Goldman's Self-Defeating Case Against a Programmer
bloombergview.com
bloombergview.com
One reason that this is an outcome of the Aleynikov case is that Michael Lewis made it so, despite the fact that it does not appear to be true: in both the Second Circuit review of original federal case and according to his own lawyer's stipulations in the new state case, the finding of fact is that the majority of the code he took was not, in fact, open source. In fact, his own expert witness in the first case was (according to filings, which may be missing context or additional facts) only able to conclusively identify a few files of open source code.
The idea that Aleynikov was victimized by Goldman's unwillingness to cooperate with open source projects is a hacker-friendly narrative. We should generally be wary of hacker-friendly narratives, like the FBI dragnetting Google searches of pressure cookers; they tend to turn our brains off.
Corrections welcome; I've read some of the filings in this case, but not all of them, and on this issue I am allergic to Lewis' reporting, which I believe to be uncharacteristically and dramatically shoddy.
But that's beside the point: this article is presented not as an honest retelling of the facts, but as a window into how engineers might perceive this case, and the impacts that perception has on banks' abilities to recruit the best talent. And from that perspective, it's spot on: it drags into the open a lot of poor practices that banks have and how they're a poor fit for the hacker culture present at the top level of engineering talent. Even if that doesn't represent reality, it reinforces that perception: young engineers graduating from college and looking for a job have a certain negative connotation with banks as a result.
If you want to work in software, try to go for companies whose main product is software.
These are the companies that will take software quality seriously because their bottom line depends on it.
These are the companies that will constantly try to improve their craft by exploring new technologies because it helps them maintain their competitive advantage.
These are the companies that will truly value talented software engineers because they have the potential to make a positive impact in the products that define the company.
If the company's focus is on anything other than software, whatever you're working on becomes a means to another, more important end. Your work then becomes that much less valuable, and you, that much more replaceable, to the company because they're only looking for the bare minimum functionality out of the software you develop to enable whatever it is the company does that really brings home the bacon.
I realize this is probably an over-generalization, and exceptions will definitely exist, but so far from my experiences in job searching, this seems to hold in an overwhelming majority of cases.
I used to think this before I worked at a software company. The problem is software companies have far more time pressure, particularly small and medium sized companies. "We'll go out of business if we miss this deadline" doesn't result in high quality code.
The best code I've seen was written for a telecom. The company had the resources and the patience to do it right, and (more importantly) the people in charge knew what they were doing.
A software company providing that same product as a vendor, would be unlikely to have the motivation and focus to do it the same way.
Key for me, is the principal/agent distinction. If you are using something as principal, for revenue, your motivations are very strong. If you are producing it as agent, for someone else's revenue, trickier. By definition, less money for you to get it right as agent for someone else.
That said, there may be dozens to hundreds of ancillary software processes at a large business which are done very poorly, but any smart business of size will take great care of where the money comes from.
Comparing an established telecom with a predictable revenue stream versus a software startup doesn't exactly make for a fair comparison.
If you instead keep the size and available resources at least somewhat consistent, and look at software written for say a large telecom vs a large software company, or say a software startup vs a hardware startup, for instance, I think the tendencies I outlined in the original post will still hold in an overwhelming majority of cases.
I am not knowledgeable about the specifics of this case, but the way that you stated the situation, this isn't double jeopardy.
Double jeopardy concerns trying someone for the same crime. If it is a different law that he is charged with (even for the same 'action' as previously charged), it isn't double jeopardy.
The entire basis of the US criminal system is that in the case of prosecutorial misconduct / incompetence, the benefit of the doubt goes to the accused. It's better to let a guilty man go free than to lock up an innocent one. If we're eroding that basic premise through an increasingly opaque legal system, that's a big problem.
Is that a good thing?
Any programmer's own code is open to whatever they want to do with it.
I want to put my code on pirate bay ? I should legally be allowed to do so.
The question that needs to asked is how is it allowed for companies to prevent the author of a codebase from using it on their own disgression ?
There is a price to pay for this - we do not allow those poor multinational to profit massively.
Programming in 2015 is socialism at its finest. How many programmers do you know who work on isolated codebases ?
We live on the shoulder's of giants. Allowing companies to force programmers to hide or take ownership from their own code is bad practice, and harms human innovation.
It also allows companies to force modern day serfdom on their knowledge employee.
Here's a hypothetical. Apple hires someone and pays them handsomely to build critical software for the iWatch. After he leaves Apple, is he allowed to take that code to Samsung?
You fund yourself have fun doing whatever you want with the code.
Company funds the code they are the owner of the code since they paid for the code.
If your analogy holds you write code for a client on contract. After you give them the code you can't just give/sell the code to the compeditor or put the code on paste bin for everyone to see. You would be unethical and open for a lawsuite.
It's also true, as my sibling commenter points out, that boilerplate contracts have CYA "for hire" provisions in them.
This is a bit of a silly digression, right, because if WFH was going to exonerate Aleynikov, his very-expensive lawyers would have deployed it as an argument. But it would be dangerous for readers to rely on an Internet argument that their own employee work contributions might be their own property, so it seems worth correcting this.
WFH is very relevant for contractors (who are by definition not employees), but less so for full-time employees like Aleynikov.
Incidentally: you don't have to answer questions about US law "from memory". The answer to this question --- which, by the way, is a whole pamphlet the Copyright Office publishes specifically to resolve confusion on this question --- is a Google search away.
§ 204 . Execution of transfers of copyright ownership
(a) A transfer of copyright ownership, other than by operation of law, is not valid unless an instrument of conveyance, or a note or memorandum of the transfer, is in writing and signed by the owner of the rights conveyed or such owner's duly authorized agent.
So it would seem that I didn't realise that there was a clause "other than by operation of law"; but you will also note that my last statement of my comment said that you should get a lawyer...
A “work made for hire” is—
(1)a work prepared by an employee within the scope of
his or her employment; or
(no further qualification is made regarding A.1)But my final point is still valid (as is supported by standard employment contracts covering IP rights even though it is covered under title 17) that if something is important to you get it written down in a contract and make sure it is checked by your own lawyer.
I don't know whether this is universal to the EU, but in Germany it works the way you describe: even if you get paid to do it, unless you're explicitly granting exclusive rights, you only grant a non-exclusive right.
For example, if you hire a freelancer to write you software, you don't have anything other than simple usage rights unless you signed a contract with them explicitly granting you additional rights. Even if you gave them a bunch of requirements and defined deliverables.
This is a case where the braindead application of existing copyright (e.g. how this works for commissioned literature) actually resulted in a good thing.
Sure, if someone else didn't buy it from them by paying them a wage.
Should I be allowed to sell the exclusive rights to all of my code to my employer, in exchange for a salary? Or do you want to deny my ability to make that contract -- that is, deny me the right to full ownership of my code?
Ford line workers don't own the cars that come of the line do they.
Under US law commissioned works may "belong" to the commissioner. Under German law, for example, they don't, unless that's explicitly part of the contract.
If anything, software is comparable to other commissioned works like art, literature or architecture.
ah, yes, of course. That's why Aleynikov encrypted the source code, uploaded it, then cleared his shell history to hide what he'd done. Because his English wasn't good enough to understand the U.S. legal system.
The same thing almost happened to me once. We did a lot of XML parsing at company A, for which we used the open source libxml. But work there got boring, and I wanted to make a fresh start, so I went to company B, where I also knew I'd be parsing some XML. For a while I considered encrypting the libxml code and secretly uploading it on my last day so that I'd be able to use it at company B. Fortunately, I grew up in the US and am familiar with the customs here, so I decided instead to wait until I arrived at company B, and then download libxml from xmlsoft.org. To think I was >this< close to jail...
This wasn't King's Quest.
I can find that King's Quest is a game, but I can't make the connection to this discussion.
From the article: "Imagine you're a highly skilled programmer, perhaps an immigrant like Aleynikov, unfamiliar with the intricacies of the U.S. legal system and not 100 percent confident in your English skills. You're probably more at ease dealing with machines and the abstract tasks they solve when interpreting code than with people -- otherwise you'd do something else for a living. "
What the heck?! What kind of professional writer writes something so child-like/troll-like?
Another: "Traditional banks tend not to be such smart employers."
We're talking about Goldman Sachs here. You know, the guys who employ people in tech (their CEO even referred to them as a Tech company) to keep ahead of the curve and who regularly make some serious profit. Yahoo, https://uk.finance.yahoo.com/q/is?s=GS , shows I think 2 billion USD net profit per quarter.
And another: "Goldman may be hoping Aleynikov's case will set an example to others like him, teach them to respect the bank's rules. Instead, it will tell good programmers to go elsewhere and perhaps, sooner than necessary, make Goldman obsolete."
Perhaps this has changed GS, I don't know. Look at GSCollections (https://github.com/goldmansachs/gs-collections), something internal that they've open sourced and is now used by a fair few projects including spring.
[edit: better layout/formatting/grammar]
That seems to be what happened in this piece, which betrays no evidence of being informed by any of the court filings.
Now, the intricacies of the US legal system is another thing - you don't have to be an immigrant to get lost in it, I'm pretty sure 99.99% of US-born population have pretty vague idea of the vast corpus of the existing law. But that's much bigger question that does not get the fair treatment by trying to sell us a condescending caricature of "poor immigrant doofus caught in the world of complicated English words".
Creating an archive of code, encrypting it, then uploading it on your last day at work.
Just before leaving an incredibly sensitive job in the single most competitive part of the financial sector for a job paying 3x at an arch-competitor of his current firm, a programmer cloned a huge collection of source code --- the majority of which was proprietary and not open source taken from the single most sensitive technical asset at his firm, an asset which his new 3x job at the competitor was to reproduce, and uploaded it to an offshore Subversion hosting service nobody had ever heard of before. Later, he is shown to have presented portions of that code to his new firm.
The only people on HN who think this is OK have that view solely because they think it's OK to do virtually anything to Goldman Sachs, because of the abuses Goldman Sachs has inflicted on the world's giant squid population.
That is a fine and intellectually coherent position to take: firms who harm giant squids do not deserve the protection of law. But people holding that position should be clearer about it, and constrain themselves to squid-based arguments.
Once a bit of copyleft code is modified and included in a binary, the legal question of whether the result is open source is not trivial and certainly open for discussion. That being said, it is certainly the intention of many people releasing the code under copyleft licenses that any modified work be open source. It is completely unfair to project the idea that all people siding with Mr. Aleynikov do so solely due to animosity towards Goldman Sachs.
It is completely circumstantial that he tried to hide the fact that he made a personal copy. It is often best to avoid having a discussion. I try to hide from my parents the fact that my wife and I... well you get the idea.
If this is true, it's a pretty big smoking gun. You really do your argument a disservice with the squid thing.
And personally, I would delete shell history on principle when leaving a job. I also delete my browser cookies and stored passwords etc. With the big plastered on warnings everywhere that all computer activity is monitored and recorded, it should be entirely reasonable to assume that these copies are redundant and disposable.
I have a lot of people I have to interact with that insist on force me to login to their stupid sftp servers using plaintext passwords and they configure their servers to force interactive mode. And I very likely have PHI in my command history, too. There's absolutely no reason to not delete shell history when leaving a job, particularly now that HITECH means that I can be personally criminally prosecuted for data breaches.
Besides, what constitutes "deleting shell history"? The way bash works by default, the last closed terminal deletes all the history of the other terminals.
Does Goldman Sacks require users to maintain full shell history files as a condition of employment or as part of their expected work behavior or work product? I very, very much doubt it.
That does not seem like sound engineering practice to me.
Edit: can't seem to reply to response below, so I'll just add here, if code theft requires intent to "permanently deprive" someone of their property then you need a pretty strange definition of "permanently deprive" as well.
Actually, it usually does: "Theft is often defined as the unauthorized taking of property from another with the intent to permanently deprive them of it." [0] (emphasis added)
[0] http://criminal.findlaw.com/criminal-charges/theft-overview....
It doesn't really matter. By uploading the code, he committed numerous violations: breaking copyright, breaking confidentiality agreements, breaking the CFAA, etc. In his case, there is no valid copying.
That he zapped his shell history is just a bunch of sugar showing that he knew what he was doing was wrong. That he did it upon the day he left for a new job gives him a financial motive for doing what he did. Both are just the icing on the cake; even if he didn't do either, he'd still be in deep shit just for uploading the code at all.
Another way of looking at it: Lets say you were a collector of widgets. And Acme Widget Co. markets a given widget, which they say only 100 instances of it are ever made or are going to be made. So you purchase that widget because you know it will be worth a premium to other widget collectors, due to its rarity. Now, assume that after you fork over big money for a 1-in-100 widget, Acme then decides to make a million of them, selling for a fraction of the original price. Now your specific widget, which you still own, is worth much less. Wouldn't you want to sue to get your purchase price back, since they sold it to you under false pretences?
Mens rea or something.
This is where the entire article just falls apart. They're trying to imply people will be afraid to work for Goldman because they might get sued if the work for someone else in the same industry.
But if you're actually taking code a former employer paid to develop to another company it's perfectly reasonable for that former employer to seek some kind of redress. Most people understand this.