6 ms·
The Friday announcement was a result of us pushing to get the profile toggle feature out that the email linked to, and shipping late. Not something I'm proud of
by ammon 6y ago
The Friday announcement was a result of us pushing to get the profile toggle feature out that the email linked to, and shipping late. Not something I'm proud of (either from an eng management perspective, or, more importantly, from a not violating the trust of our users perspective). It was a rushed schedule. In hindsight I see that the timing of the Friday announcement is ALSO a problem.
- woofie11 6y agoHi Ammon, 1. There is an opportunity. 2. You did lose a lot of trust. 3. You didn't have enough trust in the first place to really take advantage of this opportunity. I would encourage you to think about how you can earn that trust. This comes back to transparency and checks-and-balances. If you want to go that route, you will need to build hard constraints: legal and technological constraints which would have prevented this in the first place which you can't later remove. This shouldn't have been down the bad judgement by the CEO. I don't know you, but even if I did, the Board can toss you ought next month, and the next CEO might have worse judgement. Baseline: Right now, your privacy policy is not bad. However, you can change it anytime. You can eliminate it in the case of sale. Etc. You're paying a lot in trust right now for abstract flexibility down-the-line. I would not give you a model of what I know with that privacy policy, and to get to your vision, you'd need my data. Good: Think through how organizations engineer legal constraint (GPL, AGPL, CC-BY-SA, etc.) to build community and trust. Engage folks like Eben Moglen and Larry Lessig, and come up with robust ways where Triplebyte can be trusted to manage user data, without needing to trust the Triplebyte management team. Your team has a fiduciary duty to maximize shareholder value. Down the line, you might become Google (which has a trillion dollars to lose if it breaks trust) or you might become Yahoo (which is now mining personal emails in really evil ways, since that's the most effective way to scrape out the last little bits of profit). I want to know that if you go the route of Yahoo, or other companies I trusted with my data which went south, you won't be able to weasel out. You should figure problems like: * What happens if you do have a problem? If my data leaks, will you be liable, or do I bear that cost? If you are, that sets up incentives for you to have proper security. Consider it a cost of business (you can get insurance too). * How can I verify what happened to my data, as you send it off to partners and "trusted" affiliates? * How do I know my data was properly de-identified (I don't believe this at all, at this point). If you can build something really robust, it will go a long ways to making you into a Google, by ensuring you won't turn into a Yahoo. It's a trillion-dollar opportunity.
- ximeng 6y agoExtract from guidelines: Please don't comment about the voting on comments. It never does any good, and it makes boring reading. Please don't post comments saying that HN is turning into Reddit. It's a semi-noob illusion, as old as the hills.
- woofie11 6y agoRemoved.
- ammon 6y agoWe are thinking about how we can make a stronger (and specific) privacy guarantee so it's not just a matter of our future intentions. I had a long conversation with my co-founder about this yesterday. We did not get anything together in time to include it in this email. But we're planning to.
- woofie11 6y agoThat would be terrific! I would encourage you to not go it alone. 1) There are people who have been thinking about this problem long and hard for a long time. Most are pretty accessible, and would be excited to see something strong here. There's a big pool of knowledge to build on. 2) You don't need to have something finished or polished to start to engage with either those people or with the community. You can toss out an early draft and solicit feedback if you're on the right track (rather than tossing out a fait accompli). You can even just solicit ideas.
