Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In Germany I was asked to provide my criminal record while working at a payment processing startup that had to obtain certain certificates. They were probably looking for crimes of a fiscal nature however, which is understandable. Second chances are second chances but security is mostly about trust.

Another job at a startup in Germany that worked in less tightly controlled spaces has never asked me to produce my criminal record, nor could they legally. An employer can only ask questions that are reasonably necessary for them to make a fair consideration about me as an applicant. You could ask an accountant about embezzlement convictions, a pharmacist about drug convictions etc., but that is not applicable to software engineers.

This is the only sane way to do things.



Theft, fraud and violence are applicable for all jobs surely.


Surely not, if by "applicable" you mean to suggest that employers would never want to hire such a person for any job.

Should a person convicted of theft, who's served their time, paid the fine, made the victims whole, and learned not to steal, be discarded from consideration as a useful member of society? In case it's not clear, I think they should have the same rights as any other human being.

No one seriously advocates the death penalty or life imprisonment for petty crimes. But depending on the ability of a society to forget (which the information age is rapidly making very difficult) and the ability of a society to forgive (which the climate of fear is also making difficult), a conviction in your record can ruin a life.


If that is the case their record should be wiped at the end of their sentence. What's the point of a record if it can't be used to warn people of your past?


"Same rights" - no sorry, somebody who stole before will be regarded with higher suspicion than other people, and that's OK.

How do you know they "learned not to steal"? Can you look inside of their heads?

There are jobs with less opportunities to steal, for example. Trust has to be regained, simply "having been in prison" is not really worth much in that respect. You would stay in prison, regardless of your mindset, because you are forced to be there.


As an Australian, I find that perspective awful. Going to jail is the punishment society has chosen for the crime. Once you've served your time, you rejoin society on an equal footing. Denying jobs to ex-cons makes it much harder for them to integrate back into society, and increases the recidivism rate. (Which you pay for via taxes.)

The equation isn't "bad person -> steals". Its "person maladapted to society / with unhealthy community -> steals". Why would someone be a thief if they have a stable job and community?

And how do you expect someone fresh out of jail, with no connections and community, to make a stable life for themselves if nobody will give them a job?


Not "nobody should give them a job", just not a job with ability to do harm. But that's for every employer to decide for themselves.

If you don't think somebody having done X before makes them more likely to do it again than normal people, I don't know. (More accurately, people who did X are more likely to be people who would do X again). We just have to disagree - but you can not enshrine such beliefs in law.

As I said, trust has to be regained, merely doing something you are forced to do anyways does not prove anything about your real attitudes.

In "How To Change Your Life In 7 Steps", the founder of the homeless magazine "The Big Issue" John Bird describes what he had to do to be able to have homeless people work for him. I have high respect for people like him.


The issue is risk. Hiring someone with a criminal record is riskier than hiring someone with a clean record. There is no upside to mitigate that risk either. So it shouldn't be surprising that hiring managers discriminate on anything they can legally get away with.


>and learned not to steal

That's the issue at hand. Serving a prison sentence doesn't mean that you have learned not to steal. It's difficult for the company to verify that you have "learned your lesson".


What will satisfy you then? Should people who come out from prison for stealing sit around jobless since nobody trusts them? That's bound to get them back into prison.


I would be satisfied if there was a proper criminal justice system. Unfortunately, in the US (and most of the world) that is not the case, and former prisoners are more likely to commit crime than people who have never been in prison. I know that is "unfair", but I chose to live in a safe neighborhood and work with safe people. It is not my job to put my safety on the line in order to try to rehabilitate a criminal.


It’s interesting that the very people that say ‘they haven’t learned their lesson’ perpetuate that exact thing.

There was an article a little while back about a company tracking the employees behavior on the computer, and a lot of people mentioned that ‘if you are not trusted regardless, what incentive do you have to be trustworthy’.

This is the exact same thing.


I'm not responsible for strangers. If I'm a hiring manager, I'm responsible for my company and the safety of my employees. I owe nothing to a stranger. Take your problem to someone else.


How about: an insurance policy such that, if the employee does end up stealing, then the employer is made whole. The former-thief employee could pay for such a policy, and then it would seem the employer would be indifferent between the former thief and the average applicant. The policy could be paid for out of the thief's salary; he would effectively be accepting a lower wage.

If the job is minimum wage, of course, then it's not possible to lower the wage further.

Also, discovering the theft and proving it was that employee might be difficult.


No they should find jobs where they have less opportunity to cause harm.


I'm super curious - do you feel that all those crimes you mentioned should have life sentences?

