10 ms·
Certainly bold and perhaps ill-advised, but I would hardly characterize this as "injection" > Spiers told NBC News that she was inspired to create a digital no
by ninly 7y ago
Certainly bold and perhaps ill-advised, but I would hardly characterize this as "injection"
> Spiers told NBC News that she was inspired to create a digital notification because “a poster in the cafeteria is not the best way of reaching the majority of Googlers.”
> The message included a link to a statement that the NLRB required the company to post for employees following the settlement of a complaint that was filed against Google in 2016.
> Spiers, 21, said she went through the standard approval process, which requires two co-workers to greenlight changes, before updating the Chrome browser extension. Another source at Google familiar with the update approval process confirmed to NBC news that those two approvals are standard practice for a browser extension update.
- Touche 7y agoPrefixing this by saying I am not siding with Google (since people make assumptions). The standard approval process sounds like most merge review processes on any engineering team. There's a sort of assumed good-faith for this process. The fact that 2 coworkers were fine with your change doesn't mean it was made in good-faith and was within the bounds of normal types of changes. Any engineer with the freedom to make changes without manager approval knows that adding features or making major changes isn't not the sort of thing you just do on your own. You'd go through another process for that. So I don't buy this argument at all. This was a knowing violation. That does not, however, mean that they punishment was warranted, I don't think that it was.
- impalallama 7y agoYeah let's be real, if she programmed a popup to appear over twitter with a message like "Don't slack off dummy UwU" and or something equally ill informed she would have been rebuked at worst. To say that it wasn't the union overtones that got her fired is naive.
- qaq 7y agoI know 0 large companies who would tolerate what you just described from a security team member.
- dkersten 7y agoShe’s young and probably a bit naive. I think it’s absolutely a reprimand-worthy offence, and I certainly understand that a security engineer maybe shouldn’t inject code like she did, but that’s why there are reviewers, but they ok’d it. I don’t think it’s something she should have been fired over. I made dumb mistakes early in my career too, after all. Should she have done it? No, absolutely not. Not like that anyway. Should she have been reprimanded? Yes definitely. Should she have been fired? I don’t think so personally, not for a first time mistake at least (we don’t know if she did other things previously or not, of course)
- ce4 7y agoDifferent viewing angle needed but Google does similar stuff themselves, e.g: On Google.com if you present a Vivaldi user agent and arrive via a redirect, the search text box will be misaligned On Google Docs if you present a Vivaldi user agent you will receive a warning https://vivaldi.com/de/blog/user-agent-changes/ https://vivaldi.com/de/blog/user-agent-changes/
- thu2111 7y agoProbably a bit naive? Security tools, and especially extensions that run with full browser access, are in an exceptionally trusted position. Employees who can inject code into arbitrary websites can in effect get administrator access to anything in the company, as Google is run almost entirely off of web apps of various kinds. It's actually hard to get more trusted than that: without a doubt this woman effectively had a greater level of access than Sundar Pichai or other senior executives. If there's one thing you don't screw around with in any firm, its mis-using administrator access. Mis-use here means doing things that aren't related to your job description. You just don't do it! What she did would be like a logs engineer deleting internal access logs to cover up activity by political allies, or a GMail engineer spying on conversations between executives. It's complete madness to think you can abuse such a high level of trust in such a direct way and get away with it! I used to have a certain type of Google account system administrator access. The way I used it was watched very closely, and deservedly so. Eventually it was removed because Google built better security systems that could restrict employee access more, and in my team were happy about this (for one, it meant we were less likely to be hacking targets). The idea of anyone abusing this sort of access for political reasons was unthinkable. I honestly can't believe people here are defending this kind of behaviour. If Googlers feel it's OK to abuse root@chrome for unionisation related purposes, what else might they start doing? What about people perceived as 'bad'? Google needs to explain what happened here pronto, because apparently she was able to get this change through code review? So she had internal allies who approved her abuse of access? That is tremendously worrying. Google is very rapidly burning the trust it requires for its business models to function. How can anyone trust the firm when 21 year old activists are able to manipulate Chrome for political causes and Google's own security procedures are unable to stop them?
