Tata Consultancy Services ordered to cough up $210M in code theft trial
theregister.com
theregister.com
My experience of it is in advertising, look at something like GroupM. They intentionally make a set of agencies to act as different front doors into the group so they can make it look like there are no conflicts of interest. Then once work comes in the door it all gets serviced by the same shared resources. The 'front door' agencies of course promote as a centre of excellence with deep expertise etc. but you really don't need to read between the lines very much.
For the consultancy it boils down to not reinventing the wheel, learning from others and sharing knowledge about what works and what doesn't. Typically, what is shared are anonymized generic design or cases and not actual code or design files though.
Of course what is knowledge sharing and efficiency for consultants might simply boil down to IP theft for the affected companies. My question is rather how much of it is natural human social interaction and collaboration if you put dozens of people from dozens of projects into one room talking about a similar problem.
Working for a tech consultancy before, they do have clear lines to distinguish for legal reasons and make you take courses. For e.g., you can't give or receive gifts of any monetary value, etc. But management find other ways, to gain client's trust and affection. One way is to overwork the consultants, and other is to share information that is privy sometimes.
This happened in 1999-2001, so it isn't recent & won't affect any outcomes. But it goes on to say it can blunt a prior client company's competitive advantage.
To say that this always involves illegal copying of code in some way would imply that an employee is effectively forbidden from ever writing similar code in two different companies - are you supposed to be forbidden from re-using the experience you gained working for a company ?
No but adding implementations to competiting company's product based on the innovations seen in the first falls squarely under IP misuse (At the least, bypassing patent licensing etc.)
Software domain would see acrimonious litigations cases based on mundane things like the rubber band scrolling (Apple vs. Samsung). Adding readout specific databus improves acquisition speeds by order of 2 or 3x - and that is not a trivial change which can be disregarded. Most times they've been misused since they were minor trade secrets not patents. There was no way to attempt litigation in this one without opening up certain parts of software ecosystem to legal scrutiny/comparison (which probably exposes more IP).
I suppose this is an interesting question, not quite black and white? That said, don't these huge companies have armies of lawyers to protect their IP?
However in many cases of enter-rise software, everyone involved knows perfectly well that copying is happening. In which case there is nothing immoral ~ just a mismatch between elegant and actual reality.
In this case it is very straightforward legally if they copied documents over. You just can't do that, full stop. But I'm uncomfortable to say that this is an equitable relationship between all these companies, because it gives a level of protectionism to DXC to do a really poor job in delivery knowing that the American court system has their back if they lose on re-compete.
Indian engineering colleges really need to start cleaning up the detritus, it is time to provide healthy base for the young ones. Once a culture builds up, the managers at consultancy will feel ashamed to cut loose on ethics even under pressure. Or not, but a start has to be made in this aspect.
previously on HN, https://news.ycombinator.com/item?id=38432752 Zenefits Software Helped Brokers Cheat On Licensing Process (buzzfeed.com)
As if the engineering grads make these decisions and not managerial types with MBA degrees and "connections".
Indian engineering colleges already have 2-3 such courses in curriculum and don't need to fit yet another subject which nobody cares about, instead of teaching actual skills.
The actual knowledge of average Indian Engineering grad is very low, except in leetcode.
This is the root of the problem.
It's managers who usually make these decisions, not engineers.
Doesn't the ruling elite of most countries study humanities courses? Does that prevent them from commuting much worse attrocites than this?
To be clear, I see more "gaming the system" behavior in India, but it's purely a result of more cut-throat competition in the market. "Ethics" and "morality" courses have shit to do with it.
It's a problem of corporate culture and incentives.
Engineering ethics is knowing what's right or wrong when performing engineering work. Children develop a pretty decent sense of right and wrong. It isn't rocket science.
A 22-year old ordered by their manager to falsify data in their first month on the job knows it's wrong. They aren't going to refuse because they took some course in college. Whether or not they do it is more likely a function of how prevalent that behavior is in the organization, how often it's caught, and how publicly it's punished.
Now, with this kind of money and scrutiny you have to follow the letter of the law, whether it is productive or not. TCS should know better. But we can't pretend that this is about ethics.
However, the champagne corks won't be popping at CSC just yet. If the Epic experience is anything to go by – the decision was appealed – there will likely be legal twists and turns aplenty before payments are made and the case is closed.
6 days ago: TCS will be making a balance provision of $125 million in the December quarter of FY24, after the US Supreme Court rejected the company's plea in a matter pertaining to EPIC Systems Corporation.
https://www.fortuneindia.com/enterprise/tcs-to-make-125-mn-b...
> the United States Supreme Court on November 20, 2023 rejected the Company’s petition to file an appeal against the orders passed by the US Court of Appeals, 7th Circuit
Company CFO and CIOs need to do better dilligence of their vendors. Two simple contract clauses: priced soliciting to price staff pouching, and treble-5x damages for IP theft.
Develop a heuristic - any consultancies brought on from 3rd party contracts must sign enhanced protection clauses. Cite publicly available info to support your position. All it takes is a quick google and a few boilerplate clauses
(Preemptive disclaimer that I'm not a boomer. I'm not from the US, but if I were, I'd be gen X).
I believe it’s divided like so: 1947-65: Invested in National Success and self determination. Do more with less is key. Govt Jobs are the best jobs.
65-80: First Gen to start moving abroad, more private opportunities, care about making money and enterprise.
81-00: First exposure to the West, TV, entertainment. More holistic in their wants and desires, such as love. Witnessed the westernization.
00-16: Grew up with Western ideas and tech right beside them. More online, more diverse etc.
