Security audit finds dev outsourced his job to China
securityblog.verizonbusiness.com
securityblog.verizonbusiness.com
Since many people on HN will eventually find themselves having to care about the distinction between an "employee" and an "independent contractor", because hiring the first costs you extra taxes: if a person isn't allowed to outsource themselves, that is strong-but-not-dispositive evidence that they are an employee. If you sign a contract with a consultant, it is highly likely that the consultant has the right to direct fulfillment by anyone he thinks capable of giving you what was agreed upon. He has wide discretion in picking subcontractors, just like he also has wide discretion in picking what hours he works, how he performs the work for you, what tools he uses to perform the work, what other employers he works for, how he comports his professional affairs, etc etc.
I've seen a boilerplate contract or two for consultants which forbid them to do this. If your boilerplate has that, you might want to ask your competent legal representative on whether there is a risk of a contractor being retroactively reclassified as an employee by the IRS. (You profoundly don't want that. Grellas has a magnum opus on it here: http://news.ycombinator.com/item?id=1137930 )
Similarly, as a consultant, it is probably to your advantage to assist your clients in meeting their legal obligations by e.g. preserving their lack of apparent or actual control over you.
Bob wasn't even the programmer's name. It was just a pseudonym given by Verizon for the purposes of the case study.
He was able to coordinate $100's of thousands of dollars worth of outsourced work that his employers (more like 'customers' as the case may be) found to be top notch, essentially in what amounted to his spare time so they fired him. I'm sure they called it "stealing". I'd call that "management" and damn good management at that.
But you are nonetheless correct. Usually you have to rise to the level of VP of a division before this level of unethical behavior becomes acceptable business as usual.
(1) Interesting what happens when engineers outsource vs. managers, no?
I understand what you're saying about his ability to find an outsourcing firm that actually did good work, and maybe that is because he's skilled in that area, or maybe he was just lucky. But given his demonstrated inability to make good decisions, his unethical behavior, and his disregard for the security implications of his actions, I don't think he'd make for a good manager.
Otherwise it's fraud. He gave permission to access company resources and property and who knows what else without the actual owners knowing about it.
There is nothing laudable about his actions - frankly this is the type of thing I'd like to see "professionals" lose the ability work in the profession for.
If your technical specs and docs were passed along to an outside party, you probably wouldn't be happy either.
In my version Bob got permission from his employer to go overseas for a year where he would work remotely.
Instead he spent a year on the beach in Bali shipping change requests to India and doing code reviews of the work coming back. He still understood the code and everything about it. He explained and interpreted requirement from his employer to his Indian developer(s).
So instead of 8 hours at a desk, he spent 2 hours at a desk providing the expertise he was paid for (to both his Indian developer and to company meetings) and spent 6 hours on the beach.
The only thing he didn't provide was the actual keypresses.
The only problem I see with this is that the company's IP (the source code) was given to someone they company wasn't aware of (which isn't a trivial thing).
The company paid an expert to provide them with his expertise and to complete particular requirements. He did both.
However, this is an absolutely horrible piece of journalism. What company is it? For all I know, this story could have been completely made up and it certainly lacked any sort of journalistic investigation other than to rip off the report.
Or is outsourcing unethical in some other way?
Whether that be buying DVDs, software, books, watches, or any type of good or service, the big buys will try to make it illegal.
Boo fucking hoo.
Second, don't give the keys to the company to someone not authorized by the company.
Third, If you ignore all this, cover your tracks and move around between companies so that nobody can put the pieces together. ___
Otherwise, I've had ideas of putting together projects that don't divulge company secrets in the offshoring world, and for that matter, I've thought about using it to get open source done under my name. I'd maintain the project, and pay offshore developers to do the grunt work I didn't want to. Sometimes I wonder if that's what substack or Jeremy Ashkenas does. ;)
But otherwise, go read Four Hour Work Week. It's not a new idea.
On the other hand, if the work was better than the employee could have produced individually, then this was a net benefit for the company. I think it's obvious that the company couldn't keep the employee, but it might be worth bringing him back as a consultant to manage the team in China if the company finds that acceptable.
Poe's Law strikes again.
I could do with someone who can organize and manage programmers.