Live data from Hacker News

Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

bloomberg.com

331–340 of 364 posts

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#331

Earlier quoted context omitted.

I'll accept that it's hard, but why do you think Google didn't do it right?

It would require a prohibitive amount of engineering resources to be done right, i.e. a chain of guarantees that from creation time to the moment they are inspected it can be proven that the logs cannot be tampered with by nonauthorized users. There are other requirements e.g. separation of roles that are expected on audit subsystems. I am positive it would not pass an adversary expert analysis.

Google's threat models include nation-state adversaries: I suspect the effort that seems "prohibitive" to you was seen as necessary after the infamous smiley on that PRISM slide. Security is an existential threat: if user's don't trust Google, they will fail.

Google also has an internal PKI CA - I think they meet and exceed that security baseline for rigor.

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#332

Earlier quoted context omitted.

they did not offer to provide me with a laptop and the interview format was such that I could google things and share some of my personal projects etc

That is weird. What kind of tech company doesn't have an old laptop or a Chromebook for such interview format? What if you don't have a personal laptop? I'm certainly not bringing my work laptop to a job interview...

The kind that's also too cheap to buy jackets for all their SREs, apparently.

This sort of penny-wise-but-pound-foolish shit is depressing, but not nearly as rare as I wish it was.

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#333
post #2

And Google Ventures is an Uber investor... so Google is effectively suing one of their own portfolio companies.

7% share according to this article https://www.recode.net/2015/12/6/11621176/google-ventures-ow...

"So let's sue them, but.... it wouldn't be all that terrible if we lost."

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#334
post #323
post #151

Earlier quoted context omitted.

> One of our suppliers ... sent us an attachment (apparently inadvertently) of machine drawings of what was purported to be Uber’s ... Ouch, this doesn't play well for the supplier either! Presumably if Uber wins, it'd have a solid case against the supplier. If it loses, or while Waymo v Uber is ongoing, might there be a case anyway?

>Presumably if Uber wins, it'd have a solid case against the supplier. Can they really claim that the supplier damaged them by leaking trade secrets if the trade secrets aren't theirs?

> > Presumably if Uber wins, it'd have a solid case against the supplier.

> Can they really claim that the supplier damaged them by leaking trade secrets if the trade secrets aren't theirs?

If Uber wins, they are Uber's secrets.

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#335

Copy-pasting from my comment on Reddit. The first thing that caught my attention after reading the whole lawsuit! https://drive.google.com/file/d/0B7dzPLynxaXuQjY3dkllZ2ZKb0k... [Item 42- 49] itself is some of the timings regarding Otto's inception and Uber's acquisition. Timeline: * Levandowski first registered the domain for his then(now Otto) company on Nov'15 * The suit says on 3rd of Dec'15 he searched for the L…

It could also be that Levandowski met with Uber execs as the lawsuit claims, but didn't tell them he had stolen the documents.

That could very well be true. wink wink

"I know it's hard to believe, Travis, but while I worked for a company doing the exact the same thing as this company, at nights, I singlehandedly created this trove of patentable technology that will revolutionize the automobile industry, which coincidently, really, my former employer is spending billions to do. You have to trust me."

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#336

I had an interview there where the manager asked me to leave my laptop behind and go for a walk. I was hesitant after hearing stories of Uber conducting electronic espionage against its competitors. They could easily bypass Macbook security with a USB device (I had heard of that on HN too) so I was very nervous to leave my laptop behind and noted its exact orientation and position on the table. Sure enough when I ret…

So, anyone up for getting an Uber interview and using their laptop as a honeypot?

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#337

Earlier quoted context omitted.

It's pretty stupid to get paranoid over this. As GP pointed out if you logged out then it's very unlikely that they will get access.

I think it's pretty stupid to consider any consumer device to be secure enough. I did hear on HN some time before that interview that some USB device can be used to bypass the lock screen, which was the basis for my worrying. Now, some are saying in this thread that it is possible (or at least was at the time) while others saying that it is not (and was not) -- Even an educated sample of tech folks cannot make up the…

I think the consensus is that it's possible, but expensive. So like, nation-state espionage yes, corporate espionage no. But anyone who actually knows anything won't be talking about it on HN ;)

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#338

Earlier quoted context omitted.