'cause I mean...if not, what was the point of the jail term? Depending on perspective, it might be rehabilitative, or it might be punitive, but either way, time served should equate to a clear record, no? If not, you're either saying they need further punishment, or you don't believe that they've been rehabilitated, in which case why were they let out?


If you beat a man up such that he suffers lifelong injuries, it seems only fair to me that your punishment should also be life long.

I don't think you should necessarily spend all that time in prison, but not having access to trusted jobs is not comparable to being in pain every day for the rest of your life.

On the other hand, I wouldn't mind if more punishments were metered out in the form of community service.


That's the "punitive" side of things. Certainly, it seems "fair" to ensure the punishment is equal to the crime, but fair isn't the same as just. Why don't you go Code of Hammurabi on someone, and inflict the same kind of injury? The logic still holds. Of course, it now requires people willing to commit torture and rape and the like, to equal the crime, but that's the logical conclusion of trying to be "fair".

But even without taking it to its conclusion, I'd contend "fairness" as you define it there isn't necessarily the best outcome for society; an ex-hacker is probably an excellent choice when hiring for electronic security, an ex-robber an excellent choice for hiring for physical security, etc. Even a murderer can go on to great things that benefit society. I mean, hell, Miguel De Cervantes, author of Don Quixote, the first modern novel, wrote his first published work while in prison. The Birdman of Alcatraz (Robert Stroud), a murderer, published major works in ornithology, and found a cure for a bird disease. Rehabilitated criminals can still benefit all of us, as well as redeem themselves in their own eyes by doing good for themselves and their loved ones.

But all that aside, you're saying you believe the additional punishment should be societal scorn carried out by vigilantes (i.e., average citizens deciding the person shouldn't hold a job even though they've paid the price the courts decided on)? That hardly seems just or 'fair'.


There is a rights-based approach in which (a) yes, someone inflicting a harm on you gives you the right to inflict a proportionate harm on them; (b) you can then go to them and threaten to inflict this harm, and usually get them to agree to pay you a fine instead, thus benefiting both of you. Labor could be used to substitute for a fine if someone can't pay, although I think in today's prisons the prisoners don't necessarily do work.

There are problems. For example, breaking a professional tennis player's arm may be much more career-damaging, and arguably "worse", than breaking a professional chess player's arm; and excessive retaliation is itself a crime. In that case, it may be good to get a judge or some such to evaluate the severity before carrying out the retaliation. That also goes for judging the evidence—obviously, punishing someone for a crime they didn't commit is itself a crime. So one could imagine this turning into something at least vaguely resembling today's court system.


This is a jaw-droppingly horrific system you're imagining. Amongst other things you've effectively insulted rich criminals from any repercussions, and basically given them a slave underclass (please, no snarky comments about current justice system). Do you genuinely think this a good idea?


Our current legal system has evolved over many hundreds of years. I merely describe a set of initial conditions and a few possible early developments. The space of things it might evolve into seems pretty wide. I do suspect some of those things would be good. That said, in the meantime:

There have existed societies in which the penalty for murder was to pay a fine. https://en.wikipedia.org/wiki/Weregild

Also, this doesn't insulate rich criminals from all repercussions. If they have enough money to pay the fines when murdering tens of people... well, you could try killing the criminal directly. You can do that today as well, if you're prepared to pay the price.

A really rich criminal could hire bodyguards, of course, but those would be costly, imperfect, and have some chance of turning against their employer. Ultimately it would become a rich guy in charge of an organized criminal gang, which... is also something that exists today.


We know how this goes, because forms of it are what the current system evolved into; there are obvious descendents of what you say in the legal system. But that doesn't mean applying it literally, as with your "early developments", wouldn't have awful consequences.

> ...If they have enough money to pay the fines when murdering tens of people...

It's not about "murdering tens of people". It's killing someone whilst drunk driving, or murdering someone in an argument. These situations clearly still happen in the current system. But with what you're saying codifies that, if someonene is rich, as long as their crime is not against someone else rich, they can generally avoid any repercussions. Blood libel is still a thing, can literally see it in action in countries which have legal systems that allow it.


Not really sure what your point here is in relation to my post. That if we didn't have a legal system or governmental authority that we collectively have agreed to allow to arbitrate these matters, it would be left up to individuals to do, and that such a system is ripe (per your later comments) of exploitation by the rich? I mean, sure, but hardly seems relevant to the comment or the current state of most countries.


Your attitude towards someone convicted of a criminal act isn’t uncommon, but it’s short-sighted. If the judicial system determines that the appropriate punishment for a crime is X years, then at the end of that time they should be given a chance at a fresh start. There are limits, of course, perhaps you don’t want to give them a security clearance, or a job that requires carrying a gun. Someone convicted of molesting children should probably never hold a job that gives them contact with children.

