3 ms·
how would they know it's explicitly criminal though? i doubt most devs have enough understanding of their business domain, much less the regulatory frameworks t
by siegecraft 4y ago
how would they know it's explicitly criminal though? i doubt most devs have enough understanding of their business domain, much less the regulatory frameworks to be able to confidently refuse to implement something because it's illegal.
- meindnoch 4y agoignorantia juris non excusat
- tpankaj 4y agoMy understanding is they would have to prove criminal intent.
- 8note 4y agoIf there's a duty of care, negligence. But that's why software "engineers" have quotes around "engineer"
- quickthrower2 4y ago3 lawyers for each coder then?
- batmenace 4y agoAt the very least they should be aware enough of potential wrongdoing to raise questions, and do so in written form. When you write exceptions that specifically only benefit one party and no others, there is always a reason to at least be suspicious.
- cookingmyserver 4y agoWhat I’m struggling with is that what was done is not illegal in its self. It’s not necessarily suspicious in itself (from the perspective of a single dev working on tasks), unless you assume fraud. Of course we know fraud occurred so we can look back on it and have our perception of the request tainted. If my boss came to me and said, “continue showing customer funds sent to our “sister” investment company in the staff dashboards” I wouldn’t find that suspicious. I would probably push back and say that might be confusing unless we separate out that amount and rename the total to something that denotes part of this value is with our sister company. But I would assume design incompetence and not fraud. But then again if I was just one of a handful of devs that worked with the company I would probably find it suspicious, as I would confidently know that nowhere else in the codebase do we support a close integration with our sister investment company and should therefore know we shouldn’t treat them any differently. Also the modification to exempt the investment company from risk rules does seem suspicious, unless again you believed there was an integration somewhere and believed investment risk mitigation rules were handled on the other platform or something.