14 ms·
Your Triplebyte profile will NOT contain any data/details about you or your job search that will undermine you at your current employer. We should have included
by ammon 6y ago
Your Triplebyte profile will NOT contain any data/details about you or your job search that will undermine you at your current employer. We should have included a screenshot and more details in the email. I'll talk to my team about following up with more details tomorrow. We are talking about a lightweight profile, like your Stack Overflow or HN profile, to provide us the canvas to release badges. That's it.
- itronitron 6y ago>> The new profiles will be launching publicly in 1 week. You are literally taking private data and making it public without consent.
- travisjungroth 6y agoIf someone goes from not having a profile to having one, you know they’re job hunting. It’s like saying “Your Tinder profile will NOT contain any data/details about you or your dating search that will undermine you in your current relationship.”
- jwilber 6y agoExactly. This is basically like the workplace equivalent to the Ashley Madison scandal, only pre-planned.
- pmiller2 6y agoThat's a false equivalence. You're talking about a business relationship versus an intimate personal relationship context.
- travisjungroth 6y agoMy point is that just having the profile is data. He can’t predict what impact making this data public will have.
- pmiller2 6y agoCompanies that are worth a shit don't retaliate against people for looking at other opportunities. That's precisely why your Tinder example is not just off base, it's wrong. Another way to look at it: either you're a replaceable cog, or you're essential to running the business. If you're essential, they're going to do whatever they can to keep you. If you're replaceable, they probably don't care that much whether you in particular stay or go, but it will certainly cost money to replace you, which they'd rather avoid spending. Only a completely irrational company would cut someone loose just because an online profile with that person's name on it appeared somewhere.
- cameronbrown 6y agoIt's additional risk that nobody asked for.
- barbecue_sauce 6y agoVery few companies are worth a shit.
- tfehring 6y agoBeing fired because you're perceived to be looking for other jobs probably isn't a realistic concern. But being passed up for promotions or missing out on desirable opportunities because you're perceived to be looking for other jobs is a very real possibility, even if you're not easily replaceable. The Tinder analogy is imperfect because of that, but it's still a good illustration of how just the existence of a profile can destroy your plausible deniability.
- thaumasiotes 6y ago> Being fired because you're perceived to be looking for other jobs probably isn't a realistic concern. It definitely is.
- Nexxxeh 6y agoIf I had to lay off one of two employees in a role, both do the role fine, but I strongly suspect one of the two has been looking to leave... Which of the two am I keeping?
- withdavidli 6y agoThe type of relationship is different, but the example still holds. Having a profile at all can and likely will be viewed as an indicator of intention to leave the current relationship for a new relationship. This was how it was viewed having a resume profile on sites like Monster and CareerBuilder before LinkedIn made it the norm to have a public resume. Time frame is also very important. Example, a user has been with the company for over a decade, but the product has only been around for a few years. Or if one of the "achievements" was a test that was added recently.
- pmiller2 6y agoI have a TripleByte profile. Am I job hunting? This is not a hypothetical. I really do have a profile.
- reitzensteinm 6y agoNot necessarily. But what if you didn't have one yesterday, but you do have one today? What if you have only worked for one employer since TripleByte was founded (2015)? What if the only place you've worked is a startup of which you're a cofounder? If you can't think of a way in which a privacy leak can have consequences, that doesn't mean there aren't any.
- pmiller2 6y agoWhat if I have? How does that imply anything other than that I took a test?
- seebs 6y agoIn the sense of a logical implication which follows with full logical necessity: it doesn't. In the sense of a likely reason for someone to draw an inference: Most people do not specifically seek out excuses to take tests, and do so only because they want something that the test provides them with, such as access to a job-hunting platform. Most people who want access to a job-hunting platform want it because they are job-hunting or plan to be soon.
- ori_b 6y agoYou're right -- most people's livelihoods don't depend on staying together with their girlfriend.
- Aeolun 6y agoHow about if you just always have a profile?
- tasogare 6y agoYou shouldn’t expose a public profile for accounts that were private before anyway. Is that move even legal? I’m pretty sure it’s not GDPR compliant.