- deleted 7y ago[deleted]
- elisharobinson 7y agofrom an outsider perspective i can say that to me This is a security tool and it should show popup for restricted sites and/or flagged sites. if its intent was a general notification extension like office emails etc , nobody would have cared. But since it is a security tool even if your action is not malicious the expectation of security only updates is breached, which is what i believe is the core issue. More so the employee is a security engineer, the fact that this is most likely something they would be aware of and proceeded to do this change anyway is something which is extreme-ly worrying. It raises all sorts of questions like how safe is google infrastructure from rouge employees and how does this affect data collected by google and handled by googlers.
- conanbatt 7y agoIf she had made a popup that said women and men don't share the same predilection for software engineer she would have been fired as well.
- throwaway894345 7y agoI agree that "Don't slack off dummy" would have earned a rebuke, but I wouldn't be surprised if any controversial political activist message would have been grounds for termination, especially with Google's new policy regarding political activism in the workplace. She would likely have been rebuked if she had just posted a flyer in the cafeteria, but she modified an internal tool.
- ThrowawayR2 7y ago> "Yeah let's be real, if she programmed a popup to appear over twitter with a message like "Don't slack off dummy UwU" and or something equally ill informed she would have been rebuked at worst." What? Granted, I've only worked for large businesses but that would be grounds for immediate termination at any company I've ever worked at.
- trickstra 7y agoFrom her description of her job position it seems like programming a popup to appear over twitter with a message like "Don't slack off dummy UwU" was exactly what Google wanted her to do in her job. > As a security engineer who worked on the Chrome browser’s use within Google, Spiers wrote browser notifications so that employees could be automatically notified of the company’s policies and guidelines as they browse the internet. Spiers said that engineers regularly implement such code changes to make their jobs easier and share personal interests. But programming a popup to appear over a union busting law firm website with a message that such and such law exists was not. > Spiers wrote a few lines of code that created a pop-up message asserting Google employees’ labor rights whenever her co-workers visited the consulting firm’s website or Google’s community guidelines. The message reads: "Googlers have the right to participate in protected concerted activities." The pop-up would have been visible to anyone at Google. > https://www.vice.com/en_us/article/jgexe8/google-fired-an-engineer-who-wrote-code-telling-googlers-they-had-a-right-to-organize https://www.vice.com/en_us/article/jgexe8/google-fired-an-en...
- hugi 7y agoShe went through the corporate approved process with her changes. Her only mistake here is being pro union while Google is decidedly anti-union and pro-worker-abuse.
- Jare 7y agoThey approved the code that implemented the feature, but I doubt they were responsible for approving the feature to begin with.
- gambiting 7y agoI don't know how this works where you are, but when I'm asked to review code for someone, that's exactly what I do but also only what I do - I don't ask them if they have a design document for the change or approval from the features team. It's not my job to verify that.
- deleted 7y ago[deleted]
- strathmeyer 7y agoYikes make room for someone who wants to do the job
- DanBC 7y ago> There's a sort of assumed good-faith for this process. I don't understand why two people sign off changes if they assume the person making the changes isn't going to make errors or be "malicious". And I'm not sure why two people sign off changes instead of just one. There's a well understood problem when you have more than one person inspecting product - they both assume the other person is competent and will catch anything they've missed, and they each do a lighter inspection.
- wolco 7y agoTechnically it worked so the approvals would have gone through. These people would not have direct insight into her business objectives or intent.
- magduf 7y ago>And I'm not sure why two people sign off changes instead of just one. Because more eyes catch more bugs. I work in a time like this where we have 2 or even 3 people review stuff; it's extremely common for one engineer to miss stuff that another one catches. It's particularly notable I think with junior vs. senior engineers: I think you really need at least one senior engineer reviewing everything before a merge, but you don't want to keep junior engineers out of the process because then they'll never learn. With trivial tickets, however, you can relax this rule and just have one person review before a merge.
- DanBC 7y ago> Because more eyes catch more bugs. But for product inspection we have pretty good evidence, from millions of human hours of factory work, that it's a bit more complicated. X makes a widget, and sends it for inspection by Y and Z. Y has a look, but assumes Z will catch anything that Y misses. But Z also assumes that Y will catch anything that Z misses. You end up with two people doing a superficial inspection and missing problems. Of course, that's only if they're doing the same inspection twice. If they have different and clearly defined inspection roles the two inspector problem doesn't apply.
