Live data from Hacker News

Another former Tesla security manager says the company spied on employees

businessinsider.com

31–40 of 65 posts

Re: Another former Tesla security manager says the company spied on employees

#31

Earlier quoted context omitted.

> The tip from Sean Gouthro, the former head of Tesla's global security operations center and investigations, was filed on January 24 and corroborates a tip filed in August from Karl Hansen ... Hansen's tip claimed that Tesla did not disclose to shareholders the theft of raw materials and the unauthorized surveillance and hacking of employee cellphones and computers. This is not a tip about Tesla watching what its em…

>This is not a tip about Tesla watching what its employees are doing on its own equipment and data networks. I'm curious about details on this. Modern phones (well, iPhones at least) are pretty hard to break into. I wonder if it was something like having them install a root certificate to use the company wifi, then using that root cert to spy on other traffic traversing the network (such as leaks to reporters)

Most MDM's install both a cert and a profile on iOS devices that allow the MDM admin to do just about anything. Any company-owned device is going to come to the user with this pre-installed, and non-removable by the user. I'd be astounded if a company the size, and with the security stance of Tesla didn't use the most intrusive MDM available.

Re: Another former Tesla security manager says the company spied on employees

#32
post #10

As an aside, if you’re using company-provided computers and phones your default behavior should be to assume they are spying on you to the degree that they are recording every action you take in those devices. It’s a spectrum—many companies don’t do this at all—but you would be doing well by yourself by assuming they record and track everything. You should also assume all of your traffic while at the office (if your…

> You should also assume all of your traffic while at the office I fell out with my manager at FANG and she got back at me with the lowest rating possible for the year-end review. I chose to get my concerns across to HR about how this was unfair and challenged them to validate her critical feedback with peer engs. Didn't happen. Instead what followed was, I was investigated for violation of company rules such as putt…

[deleted]

Re: Another former Tesla security manager says the company spied on employees

#33
post #10

As an aside, if you’re using company-provided computers and phones your default behavior should be to assume they are spying on you to the degree that they are recording every action you take in those devices. It’s a spectrum—many companies don’t do this at all—but you would be doing well by yourself by assuming they record and track everything. You should also assume all of your traffic while at the office (if your…

> You should also assume all of your traffic while at the office I fell out with my manager at FANG and she got back at me with the lowest rating possible for the year-end review. I chose to get my concerns across to HR about how this was unfair and challenged them to validate her critical feedback with peer engs. Didn't happen. Instead what followed was, I was investigated for violation of company rules such as putt…

Remember the following:

HR is not your friend. HRs duty is to the company. If what you need and what the company needs are on the same page, sure, HR is on your side, but if not, they will do whatever it is that benefits and protects the company.

Re: Another former Tesla security manager says the company spied on employees

#34

Earlier quoted context omitted.

>This is not a tip about Tesla watching what its employees are doing on its own equipment and data networks. I'm curious about details on this. Modern phones (well, iPhones at least) are pretty hard to break into. I wonder if it was something like having them install a root certificate to use the company wifi, then using that root cert to spy on other traffic traversing the network (such as leaks to reporters)

Anymore these days its been my experience that cert pinning prevents this from working. Adding a new root cert does not force any of the apps to use the root cert if they've enabled pinning.

Interesting tidbit, I'll stash that for the next time an SRE argues that pinning requires too much overhead (in terms of managing/paying for the certs rather than CPU) :)

Re: Another former Tesla security manager says the company spied on employees

#35
post #29

Earlier quoted context omitted.

> You should also assume all of your traffic while at the office I fell out with my manager at FANG and she got back at me with the lowest rating possible for the year-end review. I chose to get my concerns across to HR about how this was unfair and challenged them to validate her critical feedback with peer engs. Didn't happen. Instead what followed was, I was investigated for violation of company rules such as putt…

I’m sorry to hear that. On that note, it seems almost impossible to not use company equipement to look at things which may not be strictly work related such as news, new tech, websites, the occasional Youtube comedy clip. Seems inhuman to have such strict rules which only serve as a way for the company to kick people out when they moment is opportune.

> it seems almost impossible to not use company equipement

Why? Just don't do it. If its not work related, stop. If you need to kill some time to stay sane, get up and take a walk to do whatever on your device. I've worked at places where the computer that I used was connected to the production network. It was not connected to the internet at all which meant no email. To get to email, we had to log into a remote system to view email. Attachments could be saved to a folder that put it up for review of relevance and virus/malware/etc. If it wasn't approved, it was silently deleted with no notification.

At another location, we blocked FB at the firewall for the day, and the employees about lost their mind. It was very telling about how much time was wasted throughout the day. It was also surprising the number of people that complained like it was their right to use the company's resources to update their friends.

Re: Another former Tesla security manager says the company spied on employees

#36

Earlier quoted context omitted.

> You should also assume all of your traffic while at the office I fell out with my manager at FANG and she got back at me with the lowest rating possible for the year-end review. I chose to get my concerns across to HR about how this was unfair and challenged them to validate her critical feedback with peer engs. Didn't happen. Instead what followed was, I was investigated for violation of company rules such as putt…

Remember the following: HR is not your friend. HRs duty is to the company. If what you need and what the company needs are on the same page, sure, HR is on your side, but if not, they will do whatever it is that benefits and protects the company.

[deleted]

Re: Another former Tesla security manager says the company spied on employees

#38

Earlier quoted context omitted.

> The tip from Sean Gouthro, the former head of Tesla's global security operations center and investigations, was filed on January 24 and corroborates a tip filed in August from Karl Hansen ... Hansen's tip claimed that Tesla did not disclose to shareholders the theft of raw materials and the unauthorized surveillance and hacking of employee cellphones and computers. This is not a tip about Tesla watching what its em…

>This is not a tip about Tesla watching what its employees are doing on its own equipment and data networks. I'm curious about details on this. Modern phones (well, iPhones at least) are pretty hard to break into. I wonder if it was something like having them install a root certificate to use the company wifi, then using that root cert to spy on other traffic traversing the network (such as leaks to reporters)

A statement from the whistleblower's attorney said Tesla had hired former members of Uber's intelligence team (that had been spying on drivers, regulators, and competitors a while back) and referenced a proposed settlement agreement for the wire tapping & corporate espionage charges that outlines the tactics (allegedly) used by Uber.[1]

It also mentions Tesla installed "specialized router equipment within its Nevada Gigafactory designed to capture employee cell phone communications and/or retrieve employee cell phone data."

Sounds like some sort of man in the middle attack? I didn't catch any similar references in the Uber document but its heavily redacted and the entirety of my knowledge in this area comes from Dinesh's criminal girlfriend so it's very possible I missed it.

[1]https://www.scribd.com/document/367287753/Uber-Jacobs-Letter...

Re: Another former Tesla security manager says the company spied on employees

#39

Earlier quoted context omitted.

> You should also assume all of your traffic while at the office I fell out with my manager at FANG and she got back at me with the lowest rating possible for the year-end review. I chose to get my concerns across to HR about how this was unfair and challenged them to validate her critical feedback with peer engs. Didn't happen. Instead what followed was, I was investigated for violation of company rules such as putt…

Remember the following: HR is not your friend. HRs duty is to the company. If what you need and what the company needs are on the same page, sure, HR is on your side, but if not, they will do whatever it is that benefits and protects the company.

This advice is about as useful as the also ever-present HN saying, “if you’re not paying for it, you’re the product”

In other words, entirely useless and just a derailment of the thread.

Re: Another former Tesla security manager says the company spied on employees

#40
post #29

Earlier quoted context omitted.

I’m sorry to hear that. On that note, it seems almost impossible to not use company equipement to look at things which may not be strictly work related such as news, new tech, websites, the occasional Youtube comedy clip. Seems inhuman to have such strict rules which only serve as a way for the company to kick people out when they moment is opportune.

> it seems almost impossible to not use company equipement Why? Just don't do it. If its not work related, stop. If you need to kill some time to stay sane, get up and take a walk to do whatever on your device. I've worked at places where the computer that I used was connected to the production network. It was not connected to the internet at all which meant no email. To get to email, we had to log into a remote syst…

> It was very telling about how much time was wasted throughout the day.

Depends on a type of work that one does, for many office jobs today more hours spent working doesn't always translate into more work done. I personally find that taking frequent short breaks surfing web, reading news, checking FB and YT, etc. helps me keep focused and way more productive.

Post reply on HN