Live data from Hacker News

Ex-Tesla worker escalates battle by blowing whistle to SEC

autonews.com

21–30 of 49 posts

Re: Ex-Tesla worker escalates battle by blowing whistle to SEC

#21
post #3

A better title would mention this is an Ex-Tesla worker currently being sued by Tesla... I'm not saying there is no story to be read, in fact I plan to look in depth a bit later, but the current title is somewhat misleading

More importantly it should mention that he was caught red handed stealing company secrets and sending them to others. This one is a bit better coverage of it: https://arstechnica.com/tech-policy/2018/07/tesla-whistleblo...

> This one is a bit better coverage of it

This article omits the crowdfunded defense and all quotes from the defendant, Martin Tripp. It also glosses over the purported issues:

> Tripp told the SEC that Tesla had installed batteries with holes punctured in them, placed battery cells too close to one another and didn’t properly affix them. ... Tripp also alleged that the company systematically reused parts that had been deemed scrap or waste in vehicles.

Is Tesla running an undercover salvage operation, to identify reusable components and reduce waste from their "totaled" cars?

Re: Ex-Tesla worker escalates battle by blowing whistle to SEC

#22
post #15
post #6

Earlier quoted context omitted.

> More importantly it should mention that he was caught red handed stealing company secrets and sending them to others That is a roundabout way of describing a whistleblower. He didn't give information to competitors, he gave it to journalists and the SEC.

Which journalists? If he did, they don’t seem to be in a hurry to print what he gave them.

The most interesting part of this article is that Tesla is involved. Beyond that, it's a lone wolf bad actor looking for a Rainmaker[0].

[0] https://www.imdb.com/title/tt0119978/

Re: Ex-Tesla worker escalates battle by blowing whistle to SEC

#23

A better title would mention this is an Ex-Tesla worker currently being sued by Tesla... I'm not saying there is no story to be read, in fact I plan to look in depth a bit later, but the current title is somewhat misleading

> currently being sued by Tesla Suing him after firing him was probably an immature overreaction on Tesla's part. It forced the former employee into a more-aggressive posture. Better strategy would have been (a) suing competitors he gave information to (if any) and (b) nudging a local DA to press criminal charges.

Immature overreaction? He alledgedly stole company secrets and gave them to others in a way that framed other employees at the company, and would continue to run after he left.

Assuming those charges are true, why would it be an overreaction to sue the person who did it!? That to me is the only valid reaction. This person is accused of knowingly purposefully trying to harm Tesla and help competition.

The only way this would be an overreaction is if Tesla really is guilty of doing illegal things. And in that case going to a DA would be the worst idea.

Re: Ex-Tesla worker escalates battle by blowing whistle to SEC

#24
post #12

Earlier quoted context omitted.

The civil complaint doesn't say anything about logging under other usernames, just that his data-scraper-exporter was running on other people's machines: https://arstechnica.com/tech-policy/2018/06/tesla-sues-emplo... > His hacking software was operating on three separate computer systems of other individuals at Tesla so that the data would be exported even after he left the company and so that those individuals woul…

How did he have permissions to run unauthorized software on other computers - let alone his coworkers' workstations? Where is the OpSec?

In just about any office I can see it being pretty trivial to walk over to a co-worker's PC and insert a USB drive and run a program. It would take seconds, and unless all employees lock their PCs 100% of the time even if they walk away for a few seconds, there isn't much in the way of "opsec" that can stop it (just things like cameras that can find the guilty party after the fact).

Things like disabling USB ports or requiring passwords to be entered constantly for everything would most likely impact the business enough that it would be more harmful than any single instance of stolen IP, and even then they only reduce the likely hood of an attack like this, they don't stop it.

Re: Ex-Tesla worker escalates battle by blowing whistle to SEC

#25
post #10
post #3

Earlier quoted context omitted.

More importantly it should mention that he was caught red handed stealing company secrets and sending them to others. This one is a bit better coverage of it: https://arstechnica.com/tech-policy/2018/07/tesla-whistleblo...

IIRC, Tesla's civil complaint accuses Tripp of writing "hacking software" but doesn't mention any other effects of the software besides exfiltration of data to unspecified third parties: https://arstechnica.com/tech-policy/2018/06/tesla-sues-emplo... > Beyond the misconduct to which Tripp admitted, he also wrote computer code to periodically export Tesla’s data off its network and into the hands of third parties. His…

From the perspective of a technologist it's clumsy and imprecise language, but it's not wrong.

He wrote code that was explicitly designed to bypass the company's security and treacherously act in a way that caused damage to the company's interests, then he inserted it using other people's security credentials. The only elements missing between what he did and what a "real" hacker might have done is breach a technical security barrier rather than be a trusted employee.

Re: Ex-Tesla worker escalates battle by blowing whistle to SEC

#26

A better title would mention this is an Ex-Tesla worker currently being sued by Tesla... I'm not saying there is no story to be read, in fact I plan to look in depth a bit later, but the current title is somewhat misleading

> currently being sued by Tesla Suing him after firing him was probably an immature overreaction on Tesla's part. It forced the former employee into a more-aggressive posture. Better strategy would have been (a) suing competitors he gave information to (if any) and (b) nudging a local DA to press criminal charges.

(a) assumes that competitors took the information knowing that it came from Tesla. And civil lawsuits can be done whether or not charges are being pressed. A lawsuit is not immature at all. He damaged the company.

Re: Ex-Tesla worker escalates battle by blowing whistle to SEC

#27
post #15
post #6

Earlier quoted context omitted.

> More importantly it should mention that he was caught red handed stealing company secrets and sending them to others That is a roundabout way of describing a whistleblower. He didn't give information to competitors, he gave it to journalists and the SEC.

Which journalists? If he did, they don’t seem to be in a hurry to print what he gave them.

I'm not sure if there is a list, but he definitely gave info to Business Insider and that is apparently what set Elon off:

http://www.businessinsider.com/tesla-whistleblower-martin-tr...

This is the piece they used his info for:

http://www.businessinsider.com/tesla-model-3-scrap-waste-hig...

Re: Ex-Tesla worker escalates battle by blowing whistle to SEC

#28

Earlier quoted context omitted.

> currently being sued by Tesla Suing him after firing him was probably an immature overreaction on Tesla's part. It forced the former employee into a more-aggressive posture. Better strategy would have been (a) suing competitors he gave information to (if any) and (b) nudging a local DA to press criminal charges.

Immature overreaction? He alledgedly stole company secrets and gave them to others in a way that framed other employees at the company, and would continue to run after he left. Assuming those charges are true, why would it be an overreaction to sue the person who did it!? That to me is the only valid reaction. This person is accused of knowingly purposefully trying to harm Tesla and help competition. The only way thi…

> He alledgedly stole company secrets and gave them to others

Is there any evidence he gave them to competitors or did anything other than act as a whistleblower ?

Re: Ex-Tesla worker escalates battle by blowing whistle to SEC

#29
post #10

Earlier quoted context omitted.

IIRC, Tesla's civil complaint accuses Tripp of writing "hacking software" but doesn't mention any other effects of the software besides exfiltration of data to unspecified third parties: https://arstechnica.com/tech-policy/2018/06/tesla-sues-emplo... > Beyond the misconduct to which Tripp admitted, he also wrote computer code to periodically export Tesla’s data off its network and into the hands of third parties. His…

From the perspective of a technologist it's clumsy and imprecise language, but it's not wrong. He wrote code that was explicitly designed to bypass the company's security and treacherously act in a way that caused damage to the company's interests, then he inserted it using other people's security credentials. The only elements missing between what he did and what a "real" hacker might have done is breach a technical…

I don't begrudge Tesla for portraying facts as damning as possible to the opposing party -- that's what any litigant would do (and should do, I would think, although IANAL), as long as no deliberately false statements are made. So "technically true" is fine by me. But since their investigation is still ongoing, and they haven't felt the need to divulge more specific and damning assertions, then it's fair to consider what's currently left open to interpretation.

"Wrote code" could include a wget cron job. "Bypass company's security" includes literally any activity done without company approval or authorization, including printing out files and putting them in his briefcase and walking out the building without announcing the fact.

No one is really disputing that his alleged acts were "treacherous" to the company, or that they "caused damage to the company's interests" -- that would cover every conceivable form of whistleblowing.

At this point, I don't see what it matters whether it was a "real" hack or not (though it's ironic you mention social engineering, since for too long that has been ignored as a real attack vector). He took info and disclosed it without company approval, now it's up to the courts to decide if that was legitimate and protected whistleblowing.

Re: Ex-Tesla worker escalates battle by blowing whistle to SEC

#30
post #10

Earlier quoted context omitted.

IIRC, Tesla's civil complaint accuses Tripp of writing "hacking software" but doesn't mention any other effects of the software besides exfiltration of data to unspecified third parties: https://arstechnica.com/tech-policy/2018/06/tesla-sues-emplo... > Beyond the misconduct to which Tripp admitted, he also wrote computer code to periodically export Tesla’s data off its network and into the hands of third parties. His…

From the perspective of a technologist it's clumsy and imprecise language, but it's not wrong. He wrote code that was explicitly designed to bypass the company's security and treacherously act in a way that caused damage to the company's interests, then he inserted it using other people's security credentials. The only elements missing between what he did and what a "real" hacker might have done is breach a technical…

If you are a whistleblower then by definition you need to bypass the company's security and cause damage to the company's interest.

The real issue is whether he is a legitimate whistleblower not the acts that he did in order to provide the data to journalists.

Post reply on HN