of my control, we have some systems playing router. They didn't like this change a whole lot, and I neglected to test this.
On network-scripts with the usual kit of sysctl and iptables rules, you're good to go.
networkd however requires more explicit configuration; particularly which interfaces may forward.
Not a big deal, unless you don't know... like I didn't
Not that I care about votes, but I can see at least three people have disagreed but said nothing.
I'm genuinely confused - this is a blunder I created/regret by implementation
The data volume was huge though and it quickly filled up our database, so we shut it off and threw it all away since it didn't seem to be worth the trouble.
This was in 2012... I didn't think much of it until Cambridge Analytica.
Not nefarious, but wasn’t how I want to spend my energy.
Feels like this is more of a human problem that hasn't become common knowledge yet, if it is capable of becoming that.
But recently I found out that an algorithm that I was a crucial part in building ended up doing some real bad things. I don't really want to talk about it directly because I'm not sure I really want to be implicated.
The point is, I feel terrible. I played a role in negatively impacting a lot of peoples lives. Sure, I wasn't the only one who built it. Nor did I play a part in what it turned into, or made any decisions about how it should be used. I just built a thing.
But I think we as programmers, tend to look fondly on our systems that we develop. They are sort of like our children (in a very loose sense). I spent years thinking back to building it, and being filled with joy. Now I see what it's done, what I helped create, where it ended up.
I just feel sick. I talked to a peer who helped on it about it. They also feel the same. Just terrible. Burnt out. Ready to switch careers entirely.
I think I might be able to continue in this field, make the right decisions, and think through the true impact of what I'm building before I commit to it.
But then again, I think back at all of the work I've done in my career, and all of it was exploitative to people at least in some sense. I'm not sure you can profit without exploitation in tech, it might be inherent (I realize that's a negative statement. I'm in a mood).
So I'm thinking I may just switch into a career I can feel good about, unless I can find a job or project that will allow me to be ethical.
We really need to come together as a community and stand up for ethics. Every day a programmer out there is faced with an ethical dilemma, one that will probably get them fired if they don't comply. Plus, that won't even matter, because they will just get someone else to do it anyway. There's not a good way to save your source of income while also doing the right thing.
Those of you implementing DPI, assisting CCP with logging, cryptocurrency daredevils, tracking enablers and even a slave helmet guy. Do know that you have changed the world. For worse. And you'll never git amend or git revert what you've done. Most likely you will never find rest for what you've done as the confessions are very indicative.
Funny, how Hollywood different the notion of an evil computer guy in movies (asian/western european/nerd) to an average american family guy Mikey Mike doing all this real damage.
But, I bet all those mortgages ain't gonna pay themselves, right?
Worked on an e-commerce site for an extremely well known media company. Again, tech wise it was cool, but the way it worked and how the marketing and other folks talked about the audience and their schemes to extract $ from them was gross and disgusting.
Now I work in boring enterprise SaaS, but at least I know I'm actually helping our users do their jobs better. The job kind is boring af, the tech stack is lame, but that's fine. Every so often I'll be on customer calls and I love hearing them tell us that our fix or some new feature is wonderful.
I will never work for big tech or adjacent companies ever again. I want to be able to sleep at night and not be associated with psychopaths and people who care only about money at any costs.
Working on useful software is good, glad you're doing that now.
Hey at least I’m not the AMP guy.
I did at the time Angular was hot and I wanted to learn it. Also because it made my life easier at my job. I developed it fully at home outside office hours (I did not work remotely at that time), published it on github and deployed it on a personal public VM, and I told one or two direct colleagues about it.
A few months later, some people in the company who I did not know started using it (from the public site, not running it locally) and then later even manual validation plans or troubleshooting guides referred to it (its url).
I noticed through the server logs that it was used from many different countries, it was barely active but still got between 2 to 5 visits per day. And from the location I knew that it was very likely people from my company (no zscaler at that time).
One day I wanted to upgrade the VM and also cut down old sites that I maintained. So I shut down the website. A few days later I received a complaint in my company from 2 guys asking me to put it back on. I had to explain them that no way, I would not put it back on, it was a personal project fully developed outside business hour on my personal laptop, hosted on a personal VM that I paid for, etc.
This could have got me fired maybe, even though the cryptographic functions were really generic, I could have been accused to have stolen company time or whatever. The company was really not the kind to give 20% of our time to work on personal ideas.
In VB.
VB ..... 3
It didn't care (much) about well-formed documents.
You could mix it with snippets of RTF. We did. I used it to parse report templates out of hybrid RTF/XML files.
Not really morally evil though.
I kinda regret that I didn't just build one thing, and stick to it until it succeeded, but each project had valuable lessons (both business and code/architecture) that carried over into the next one. So far I've built:
- bill splitting service (2017)
I spent days agonising over which new framework to use (this was late 2017 after all), eventually learned to just use the tools I knew (react, node, postgres). I didn't really care about the problem space, so shut it down.
- jobs aggregator (2017/2018)
I learned that implementation is meaningless to the user if you're not delivering value. I wanted to copy remoteok.io and make it serverless (effectively free to serve traffic), I didn't realise existing sites provided value via their traffic. The reason StackOverflow can charge as much as it did is the millions of page views per month it receives, creating value for its job posters.
- appointment scheduler (2018)
I built an appointment scheduler, had no real means of attracting users, shut it down.
- room booking service (2018)
Spin-off of the previous idea, but for meeting rooms. Tried to build the whole thing using Google APIs, eventually got stung by API limitations, gave up (learned not to rely on other's APIs without understanding their limits first).
- graphql API monitoring service (2018/2019)
Traction again, couldn't find users (tried in-person sales for the first time, too).
- site speed monitoring service (2019/2020)
Essentially running google lighthouse as a service. had some users, but fixing all the edge cases around chrome/puppeteer/lighthouse across super slow websites was a total pain. Couldn't figure out distribution.
- uptime monitoring service (2021-current) - https://onlineornot.com
Doesn't seem to be as useless as the other projects. Has bought me the MacBook Air M1 I'm typing this comment on now.
Rewrote my old graphql API monitoring service from scratch to monitor APIs, websites and web apps, seems to be going well so far. Now also a status page service.
I made sure I don't collect any data except the URLs that come in, for debugging purposes, so that if I see too many failures I can fix whatever the issues is and attached an inbox so people can reach me.
I've seen some really disturbing stuff in the logs, you can tell from the URL alone, zoophilia, murder and executions, rape, but that's all stuff you can find on the internet.
I stopped looking at the logs long time ago, but I vowed that if I ever get a whiff of underage sexual content going trough the site, I will take it down and use it only in private.
----
Ow, I also get emails from horny people who really want to download specific porn videos from unsupported websites.
I still feel really bad about this. Sorry.
I didn't know what to do with it, so I collected GIFs of women... Jiggling.
At the time I thought it was humourous but now I just cringe.
I should probably take it down sometime, but I just don't know what to do with it.
Truly ingenious technology but everything else was shit, truly bad moment in my career that fortunately lead to a better place for me...
(Also this was pre-https everything so it was super-easy to sniff the traffic)
https://iaindooley.com/post/57313703317/an-open-letter-and-a...
EDIT: actually I just remembered that around 2011 I repurposed SMS subscription software I had written to run a (basically) spam premium SMS service in Ireland. It wasn’t my service, it was for a client, but I knew it was shit and I did it anyway. What can I say I needed the cash.
In some cases, something that I wrote some time earlier, and had "let go of," proved valuable, at a later time (that has been the case for the app that I'm writing now). In other cases, it took years longer for something to "catch fire," than I initially expected.
I was gone in 6 months, but 3 years later the team (having doubled and doubled) still used that dumb script. Had they buckled down redo it in Java, they would have learned a lot and would have relevant experience to get jobs in the then-burgeoning enterprise server market.
Not bad for society, just for them.
It was co-opted as a time tracking system. A bad one that, as far as I can tell, produces no actionable data while simultaneously being a pain in the ass for the poor bastards using it.
It is the last time I will ever go out of my way to improve a non-IT aspect of the company.
The management guys are not in prison and i think will never be.
I usually don’t let myself get caught in such a scenario, this one slid by and I regret it.
It was a chemical thing. Toxic too.
You've got to figure it's a lot more likely to have impact if there's a somewhat likely negative outcome within the reach of unscrupulous operators, especially if popularization can be a factor in a more widespread negative effect.
there were 2 webproperties
a people search engine a travel social network a yelp clone
i was in charge of SEO
in it was a major success
the people search engine became part of the biggest websites of the western world, top 10 in europe
the travel social network became a travel guide with more traffic than tripadviser then
the yelp clone became bigger them qype, the then leading yelp clone in europe
all with technical SEO
felt like a superstar
all resources were shifted to SEO and monitization
all 3 webproperties dont exit anymore (sometimes the companies behind them still do)
we did scaleable SEO before we had a product that users wanted.
so by now, I don't touch projects before they are not (near) product market fit. SEO kills if done otherwise.
said that, the people search engine had a 100m exit i think, which was a lot at that time.
Because of the opportunity cost. It's a fun hobby but I wish I made something that made me money. Being a salaried software engineer kinda sucks.
Except for that one time I built something pretty good and he didn’t want to pay me for it. Big regret. Shouldn’t have finished that job.
I set up a startup with an acquaintance (also the life partner of an ex colleague and now former friend). We were equal partners: I did the tech, they did the marketing/strategy and occasional bit of UI design.
We got pre-seed investment with a 7-figure valuation, and we were doing the standard startup thing: building features, looking for product market fit. We had a good working relationship, with zero arguments and barely a disagreement.
Then, my one-year-old son was suddenly taken seriously ill with a life-changing condition. There was a horrible period where we weren't sure if he was going to live or die. To add to this, my wife was also 6 months pregnant at the time.
My son had some very serious operations, and required a long time to recover. The operations didn't go as planned, leaving him still with a life changing illness with a very dim outlook.
Obviously, as soon as this happened I told my partner, and they told me they would take care of everything and to take the time we needed. Everything was set up to run without intervention, and for marginal cost, so I things could be on hold without really affecting our runway.
There were some accounts we had set up with 3rd parties where I was the account admin so I transferred these over when my partner asked me to. I did this outside the paediatric intensive care unit where my son's life was in the balance.
After nearly two months of bad news after bad news, we finally made it home and began adapting to our new life.
I told my partner that I would be ready to begin returning to work gradually if possible. I got no reply.
After a few weeks, I finally got a response. My behaviour was apparently so bad that it put the company at risk, and I had been fired from my own company, with all my shares being transferred back with zero value.
Now, obviously this was absolute nonsense, and I had done nothing of the sort, so I phoned our investor to see if they knew anything. Apparently my partner had told a complete tissue of lies about how we'd been arguing and etc., etc. which was all 100% false.
Anyway, I immediately instructed the most expensive lawyer I could find who told me there was absolutely no way on earth they could lawfully do what they had done, so we began action for breach of contract.
It turned out ok for me in the end, but not after a lot of turmoil.
I absolutely cannot believe someone could be so evil, cruel and opportunistic. Basically, I'd built something that was a working, sellable product as is, requiring very little human intervention, and they decided to steal it off me.
I'm actually glad to be out of it, but I have to say getting into business with that person is a huge regret. Also, my ex-colleague who was her life partner obviously helped with figuring out what accounts and stuff they needed to take complete control of everything. I didn't think at the time what was going on when they were asking for owner access to everything. It did strike me as slightly odd but I trusted them.
As bad as it was, I've learned a lot from it: 1. Don't go into business with people you don't know really, really well. 2. Some seemingly nice people can be utter, utter shitbags for money. 3. It turns out that some people will literally completely make up stuff about you and tell it to other people. Things with not even a grain of truth. 4. Expensive lawyers are worth the money. 5. It feels good to win when someone does something shit to you like that. 6. Nothing matters more than family.
Sometimes we make things in our youth that end up getting people arrested. Sometimes nobody knows you even participated in coding and releasing some of the worst bots that are still used today in variants for banking theft software. Sometimes you just have to keep it to yourself and be the hacker you were when you built those evil things. Above all else you were/are a hacker and you should never claim your evil hacking deeds for yourself and should always do it for the love of the game.