Live data from Hacker News

Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

bloomberg.com

291–300 of 364 posts

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#291
post #282

Earlier quoted context omitted.

None of that would solve the issue. Google can only verify what hardware you're running by sending a packet via ethernet to your device. You control all software running on your device, and can send a spoofed result. If you were crazy, you could even just emulate Google's hardware entirely and proxy all requests to that emulated hardware. Nonetheless, while this guy certainly wouldn't be able to do it, many Google em…

Couldn't they do a chip and pin style hardware solution where a security chip generates a response using a unique secret algorithm?

That would work — until someone decaps a few of these chips.

They're already doing something similar, after all.

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#292
post #131

Wow this has got to be the worse single month for a company that I've ever seen.

Or Microsoft antitrust?

Please - Microsoft antitrust was nothing like this.

Microsoft was basically extremely successful - and then became a monopoly provider. In general, I wouldn't call this an 'immoral act' or whatever.

Also - I'd suggest that Google is just as much a Monopoly provider as MS ever was, they could face the same type of case in EU soon.

Stealing IP, lying, corruption - this is in a whole different league from being so successful that you become a monopoly.

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#293
post #35

There's something very wrong in the world when the people who invent things aren't the main beneficiary of their own inventions. Edit: A guy downloads 9.7GB of other people's work, walks off with it, and sells it. Flushing years of work from hundreds of engineers down the toilet. You down voters really support that? Amazing.

"There's something very wrong in the world when the people who invent things aren't the main beneficiary of their own inventions"

Anyone can be the primary beneficiary of their own invention, it they want to pay their own salary, build their own products, hire their own layers, sell their wares etc..

If you want to collect $150K/year while you do R&D for Google, which may produce not that much, while you leverage all of their knowledge, investment, user-base tools etc - well, then you fork over the rights to Google.

'Inventing' something is not just some guy coming up with an idea, and then making that 'invention' worth something is usually harder than inventing it in the first place.

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#295

Earlier quoted context omitted.

im just gonna say the fact that they told you to go for a walk and leave your laptop is pretty creepy.

Sounds more normal than asking you to take your laptop on a walk.

As a security-minded person, I would be suspicious under any circumstance where someone unfamiliar distanced me from my devices.

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#296
post #174

Earlier quoted context omitted.

Nice link, this is a great read for anyone interested in endpoint security research.

... all which are easily compromised by a commodity phone. "Ah you know, I forgot my charger! Dang! I'll just plug this into the USB port of this sooper secure machine connected to this sooper secure network."

Computer says no.

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#297

Earlier quoted context omitted.

I used to work at a small company that made a SaaS product for a niche HR function. One of our largest customers, a bank whose ATMs you likely see every day if you're in the US, decided to drop our service in favor of a solution built in-house. We were disappointed, but had to let them go. Then, about 2 years after they'd canceled, our support department got a strange email from a user that was having problems. At fi…

> When we called them on it, they basically threatened to use lawyers to put us out of business if we pursued the issue, so I guess our management decided to drop it. We did make them change the support email and phone number. This is why we can't have nice things. Darned lawyers. Can't live with them, can't live without them

>can't live without them

Really?

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#298

Earlier quoted context omitted.

I used to work at a small company that made a SaaS product for a niche HR function. One of our largest customers, a bank whose ATMs you likely see every day if you're in the US, decided to drop our service in favor of a solution built in-house. We were disappointed, but had to let them go. Then, about 2 years after they'd canceled, our support department got a strange email from a user that was having problems. At fi…

you could have put their ip in a firewall or rate limited their access to mess with them.

One does not simply "mess with" an international bank.

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#299

Earlier quoted context omitted.

Even if they do, it is very unlikely they were built with provable nonrepudiation requirements. From personal experience designing the security of a PKI CA that passed gov security certifications, the audit subsystem is the most challenging part to do right. Could probably consult for the defense in tearing down the evidence :)

I'll accept that it's hard, but why do you think Google didn't do it right?

It would require a prohibitive amount of engineering resources to be done right, i.e. a chain of guarantees that from creation time to the moment they are inspected it can be proven that the logs cannot be tampered with by nonauthorized users. There are other requirements e.g. separation of roles that are expected on audit subsystems. I am positive it would not pass an adversary expert analysis.

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#300

Earlier quoted context omitted.

This is entirely not related to what we're talking about here. It's not about trust, it's about good practice. If someone needs access to something, they request it, you grant it. Simple. But there should be common sense controls on data access, for everyone's benefit. You're talking about a hostile work environment. I'm talking about a secure one.

That's more than just an oversimplification. Security is inherently hostile, I don't see any other way of putting things. We tolerate a certain amount of hostility in order to reap the benefits that security gives us, and we tolerate a certain amount of vulnerability in order to reap the benefits that laxness gives us. > If someone needs access to something, they request it, you grant it. Simple. The saying goes that…

The problem is, it doesn't seem like prevention or detection was working here at all. Even though they clearly collected enough data to reconstruct what happened, they both failed to prevent this, by not having even common sense security protections, nor did they detect it when it occurred, only finding out because a supplier ratted out another client.

These are not high cost processes, these are basic, common sense practices we're talking about, that nobody really has any excuse to not have in place.

You are continuing to let your experience with a single, hostile work environment cloud your openness to something that... isn't even controversial. If you aren't locking down your files to only those who need them, you aren't equipped to be in business. If this is somehow uncommon among Silicon Valley, it explains why so many "they stole our trade secrets" lawsuits are going on right now.

Post reply on HN