I am not an AI guru, but, from my limited understanding, LLMs use trillions of inputs, and that's one reason why they work so well.
What we have now, is barely out of the playpen. I am quite sure that specialized LLMs (like troubleshooters) are well under way.
What did you say? That it is also complicated to deploy properly? And there is no objective way to measure its success? Christmas keeps coming early.
I have been using 3.5 to write code. I wrote a 'simple' app (200-300 lines) that although 'simple' it took A LOT of back and forth with the 3.5. In the end I had to spend a couple of days combing through it to add some key features (i.e. set values to zero so you don't see old data, etc.). Basically crude (but smart?) coding (I am not a professional developer).
When I finished the code and the app was performing EXACTLY as I wanted (v1.0), I thought to start planning for the v1.1 and when I pasted my code to the 3.5 and asked it to 'work on it on the new features' it was a shitstorm :)
Perhaps it was me feeding the requirements 'wrongly', but it was like pulling teeth 'guiding' it to correct even the simplest mistakes.
I'm surprised by the inability of people in tech to extrapolate the advancement of this particular tech.
But even if you want to torture this analogy, LLMs are a godsend to techncial service Companies. It's like saying "Oh, planes are faster so I guess people won't be spending as much time traveling and there will be less of it now".
> Even chatGPT 3.5 can be better than them.
Have you actually worked with a consultancy? Have you priced out what the back and forth you had with 3.5 would have cost with a real human with a similar level of depth?
_
I personally don't think AI's effect on offshoring will be so cut and dry, since it's not like offshore developers can't level up with it too, but your example is showing how badly people are underestimating the impact AI will have on programming.
But I have no way of knowing what happened behind the scenes. Perhaps the state agency gave TCS a license to use the code we developed (the agency, not our consultancy, retained ownership of the code). Or maybe some of the TCS people who worked on maintaining the code for the agency later went on to build a new system from scratch inspired heavily by our system. There's no way to really know from my vantage point, but given this story, it sure makes me wonder.
Why would it have to be one, and not both?
That's the situation TCS contractors are in. Now, laws are laws, and we have to follow them. There is always plenty of money to do things by the book. I thought this was a gov. project, not insurance, but the principle is the same. Transamerica is getting worse service because the contractor that they prefer wanted to look at documentation for a system they payed for. This is why enterprise IT is a legally mandated mess.
No, I don't believe that's at all what was happening. I really recommend reading the original compliant[1]. TCS was leveraging their employees with access to CSC's documentation and source code to glean information about how a particular feature was implemented, _not_ for supporting Transamerica, but for reimplementing the feature in their own product.
From paragraph 29 of the compliant:
> A TCS employee, who upon information and belief is part of the U.S. BaNCS development team, wrote in an email: “Quite honestly, I’m not sure how VTG [Vantage] does this today, so maybe we should engage [TCS employees with access to the Vantage source code] if we want to emulate that?”
The complaint goes on to describe the engineers sending the actual source code to the team. This is pretty clear cut theft IMO.
This is why enterprise IT is a mess. Every time you need to do anything, you have to triple check that you aren't violating some clause buried in some obscure legal agreement that you probably don't have access to. Or else, you could cost your firm a quarter billion dollars or more. So you end up with reams of dead software that is unusable by design since it is being held hostage by various different commercial interests. I understand that is just the world we live in when millions of dollars are involved, but we can do better.
On the other hand I get the concern: you would want some legally enforceable agreement with TCS that they won't steal confidential information you share with them in good faith to steal business. Nor go and hire a bunch of staff to poach your contract. But documentation of the software that Transamerica paid for is secret, are you kidding me? They would have been fine, legally, if they got the materials directly from Transamerica. Because they got it from someone who merely used to work there, it is a quarter of a billion dollar mistake. Seems like a pretty narrow difference to me, hardly some kind of grand ethical quandary.
This is not the case. Regardless you state that there is a single choice to be made, getting something that works OR having it done legally.
It seems TCS might have tried to plagiarize those rule implementations.
> "In any given quarter, there will always be some amount of de-growth. What's happening now is that de-growth is not being compensated fully because clients are optimising and there is some deferral happening," said K Krithivasan, MD & CEO, TCS.
> "If the existing projects get paused or optimised more than the incoming revenue, it results in muted or moderated revenue growth," Krithivasan added.
> According to Krithivasan, once things settle down, this optimisation will be compensated by new projects.
"Every quarter experiences some level of decline. Currently, this decline is more noticeable because our clients are optimizing their operations and delaying certain activities, which isn't being completely offset," explained K Krithivasan, MD & CEO of TCS.
Actual words for this are "decline", "reduction", "shrinkage", "decrease", hell even "atrophy".
Either it leaves a better or less worse opinion of what was said compared to normal language, or it makes everything so unclear that the listener has no hopes of understanding the real, desolate, message.
This, combined with "never saying no" and "never give bad news", has twisted simple communication behaviours.
It was supposed some event about signing up for intern roles with them.
Instead they had some activity that people had to do and it was more like a mini competition.
The example activity was they had acquired some company and the objective of the task was giving ways to tear the acquired company apart to extract value (layoffs, spinoffs, IP etc).
I left during the break.
It's a bottom to top evil company.
Worked there for a while, can confirm
And the winning kid to join the Wonka consultancy was the one who not only chopped up the hypothetical company, like all the other kids did... but then also loaded what remained with debt, while self-dealing (or whatever it is they do)?
And these (ladies and gentlemen) is why you need smart IT auditors in your corporations. Also robust DLP systems with alerts when emails are sent to 'some' specific domains.