4 ms·
I would call it a fear issue more so than loyalty. I would be willing to bet not a lot of people knew to begin with, and the few that were told or stumbled upon
by baakss 11y ago
I would call it a fear issue more so than loyalty. I would be willing to bet not a lot of people knew to begin with, and the few that were told or stumbled upon it didn't want to make it into a big deal for fear of getting caught up in a problem.
In the past, when I've seen a situation like this, one person in middle to middle-upper management made the call, and seriously only 1, maybe 2 devs were involved. If those devs said anything, it was usually a halfhearted attempt to escalate the risk, and was ignored as "well, that manager must have some reason" or "That's too hot of an issue."
I know, it's a crappy mentality, but most people don't want to get caught up in a big ethics issue at work. It's extremely risky for the person escalating.
As far as how only a couple people might know this even happened, corporate codebases are sometimes a total mess. There usually aren't things like code reviews. Project managers sometimes have absolutely no idea what the project actually is or what the requirements are. Devs often work in a bubble with shoddy requirements worked out by managers in the business and/or IT management. Not every company works this way, but I've seen three like this where the SDLC was miserably flawed.