<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Essays by Erik</title>
    <atom:link href="/essays/feed.xml" rel="self" type="application/rss+xml"/>
    <link>https://erikbarbara.github.io/essays/</link>
    <description>Essays by Erik Barbara. All opinions are my own.</description>
    <pubDate>Tue, 25 Aug 2026 20:18:47 +0000</pubDate>
    
      <item>
        <title>Where to Put the Bolt</title>
        <link>/essays/2026/05/20/the-bolt.html</link>
        <guid isPermaLink="true">/essays/2026/05/20/the-bolt.html</guid>
        <description>&lt;p&gt;From time to time, direct reports will voice concerns about their output. This is typically some variant of how much code they’ve not written recently while coordinating some complex aspect of a project. Recently due to leadership emphasis on “AI fluency” this is with respect to token usage.&lt;/p&gt;

&lt;p&gt;My goto reply is the following parable. First told to me by a manager early in my career, now others &lt;del&gt;suffer&lt;/del&gt; receive it similarly.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;A factory worker retires after 40 years on the job. The next week a critical machine breaks down bringing the assembly line to a halt. The worker was an expert in this machine.&lt;/p&gt;

  &lt;p&gt;The company tries everything to get it running. They take it apart and put it back together, bring in consultants, fly in workers from other plants. Nothing works.&lt;/p&gt;

  &lt;p&gt;Finally, they contact the worker, “Please help us get this machine back online. You can charge us whatever you want.”&lt;/p&gt;

  &lt;p&gt;Factory worker comes onsite, walks around, finds a bolt on the floor, screws the bolt back onto the machine, and presses the power button. It whirs to life. Worker tells them, “All set. I’ll invoice you.”&lt;/p&gt;

  &lt;p&gt;The worker sends in the invoice and the factory head calls them up, “What do you mean $20K?! You spent 20 seconds on this. I need this itemized.”&lt;/p&gt;

  &lt;p&gt;The worker sends in an itemized invoice:&lt;/p&gt;
  &lt;ul&gt;
    &lt;li&gt;Bolt: Free&lt;/li&gt;
    &lt;li&gt;Knowing where to put the bolt: $20K&lt;/li&gt;
  &lt;/ul&gt;
&lt;/blockquote&gt;

&lt;p&gt;Outcomes »&amp;gt; outputs. 🔩&lt;/p&gt;
</description>
        <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>The (AI) Road Ahead</title>
        <link>/essays/2026/04/24/the-road-ahead.html</link>
        <guid isPermaLink="true">/essays/2026/04/24/the-road-ahead.html</guid>
        <description>&lt;p&gt;The job market does not have to be net negative due to AI.&lt;/p&gt;

&lt;p&gt;As I’ve confessed before, my 🔮 is cloudy. With that profession, here are two theories with respect to the job market and this moment of AI uncertainty.&lt;/p&gt;

&lt;p&gt;I believe these hold for at least the conditions where superhuman intelligence is not achieved. Otherwise, we will have unstable equilibrium.&lt;/p&gt;

&lt;h2 id=&quot;crushing-the-competition&quot;&gt;Crushing the Competition&lt;/h2&gt;

&lt;p&gt;Companies are marveling at AI in the moment. They say “Wow, look at what we can do with this. We can be so efficient.”&lt;/p&gt;

&lt;p&gt;There are two roads to take from there.&lt;/p&gt;

&lt;p&gt;The organization continues, saying, “We can do the same amount of work with fewer people.”&lt;/p&gt;

&lt;p&gt;This is the scarcity mindset. The path Block has taken, laying off 40% of the company.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;we’re not making this decision because we’re in trouble. our business is strong. gross profit continues to grow, we continue to serve more and more customers, and profitability is improving. but something has changed. we’re already seeing that the intelligence tools we’re creating and using, paired with smaller and flatter teams, are enabling a new way of working which fundamentally changes what it means to build and run a company. and that’s accelerating rapidly.&lt;/p&gt;

  &lt;p&gt;– &lt;a href=&quot;https://x.com/jack/status/2027129697092731343&quot; target=&quot;_blank&quot;&gt;Jack Dorsey, CEO&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;In the other, the organization instead says, “We can do so much more with the same amount of people.”&lt;/p&gt;

&lt;p&gt;This is the growth mindset. These organizations keep their existing hiring plans or expand them. They retool and reorganize. They accelerate, not maintain, their roadmaps. They pull ahead of the competition, the ones maintaining their existing pace with fewer people. They crush them.&lt;/p&gt;

&lt;p&gt;The job market does not have to be net negative due to AI.&lt;/p&gt;

&lt;h2 id=&quot;computers-as-jobs&quot;&gt;Computers as Jobs&lt;/h2&gt;

&lt;p&gt;Computer used to be a job that people did. Very intelligent people. Often women. We’ll refer to them as capital-C “Computers”.&lt;/p&gt;

&lt;p&gt;These Computers, well, they &lt;em&gt;computed&lt;/em&gt; complex maths: planetary orbits, rocket trajectories, flight paths.&lt;/p&gt;

&lt;p&gt;Then computers as we know them came. Computers that could work tirelessly, consistently, and with near flawless execution given proper instructions and oversight.&lt;/p&gt;

&lt;p&gt;What about the Computers? Were they relegated to the dustbin of economic history? No.&lt;/p&gt;

&lt;p&gt;Yes, there may have been momentary disruption in how we applied them.&lt;/p&gt;

&lt;p&gt;Capitalism is ruthlessly efficient.&lt;br /&gt;
It would be economically wasteful to not utilize these individuals.&lt;br /&gt;
It would be capitalistically irrational.&lt;/p&gt;

&lt;p&gt;And so we found new uses for them. In overseeing the computers. Taking on higher order levels of work. New abstractions. The job market was not zero sum, exchanging Computers for computers. Computers are the spiritual ancestors of today’s software engineers.&lt;/p&gt;

&lt;p&gt;And so it can be with AI.&lt;/p&gt;

&lt;p&gt;While handcrafting code may become a hobbyist endeavor, utilizing their human intelligence will not.&lt;/p&gt;

&lt;p&gt;We will find new, knowledge-based uses for intelligent people. The uses are hard to see right now in the fog of war.&lt;/p&gt;

&lt;p&gt;Capitalism is ruthlessly efficient.&lt;br /&gt;
It would be economically wasteful to not utilize these individuals.&lt;br /&gt;
It would be capitalistically irrational.&lt;/p&gt;

&lt;p&gt;The job market does not have to be net negative due to AI.&lt;/p&gt;
</description>
        <pubDate>Fri, 24 Apr 2026 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>Winter Is Coming</title>
        <link>/essays/2026/04/10/winter-is-coming.html</link>
        <guid isPermaLink="true">/essays/2026/04/10/winter-is-coming.html</guid>
        <description>&lt;blockquote&gt;
  &lt;p&gt;Winter is coming.&lt;/p&gt;

  &lt;p&gt;– House of Stark&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A year ago, most engineers, myself included, thought Copilot and Cursor were “cute”. That’s nice. They can write tests or auto-complete a few lines.&lt;/p&gt;

&lt;p&gt;Today engineers turn over entire features to Claude Code and let it burn.&lt;/p&gt;

&lt;p&gt;A sea change has occurred in AI capabilities these past 6 months.&lt;/p&gt;

&lt;p&gt;Security is not unaffected. A few recent Anthropic announcements:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;…found and validated more than 500 high-severity vulnerabilities.&lt;/p&gt;

  &lt;p&gt;– &lt;a href=&quot;https://red.anthropic.com/2026/zero-days/&quot; target=&quot;_blank&quot;&gt;Evaluating and mitigating the growing risk of LLM-discovered 0-days&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;blockquote&gt;
  &lt;p&gt;…discovered 22 vulnerabilities over the course of two weeks…a fifth of all high-severity Firefox vulnerabilities that were remediated in 2025.&lt;/p&gt;

  &lt;p&gt;&lt;a href=&quot;https://red.anthropic.com/2026/firefox/&quot; target=&quot;_blank&quot;&gt;Partnering with Mozilla to improve Firefox’s security&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;blockquote&gt;
  &lt;p&gt;…capable of identifying and then exploiting zero-day vulnerabilities in every major operating system…subtle or difficult to detect…27-year-old bug in OpenBSD—an operating system known primarily for its security.&lt;/p&gt;

  &lt;p&gt;&lt;a href=&quot;https://red.anthropic.com/2026/mythos-preview/&quot; target=&quot;_blank&quot;&gt;Assessing Claude Mythos Preview’s cybersecurity capabilities&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Where does this leave us? My 🔮 is cloudy, but here is a guess.&lt;/p&gt;

&lt;h2 id=&quot;micro-pessimism&quot;&gt;Micro-pessimism&lt;/h2&gt;

&lt;p&gt;The next 2-3 years will be bad. It will feel like a reset of the internet to the early 00’s when OWASP Top 10 in the wild was the norm, not a cautionary tail.&lt;/p&gt;

&lt;p&gt;We’ll see an unprecedented volume of high-severity vulnerabilities in open source projects foundational to modern software. Teams will be buried in triage and patching.&lt;/p&gt;

&lt;p&gt;Adversaries will abuse frontier models to identify and exploit new vulnerabilities in open source, compromise supply chains, and directly attack corporate applications.&lt;/p&gt;

&lt;p&gt;There are tremendous asymmetries for attackers. They can scale up more agents, hunting across companies and attack surfaces. In spite of organizations’ best defenses, failure only requires one successful attack. And of course, attackers have an asymmetry in morals.&lt;/p&gt;

&lt;p&gt;Given this, there are only a few obviously useful asymmetries in the other direction.&lt;/p&gt;

