EDIT: Also, all of their press releases sound very immature.
EDIT: Also, all of their press releases sound very immature.
The way this works is that you, as an ADP client, call them up and says "hey, I've asked my HR firm, XYZ-HR, to manage my payroll. Can you create an account for them to access my payroll system?" ADP creates this account, and XYZ-HR then handles all the payroll admin work going forward -- adding employee, terming them, inputting hours worked, managing deductions, etc.
This is how this has worked for years, and it's how thousands of companies do this via ADP. Even today, as an ADP RUN client, you can call in and add any third-party person you want as an admin to your payroll system -- as long as it's not Zenefits. ADP has marketing materials that describe this feature, both for companies and HR / bookkeeping / accounting firms. This is how Zenefits was accessing client's payroll, and doing so in order to take on all the administrative work related to payroll that you don't want to handle. We weren't "hacking" anything. We were doing this at our customers' request, with their full knowledge of what we were doing, and ADP set up these accounts with @zenefits.com email addresses, knowing it was Zenefits.
There is nothing improper about how we were doing this.
You were automating it, weren't you?
With bookkeepers, accountants, etc. the login and work done on the system was manual. It was an actual person doing it.
In your case, a computer is doing it instead.
Virtually every site out there, from Facebook to Twitter, prohibits the use of bots and scraping. Not surprising ADP isn't a fan.
What is surprising is that you feel you're entitled to access their system however you want? It's their system. If they want to prohibit bots and allow only people, that's their biz. If you think ADP is full of it, create your own system with a public API and put them out of business.
So they will create an admin account for a person - a single, human individual.
> In addition, Zenefits’ method of extracting data from ADP’s RUN system via “screen-scraping” put excessive demands on ADP’s servers, potentially impacting service delivery to the entire client base.[1]
If you weren't using the API, and instead were having a machine log in to access the data, that is pretty much the definition of scraping. There is a difference between a person using an admin account setup for them to log in and perform a certain set of actions and hundreds of accounts setup for the purposes of continual automated logins.
How many requests did you make? Do you rate-limit your queries to the rate of a human-being (maybe 1 click every couple of seconds)? Do you only login to one or two accounts at a time?
I still don't see a valid reason why any company (big or small) should have to invest resources in supporting a third-party that wants to use its data in an unsupported manner. Of course you can argue that they allowed it in the past, but an entire business shouldn't rely on unsupported access to something without the assumption that it could disappear at any minute.
[1] http://techcrunch.com/2015/06/10/adp-sues-zenefits-for-defam...
Imagine if a company asked for your Google password instead of using the proper API channels. I don't know many users who would do that.
This would be more like creating a new Google Apps email account for someone, and allowing them to use it to (e.g.) manage things on your Google Drive (by sharing a group folder with them).
How many companies hire a 3rd party accounting / HR firm (or person) to manage their bookkeeping? How many of them create an ADP admin account for these people so that they can manage payroll? How is this that much different than Zenefits?
Of course, ADP doing that is not doing right by their customers, but who cares, they're just cash cows.
I feel like maybe the point of my post was not completely clear, though: this would not be a problem, and Zenefits would not be doing this, if ADP was good (not good in the "not poor software" sense, but good in the moral sense). And we should be faulting ADP for not being good to its customers, not Zenefits for trying to bring good to ADP's customers.
Furthermore, a profit-seeking corporation shouldn't really be on the moral scale to begin with. At best, they should be amoral, that is, not involved at all in morality. Their primary goal is, and should be, to earn more money, not to be good citizens of the world.
I would suggest it's much better for the laws and regulations to be setup so a profit seeking company would end up being a net benefit. But, suggesting company's should for example try and corrupt politicians in the name of profit seems rather dystopian.
PS: It could even go the other way where a CEO feels it's his patriotic duty to aid his government so he wants to start a bio-weapons division. The point is not the choice the point is why it was made.
You are very much mistaken. Society provides the corporation with legal protections and recourses as a fictive person with the understanding that the corporation's existence betters the society, betters the people within it. When this agreement is breached, the society can--though, unfortunately, rarely does, due to globally weird veneration of toxic behavior as "just business"--destroy it. (It has happened before. It should happen more often.)
And let's be really real for a sec: if you look at the stretch of history, neutrality is effectively tacit support for bad behavior. And from a practical perspective, a call for "amorality" is tacit support for immorality.
You access HN by your browser, the same as Zenefits' customers accessed ADP services indirectly ..
The point is where to put the line between what's a good allowed access, and a bad too-much-indirection access
The existence of a public interface usable by humans (a web app) does not in any way imply the existence of a machine-usable protocol for accessing that same functionality. If you infer one, you do so at your own risk. By the same token, the existence of a machine-usable interface that is not public does not imply a contract that it will continue to exist.
If you build your business on an imagined contract, be prepared to have a bad day when the other "party" to the non-contract "violates" it.
Is that non-implication better for consumers? For people?
If not, why should it exist?
Machine-usable protocols is what make possible to humans use public interfaces (web apps)
When was the last time that you injected electricity to a cable to send a HTTP request?
How is that relevant? Putting up a web site does not obligate you to then do more just because it would be even better.
Where it seems to have worked: Uber, Paypal, et al.
Where it failed: Twitter clients, Craigslist front-ends, et al.
https://news.ycombinator.com/item?id=9694530
The "right way" is hard, and more likely to be painful, certainly. But when you're done, you're done. The "forgiveness>permission" way has the added downside of your customers getting screwed too, and likely considering litigation.
Every U.S. business gets sued, it's the American way.
As a gratuitous side-note: despite the HN hatred of Uber (and I'm one of those who hate the company), the company wouldn't be growing if it's users didn't love it. Unlike the other most hated companies--mainly airlines, cable TV providers, and telecomms--users of Uber can very easily choose to use an alternative. Here in NYC, the alternative--flagging down a yellow cab--is probably actually easier to use than Uber, yet everyone I know uses Uber anyway. They're clearly doing something right.
I believe we had incurred over $50,000.00 in fees before we ever reached the testing stage or purchased the right to use the API (that license is on a client by client basis, too). That $50M number was fees directly to ADP, and does not include our own payroll and expenses.
We were completely bootstrapped and started with about $70M in the bank, yet we were still able to complete that integration. I can't see how a company with over $500MM in funding[0] couldn't unless they were prohibited by ADP.
I'd go the Zenefits route too [and we do for our automation in relation to ADP precisely because ADP's API is insufficient]
I don't think the issue is as cut and dried as the typical web scraping situation and I wonder how HN readers feel about this kind of thing. The data belongs to the client. The client chooses to use both services. Should it matter how the client accesses their own information from the service? Are they required to use a web browser? Would you feel the same about them using their own wget script to automate interactions ADP? At what point does it become improper to access a service differently than that service wishes you to access it?
From a legal perspective, the profit-making purpose is irrelevant. Improper access matters when you start using the service.
Why? They are having to pay them and then buy your services for data entry. This is no more unethical than hiring someone to do your banking for you.
Violating an EULA by doing this may be unethical, but in that case, it is violating the EULA that is unethical, not the general practice of providing a new interface.
> Improper access matters when you start using the service.
I don't know what this means.
I don't think so either. Would people feel the same if a store banned wheelchairs? You can write a EULA however you want, but I don't think you should be able to enforce arbitrary provisions which harm customers and potentially violate the Americans with Disabilities Act. Probably this has nothing to do in practice with accessibility for disabled people, but it is related to accessibility and user experience for everyone.
(Disclosure: I write web scraping software... nothing related to this. Also I'm speculating about general circumstances, not individual companies, so please no libel lawsuits :)