- g_p 6y agoThis is good to hear. I have spent a lot of time looking at this topic, and for me there's 3 things worth exploring. 1. Versioning of user consent. A lot of services have been designed around the idea that once a user consents to the terms, they consent to any alternations you make in the future. This is legally very questionable, at least in many countries. Some services manage to keep track of the version of the agreement a user has approved, but then force agreement with any updated version. But in reality there's no need for this - users should be able to granularly consent (and withdraw consent) to different things, as and when it's desired. In any case given the way this is interpreted in GDPR, and the direction of travel in California and other states, having granular consent seems to be a sensible short term investment to save a lot of pain down the line. 2. Handling data at a sale, acquisition or liquidation. This one is more tricky, and I believe a Stripe co-founder mentioned this recently on HN as something to look into. Lots of companies see their database as an asset to sell. There's an interesting history of companies like RadioShack, ToysRUs, and others going through this issue and ending up in court over it... 3. Aligning your goals with your users. It might be a bit idealistic, but it always seems to me that privacy works best when everyone's interests are aligned. I'm not sure how this fits for your situation, but it strikes me users wanting visibility get visibility, and if they get a job you'll benefit, as do they. That seems nicely aligned. And for people who want to be incognito, they remain incognito, but they know you're there. It's probably counter to lots of the "startup playbook", but even these incognito users are likely still valuable, maybe even net promoters, just not currently looking to be seen. So it seems your goals align nicely with users', and there need not be any hyper growth "dark patterns".
- camjohnson26 6y agoUnfortunately the most vocal people are the only ones you’re hearing. I got the email and didn’t really care. My angel.co and LinkedIn are already public, why not Triplebyte too, especially if it raises my market value. Haters gonna hate and I wouldn’t take it too seriously.
- BoysenberryPi 6y agoJust because people are not being vocal does not mean they do not care about the situation. I haven't commented on the drama from this situation but I also got the email from them and my immediate reaction was "huh, thats kinda shitty." and proceeded to hide my profiles. A lot of people feel that only people who are displeased voice their opinion and people who are satisfied stay quiet but I would be wary about that line of thought. While the angriest voices are the loudest there are definitely a good number of people who aren't happy but don't feel the need to jump into every argument
- folli 6y agoThis speaks for an opt-in and not an opt-out.
- GordonS 6y ago> My angel.co and LinkedIn are already public, why not Triplebyte too Because you opted in to creating those profiles and the information they contain, and made them public. You opted in.
- camjohnson26 6y agoIt was wrong not to make it opt in but not deserving of the level of hate they’re getting for the decision. The big tech companies do things every day that are much more damaging to your privacy and they don’t send you an email telling you. LinkedIn’s spam marketing in the early days was downright scandalous. I’ve always found Triplebyte open and insightful and their response shows they’re receptive to feedback, which is a rare thing these days. People should be respecting that instead of crucifying one of the only companies that actually listens to them. No company is perfect all the time.
- adnanh 6y agoJust curious, did you have any engineers/product owners telling you that you should probably not do this feature, especially not push so hard (doing stuff late on Friday that can easily wait for Monday, etc...) to get it out?
- WrtCdEvrydy 6y agoYeah, those guys got laid off early on the COVID-19 cost reductions as being 'troublemakers'.
- yjlim5 6y agoThis, I'm very curious to know. Did anybody speak up about it? That's what product discussion meetings are for, right?
- ponker 6y agoYeah, we don’t even do any kind of code deploy on Friday after 10am. Not even bug fixes unless they are for site reliability.
- capableweb 6y agoIt's one thing to do regular code deploys and there is no harm in doing it on fridays, if the code happens to be ready. If something goes bad, you rollback, which hopefully is automatic. But, pushing features out the door is different than just deploying, so seems this is what happened. Then it doesn't matter what day you release your unfinished feature, it's gonna cause bad times.
- gjs278 6y agothe site is offline - well we won’t fix it until monday
- travisjungroth 6y agoThe tree of possible causes here looks really bad. Either no one spoke up, or someone did. If no one spoke up because no one knew this would be a problem, it means the team is completely unqualified. If no one spoke up but they did know this would be a problem, then it means people are afraid to speak out (my money is on this one). If people did speak out, then the right people with the right concerns aren't getting listened to.
- dylz 6y ago> The Friday announcement was a result of us pushing to get the profile toggle feature out that the email linked to The absolute most important part of the feature was a last-minute addition?
- ummonk 6y agoIt sounds like the overall feature was delayed because the eng work for the profile toggle landed late.
- cryptonector 6y agoYour reputation is shot.
- lspears 6y agoI have used TripleByte as a candidate and company and it’s an awesome product. If we keep getting great hires, I could care less what you make public. Thanks for your hard work.