&lt;p&gt;First, organizations know their most worrisome areas (weakest || most important). They know what keeps them up.&lt;/p&gt;

&lt;p&gt;Second, organizations are the only ones with access to their codebase.&lt;/p&gt;

&lt;p&gt;Organizations should act on both in combination. Run agentic vulnerability scanners against codebases. Direct them to the most worrisome areas and entry points first. Prioritize ruthlessly. Repeat.&lt;/p&gt;

&lt;p&gt;Because attackers can’t–yet. They’re limited to external attack surfaces.&lt;/p&gt;

&lt;p&gt;Go.&lt;/p&gt;

&lt;h2 id=&quot;macro-optimism&quot;&gt;Macro-optimism&lt;/h2&gt;

&lt;p&gt;The future can be better. The systems we build and code we write 1-2 years from now, reviewed by frontier models for flaws from the start, can be the most secure in history.&lt;/p&gt;

&lt;p&gt;5 years from now, we can shake out the worst of the legacy issues. The new norm can be laughably secure systems.&lt;/p&gt;

&lt;p&gt;Onward.&lt;/p&gt;
</description>
        <pubDate>Fri, 10 Apr 2026 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>The Weight of Privacy</title>
        <link>/essays/2024/05/30/weight-of-privacy.html</link>
        <guid isPermaLink="true">/essays/2024/05/30/weight-of-privacy.html</guid>
        <description>&lt;p&gt;&lt;em&gt;N.B. The goal of examples and cases below is to examine what went wrong, not cast aspersions at companies or past decisions.&lt;/em&gt;&lt;/p&gt;

&lt;h2 id=&quot;what-is-privacy&quot;&gt;What Is Privacy?&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://www.youtube-nocookie.com/embed/BlisJgS_lyA?rel=0&quot; target=&quot;_blank&quot;&gt;Video: Steve Jobs On Privacy&lt;/a&gt; (34s)&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Privacy is the right to control &lt;em&gt;your&lt;/em&gt; data.&lt;/strong&gt; Boil away the legal details and this is its essence.&lt;/p&gt;

&lt;p&gt;This post provides a survey of real privacy issues, and how they can be mitigated. The goal is to convey the weight of privacy that we all bear as engineers handling user data.&lt;/p&gt;

&lt;h2 id=&quot;why-care-about-privacy&quot;&gt;Why Care about Privacy?&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://www.youtube-nocookie.com/embed/EZVPEeG4h7s?rel=0&quot; target=&quot;_blank&quot;&gt;Video: Mythic Quest Has Been Hacked&lt;/a&gt; (42s)&lt;/p&gt;

&lt;p&gt;Respecting privacy &lt;strong&gt;is&lt;/strong&gt; users first.&lt;/p&gt;

&lt;p&gt;Set aside the alphabet soup (GDPR, CCPA) of privacy legislation and how you may feel about these laws. Many, many users care deeply about how their and their customers’ data is used; a significant degree consider privacy to be a fundamental &lt;a href=&quot;https://www.un.org/en/about-us/universal-declaration-of-human-rights#:~:text=Article%2012,against%20such%20interference%20or%20attacks.&quot; target=&quot;_blank&quot;&gt;human right&lt;/a&gt;. Not sufficiently considering user privacy in your products and systems is to disrespect your users’ privacy, violate their rights, and go against company values to put users first.&lt;/p&gt;

&lt;p&gt;When users discover violations, trust is lost. Users expect that by default:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Products protect privacy (&lt;a href=&quot;https://22-8miles.com/public-by-default/&quot; target=&quot;_blank&quot;&gt;Public By Default: What Venmo and the Whole World Knows About You&lt;/a&gt;)&lt;/li&gt;
  &lt;li&gt;Data access is limited (&lt;a href=&quot;https://www.reuters.com/technology/tesla-workers-shared-sensitive-images-recorded-by-customer-cars-2023-04-06/&quot; target=&quot;_blank&quot;&gt;Tesla workers shared sensitive images&lt;/a&gt;)&lt;/li&gt;
  &lt;li&gt;Internal tools are safe (&lt;a href=&quot;https://www.forbes.com/sites/kashmirhill/2014/10/03/god-view-uber-allegedly-stalked-users-for-party-goers-viewing-pleasure/&quot; target=&quot;_blank&quot;&gt;Uber Allegedly Stalked Users, Snapchat Employees Abused Data Access&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is trust that takes years to build, but would take seconds to break, and may take forever to repair.&lt;/p&gt;

&lt;h2 id=&quot;privacy-engineering-and-how-it-is-different-from-security-engineering&quot;&gt;Privacy Engineering (and How It Is Different from Security Engineering)&lt;/h2&gt;

&lt;p&gt;Privacy engineering teams builds frameworks to meet the privacy expectations of users.
Security and privacy are adjacent but distinct disciplines. Privacy is about the right to control how personal data is collected and used. Security is about protecting that data, including preventing unauthorized access, data corruption, or theft. Often good practices overlap between the two.&lt;/p&gt;

&lt;p&gt;The first OWASP Top 10 dropped in 2003 with your favorite PHP and IIS-powered site vulnerable to script kiddies. Twenty years later robust security protections come out-of-the-box in popular frameworks. For example, a default Rails app provides protections for CSRF, SQL injection, and more.&lt;/p&gt;

&lt;p&gt;Privacy engineering is today where web app security was 20 years ago. There are few paved paths and even fewer plug-and-play frameworks for achieving the ends expected by users and demanded by legislation. Because of this, the frameworks companies use to ensure they respect user privacy evolve drastically year-to-year.&lt;/p&gt;

&lt;p&gt;By seeing the consequences of privacy issues in practice, you can better understand why you’re asked to implement privacy controls or adopt privacy frameworks.&lt;/p&gt;

&lt;h2 id=&quot;selected-case-studies-and-lessons&quot;&gt;Selected Case Studies and Lessons&lt;/h2&gt;

&lt;blockquote&gt;
  &lt;p&gt;Invert, always invert.&lt;/p&gt;

  &lt;p&gt;— Charlie Munger&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The front page test is an excellent litmus test for privacy issues. It’s useful to examine real-world privacy issues and then invert these into practices to adopt instead.&lt;/p&gt;

&lt;h3 id=&quot;was-clear-plain-terms-consent-obtained-before-data-collection-or-use&quot;&gt;Was clear, plain-terms consent obtained before data collection or use?&lt;/h3&gt;

&lt;p&gt;In 2011, Google &lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2011/03/ftc-charges-deceptive-privacy-practices-googles-rollout-its-buzz-social-network&quot; target=&quot;_blank&quot;&gt;agreed&lt;/a&gt; to an FTC consent decree requiring 20 years of independent privacy audits. This came from Google Buzz sign-up and data sharing. In the FTC’s own words:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Google led Gmail users to believe that they could choose whether or not they wanted to join the network, [but] the options for declining or leaving the social network were ineffective…the controls for limiting the sharing of their personal information were confusing and difficult to find[.] [Consumers were] concerned about public disclosure of their email contacts which included, in some cases, ex-spouses, patients, students, employers, or competitors.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;In another case in 2022, CNIL–France’s privacy regulator–&lt;a href=&quot;https://www.theverge.com/2022/1/7/22871719/france-fines-google-facebook-cookies-tracking-dark-patterns-eprivacy&quot; target=&quot;_blank&quot;&gt;fined&lt;/a&gt; Google and Facebook €150M and €60M respectively for nudging users to “accept all” cookies in their consent banners. Consent must be provided freely. That means making it as easy to reject non-essential cookies as accept them.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://web.archive.org/web/20220114092730im_/https://pbs.twimg.com/media/FJDVVirX0AI1Qlt.png&quot; alt=&quot;Opt-out checkbox&quot; width=&quot;600px&quot; /&gt;&lt;/p&gt;

&lt;p&gt;In 2022, a Twitter user &lt;a href=&quot;https://web.archive.org/web/20220114092730/https://twitter.com/type__error/status/1481918942474035203&quot; target=&quot;_blank&quot;&gt;called out&lt;/a&gt; Stripe for a checkbox to subscribe to email product updates. The issue was quickly remediated once flagged.&lt;/p&gt;

&lt;p&gt;Users have high standards for companies and expect the same excellence and clarity in the privacy experience as the rest of the product experience.&lt;/p&gt;

&lt;h4 id=&quot;inversion&quot;&gt;Inversion&lt;/h4&gt;

&lt;blockquote&gt;
  &lt;p&gt;Privacy means people know what they are signing up for in plain English…Ask them.&lt;/p&gt;

  &lt;p&gt;— Steve Jobs&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;When building user journeys–for example, signup pages–Jobs’ advice from the first video is trustworthy.&lt;/p&gt;

&lt;p&gt;Ask users unambiguously for permission. A user is signing up for a product? Ask them. Want to collect web analytics? Ask them. And if asking is difficult for whatever reason, ask your privacy-focused colleagues whether there are alternatives.&lt;/p&gt;

&lt;p&gt;Respecting the &lt;a href=&quot;https://globalprivacycontrol.org/&quot;&gt;Global Privacy Control&lt;/a&gt; setting for &lt;em&gt;all&lt;/em&gt; users is a clear illustration of prioritizing and respecting users’ privacy. Beyond merely complying with legal requirements, you can prioritize users’ privacy preferences. Even in jurisdictions where it’s not required, respect users’ GPC setting opting them out of advertising cookies. Users with the GPC setting proactively communicate their preference, so respect this and don’t set those cookies or use their data for that purpose.&lt;/p&gt;

&lt;h3 id=&quot;did-the-reason-for-collecting-the-data-remain-consistent&quot;&gt;Did the reason for collecting the data remain consistent?&lt;/h3&gt;

&lt;p&gt;In 2022 as part of a 20 year consent decree, the FTC &lt;a href=&quot;https://www.ftc.gov/news-events/news/press-releases/2022/05/ftc-charges-twitter-deceptively-using-account-security-data-sell-targeted-ads&quot; target=&quot;_blank&quot;&gt;ordered&lt;/a&gt; Twitter to pay $150M for collecting phone numbers for 2FA and then using those numbers for targeted ads. The data used was not clearly annotated, leading to this mishap. Users were frustrated. They provided their phone numbers with the understanding that they’d protect their accounts, not enable advertising.&lt;/p&gt;

&lt;p&gt;A 2020 blog post was picked up by &lt;a href=&quot;https://news.ycombinator.com/item?id=22936818&quot; target=&quot;_blank&quot;&gt;Hacker News&lt;/a&gt; with concerns over Stripe’s collection of advanced fraud signals. There were concerns that Stripe’s privacy policy allowed for using this data for advertising purposes. Patrick Collison, Stripe’s CEO, quickly promised that this data is collected exclusively for anti-fraud purposes. Stripe followed this up with a &lt;a href=&quot;https://stripe.com/blog/advanced-fraud-detection-updates&quot; target=&quot;_blank&quot;&gt;blog post&lt;/a&gt; and updates to its privacy policy.&lt;/p&gt;

&lt;p&gt;Distrust of how companies use data is the norm. Regardless of your intent, users are quick to point out incongruencies and potential loopholes between policies and practices.&lt;/p&gt;

&lt;h4 id=&quot;inversion-1&quot;&gt;Inversion&lt;/h4&gt;

&lt;p&gt;You must adhere to the purposes of processing for which data was collected. In practice this is called business purpose limitation. If data was collected for anti-fraud purposes then that’s what the data can be used for. You can’t later change your mind without gathering consent again.&lt;/p&gt;

&lt;p&gt;Individuals have the right to a copy of their data (via a Data Subject Access Request), often grouped by the purposes of processing. Imagine seeing data a user provided for risk purposes displayed under analytics because it was copied inappropriately from one system to another. Users also have the right to be forgotten and for their data to be deleted.&lt;/p&gt;

&lt;p&gt;Data annotations are key to knowing what data you have, to whom it belongs, and why it was collected. Annotations are foundational to infrastructure limiting access to closed account data, a special case of business purpose limitation. They can also be used to identify data to delete when you no longer have a justification for retaining it.&lt;/p&gt;

&lt;p&gt;When creating or editing data models, add annotations. Yes, this should be the case even if the dataset is intended to be short-lived or only go to QA. Usage evolves, data is forgotten, people move on. Without annotations you can’t account for the data you have.&lt;/p&gt;

&lt;p&gt;While privacy engineering teams can create inference models and tools to improve the ease of annotation and accuracy, you are ultimately the expert in your data and responsible for us handling it well.&lt;/p&gt;

&lt;h3 id=&quot;is-access-to-data-limited-to-proper-use-cases&quot;&gt;Is access to data limited to proper use cases?&lt;/h3&gt;

&lt;p&gt;In 2024, a Carta employee inappropriately accessed and &lt;a href=&quot;https://www.axios.com/2024/01/08/carta-credibility-startup-founder-allegations#:~:text=In%20short%2C%20someone%20on%20Carta%27s%20%22liquidity%20solutions%22%20team%20had%20accessed%20Linear%27s%20confidential%20cap%20table%20data%3B%20leveraging%20the%20core%20product%20as%20lead%20gen%20for%20a%20more%20lucrative%20effort.%20It%20was%20a%20massive%20ethical%20breach%2C%20no%20matter%20how%20different%20lawyers%20might%20interpret%20Carta%27s%20privacy%20policy.&quot; target=&quot;_blank&quot;&gt;shared&lt;/a&gt; customer data to generate interest in an unauthorized, secondary sale of stock. As a result and to stave off brand damage, within 72 hours Carta shuttered their entire secondary stock sale business.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;One VC [said] it was akin to ‘Oracle using your database to share supply-chain data or Salesforce using your CRM data to inquire about the state of your sales leads.’&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Abuse of internal tools and data access is deeply corrosive to user trust.&lt;/p&gt;

&lt;h4 id=&quot;inversion-2&quot;&gt;Inversion&lt;/h4&gt;

&lt;p&gt;Least privilege dictates that only the people and workloads that need access to specific data for their job have it. That access must also be monitored and audited.&lt;/p&gt;

&lt;p&gt;Authorization controls including two-person confirmation and expiring permissions on internal tools and data can enforce least privilege. These checks may add friction to your workflow. And, yes, you are trying to help your users. Remember though that the abuses mentioned at the beginning of this article stemmed from permissive access. Continual investments in ergonomics can minimize the impact of these controls on daily productivity.&lt;/p&gt;

&lt;p&gt;In the long term, privacy preserving technologies like tokenization, pseudonymization, and differential privacy can enable open access to data without compromising an individual’s privacy.&lt;/p&gt;

&lt;h2 id=&quot;a-vector-not-a-destination&quot;&gt;A Vector, Not a Destination&lt;/h2&gt;

&lt;p&gt;Like security or reliability, privacy is a vector, not a destination. There will not come a time when the work is done.&lt;/p&gt;

&lt;p&gt;In all likelihood, your company’s use of data is complex and building excellent privacy controls means that privacy engineering teams must make it simple for engineers to reason about its collection and use.&lt;/p&gt;

&lt;p&gt;While building your own products and systems, reflect on the above cases. Whether you are using a privacy engineering framework or implementing controls on your own, we all bear the weighty responsibility of respecting user data and privacy.&lt;/p&gt;
</description>
        <pubDate>Thu, 30 May 2024 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>The RSU Cookie Jar</title>
        <link>/essays/2023/11/13/rsu-cookie-jar.html</link>
        <guid isPermaLink="true">/essays/2023/11/13/rsu-cookie-jar.html</guid>
        <description>&lt;blockquote&gt;
  &lt;p&gt;Who stole the cookie from the cookie jar?&lt;/p&gt;

  &lt;p&gt;— &lt;a href=&quot;https://www.youtube.com/watch?v=_2qofl5LGg8&quot; target=&quot;_blank&quot;&gt;Sesame Street&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;If a company’s valuation increases and its growth prospects taper enough, they’ll switch from granting employees &lt;a href=&quot;/essays/2023/10/25/of-isos-and-edge-cases.html&quot;&gt;Incentive Stock Options (ISOs)&lt;/a&gt; to Restricted Stock Units (RSUs).&lt;/p&gt;

&lt;p&gt;With RSUs, the company essentially &lt;em&gt;gives&lt;/em&gt; the employee company stock over a period of time.&lt;/p&gt;

&lt;h2 id=&quot;double-trigger-rsus&quot;&gt;Double-Trigger RSUs&lt;/h2&gt;

&lt;p&gt;There are different &lt;em&gt;triggers&lt;/em&gt; on the RSUs that must be satisfied before the employee receives units of company stock. A time-based trigger is nearly always present on the RSUs. This is the same as ISO vesting where an employee must achieve tenure at a company. RSU grants typically have a one year cliff when an employee first joins the company; subsequent grants then vest quarterly.&lt;/p&gt;

&lt;p&gt;Sometimes there’s a second trigger on private company stock where not only must the employee be at the company a period of time before they receive the stock but the company must also experience a liquidity event like a public offering or an acquisition.&lt;/p&gt;

&lt;p&gt;Until both triggers are met, employees aren’t taxed by the government on their vested RSUs. In exchange, the IRS &lt;a href=&quot;https://www.irs.gov/businesses/corporations/equity-stock-based-compensation-audit-techniques-guide&quot; target=&quot;_blank&quot;&gt;requires&lt;/a&gt; that there be a &lt;strong&gt;substantial risk of forfeiture&lt;/strong&gt;. Often this risk comes in the form of expiration.&lt;/p&gt;

&lt;h2 id=&quot;susans-rsus&quot;&gt;Susan’s RSUs&lt;/h2&gt;

&lt;p&gt;Let’s go back to Susan. Widgets.io no longer grants stock options and instead has switched to RSUs. This happens when the future expected growth of a stock is much lower. If the value of a share is $1,000, it’s far less likely to 100x again. So companies switch to RSU grants to incentivize employees joining.&lt;/p&gt;

&lt;p&gt;When Susan joined Widgets.io 6 years ago, Susan received a grant for 1,000 double-trigger RSUs vesting over 4 years. 7 years later that initial grant is fully vested and the company shares are worth $2,000 each. But the bad news is that Widget.io is not planning on going public or being acquired anytime soon. And the worse news is that the RSU plan is written such that grants will expire after 8 years. So on paper Susan theoretically has $2M of stock that may just vanish in a year if the second trigger isn’t met.&lt;/p&gt;

&lt;p&gt;The company wants to retain Susan. If they start letting RSUs expire before the second-trigger is met and they’re converted to full shares, employees will lose trust in their compensation.&lt;/p&gt;

&lt;p&gt;But the IRS requires that RSUs carry substantial risk of forfeiture. What the company can’t do is say “Don’t worry, Susan, even if your $2M in RSUs expire we’ll just give you $2M immediately in new ones that expire in 8 more years.” A statement or practice like that would immediately throw up flags with the IRS.&lt;/p&gt;

&lt;p&gt;The company would be signaling there isn’t substantial risk of forfeiture. And if the IRS noticed, not only would they say that Susan owes taxes on the $2M because the company winked and nodded about her shares expiring but &lt;strong&gt;every&lt;/strong&gt; employee with RSUs would owe taxes once their time-based trigger was met.&lt;/p&gt;

&lt;h2 id=&quot;the-rsu-cookie-jar&quot;&gt;The RSU Cookie Jar&lt;/h2&gt;

&lt;p&gt;Another way to think of it is like a giant, hermetically sealed cookie jar. The cookies in the jar represent the RSUs belonging to each and every employee. So long as the jar stays sealed, the IRS doesn’t tax employees.&lt;/p&gt;

&lt;p&gt;Some of the cookies though are due to expire, and those employees are sad. The dilemma is that if just one person were to extract their cookies or have their expired cookies replenished with a new one, the IRS consider the seal broken. Now all those employees are required to pay the cookie tax.&lt;/p&gt;

&lt;p&gt;The company is responsible for withholding income tax from the RSUs that just failed to meet their risk forfeiture test. This could be problematic for a company with billions of dollars of employee income tax liability. Most non-public companies don’t store those sort of cash reserves on hand for the purpose of paying employee taxes.&lt;/p&gt;

&lt;p&gt;So what’s a company to do?&lt;/p&gt;

&lt;h2 id=&quot;stripes-fundraise&quot;&gt;Stripe’s Fundraise&lt;/h2&gt;

&lt;p&gt;Stripe faced this conundrum in early 2023. The company was about a year out from their first RSU expiration. Employees were restless to know what the company would do since the economy and market didn’t seem to indicate that a public offering would be imminent. Would the company allow those first RSUs to expire? This would signal to remaining employees that the company may allow their RSUs, even with distant expirations, to become worthless too.&lt;/p&gt;

&lt;p&gt;Stripe in this case decided to &lt;a href=&quot;https://stripe.com/newsroom/news/stripe-series-i-employee-liquidity&quot; target=&quot;_blank&quot;&gt;raise&lt;/a&gt; a substantial sum of money. The fundraise was done in such a way as to satisfy the liquidity trigger requirement. In addition, enough funds were raised so that employees could sell as much of their now vested RSUs as they desired.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;The exact mechanism of meeting the liquidity requirement isn’t clear. A brief, circular, and hand-wavy explanation was once provided along the lines of “It’s somewhat complicated, but I’ll just say that it was met.”&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Typical liquidity events are public offerings or acquisitions. I imagine the legal definition of an acquisition involves a transfer of control. Maybe on paper Stripe was “acquired” via a transfer of control to a shell company. I’m sure outside counsel earned their stripes (no pun intended).&lt;/em&gt;&lt;/p&gt;

&lt;h2 id=&quot;22-vs-37&quot;&gt;22% vs 37%&lt;/h2&gt;

&lt;p&gt;In Stripe’s fundraise, they gave employees a choice of how much withholding they would observe. In order to simplify the administration, if you had &amp;lt;$1M in RSUs vesting you could choose for the company to withhold either 22% or 37% in federal taxes.&lt;/p&gt;

&lt;p&gt;22% was the minimum withholding the IRS requires below $1M; 37% was the highest tax bracket at the time.&lt;/p&gt;

&lt;p&gt;Employees now faced another choice. They were told they’d be able to tender (sell) as much of their stock as they wanted. The tax event and the tender offer were separated by over a month. Because of this, I felt there was some risk. What if the company hit the liquidity event and had cash for the taxes, but some adverse event (for example, a breach) occurred that caused the tender offer to be withdrawn before employees could sell their shares.&lt;/p&gt;

&lt;p&gt;In addition, Stripe would apply this same withholding rate to all future RSU vesting events for the year. And no further employee tender events were planned.&lt;/p&gt;

&lt;p&gt;Lest I end up in another tax man pickle where I chose 22% withholding but actually owed more and couldn’t sell, I opted for the conservative route of 37%.&lt;/p&gt;

&lt;p&gt;The added benefit of this is that with a federal marginal tax rate &amp;lt;37%, you are actually guaranteed a refund on your year end taxes. This essentially acts as tendering a small portion of your stock without actually being at the mercy of the company to plan a full tender event.&lt;/p&gt;

&lt;p&gt;In the end, I tendered all my available shares. After already having seen the share value drop &amp;gt; 50% during my tenure, I preferred to index into the broader market. With more illiquid shares vesting over the next year; it was the right psychological move for me. If the price went down further, I’d feel good about selling. And if the price went up, I’d experience the gain on the future vests.&lt;/p&gt;

&lt;p&gt;Win win.&lt;/p&gt;
</description>
        <pubDate>Mon, 13 Nov 2023 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>Of ISOs and Edge Cases</title>
        <link>/essays/2023/10/25/of-isos-and-edge-cases.html</link>
        <guid isPermaLink="true">/essays/2023/10/25/of-isos-and-edge-cases.html</guid>
        <description>&lt;blockquote&gt;
  &lt;p&gt;It’s not fun…taxes…it’s the worst part of the game!&lt;/p&gt;

  &lt;p&gt;– &lt;a href=&quot;https://www.youtube.com/watch?v=DF_PPPNkw1o&quot; target=&quot;_blank&quot;&gt;Donny&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Startup employees often receive stock options. These are most commonly Incentive Stock Options (ISOs), which carry special tax treatment.&lt;/p&gt;

&lt;p&gt;When a company has a positive financial result, its employees are exposed to some peculiar edge cases within the US tax code. Below are some interesting (and sometimes simplified) scenarios.&lt;/p&gt;

&lt;h2 id=&quot;stock-option-background&quot;&gt;Stock Option Background&lt;/h2&gt;

&lt;p&gt;Susan is an employee of Acme.ai. She is granted 1,000 Incentive Stock Options with a strike price of $1.00 vesting over 4 years.&lt;/p&gt;

&lt;p&gt;Contrary to what many people believe, the employee isn’t given Acme.ai stock. What Susan receives (is granted) is the &lt;em&gt;option&lt;/em&gt; to purchase the company’s stock at a predefined amount. Hence the phrase stock &lt;em&gt;option&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;Employees can only purchase this stock as they gain tenure at the company. This is referred to as vesting. Vesting follows a schedule. Most commonly the stock vests over 4 years. The first 25% vests at the employee’s 1 year anniversary. Then 1/48th vests every month thereafter.&lt;/p&gt;

&lt;p&gt;In the above case, Susan can &lt;em&gt;buy&lt;/em&gt; 1,000 shares of Acme’s stock for $1.00/share.&lt;/p&gt;

&lt;p&gt;Why would she do this? Well, she may believe that the stock will someday be worth more than that.&lt;/p&gt;

&lt;p&gt;The cool thing, is that Susan doesn’t have to buy it as soon as it vests. She may be equivocal about the company’s future success, especially in those early years.&lt;/p&gt;

&lt;p&gt;Instead, Susan can work for Acme.ai for 6 years and decide to purchase those 1,000 shares after that time. Maybe Acme.ai is then valued at $1,000/share. That would be $999K of profit. This is a pretty great deal. Susan gets to buy the stock at the price she was offered 6 years ago and gets the value it’s at today.&lt;/p&gt;

&lt;p&gt;It looks like Susan’s hard work for Acme.ai was worth all those late nights and ramen.&lt;/p&gt;

&lt;h2 id=&quot;alternative-minimum-tax&quot;&gt;Alternative Minimum Tax&lt;/h2&gt;

&lt;p&gt;Hers’s where things start to get wonky. After 6 years, Susan is ready to move from Acme.ai to Widgets.io. Her stock options usually require that she exercise (buy) any shares within 30 days of leaving Acme.ai. $1,000 is meaningful to Susan but she believes in Acme.ai’s future.&lt;/p&gt;

&lt;p&gt;So she buys all 1,000 shares. Now the weird thing is that, yes, Susan owns shares of Acme.ai that are technically worth $1,000,000. However, it’s all funny money. The startup stock is illiquid. She can’t sell it to someone else. She knows of no future IPO or acquisition of Acme.ai. It’s all just Monopoly money.&lt;/p&gt;

&lt;p&gt;But in the eyes of the IRS, Susan &lt;em&gt;may&lt;/em&gt; be taxed on that funny money. The IRS will require that Susan complete forms considering her Alternative Minimum Tax, a parallel tax code that was created to ensure that high earners with uncommon income situations pay their dues.&lt;/p&gt;

&lt;p&gt;Through the infinite wisdom of some tax code creating lawyer, the gains from Susan’s stock are treated as income under the Alternative Minimum Tax code. There are some conditions that attenuate the impact, but overall Susan must think carefully about leaving Acme.ai or exercising her options lest she end up with a tax bill she can’t afford on that $1M of funny money.&lt;/p&gt;

&lt;p&gt;Worse still Susan may choose the exercise all 1,000 options, leave for Widgets, and pay a large tax bill that year. Later if Acme goes bust and her shares are worth $0, she doesn’t get a refund for that tax on her paper wealth. She would get to claim a $999K capital loss, but that probably does her little good unless she has other gains for it offset.&lt;/p&gt;

&lt;h2 id=&quot;deal-close&quot;&gt;Deal Close&lt;/h2&gt;

&lt;p&gt;Now, let’s say Acme.ai signed a letter of intent to be acquired by MegaCorp. Susan may have the opportunity before the deal closes to buy her shares for $1,000 and receive $1M from the deal broker after close. If she doesn’t, the deal may be structured whereupon close MegaCorp will &lt;em&gt;net exercise&lt;/em&gt; her shares and just give her the net proceeds through payroll.&lt;/p&gt;

&lt;p&gt;Why purchase the shares early? Well, if MegaCorp processes the proceeds through payroll, Susan will also be subject to Medicare-related taxes. At her income level this will be 2.25% of additional taxes.&lt;/p&gt;

&lt;p&gt;So should Susan purchase her shares pre-close? Maybe. It would certainly be nice not to pay an additional $20K in taxes. However, deals fall apart all the time. Susan is confronted with a tax pickle choice.&lt;/p&gt;

&lt;p&gt;She could steal away (legally) from 1st base and avoid the Medicare taxes by exercising pre-close. However, if the deal falls apart she would then owe AMT as described above on the $1M of funny money income for which she no longer is receiving cash payment. Susan may effectively go bankrupt in this case for lack of ability to pay the IRS.&lt;/p&gt;

&lt;p&gt;Will she make it to base safe?&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://wp.usatodaysports.com/wp-content/uploads/sites/90/2013/12/red-sox-cardinals-game-6-world-series-jacoby-ellsbury-rundown-103013.gif&quot; alt=&quot;Baseball Pickle&quot; width=&quot;350px&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;The above is a real scenario. I knew employees during the acquisition of Duo Security who faced this very situation. They chose the extra Medicare taxes–likely totaling over $100K–over the risk of bankruptcy.&lt;/em&gt;&lt;/p&gt;

&lt;h2 id=&quot;83b-elections&quot;&gt;83(b) Elections&lt;/h2&gt;

&lt;p&gt;Some companies offer their employees the chance to early exercise their options. In Susan’s case this would mean that she could pay $1,000 some time after she starts at Acme.ai and before the stock has actually vested. Then as she gains tenure with the company, she automatically receives the stock she has already purchased.&lt;/p&gt;

&lt;p&gt;The nice thing here is that the IRS lets her claim the stock as income immediately. And because Susan is buying stock that is worth $1.00/share for $1.00/share her net gain is $0. So there are no tax implications.&lt;/p&gt;

&lt;p&gt;Six years later when Susan’s stock is worth $1,000/share, she already “paid” ordinary income on the stock option exercise and all of her gains are treated as long-term capital gains taxed at 20%.&lt;/p&gt;

&lt;p&gt;But (yes, there’s a but) this is only the case if Susan remembers to fill out and file an 83(b) election with the IRS stating that she wants this specific tax treatment. And she is under fairly strict time requirements to file this soon after early exercising the shares.&lt;/p&gt;

&lt;p&gt;If she doesn’t, the IRS will tax her as she vests her shares. So if at year 4 the stock is worth $900/share, the IRS may tax her newly vested shares under the Alternative Minimum Tax as if she made $899/share on every share she vested.&lt;/p&gt;

&lt;p&gt;Like most tax-related niceties, early exercises are a fun feature of the tax code so long as you understand the paperwork requirements.&lt;/p&gt;

&lt;h2 id=&quot;qualified-small-business-stock&quot;&gt;Qualified Small Business Stock&lt;/h2&gt;

&lt;p&gt;Another cool feature of early exercises is the Qualified Small Business Stock. If you early exercise and file your 83(b), you start the clock on avoiding Federal taxes.&lt;/p&gt;

&lt;p&gt;Essentially for Susan, she needs to hold the stock for at least 5 years before acquisition, and Acme.ai needs to have had &amp;lt;$50M in assets when she exercised.&lt;/p&gt;

&lt;p&gt;If these conditions are met, then Susan doesn’t pay Federal taxes on the greater of $10M or 10 times her basis.&lt;/p&gt;

&lt;p&gt;In Susan’s case, she would avoid Federal taxes on her $999K of profit.&lt;/p&gt;

&lt;p&gt;Technically the QSBS benefit doesn’t require early exercise. But startups that grow past N years of life tend to raise capital that causes the company assets to exceed $50M and disqualify it from the benefit before employees can exercise most of their stock. Early exercise gets you in before the company is disqualified.&lt;/p&gt;

&lt;p&gt;All in all, ISOs are largely a positive feature of the tax code. Their pointy edges though have maimed more than a handful of employees over time.&lt;/p&gt;
</description>
        <pubDate>Wed, 25 Oct 2023 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>The Sacred Timeline</title>
        <link>/essays/2023/09/25/sacred-timeline.html</link>
        <guid isPermaLink="true">/essays/2023/09/25/sacred-timeline.html</guid>
        <description>&lt;p&gt;Humans are remarkably great at revisionist history. Business is no exception. When I discuss a startup or growth company’s future prospects, my crystal ball is typically cloudy. And it’s cloudier the closer I am to the operations and execution of the organization. It’s easier to prognosticate positively about a competitor when you only see their good press and growth rates from the outside.&lt;/p&gt;

&lt;p&gt;Patrick Collison once said at a Stripe all-hands, “We live our self-doubt.”&lt;/p&gt;

&lt;p&gt;On the inside, the likelihood of negative events &lt;em&gt;feels&lt;/em&gt; higher than positive ones. This is probably because negative events occur easily through inertia and complacency while positive breaks require tremendous effort to inflect the business.&lt;/p&gt;

&lt;p&gt;Looking forward, it feels like we as employees are the &lt;a href=&quot;https://en.wikipedia.org/wiki/Time_Variance_Authority&quot; target=&quot;_blank&quot;&gt;Time Variance Authority&lt;/a&gt; working to ensure that the timeline of the company stays on the best, predictable path. We work to cleave branches that threaten to destabilize our trajectory.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://qph.cf2.quoracdn.net/main-qimg-d3935e77983e278a215a50011ef6ea33-lq&quot; alt=&quot;Time Variance Authority Monitor&quot; width=&quot;500px&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Retrospectively, the timeline followed feels self-evident. All the branches that could have been are cleaved and the narrative is set. Of course we ended up here, that’s where we are.&lt;/p&gt;

&lt;p&gt;This comes up from time-to-time with former coworkers from Duo Security. Cisco acquired Duo in 2018 for $2.35B. This was undeniably a great result.&lt;/p&gt;

&lt;p&gt;One of the former Duo executives likes to quip along the lines of “Yes, and we could have done a lot better if we had been more disciplined.”&lt;/p&gt;

&lt;p&gt;I’m not so sure about that. It’s hard to know prospectively which ideas may lead to the next $100M in ARR. And I’ve been skeptical of enough ideas that do so to remain skeptical of my own predictive abilities.&lt;/p&gt;

&lt;p&gt;Conversely, there were a lot of paths that might have been worse than the result Duo arrived at. Nation state adversaries were constantly trying to breach Duo and compromise customers’ authentication systems. Attacker luck or a simple error like an employee getting phished may have led to this. For a security company whose sole purpose is protecting customers, that’s game over and would decimate the company’s value.&lt;/p&gt;

&lt;p&gt;About a year before the Cisco acquisition Duo was in the process of being acquired by another MegaCorp for just under $1B. A signed term sheet and everything. Just before close, the acquirer pulled out. It felt devastating at the time, like we’d peaked. Duo instead raised $70M and just 12 months later was acquired for &amp;gt;2x those terms. Not a bad ROI for a year’s time.&lt;/p&gt;

&lt;p&gt;There’s a reason that one of Stripe’s Operating Principles was once: We Haven’t Won Yet.&lt;/p&gt;

&lt;p&gt;It’s easy to revise the narrative of what occurred; fortune telling forward is far more fraught with peril.&lt;/p&gt;

&lt;p&gt;Avoid complacency and stay diligent.&lt;/p&gt;
</description>
        <pubDate>Mon, 25 Sep 2023 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>More Strange Things</title>
        <link>/essays/2023/02/04/more-strange-things.html</link>
        <guid isPermaLink="true">/essays/2023/02/04/more-strange-things.html</guid>
        <description>&lt;p&gt;More strange experiences, this time less corporate.&lt;/p&gt;

&lt;h2 id=&quot;youre-a-hard-man-to-find&quot;&gt;You’re a Hard Man to Find&lt;/h2&gt;

&lt;p&gt;When I was in undergrad, my brother or neighbor called me from the city where my parents lived in another state. They said that the police were looking for me. Not really the phone call I wanted to get.&lt;/p&gt;

&lt;p&gt;I called the number that they. It turns out it was the police local to me who wanted to get ahold of me. The somehow looked up me up via my parents. Umm…&lt;/p&gt;

&lt;p&gt;I called the number and a detective answers. He asked me if when I last saw my car and what state it was in. I told him I saw it that morning when I left my place and biked to class. Wrong answer. Apparently, I fabricated that memory.&lt;/p&gt;

&lt;p&gt;In the middle of the night the wheels on my car had been stolen. A neighbor had seen another truck in the parking lot and a bunch of wheels in the bed. My truck was left on the ground. They grabbed the plate number and reported it to the police. Local SWAT suited up and enjoyed some nice practice breaking down their door and recovering the wheels. The detective told me that they had had fun getting them back.&lt;/p&gt;

&lt;p&gt;I could head downtown now and recover the wheels from evidence. Problem was that I didn’t have a car to get them. What was I going to do, roll them home one at a time? No luck on getting an assist from the department bringing them to me. Luckily a friend helped me out.&lt;/p&gt;

&lt;p&gt;The detective though mentioned to me that I had been hard to track down. I didn’t have a presence on social media and had removed my contact info and name from the university’s public directory.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;You’re a hard man to find, Mr. Barbara. Please don’t ever become a fugitive of the law.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2 id=&quot;mexico-bus-robbery&quot;&gt;Mexico Bus Robbery&lt;/h2&gt;

&lt;p&gt;In high school, I did a multi-week summer langauge immersion in Mexico. Every day I’d take the bus to the language school from my host house. Let’s call it the #2 route. Usually we’d take another bus back.&lt;/p&gt;

&lt;p&gt;One day late in the evening another student and friend of mine who was staying in the same host house wasn’t feeling too great. We were ready to head home for the evening. The #2 bus going the opposite direction was pulling up, and we were impatient. Brilliant idea, we’ll just take that. It probably takes the same route in reverse. Clearly, I didn’t understand bus routes.&lt;/p&gt;

&lt;p&gt;We got on and rode for a bit. It kept going and going and going. Soon nothing was recognizable. It was getting dark. More and more passengers were exiting the bus and it didn’t seem to be heading at all in the direction we needed.&lt;/p&gt;

&lt;p&gt;Finally we were down to just 7 or so people on the bus including the driver. Two men got up from their spots. One went to the front and the other toward the back where the remaining passengers were located. After hassling the riders in front of us, he approached us with his hand in the pocket of his jacket and what looked like a solid object pointed toward us.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Give me all your money.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;My friend generously replied.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;I don’t have anything, he’s got it all. (pointing to me)&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That was the most fluent and fastest Spanish I’d ever heard him utter. This was also a lie. It was nearly the opposite. I had lost my wallet on the trip and only had Mex$110 ($11 at the time) left: a 100 peso bill and a 10 peso one. My friend on the other hand had a wallet full of USD, cards, etc.&lt;/p&gt;

&lt;p&gt;I reached into my pocket and grabbed one of the bills, hoping it was the 10 peso note. Bad luck.&lt;/p&gt;

&lt;p&gt;After handing him the bill, he was quite unsatisfied and started patting my cargo shorts. Yes, it was the 2000’s. I figured it would be bad to hedge at this point and give up the other bill, so I offered him the laundry detergent I had purchased earlier that day. He was clearly disappointed and went away.&lt;/p&gt;

&lt;p&gt;Up front I could see the other guy clearing out the driver’s change sorter into a bag. He motioned for the driver to pull over. Before they stepped off, he ripped the stereo receiver out of the bus and said something in Spanish about the driver’s mom.&lt;/p&gt;

&lt;p&gt;At that point we hoped it was the end and we’d now get to return home safely. The driver instead went a few blocks down, pulled over, and told the rest of us to get off. So much for solidarity.&lt;/p&gt;

&lt;p&gt;We slinked through the shadows, two gringos running between street lights until we found an open cantina that would let us use their phone to call a cab. It took 2 or 3 bars until we found one. Then we had to convince them to take USD, which was less difficult than I imagined. Finally, we made it back to our host house and collapsed on the entry steps tired from the subsiding adrenaline.&lt;/p&gt;

&lt;p&gt;We didn’t mention it to our host parents, but told our US teacher in the morning about the incident. Phone calls to parents promptly ensued.&lt;/p&gt;

&lt;h2 id=&quot;bora-bora&quot;&gt;Bora Bora&lt;/h2&gt;

&lt;p&gt;I was part of an acquisition in quaint, humble Ann Arbor. As Midwestern as fresh-pressed apple cider. The CEO of the acquiring company eventually dropped in, and we carved out an hour to hear as we squeezed into our 20-person conference room.&lt;/p&gt;

&lt;p&gt;An HR administrator had to fly in special from California just for this visit to prepare for him. I don’t know all what she had to do. I do remember a very special component was ensuring that the CEO had Diet Pepsi Cola Wild Cherry chilled in the fridge for him in case he got thirsty. It was even labeled with his name and with orders for us not to drink it. Apparently the Diet Pepsi Cola Wild Cherry was a key to his success.&lt;/p&gt;

&lt;p&gt;The CEO was dripping in his suit and watch that cost more to buy than I made in a year at the time (I looked it up).&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;I’m &lt;em&gt;really&lt;/em&gt; tired. I’m just stopping in on my way back from Bora Bora from our top sellers event. Who here’s been to Bora Bora? Raise your hand!&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;One person raised theirs. Some people I could see pulling out their phones to look up Bora Bora. I wasn’t too familiar with my French Polynesian islands either to be honest.&lt;/p&gt;

&lt;p&gt;It was a real Mitt Romney moment. Like when he made a bet for $10K in a national debate like it was nothing.&lt;/p&gt;

&lt;p&gt;Anyways, in a 1:1 session with the former CEO of the acquired company, apparently some advice was dispensed about a difficult employee. The big shot’s advice?&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;It’s the a*$holes who get things done.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Ah, two keys to apparent success. That and a cold Diet Pepsi Cola Wild Cherry.&lt;/p&gt;
</description>
        <pubDate>Sat, 04 Feb 2023 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>Strange Things</title>
        <link>/essays/2023/02/03/strange-things.html</link>
        <guid isPermaLink="true">/essays/2023/02/03/strange-things.html</guid>
        <description>&lt;p&gt;A collection of strange experiences I’ve had in corporate America.&lt;/p&gt;

&lt;h2 id=&quot;corporate-espionage&quot;&gt;Corporate Espionage&lt;/h2&gt;

&lt;p&gt;I worked at a Fortune 500 via acquisition. I had high-privilege access to the acquisition company’s systems. One day I was asked to join a video conference with a member of the security team. They informed me that the parent company’s corporate espionage team suspected insiders in the broader org.&lt;/p&gt;

&lt;p&gt;I was given a few usernames and asked to see if they appeared at all in our systems’ audit logs. I was instructed not to search for those usernames on the corporate directory or elsewhere. They were unsure what other systems these individuals may have infiltrated, and didn’t want searches to tip them off that the mole was compromised.&lt;/p&gt;

&lt;p&gt;Never heard where that one went. But it was my first personal exposure to the reality of corporate espionage.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lesson learned&lt;/strong&gt;: Spycraft persists, especially in high tech fields.&lt;/p&gt;

&lt;h2 id=&quot;stickup-stills&quot;&gt;Stickup Stills&lt;/h2&gt;

&lt;p&gt;Another time I was contacted by corporate legal from a Fortune 500. They were cooperating with law enforcement on a local crime. Someone had robbed a convenience store at gunpoint wearing a jacket with a company logo on it. This was a rare jacket that not many employees would have. They suspected that it had been donated to an organization and picked up at a secondhand store. However, the police still wanted to rule out that this wasn’t an employee in our office.&lt;/p&gt;

&lt;p&gt;I was a long-tenured employee who had interacted with many folks in that office throughout the years. Hence why I was brought in. Before they showed me the security camera stills, the attorneys briefed me that it’s natural to want to be helpful. However, unless I really did recognize this person don’t say something like “Hmmm…well maybe it kind of sort of looks like…” I should just state whether I recognize the person or not.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lesson learned&lt;/strong&gt;: Answer the question you’re asked, nothing more; being helpful sometimes isn’t.&lt;/p&gt;

&lt;h2 id=&quot;embargoed-vulnerabilities&quot;&gt;Embargoed Vulnerabilities&lt;/h2&gt;

&lt;p&gt;Not too surprising now, but when I was early in my security career I learned that vulnerabilities get embargoed. This works similar to press stories.&lt;/p&gt;

&lt;p&gt;A company may discover a bad vulnerability in a piece of open source software. They share the issue privately with the organization that maintains the software of course to determine a fix. Before the vulnerability is publicly disclosed, the discovering organization may decide to share it with critical partners under embargo.&lt;/p&gt;

&lt;p&gt;The idea is to give them a heads-up and a chance to fix the issue on their own systems before it goes public and is explicted. The partner is sufficiently important to the main organization’s security that just letting them patch the issue after public disclosure would present sufficient risk.&lt;/p&gt;

&lt;p&gt;I’ve worked a few of these. You’re always under pressure to remediate on a tight timeline and sharing context for the changes with as few people as possible.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lesson learned&lt;/strong&gt;: It’s nice to have powerful friends who find you important.&lt;/p&gt;

&lt;h2 id=&quot;performance-management&quot;&gt;Performance Management&lt;/h2&gt;

&lt;p&gt;I was working for a company that had rolled out a new tool for managers to complete performance reviews. There was weird UI issue that kept recurring, so I decided to open Developer Tools. While inspecting the issue I noticed something weird about the network calls.&lt;/p&gt;

&lt;p&gt;Two parameters were being passed when loading a performance review: the ID for the employee’s review and the email address of the person loading the review.&lt;/p&gt;

&lt;div class=&quot;language-json highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;w&quot;&gt;
    &lt;/span&gt;&lt;span class=&quot;nl&quot;&gt;&quot;employee_id&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;1234&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;w&quot;&gt;
    &lt;/span&gt;&lt;span class=&quot;nl&quot;&gt;&quot;email&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;erik@example.com&quot;&lt;/span&gt;&lt;span class=&quot;w&quot;&gt;
&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;w&quot;&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Huh, that seems goofy. What happens if I change employee ID to my own and my email to my boss’s?&lt;/p&gt;

&lt;div class=&quot;language-json highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;w&quot;&gt;
    &lt;/span&gt;&lt;span class=&quot;nl&quot;&gt;&quot;employee_id&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;5678&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;w&quot;&gt;
    &lt;/span&gt;&lt;span class=&quot;nl&quot;&gt;&quot;email&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;john@example.com&quot;&lt;/span&gt;&lt;span class=&quot;w&quot;&gt;
&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;w&quot;&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Sure enough, there was my performance review. Fun! I reported it to HR, an incident was opened, the vuln was fixed. They ended up pulling audit logs to see who else may have accessed records with a mismatch between the signed in employee and the email address.&lt;/p&gt;

&lt;p&gt;Some time later, I mentioned that I found this issue to another employee. They told me about a case from years before where interview scorecards were being exported to the company’s data warehouse with limited access controls. Numerous employees found out and queried the data before it was reported.&lt;/p&gt;

&lt;p&gt;Audit logs were pulled again and HR reached out to the employees who accessed the data. Most employees either selected a few rows or just their own interview results.&lt;/p&gt;

&lt;div class=&quot;language-sql highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;k&quot;&gt;select&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;*&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;from&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;interview_scorecards&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;limit&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;5&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;c1&quot;&gt;-- or &lt;/span&gt;
&lt;span class=&quot;k&quot;&gt;select&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;*&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;from&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;interviews_scorecards&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;where&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;username&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;&apos;erik&apos;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;But a few had queried well beyond personal curiosity it seems.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lesson learned&lt;/strong&gt;: If you find a vuln don’t abuse your discovery. Report it responsibly and move on with your life. The audit logs don’t lie.&lt;/p&gt;
</description>
        <pubDate>Fri, 03 Feb 2023 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>Patent Programs</title>
        <link>/essays/2022/10/31/patent-programs.html</link>
        <guid isPermaLink="true">/essays/2022/10/31/patent-programs.html</guid>
        <description>&lt;p&gt;A VP of Engineering I used to work with asked me the following:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Would you happen to know of any patent programs or processes that work?&lt;/p&gt;

  &lt;p&gt;I was trying to give feedback on some proposal on how to make our patent program work better, and thus interested in leveraging what works for other people. Basically wondering what prior art there is.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;My short reply was “no”. Every program I’ve ever participated in has been roughly the same shape.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Submit your idea in a tool&lt;/li&gt;
  &lt;li&gt;Maybe get followed up for more info and to proceed&lt;/li&gt;
  &lt;li&gt;Otherwise, you’re quietly told “thanks, better luck next time”&lt;/li&gt;
  &lt;li&gt;Even when your idea gets filed, you have no clue what parts are patentable, especially compared to other rejected ideas that seem more novel&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I started thinking how to build a differentiated patent program at least two orders of magnitude more effective than the norm.&lt;/p&gt;

&lt;p&gt;Usually the extent of education and feedback received by employees is limited to ideas like &lt;a href=&quot;https://www.youtube.com/watch?v=hyv75d4JG7c&quot; target=&quot;_blank&quot;&gt;these&lt;/a&gt; from the Schox Group:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Don’t search to see if the idea is already filed, otherwise damages are tripled&lt;/li&gt;
  &lt;li&gt;First-to-file vs first-inventor-to-file&lt;/li&gt;
  &lt;li&gt;We’re building a defensive patent portfolio&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The rudimentary nature of the education and feedback is probably done with good intentions. That way potential inventors don’t worry too much about their ideas or whether they are worthy of being submitted.&lt;/p&gt;

&lt;p&gt;However, this is a bug, not a feature for patent programs. The typical engineer thrives off pattern matching and case studies. Here are two ideas to correct this.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;First&lt;/strong&gt;, commit to feedback after submission. This creates a positive feedback loop that leads to more and better ideas submitted.&lt;/p&gt;

&lt;p&gt;If an idea doesn’t qualify, spend 5-10 minutes with the submitter on why (in layman’s terms). This helps them get resolution and to try again with a new perspective.&lt;/p&gt;

&lt;p&gt;If an idea does qualify and is worth filing, spend 15 minutes educating the submitter on what aspects led to this result.&lt;/p&gt;

&lt;p&gt;Similarly, let them know how to better frame their submitted ideas.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Second&lt;/strong&gt;, give a quarterly case presentation on a patent the company successfully prosecuted. This improvement is less personal but magnifies the reach of the education. It could slot into an existing tech talk program.&lt;/p&gt;

&lt;p&gt;These should be joint presentations between the inventor and an attorney from the patent team. The inventor presents their idea and its use at the company. Then the attorney discusses what was worth filing in the idea. Close with a final plug on how to submit ideas and Q&amp;amp;A.&lt;/p&gt;

&lt;p&gt;These talks resurface the program to the fore of employees’ minds and help them build mental muscle in thinking about their ideas. Of course, the speakers must be engaging. If a company did these talks well, I guarantee they’d have strong attendance.&lt;/p&gt;

&lt;p&gt;These ideas are relatively cheap to try for a year. I’m convinced they’d work at a sizable company and would be willing to place a gentleman’s bet on it. 💡&lt;/p&gt;
</description>
        <pubDate>Mon, 31 Oct 2022 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>Every Flaw</title>
        <link>/essays/2022/10/25/every-flaw.html</link>
        <guid isPermaLink="true">/essays/2022/10/25/every-flaw.html</guid>
        <description>&lt;p&gt;Craftsmen are cursed in any endeavor they pursue. The curse is the gap between their vision and reality.&lt;/p&gt;

&lt;p&gt;It’s not easy to live up to the imperfection. Some cultures develop entire world views dedicated to accepting the imperfection. For example, the Japanese have &lt;a href=&quot;https://en.wikipedia.org/wiki/Wabi-sabi&quot; target=&quot;_blank&quot;&gt;wabi-sabi&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Whether it’s career, how a project was delivered at work, or even the result of a home improvement project, we’re burdened with the gap.&lt;/p&gt;

&lt;p&gt;We enjoy the finished product. Yet knowing where expectations didn’t meet execution forever taunts us.&lt;/p&gt;

&lt;p&gt;The sense of imperfection attenuates with time. But it never dissipates.&lt;/p&gt;

&lt;p&gt;I used to think that agonizing over the delta was my curse alone. That those who I clearly knew to be masters in their craft didn’t suffer this. I was wrong.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;I only got 25% of what I wanted on Star Wars.&lt;/p&gt;

  &lt;p&gt;I can see all the scotch tape and the rubber bands that are holding it together.&lt;/p&gt;

  &lt;p&gt;But that’s how movies get made. They don’t get made right. They get made the best possible way under the circumstances.&lt;/p&gt;

  &lt;p&gt;– &lt;a href=&quot;https://www.disneyplus.com/series/light-magic/3OtlwhtW6Z7E&quot; target=&quot;_blank&quot;&gt;George Lucas, Episode 2, Light &amp;amp; Magic&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Lest we think it’s only the famous who suffer this.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;You live it and breath it for the whole time you’re doing it…&lt;/p&gt;

  &lt;p&gt;In my head I can visual the images I’ve been looking at…&lt;/p&gt;

  &lt;p&gt;I don’t think I’ll ever be satisfied no matter how well I’ve made a piece. I just think it’s in my nature to always think I could have done better.&lt;/p&gt;

  &lt;p&gt;– &lt;a href=&quot;https://www.discoveryplus.com/video/handcrafted-hotels-us/graduate-nashville&quot; target=&quot;_blank&quot;&gt;Ricky Pittman, Chicken Wire Sculptor, Handcrafted Hotels&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Where we see perfection, they see anything but. Welcome to the club.&lt;/p&gt;
</description>
        <pubDate>Tue, 25 Oct 2022 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>Square Root</title>
        <link>/essays/2022/10/22/introducing-bugs.html</link>
        <guid isPermaLink="true">/essays/2022/10/22/introducing-bugs.html</guid>
        <description>&lt;p&gt;Occasionally I’m asked why even seemingly simple software is riddled with bugs.&lt;/p&gt;

&lt;p&gt;For example, a friend or family member asks why their favorite app had an obvious bug recently.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Come on, you just have to upload photos and let me see others’. Why is that so hard?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;I’ve developed a small illustration to help convey the challenges. Let’s start simple and build up.&lt;/p&gt;

&lt;p&gt;Imagine you’re asked to make a black box. This is our app.&lt;/p&gt;

&lt;p&gt;The user punches in a number and it returns the square root of that number.&lt;/p&gt;

&lt;p&gt;Ok. Let’s go!&lt;/p&gt;

&lt;p&gt;The user inputs zero. And we return…zero.&lt;/p&gt;

&lt;p&gt;The user inputs four. And we return…two.&lt;/p&gt;

&lt;p&gt;So far so good? Great!&lt;/p&gt;

&lt;p&gt;Actually, we already have our first bug. Maybe. Both two and negative two are square roots of four.&lt;/p&gt;

&lt;p&gt;Did we want our black box to return only the implied (positive) square root of the input? Or did you want any of the possible square roots?&lt;/p&gt;

&lt;p&gt;I can hear the protestations now.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;But you didn’t tell me that’s what you wanted!&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;You don’t say!&lt;/p&gt;

&lt;p&gt;This is the exact problem engineers face when developing software.&lt;/p&gt;

&lt;p&gt;Our illustration had one simple job, and we’re already into the ambiguity of requirements.&lt;/p&gt;

&lt;p&gt;Now imagine developing high-stakes software. Maybe it needs to send rockets to space. Maybe it will process your mortgage application screening you for creditworthiness. Maybe it will drive your car autonomously.&lt;/p&gt;

&lt;p&gt;It’s a minor miracle software works as well as it does. There’s an army of engineers employed at the companies building the software we use daily.&lt;/p&gt;

&lt;p&gt;And they care about what they build. A lot. They sweat the details to minimize issues like the ones above.&lt;/p&gt;

&lt;p&gt;In spite of all of this, there will always be bugs.&lt;/p&gt;
</description>
        <pubDate>Sat, 22 Oct 2022 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>Leader Lore</title>
        <link>/essays/2022/10/21/leader-lore.html</link>
        <guid isPermaLink="true">/essays/2022/10/21/leader-lore.html</guid>
        <description>&lt;p&gt;Silicon Valley lives off leader lore. Whether truth or myth, the lore forms and perpetuates an image of the leader.&lt;/p&gt;

&lt;p&gt;Stories abound how Steve Jobs acted in a particular situation.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;The designing of iPhone was not the first time that Steve Jobs put his foot down about this kind of Simplicity. A former director of product marketing at Apple, Mike Evangelist, has told the story of one of his first meetings with Steve Jobs, a meeting that took place in 2000 inside the Apple boardroom.&lt;/p&gt;

  &lt;p&gt;Mike’s team had been charged with developing a simple way to turn a home movie into a DVD, an app that would later show up as iDVD (one of the iLife apps). He and a partner worked hard to develop their ideas for an interface that would be user-friendly enough for Steve, and prepared to share their work with him by creating all kinds of sample screens and verbal explanations.&lt;/p&gt;

  &lt;p&gt;Mike was shocked when Steve Jobs walked into the room, ignored their work, and walked right up to the whiteboard. “Here’s the new application,” he said. “It’s got one window. You drag your video into the window. Then you click the button that says ‘Burn.’ That’s it. That’s what we’re going to make.”&lt;/p&gt;

  &lt;p&gt;— &lt;a href=&quot;https://www.amazon.com/Insanely-Simple-Obsession-Drives-Success/dp/1591846218&quot; target=&quot;_blank&quot;&gt;Ken Segall, Insanely Simple&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;While Steve Jobs focused on radical simplicity, Bill Gates was said to test the depth of your knowledge to determine if he could trust your recommendations. In meetings he’d relentlessly ask probing questions, a technique known as dip-sticking. Eventually he’d bottom out your knowledge and either be satisfied or not. If you won his trust, you were free to proceed and gained his esteem.&lt;/p&gt;

&lt;p&gt;Here I contribute a few pieces of lore to the canon. The stories are second-hand. Minor details may differ from reality (e.g., it was 20 hours, not 24 hours). Regardless, the lore supports the reputation.&lt;/p&gt;

&lt;p&gt;I interviewed a candidate who worked at Tesla. At one point the Tesla build process was taking over 24 hours to complete, delaying development. A group of engineers was selected to improve the situation. Elon dropped in on their project kick off. His ultimatum was that the build must take less than 5 minutes. He’d be checking in daily on the team’s progress. They were incredulous it could be done. They got it down to 30 minutes. Good enough. Elon moved on.&lt;/p&gt;

&lt;p&gt;Another time I worked at a company that built internal IT software. We were working to sell Tesla. Elon didn’t like an aspect of the user interface. The sales team joined a call with Elon and our CEO. We weren’t willing to change our roadmap for a CSS customization. We moved on.&lt;/p&gt;

&lt;p&gt;Both stories are congruent with Elon’s self-acknowledged &lt;a href=&quot;https://www.youtube.com/watch?v=YcQwkL3eNmE&quot; target=&quot;_blank&quot;&gt;nano-managerial style&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Speaking again of build systems, let’s talk about Sergey Brin. Sergey took a different tact from the ruthless grilling of Gates. His humor was a weapon to cajole performance and make a point. A coworker and ex-Googler relayed a story when he was in a meeting with Sergey. One team was reporting out that their build was taking over 30 hours to complete (apparently a common theme across these companies). Sergey remarked,&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;30 hours? Really?! I can crawl the world in 30 hours.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Tails between their legs, the team fixed their build lest Google crawl the web faster than their team’s build.&lt;/p&gt;

&lt;p&gt;Here’s one more as we round third and head for home. Google is famous for the criteria that something must be a $1B idea to even be considered. An ex-Googler shared that Sergey was reviewing the Google Earth Enterprise growth charts with revenue sitting in the low 8-figures. He squinted at the chart and gestured with his finger drawing a line,&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Yeah, if I extrapolate way out, we might hit one billion. Though, I’m not sure if I’ll retire before that happens.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Google Earth Enterprise was retired in 2015.&lt;/p&gt;
</description>
        <pubDate>Fri, 21 Oct 2022 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>Local Maxima</title>
        <link>/essays/2022/04/25/local-maxima.html</link>
        <guid isPermaLink="true">/essays/2022/04/25/local-maxima.html</guid>
        <description>&lt;p&gt;A regular topic occurs in professional coffee chats. A leader has inherited a particularly dysfunctional $X: team, project, product. It’s the type of mess that if you knew what you were getting yourself into ahead of time, you never would have accepted the challenge.&lt;/p&gt;

&lt;p&gt;The question the person wants to answer is, “Where do I start? How do I know I’m working on the most important thing to fix in these situations?”&lt;/p&gt;

&lt;p&gt;The good thing is that identifying the most important thing doesn’t actually matter. And that’s for two reasons.&lt;/p&gt;

&lt;p&gt;First, you’ve likely inherited a complex system of interrelated problems contributing to dysfunction. The likelihood that your mess is caused by just one thing is very low. Otherwise, the previous leadership would have fixed it by now. In reality, there are a dozen contributing factors to your mess.&lt;/p&gt;

&lt;p&gt;When the person frets that they’re not working on the most important thing, they’re concerned about the search space. They want to make sure that they locate and fix the global maxima of their problems. This is a strong intuition, but slightly misguided. What they’re trying to avoid is fixing window dressing. For example, if they’re reorging an underperforming team, focusing on a team logo is not that important.&lt;/p&gt;

&lt;p&gt;The reality is that there are a multitude of high impact things that they could work on. Each of those items has a local maxima that really isn’t that far off from the global maxima. Instead of focusing on &lt;em&gt;the&lt;/em&gt; highest leverage item to fix, just find &lt;em&gt;a&lt;/em&gt; high leverage item and fix that.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;https://www.researchgate.net/profile/Tshilidzi-Marwala/publication/252559450/figure/fig3/AS:668963637829639@1536504768501/Figure-illustrating-a-local-maxima-versus-a-global-maxima.ppm&quot; alt=&quot;Figure illustrating a local maxima versus a global maxima&quot; width=&quot;350px&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Second, progress you make on material items creates a positive feedback loop. Pounding down a high leverage local optima reduces the total volume of outstanding problems. The team is freed up to focus on fewer things, the system is made less complex, momentum builds. Goto new problem.&lt;/p&gt;

&lt;p&gt;This is not dissimilar to the idea behind the “debt snowball” in personal finance. Tackling your biggest, hardest debt may not always be the right thing. &lt;em&gt;Completing&lt;/em&gt; something tangible allows the team to accrue wins and carry that forward into the next problem.&lt;/p&gt;

&lt;p&gt;There are exceptions to this rule though; issues you absolutely must fix. I was once part of a reorg. It was clear that hiring was broken, and we weren’t selecting for the people we needed to turn things around. That was a must-fix issue. From there though, the wins (slowly) compounded.&lt;/p&gt;
</description>
        <pubDate>Mon, 25 Apr 2022 00:00:00 +0000</pubDate>
      </item>
    
      <item>
        <title>Impostor Syndrome is Fractal</title>
        <link>/essays/2022/04/24/fractal-impostor.html</link>
        <guid isPermaLink="true">/essays/2022/04/24/fractal-impostor.html</guid>
        <description>&lt;blockquote&gt;
  &lt;p&gt;Comparison is the thief of joy.&lt;/p&gt;

  &lt;p&gt;– Unknown&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;For those of us who suffer from impostor syndrome, and it’s not everyone, the mark it leaves is indelible. The constant comparison and concern about delivering and keeping up both fuels and depletes. Strivings completed provide an all too brief reprieve. They are ended soon by the question “What’s next?” as you watch your contemporaries push forward while you rest.&lt;/p&gt;

&lt;p&gt;Impostor syndrome is fractal. It doesn’t fade away. As cyclist Greg LeMond said, “It never gets easier, you just go faster.”&lt;/p&gt;

&lt;p&gt;No matter your position or talent, the deficit between “their” skill and yours feels constant, infinitely nuanced, and ultimately un-closable.&lt;/p&gt;

&lt;p&gt;Say you’re a beginner whose skill is 10. Examining someone a bit ahead of you at 100, the delta seems so wide.&lt;/p&gt;

&lt;p&gt;But even for an expert–say a world class operator in their field–who executes at 1000, the delta between them and someone at 1010 is perceived to be just as wide.&lt;/p&gt;

&lt;p&gt;This is demonstrated in episode one of &lt;em&gt;Get Back&lt;/em&gt; by Peter Jackson.&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;&lt;strong&gt;George Harrison&lt;/strong&gt;: …the difference between me and, say, Eric, I’m just another guitar, sometimes playing bits and sometimes singing…So…I feel now I can play things. I can learn things that will sound okay, especially fast fingering like that.&lt;br /&gt;
&lt;strong&gt;Paul McCartney&lt;/strong&gt;: It’s jazz, man.&lt;br /&gt;
&lt;strong&gt;George Harrison&lt;/strong&gt;: Not really, Just Eric. He’s very good at that. At like, improvising and keeping it going…which I’m not good at.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The words alone don’t justify the exchange. George suffers throughout the clip. Here’s one of the most famous, most accomplished musicians forlorn over the gap between himself and Eric Clapton. Mind you, this is after Beatlemania, after fame and fortune has been attained. And yet George Harrison feels under-accomplished, trapped, and lacking.&lt;/p&gt;

&lt;p&gt;Let’s take a more modern example from the podcast episode &lt;em&gt;&lt;a href=&quot;https://www.npr.org/2021/02/03/963592148/how-i-built-resilience-m-night-shyamalan&quot; target=&quot;_blank&quot;&gt;How I Built Resilience: M. Night Shyamalan&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;&lt;strong&gt;Guy Raz&lt;/strong&gt;: How did you overcome self-doubt?&lt;br /&gt;
&lt;strong&gt;M. Night Shyamalan&lt;/strong&gt;: You don’t. You don’t. I have it right now in front of you. I mean, I just came from the editing room and I have all these issues with this reel and I’m trying to figure it out and the voice inside of you says, “You’re not, you’re not going to figure it out.”…I’m scared to write [my next movie]. Maybe today I won’t be able to think of that thing. My oldest daughter is an artist and I said, “That is your plight. You are going to wrestle with your demons every single day of your life.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;If you suffer from impostor syndrome–and I think “suffer” is an appropriate verb to describe its effects–you’re in good company.&lt;/p&gt;
</description>
        <pubDate>Sun, 24 Apr 2022 00:00:00 +0000</pubDate>
      </item>
    
  </channel>
</rss>