- singron 7y ago
- GhettoMaestro 7y agoIf all of them signed off then they all should be canned. Work is called work for a reason. Millennials struggle with this core concept.
- magduf 7y agoNo, it really depends. It's easy to overlook stuff on a merge request. I'd interview both of the reviewers, and with them look at the actual MR and see what they were looking at, and ask them how they missed this and why they thought it was OK to merge. I've seen some pretty glaring stuff get through a review process, particularly with junior engineers.
- icebraining 7y agoEverywhere I've worked, "signing off" on the changes just meant we were OK with the technical implementation. Unless you were junior, you were trusted to have approval for the purpose of the change. A change like this, which was linking to an official policy document, wouldn't have raised any eyebrows.
- Alex3917 7y ago> The fact that 2 coworkers were fine with your change doesn't mean it was made in good-faith The standard for whether a company is legally allowed to fire an employee for organizing isn't whether their action is in "good faith", but whether their action is concerted. The fact that it passed code review is therefore critical evidence.
- Touche 7y agoIANAL, but California is an at-will state. Again, IANAL, but my educated understanding is that you can fire someone for any reason as long as the reason is not illegal. Lastly, IANAL.
- sdenton4 7y agoOrganizing is protected by law. Firing for organizing is intimidation.
- Touche 7y agoYep, that's what's contested here and is unclear.
- ralusek 7y agoIs using whatever mechanism is available to you, including company privileges, in order to organize perfected by law? As a customer support person, would you be able to add "you have the right to sue Google," simply because they did have the right, and I felt like it? Am I allowed to write a script that helps draft automated verbiage to assist you in suing Google?
- space_fountain 7y agoBut IANAL firing some one for telling their co-workers about their right to unionize is an illegal reason to fire someone. I'm not completely convinced that's what happened here but still
- matwood 7y ago
- Frost1x 7y agoI have to agree. I'm all for unionization in our industry to improve employee leverage and even more open compensation sharing to help drive comp up... but this is a step too far. Pushing your message in this fashion is clearly irresponsible no matter how "by-the-book" it is. With that said, the organization and orchestration problem for movements is a very real problem (finding the correct people and disseminating information). This is something businesses are well aware of and they use that to their advantage.
- sdenton4 7y agoIt's an even harder problem when the employer is firing people for trying to organize. Change the words in the message, and I can't imagine it being anything but a reprimand, at worst. This is a message to other employees that organizing gets you fired.
- fxleach 7y agoI think the punishment is warranted for the fact that it is an internal security tool. I don't know of any large company that would allow this kind of code commit without that level of punishment being taken. She was trying to be sincere in her actions but comes off as completely naive that what she was doing was a serious violation. I don't see her winning this to any degree and at 21 it will be a big learning lesson.
- deleted 7y ago[deleted]
- CodeMage 7y ago> Prefixing this by saying I am not siding with Google (since people make assumptions). Prefixing this by saying I'm not making an assumption about who you're siding with, but offering my opinion on the argument you're using. > The standard approval process sounds like most merge review processes on any engineering team. There's a sort of assumed good-faith for this process. The fact that 2 coworkers were fine with your change doesn't mean it was made in good-faith and was within the bounds of normal types of changes. Other people have already argued about whether what she added to the extension is in line with the purpose of the extension and whether it was within her purview. Regardless of that, I would like to point out that we're not hearing that these two coworkers -- or anyone else involved in the process -- have been fired. Only Spiers. If the concern is really about the security and the trust, why is one person singled out?
- lr4444lr 7y agoThat just means the code was made to quality standards, not that the she had authority to make that kind of feature modification without approval. In a less technical analogy, just because you have a right to put up flyers doesn't mean you have the right to use the company paper and printers to make them.
- lnanek2 7y agoLet me preface this by saying I think what she posted is true, employees have a right to unionize. That said, it seems kind of strange, if this was a better way to post something than the cafeteria, that she added it to the union buster's site, though. Wouldn't only execs and management hiring the union busters go there? Seems like it was a way to argue back with the execs who hired the union busters by essentially defacing the union busters site? She probably pissed off a high level exec who hired the union busters in the first place and was fired by their order. She was making all the management who visited their site see her notice, and some management obviously support the union busters since they hired them in the first place...