It would require a prohibitive amount of engineering resources to be done right, i.e. a chain of guarantees that from creation time to the moment they are inspected it can be proven that the logs cannot be tampered with by nonauthorized users. There are other requirements e.g. separation of roles that are expected on audit subsystems. I am positive it would not pass an adversary expert analysis.

Google's threat models include nation-state adversaries: I suspect the effort that seems "prohibitive" to you was seen as necessary after the infamous smiley on that PRISM slide. Security is an existential threat: if user's don't trust Google, they will fail. Google also has an internal PKI CA - I think they meet and exceed that security baseline for rigor.

Yes, for purposes of issuing certificates I'm sure they are OK wrt auditing (I was just establishing my "credentials" with the CA comment).

The threat models targeting anti-Google malicious actions obviously worked since they have traces of the Otto guy's activities. What I am asserting is that these forensics logs they use as evidence can be attacked in court as not being sufficiently protected from tampering by an internal Google party interested in fabricating evidence.

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#339
post #9

Earlier quoted context omitted.

Yea that's incredibly bad if that's what that guy did.. in general for EE designs, the schematic/layouts are not that hard to deduce how you would do it if you are in contact with the company that makes the LIDAR device (the unique and difficult part -- basically just need to ask them, like "yo, how roughly should I interface with this thing and whats your recommendation on a number of the components.. and can you gi…

Many many years ago, I was at a software company, and a competitor popped up making very similar software. They made a presentation of their software at a conference, and had a slide showing a screenshot. Our typos were clearly visible. Fun times, fun times. We got a few people fired, but that was about it.

https://en.wikipedia.org/wiki/Trap_street

Re: Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets

#340

Earlier quoted context omitted.

That's more than just an oversimplification. Security is inherently hostile, I don't see any other way of putting things. We tolerate a certain amount of hostility in order to reap the benefits that security gives us, and we tolerate a certain amount of vulnerability in order to reap the benefits that laxness gives us. > If someone needs access to something, they request it, you grant it. Simple. The saying goes that…

The problem is, it doesn't seem like prevention or detection was working here at all. Even though they clearly collected enough data to reconstruct what happened, they both failed to prevent this, by not having even common sense security protections, nor did they detect it when it occurred, only finding out because a supplier ratted out another client. These are not high cost processes, these are basic, common sense…

> You are continuing to let your experience with a single, hostile work environment cloud your openness to something that... isn't even controversial.

I'm flattered that you want to talk about me, but really, I'm not the subject of the discussion here, and it's inappropriate to talk about what's going through my head or to try and psychoanalyze me.

> These are not high cost processes, these are basic, common sense practices we're talking about, that nobody really has any excuse to not have in place.

I've worked at a few different places on this spectrum in my career. Three of them have been fairly open, internally, like the way Google apparently operates. Maybe there are some high-value IP repositories you don't have access to, but you mostly have access to any source code you want to look at without getting access reviewed first. These companies were very open about the risks that this entailed, and openly discussed the fact that leaks were possible. The benefits became rather clear the longer I worked at each place. Whenever a system I worked on interacted with another system, I could follow what the other system was doing and even submit patches to other systems if necessary.

Saying that restrictive security is "common sense" or "not even controversial" is begging the question and argumentum ad populum, respectively. My argument here is that there are benefits to open access to most company IP, and that these benefits are important enough that the decision should be made on a company-by-company basis.

The access controls that would have prevented this particular case from happening would have to be rather draconian indeed. Anthony Levandowski's work was basically the genesis of autonomous vehicles at Google. Google purchased Levandowski's autonomous driving startup, 510 systems, in 2011. I don't know what kind of access controls you'd need to prevent a startup founder from accessing the technology built on top of his company's IP.

Post reply on HN