In the US at least, having a felony conviction (and the bar for that is not that high) is effectively a lifetime punishment. It’s incredibly difficult for someone with a felony conviction on their record to get a job with potential. That’s a big part of why the recidivism rate for felons is so high. They often don’t have many options to make a living.


> If the judicial system determines that the appropriate punishment for a crime is X years, then at the end of that time they should be given a chance at a fresh start.

This is a poor argument: the judicial system has also determined, by lack of prohibition, that it's appropriate for employers to discriminate based on criminal record.


'Determined that it's appropriate' is rather strong language for something the system simply does not universally address. In fact, EEOC guidance, and recent court cases, seem to indicate that were it brought in front of the courts, they would likely rule in favor of the plaintiffs (obviously with recent court packing by GOP that's more in question than it was a few years ago though). It's just that oftentimes, ex-criminals searching for jobs don't have the money to take such cases to court.


That doesn’t mean it shouldn’t be changed.


But that wasn't your argument!


> at the end of that time they should be given a chance at a fresh start

It really was.


It might have been something you were thinking, but it's pretty much the opposite of what you said.


Often the judicial system is flat out wrong. In Ireland the prisons are so full everyone gets a slap on the wrist and a suspended sentence for even public endangerment crimes.


Where do the occupants of the full prisons come from then? Are the prisons full of life sentence prisoners from back when they weren't full?


That's a good question which I don't have the answer to. Things used to be less lenient so it would stand to reason that spaces are taken by previous longer sentencees. Ireland doesn't have many spaces to begin with. From wikipedia:

> Prisons and prison population

>There are 12 prisons in the Republic of Ireland with a total bed capacity of 4,106 as of 31 December 2009. The daily average number of prisoners in custody in 2009 was 3,881. However, most of these prisons currently operate at or above capacity.[13] On 25 January 2011 the prison population stood at 4,541. There were about 80 prisoners per 100,000 inhabitants in October 2015,[11] and in Northern Ireland it was 78 per 100,000 in February 2016.


This points to a cultural difference there that might be at the core the argument. In Europe prison has rehabilitation as one of it's goals. In the US it's almost entirely about punishment.


The state does more injustice in the name of "fairness" than almost any other agent for any ther reason.

I have to say "almost" as there is the very rare criminal who is actually mean and targets people the way the state does.

People denied access. Denied votes. Denied work. Denied the means to live.


Hard disagree on that. As a programmer we have access to more than most accountants. How hard would it be for most programmers to put in a backdoor they could later claim was a bug?

Criminal convictions are perhaps not the best measure of trustability.


> As a programmer we have access to more than most accountants

Do we? What does the average programmer working on internal business applications, b2b services or CMSs have access to that is of any risk?


It's always hard to estimate what the average case is for something like this. But I would guess that the average programmer do have access to "production data". What that contain is obviously industry specific, and the most sensitive industries are (hopefully) well regulated and not average, like health care or finance.

But I would guess that programmers at Tinder/Grindr/$datingSite had access to production data in the early days. Probably many SaaS things, perhaps doing stuff in the HR/recruitment/time reporting area. For B2B I'm guessing many programmers have access to business sensitive data, that competitors would like to get their hands on. At the least I would guess that at least the average backend developer have access to all contact info / emails for all users in services they work on.

Obviously all best practices say that random Joe programmer shouldn't have access to these things, but I don't think that match the _average_ reality.


I think so. Many sites have some sort of sensitive user data that could be exploited. If you work in ecommerce, you likely have access to the payment gateway as well.


> How hard would it be for most programmers to put in a backdoor they could later claim was a bug?

My guess is that is actually pretty fricking hard, as otherwise it'd be happening all the time. I.e. you can maybe make a backdoor to something without monetary consequences (even in a bank most systems don't handle money), but introducing a backdoor to the core system (i.e. a money-dealing one) in such a way that it is not noticed in code reviews or testing AND you can claim plausible deniability seems hard.


This is why all non-trivial applications need to have a code review process and a CI/CD pipeline that ensures that no application goes into production except via that pipeline, and that all code is reviewed prior to deployment. It’s not a guarantee, of course, but it’s a start.


How do you hotfix production? Do you have a special "go fast" flag in the pipeline?


In my experience, the pipeline itself is a negligible amount of time. Directly hotfixing something is a high risk thing that no company I've ever worked for would tolerate.


If your pipeline doesn't allow you to deploy quickly, fix the pipeline. Nothing should go to production that doesn't go through the pipeline.


You don't. You build the ability to roll back to a good state.


> Criminal convictions are perhaps not the best measure of trustability.