- wolfgang42 6y agoEven so, the decision to make this opt-out instead of opt-in is extremely questionable. If it’s just a spot to put badges, why is it so critical that it be rushed through next week? And why are you so carefully avoiding talking about the opt-out when a significant chunk of the people in this thread are telling you that it’s the main thing they’re upset about? “Sorry that you feel this way” is the worst kind of corporate-speak non-apology that makes it clear that you’re apparently not interested in responding to feedback, but just making soothing sounds at everyone until the smoke clears and you get to continue doing exactly what you planned.
- marcinzm 6y ago> If it’s just a spot to put badges, why is it so critical that it be rushed through next week? I'm guessing it's because their corporate metrics took a dive due to covid hiring slowdowns and now they need to justify their worth to investors who have put in $50 million.
- ALittleLight 6y agoI don't get why you'd think it's okay to suddenly make private information about your users public. The lesson is not "We should've included a screenshot" but rather "We shouldn't automatically opt our users in to sharing information they thought was private.". This is a betrayal of user trust. I saw your email in my inbox but didn't read it. I never would've noticed with improved screenshots or not. Do you read every email you get?
- ako 6y agoDid you read the fine print when signing up? Maybe this goal has been in their fine print for a long time.
- g_p 6y agoFrom a GDPR perspective, for anyone who is able to lay claim to GDPR protections, it wouldn't matter whether this is written in red on the first line of the agreement - "data protection by default" means that you must default to not sharing with an unlimited number of people. What this means in practice is you can't default anything containing personal info to being public by default.
- TeMPOraL 6y agoYup. One of the best benefits of GDPR is that you don't have to read the fine print anymore, because companies can't legally put anything abusive in there, at least with respect to processing your data.
- g_p 6y agoAbsolutely. Article 25(2) is written for this specific situation, and expressly prohibits opt-out situations where personal data might be made publicly accessible: "In particular, such measures shall ensure that by default personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons."
- 6y ago
- iovrthoughtthis 6y agoHey! Welcome to your first PR disaster. I would suggest you step away from any scripts and turn on the company ears. Simply explaining what is going on more “clear” and repeating it more often probably won’t get you anywhere good. Why does this make your users uncomfortable? How can you work with them to achieve your product goals without undermining your relationship with them? Good luck!
- travisjungroth 6y ago> How can you work with them to achieve your product goals without undermining your relationship with them? Literally just make it opt-in.
- localcrisis 6y agoOpt-In doesn't help them achieve their product goals. Triplebyte as founded isn't working so they're trying to take a valuable asset they have (engineers looking for jobs) to compete with linkedin The problem with bootstrapping a linkedin competitor is the same chicken-and-egg problem with networks generally. You need people on it for people to join it. What Triplebyte wants is your identity public. That's the product goal. The problem is that opt-in won't get them that. What are the incentives for anyone to make theirs public? How many people who were searching for a job without telling their company are going to opt-in to make that public? Most certainly not enough to bootstrap a LinkedIn competitor. So someone had the idea to move fast and break things, either: a) hoping no one would notice b) hoping the fallout wouldn't be bad c) not caring that the fallout would be bad d) not knowing that there would be fallout none of the above are particularly inspiring. It does seem hard to miss this coming
- shawnz 6y agoThey could prompt at next login instead
- toyg 6y ago> How many people who were searching for a job without telling their company are going to opt-in to make that public? I think that's the real issue: timing. The only time this can work is when someone has just resigned or joined a new company, so they can (and are actually willing to) "legitimately" pump up the volume about themselves. So make it an easy opt-in triggered by these events. Any triplebyte candidate that "closes the deal" should get opted-in automatically. Anybody without an ongoing work relationship, should get opted-in automatically. Everyone else, you hold fire until something significant happens publicly, at which point you gently prod them. You can even ask, when someone signals they are looking for a job, "do you want your profile public at this time? It's a pretty cool thing! If not, no biggie, we'll ask again once things change." It's not rocket science to do this respectfully and it's sad that they didn't.
- inimino 6y agoThe fact that this is the top comment and that folks who trusted you are seeing this email first on HN instead of in their inbox means you fucked up. The details of what trimmings you put on the email were not the fuckup.
- pleasecalllater 6y agoFor now. What about the future? I just don't trust any company which changes the agreements without asking for my consent. In this case I just want to close my account and delete all my data. Seems like impossible. In Europe after making things like this they could end in jail for breaking GPDR rules. In US it looks like it's fine to gather user's data, sell them without consent, and then forbid to close accounts. And there are always people who repeat "the company is fine, they have right to do it". Except they don't.
- jacquesm 6y agoJust the fact that someone used your service is a signal for their current employers, it might be used against employees during lay-off rounds as interpreting it that they are 'on the market'. In the current employment climate that is super dangerous. I strongly urge you to reconsider this re-use of data, especially for EU citizens where all use other than the one for which the data is gathered is illegal. See also: GDPR, specifity as well as the section on mandatory opt-in for future use. Note that you are opening yourself up to major legal and financial liabilities, besides the obvious personal ramifications, ie: you're on the record as a sleaze unless you handle this with velvet gloves from here on in. https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#1_Transparency_and_modalities https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
- battery_cowboy 6y agoI am very glad that I sent you all a rude message requesting my account deletion a few years ago, this is an awful response to a huge issue. Good luck with the recruiting business when no one trusts you!
- nilkn 6y agoThe message you should have received is that this should be opt-in, not opt-out. You're abusing your users' privacy. Screenshots don't change that.
- g_p 6y agoRegardless, this breaches GDPR by making data public and accessible to an unlimited audience by default. I hope (for your sake) that you don't have any users that can invoke their GDPR rights against you by virtue of their citizenship. For the sake of incentivising companies to do the right thing, however, I hope you do have some EU or UK citizen users who do litigate or have their data protection authority investigate and formally punish Triplebyte, even if only to establish clear precedent here for the future.
- im3w1l 6y agoTriplebyte is only targetting Americans afaik.
- dirtydroog 6y agoI'm a European in Europe and seem to have a triplebyte account
- g_p 6y agoIn which case, it sounds like at the moment they carry out a "data processing operation" to make your data public, you would have standing to make a formal complaint to your local data protection authority. Article 18 restriction of processing can apply here. Art. 25 "Data protection by design and by default" would seem to be relevant as well. The section I alluded to above is the latter half of 25(2), saying "In particular, such measures shall ensure that by default personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons." There's also the question of whether their consent or other grounds of processing suffice, which likely wouldn't for making anything public, but Article 25 makes it clear enough anyway this is illegal.
- josephg 6y agoI am not a lawyer and this is not legal advice but ... I don’t think the European government has legal standing to fine triplebyte. Triplebyte doesn’t have offices, employees or customers in Europe. A European visiting the US and interacting with an American business does so under the protection of US law, not EU law. This is complicated in the case of Facebook and google because they also do business in Europe, so European courts can fine their European branch offices. But Triplebyte has no such EU presence that the European courts could pursue. And they don’t advertise European jobs. I suspect an EU citizen interacts with triplebyte legally the same way they would if they went to a cafe in SF while on vacation. The opposite would be crazy. If triplebyte can be fined by the EU, that would also mean the government of Australia or China or Russia could arbitrarily levy fines against any US company if one of their citizens interacted with a US website one time. And everyone would put geo blocks on their websites to protect from liability.
- prox 6y agoStill, please don’t do things that need actual consent in IRL (making something that was private, public) If your new service is of true benefit, it will be used.
- pmiller2 6y agoWhat makes you think anything on your TripleByte profile was ever "private." It was not. It was merely hidden from the majority of the world. If you have a TripleByte profile, presumably, at some point, you were job hunting, and likely advertising that fact to anyone you thought could help you.
- eganist 6y ago> GDPR 25(2). The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons.
- JadeNB 6y ago> What makes you think anything on your TripleByte profile was ever "private." It was not. It was merely hidden from the majority of the world. If you have a TripleByte profile, presumably, at some point, you were job hunting, and likely advertising that fact to anyone you thought could help you. Are you arguing for this change? Whatever the argument is seems to be based on misinterpreting 'private' as 'known by no-one else'. Exactly the same argument could apply to e-mail: it's not private in the sense that no-one else sees it, just hidden from the majority of the world; presumably, when you sent it, you were advertising what it said to the recipient.
- marcus_holmes 6y agoI interviewed with TB a couple of years ago. Didn't do too great in the technical interview. Is that about to be public?
- whymauri 6y agoSame here. It's annoying that a technical aptitude test that I took when I was a freshman in college might now be publicly viewable as a benchmark for my skills. And I know the e-mail says that results will only be shared if you did well. But, if you have a profile on TribleByte and there's no signal on your profile that you did well, the only logical conclusion is that you did not do well. I'll be deleting my account, anyways. I didn't ask for this.
- prepend 6y agoSimilarly, I took a test in a language I’m not very familiar with to understand the process. I’m not terribly embarrassed, but I don’t want that publicly available.
- abacadaba 6y agoSee I did fantastic in the interview, but the interviewer was a noob :/ Edit: To be fair in their survey i think i said something like this sounded good, but it was phrased as "be part of an exclusive club of competent engineers" rather than "show current employer you're interviewing because you clicked on a banner add. And my whiteboard code had a bug.
- anewvillager 6y agoDude, just make it opt-in. It's that simple.
- eganist 6y ago> 25(2). The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual's intervention to an indefinite number of natural persons. You may wish to consult your privacy attorneys; you'll likely be the subject of a number of GDPR complaints considering the above. My interpretation of the above if you were to do it within the letter of the law (again, talk to your attorneys; I'm just a security director): 1. opt-in via settings page (or a modal on next login) for all people who already have accounts. 2. opt-in during registration for all people who choose to register accounts after the roll-over date. Again, talk to your attorneys. If you successfully roll over without having taken the suggestion to talk to your attorneys, your conversation with your attorneys may change from "how to best implement this" to "how to avoid getting fined."
- flareback 6y agoYour site is a job search site so the fact that someone has an account means they have been job hunting. This is not like Stack Overflow or Hackernews that you seem to like comparing the profiles to. StackOverflow may have job search functionality but it started as primarily something not related to a job search so my having an account there doesn't mean I have been job hunting.
- inimino 6y agoYour SO account was also never private, didn't contain "test scores" for job skills, and was never a repository of sensitive information about you that you only allowed them to have because you trusted them to keep it private. I've seen some epic CEO fuckups but this one is special.
- kerkeslager 6y agoI don't want a public profile of any kind on your website. There isn't a spin you're going to be able to put on this that's going to change that what you're doing here is diametrically opposed to my goals. You knew that, which is why you tried to sneak it past everyone. The problem isn't that people think what you're doing is unethical. The problem is that what you are doing actually is unethical.
- thaumasiotes 6y ago> The problem isn't that people think what you're doing is unethical. The problem is that what you are doing actually is unethical. In order for this to hold, there would have to be objective ethical claims which were independent of what people thought about ethics.
- tablethnuser 6y agoPlease don't make your team work on a U.S. holiday weekend for this. Just don't hit the deploy button on this change and now there's no deadline and no need for crunch.
- deleted 6y ago[deleted]
- king_magic 6y agoWhat you're doing is wrong and unethical, period. Do the right thing and walk back this ridiculous plan. Until then, I will do everything I can do to avoid your service and have others in my network do the same.
- MisterBastahrd 6y agoYOU are not in a position to determine what will or will not undermine me at my employer or my business partners. You can still fix this. Make it opt-in for existing users and opt-out for new users. Simple.
- Non24Throw 6y agoNot according to your own FAQ[0] on public profiles: > Your public profile includes any badges you've earned, your basic info (current job title and company, current location, and years of experience), and the tech experience & resume section. This information can very easily be used to identify a person, especially at smaller companies. > ... to provide us the canvas to release badges. That’s it. So before you were taking on LinkedIn, but now it’s just a place to release badges? [0] https://triplebyte.zendesk.com/hc/en-us/articles/360043820611-Launching-Soon-Triplebyte-Public-Profiles- https://triplebyte.zendesk.com/hc/en-us/articles/36004382061...
- chinathrow 6y agoThanks Ammon. I requested to delete my profile (I was trialling to see if we could use your service for our hiring pipeline. Narrator: we will not).
- RobertRoberts 6y agoYou have become a class 'A' manipulator. I thought I could see through people's crap. But you take the cake. Thankfully I felt "odd" when I signed up for your "interview" test and never fully finished it. Also, you single handedly brought me out of hiatus from commenting on HN. What you have done with this decision is a friggin stab in the gut. If you think your foolish "it's only X we are making public! Not Y!" means something other than "oops, we got caught, how do we cover this up?!" then you are deluding yourself.