5 ms·
People here are commenting that he stole code. That that's why Goldman is prosecuting but what constitutes stealing code? I mean the definition is "loosey-goose
by neonbat 11y ago
People here are commenting that he stole code. That that's why Goldman is prosecuting but what constitutes stealing code? I mean the definition is "loosey-goosey-bullshit" at best. I used to work building trading algorithms; there is no clear legal consensus on what constitutes "stealing" code. If I just remember all the code because I have some kind of special photographic memory is that stealing? If I created the code, it's in my mind. I mean if you hire someone from a firm where they currently are part of the reason you're hiring them is because they have a particular area of expertise and definitely know what their current employer's code in this area looks like. That's WHY you hire them, so they can do awesome stuff for you instead. The point of the article is that in doing this kind of crap Goldman makes it extremely uncertain for programmers who go to work there if they will be able to go and work somewhere else exporting the skill set and tangible knowledge of code they acquired at Goldman to a new workplace. This uncertainty makes programmers NOT want to work for Goldman and will definitely kill Goldman. Bershidsky has got it right.
- tedunangst 11y ago> what constitutes stealing code? Creating an archive of code, encrypting it, then uploading it on your last day at work.
- baldfat 11y agoAlso trying to cover your tracks by trying to clear it from history. This one was a big issue for me. It showed he knew he did something wrong and was trying to hide it.
- joshuapants 11y agoThat act doesn't affect whether the preceding act was legal or not, so that really shouldn't be the big issue.
- ape4 11y agoWell maybe. Don't you clean out your desk on your last day. Why not also clean up your history.
- neonbat 11y agoThis kind of thinking is seriously dangerous. This is why burden of proof rests on the state. What something "appears to look like" is irrelevant to the actual crime. That's like saying running from the cops proves your guilt. It doesn't prove anything. Innocent people run all the fucking time because they know the cops will try to violate their rights. Cops are scary. Some people have standard practice to wipe everything. I mean it was his last day at work right? If it was your last day at work, maybe you're just doing general log clearing, like if you were never going to use a browser again one idea might be to wipe the history on that browser, clean out the work station so to speak. Doesn't sound so menacing now does it? Now maybe Goldman has policies against this; it's just an example of how these kinds of non-evidence tangential facts can be used to obscure the reality of a case. Also It would surprise me greatly if this guy was the first guy to wipe his workstation before leaving his job at Goldman.
- tptacek 11y agoBy all direct accounts the state amply met their burden of proof in this case. The case didn't turn on the bash history; that was part of a much larger pattern of facts. Just before leaving an incredibly sensitive job in the single most competitive part of the financial sector for a job paying 3x at an arch-competitor of his current firm, a programmer cloned a huge collection of source code --- the majority of which was proprietary and not open source taken from the single most sensitive technical asset at his firm, an asset which his new 3x job at the competitor was to reproduce, and uploaded it to an offshore Subversion hosting service nobody had ever heard of before. Later, he is shown to have presented portions of that code to his new firm. The only people on HN who think this is OK have that view solely because they think it's OK to do virtually anything to Goldman Sachs, because of the abuses Goldman Sachs has inflicted on the world's giant squid population. That is a fine and intellectually coherent position to take: firms who harm giant squids do not deserve the protection of law. But people holding that position should be clearer about it, and constrain themselves to squid-based arguments.
- BlackFly 11y agoThe one point consistently being missed is that many open source licenses carry a "taint" with them that causes most commercial companies to avoid them. What does it mean to propagate a program? If an employee checks out a personal copy outside of business hours, is that propagation, or modification of the single licensed copy that the business owns? When two employees modify the code simultaneously, who owns the copies? The amount of taint is irrelevant, either one included license taints it or no included license taints it. Once a bit of copyleft code is modified and included in a binary, the legal question of whether the result is open source is not trivial and certainly open for discussion. That being said, it is certainly the intention of many people releasing the code under copyleft licenses that any modified work be open source. It is completely unfair to project the idea that all people siding with Mr. Aleynikov do so solely due to animosity towards Goldman Sachs. It is completely circumstantial that he tried to hide the fact that he made a personal copy. It is often best to avoid having a discussion. I try to hide from my parents the fact that my wife and I... well you get the idea.
- fluidcruft 11y agoBy that logic anyone using private browsing mode on a web browser should is suspect. And personally, I would delete shell history on principle when leaving a job. I also delete my browser cookies and stored passwords etc. With the big plastered on warnings everywhere that all computer activity is monitored and recorded, it should be entirely reasonable to assume that these copies are redundant and disposable. I have a lot of people I have to interact with that insist on force me to login to their stupid sftp servers using plaintext passwords and they configure their servers to force interactive mode. And I very likely have PHI in my command history, too. There's absolutely no reason to not delete shell history when leaving a job, particularly now that HITECH means that I can be personally criminally prosecuted for data breaches. Besides, what constitutes "deleting shell history"? The way bash works by default, the last closed terminal deletes all the history of the other terminals. Does Goldman Sacks require users to maintain full shell history files as a condition of employment or as part of their expected work behavior or work product? I very, very much doubt it.
- tptacek 11y agoI would be wary of hiring someone who told me that it was their habit upon leaving a job to erase all traces of what they'd done while working at that job. That does not seem like sound engineering practice to me.
- fluidcruft 11y agoWho said anything about erasing all traces? If you want to use keyloggers to record the minutiae your employee's behavior, by all means record them. That has nothing at all to do with sound engineering. Sound engineering is always about process and documentaion, not surveillance.
- chrisbennet 11y agoAs I understand it, if he didn't clear the history,sensitive information (password?) would be readable/available. He probably did this pretty much every day he worked at G.S. The narrative that "he tried to cover his tracks" was meant to make him look guilty.
- tedunangst 11y agoIf your subversion password is in your shell history, well... you suck at life.
- o_nate 11y agoDon't know why this is being downvoted. This is a very valid point. Stealing code seems to be like pornography, i.e, you know it when you see it. Except there are lots of grey areas. What if instead of downloading the code on his last day of work, he had downloaded it a few months earlier? What if he hadn't erased his shell history? It seems that what constitutes stealing versus valid copying depends on his intent - which is a pretty weird definition of stealing when you think about it. Whether or not I stole your wallet doesn't depend on my thought process at the time. Edit: can't seem to reply to response below, so I'll just add here, if code theft requires intent to "permanently deprive" someone of their property then you need a pretty strange definition of "permanently deprive" as well.
- dragonwriter 11y ago> It seems that what constitutes stealing versus valid copying depends on his intent - which is a pretty weird definition of stealing when you think about it. Whether or not I stole your wallet doesn't depend on my thought process at the time. Actually, it usually does: "Theft is often defined as the unauthorized taking of property from another with the intent to permanently deprive them of it." [0] (emphasis added) [0] http://criminal.findlaw.com/criminal-charges/theft-overview.html http://criminal.findlaw.com/criminal-charges/theft-overview....
- DanBC 11y agoWell, theft means to take something with the intention of permanently depriving its owner of it, which is why there are different crimes for TWOCing (taking without owners consent) in UK and probably similar in US, so it's not that unusual to consider the intent of the perpetrator. Mens rea or something.
- o_nate 11y agoOK, you guys got me. I'm not a lawyer. So the legal definition of theft does depend to some degree on intent. I've learned something today. In that case, allow me to reframe my argument. I'll be generous and replace the term "intent to permanently deprive" with "intent to harm". Still, proving intent to harm is (or should be) much more difficult in cases when you have only made a virtual copy of something, and I think the bar is being set too low in some of these cases. So I think there is some validity to the argument that these financial firms are shooting themselves in the foot by being too zealous in persecuting behavior that can (or should) fall into a grey area.