Unskillful or unlucky criminals are prosecuted by the law, more careful criminals often defy the law.


What crimes are applicable to software engineers, then? I don't think there are any laws punishing you from writing bad code, nor are there laws addressing data theft or security misconfigurations. GDPR applies against companies and not individual people, as far as I can tell.

Would the only valid crimes be related to computer hacking?


> Would the only valid crimes be related to computer hacking?

Not necessarily. When working for a fintech or a bank, financial crimes can be very relevant. Writing bad code is, lucky me, not directly punishable as a crime.


I could assume hacking, fraud, corporate espionage, etc. along with info relevant to the software (i.e. if you make banking software I'd assume fiscal crime would be at least somewhat relevant)


Hacking would probably be a plus for a software enginer. They know how to debug systems.

Espionage, theft, and violent crimes... That's a different situation (I don't want someone coming after me after I liter their PR with comments)


A charge of 'hacking' is like a charge of 'breaking and entering'. They could have cracked a bank vault mission-impossible style, or maybe they threw a brick through the window.

For all you know, they could have 'hacked in' via the password on the post-it on their coworkers monitor.


I threw a brick through a bank vault. Does that qualify?


I know a guy who spent a year in federal prison on bogus wire fraud charges for an article published in a hacker magazine. He was afraid it would cripple his career, but the opposite was true. He's now the chief technologist at a major CDN and his prison time translated into a badass semi-legendary hacker image.


Sure, and embezzlement might be a plus for a very specific finance job, namely, searching for evidence that embezzlement has happened.

Point is that it's relevant under those circumstances, and fair play for an employer search. Drunken and disorderly is not.


> Hacking would probably be a plus for a software enginer. They know how to debug systems.

They also apparently have poor judgement and/or security practices, if they got themselves convicted under CFAA or similar. And possibly questionable moral integrity depending on what and how they were hacking.

Background checks are not intended to evaluate skills but to find risks. Having a hacking conviction is generally not a positive signal.


Whereas if they're convicted for hacking, they'll only go after your digital assets/devices, so... no worries? After all, hacking convictions are a plus.


Writing an entire operating system in an inherently insecure language?


This seems to be a pretty popular crime.


If you write software for banks, than all the crimes a banker could commit are easy for your to hide in code. If you write software for pharmacies then you can probably figure out how to to get any prescription you want to abuse into the system.


>What crimes are applicable to software engineers, then?

Ever see office Space? ;-)


>Would the only valid crimes be related to computer hacking?

Or willingly install Windows Server facing the internet directly, that would be the other one ;)


"Directly facing the internet" is a legitimate Windows Server configuration scenario for some use cases.


Yes a Honeypot...but i thinks that's it.


DirectAccess and Web Application Proxy are 2 actual examples.


Yeah just leave me out of your projects please ;)


I would think any crime inflicting bodily harm is relevant, as long as you work near people with bodies.


What you said implies that any person that has committed a violent crime remains a danger to other people, forever - and should also be punished, forever.

This is what the American justice system is like.

In a saner world, (only) people who are a danger to others would be separated from the society, and being set free would be and indication that you are no longer a danger.

In the US, being released from prison signals you are more dangerous than if you got away with your crime.


Conversely, someone who was already willing to violently attack another person is probably much more likely to do it again?


They’ve likely also noticed that the time they spent in the funhouse afterwards was not so fun after all. So even if this were true (which I don’t think it is), they might think twice about going at it again.

If someone is more likely to do it again because they are mentally unstable, they shouldn’t be released.


Most people will attack another person, if sufficiently provoked.


Crimes of passion are a thing.


It may be that it's not a criteria for not hiring them, but never-the-less something you want to keep an eye one once you do. And perhaps something you want to ask them about at interview.


I dunno, it takes a lot more than a fistfight to get put in prison for violent offense. Sure people can change but only a solid work history or trusted recommendation can give you any real confidence. You may have to fire this person, or they may have to report to an abusive manage for some period of time. Some offenses are difficult to walk away from untainted.


The summer after I graduated from HS a kid I knew got into a fist fight in the parking lot of a bar. He was punched once and he went down and cracked his skull on the curb and died.

The person who hit him was charged with manslaughter.


Wow, that’s tragic


>I dunno, it takes a lot more than a fistfight to get put in prison for violent offense.

Citation needed.


Perjury maybe? A lot of compliance relies on truthful reporting by employees.


I don't know of specific cases where a programmer was prosecuted, but I believe that knowingly and negligently leaving holes in compliance-heavy health technology (HIPAA) could result in prosecution.


In the United States "Unauthorized use of a computer" is a felony.


Scrollbar hijacking should be 20 years to life.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: