Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Any reasonably sized company is going to have the dollars and IT smarts to not worry about former employees causing damage (passwords, keycard access, etc. are all immediately cut off on the day of leaving.. and any actual damage someone does is grounds for a likely felony-level criminal case with years behind bars). As others have mentioned they don't even need to take people to court to enforce a non-compete--just the fact that a former employee is under a non-compete is enough to scare away and stop potential new employers (read the comments on this page to see examples of this). By making the non-compete something the company has to pay for it pushes it more into the realm of only applying to people that absolutely need it (high level executives, critical engineers, etc.) and who will be compensated while under it.


How about IP being leaked? EX: saving all your code on a flashdrive on the 1 day that you work from home.

Sometimes crazy people do stupid things.

Obviously you should never actually do something like that, but from the companies perspective, an X% chance of millions in damages is a stupid risk to take, for little benefit.


>Any reasonably sized company is going to have the dollars and IT smarts to not worry about former employees causing damage (passwords, keycard access, etc. are all immediately cut off on the day of leaving..

At least on the sysadmin side? The only way to be sure that someone who once had root on your server no longer has root on that server is to wipe and re-install using scripts that person didn't develop/sources that person didn't control. Of course, you kill the logins, but there are a million ways to leave a hard to detect backdoor... and many of those are impossible to distinguish from a simple mistake.

This is definitely something you need to worry about; and at the very minimum, you go out of your way to make sure you don't piss off ex employees more than you have to.

Yes, yes, if you have your whole process in source control, that's great, and will really help when trying to track down who put in the back door (However, can you prove it was a backdoor and not just, you know, a dumb mistake that left a security hole open? Innocent mistakes of this type are pretty common.) - even then, what of the sysadmins who have root on your revision control server? (this is actually an area where smaller shops, which tend to just use git, have an advantage; it's way harder for the repo owner to insert something without anyone noticing on a git system, say, than a more centralized setup like perforce, which tends to get used by the much larger companies.)

For that mater, even the ground-pounding so-called "rebooter monkeys" have a lot more power than you think. Anyone who has root on your workstation, even for a short period of time, can cause all sorts of mayhem, and worse, make it look like you did it, for some time to come.

>and any actual damage someone does is grounds for a likely felony-level criminal case with years behind bars).

I mean, I'm not saying you couldn't make things pretty miserable for the perpetrator, you could. but that doesn't really help the business that was harmed. It does provide a pretty good deterrent. but that's why the comment you are responding to was talking about "crazy" - there are people who do things that are not in their long term best interest, and if those people have root on your systems, or access to your codebase, they can do more damage to you than you can possibly hope to recover from them. It's a pretty rare sysadmin who couldn't do millions of dollars in damage to his or her employer; and a pretty rare sysadmin who has the assets/insurance to cover a judgment that large.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: