Live data from Hacker News

Gitlab considers not hiring SREs and Support Engineers in China and Russia

gitlab.com

141–150 of 584 posts

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#141
post #7

The title seems misleading, the article specifically states this does not effect any current employees, presumably as they have none in China and Russia. > As such we feel a country block is the most humane solution at this time--especially because it affects zero current employees

Correct, this block would be for two functions (Site Reliability Engineer and Support) and we currently have no people in that role in China and Russia. Please note that we're still discussing this change. We work out in the open so you can see us working on it. I hope that people appreciate the difference between that and what you would see in a non-transparent company (probably nothing, they would just not open up…

Would you consider extending this to other roles? If you remember the Juniper VPN backdoor was so well done it would have likely (or did) passed code review, putting most software engineering in to scope.

Additionally would this extend to individuals who are of Chinese or Russian origin? China in particular leans on nationals who are on visas or have family still in country to conduct espionage operations.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#142

Earlier quoted context omitted.

It does block them from moving to that country. So if a current employee was planning to move to either country soon they'd be prevented from doing that. I've danced this dance at a previous company when we had an employee working from a country of interest for an extended period of time. They were air-gapped from our systems and it worked because they submitted everything by pull requests (the original way, sending…

I've done some travelling to risky places before (Kiev and other places) and even though the networks were hostile there, I still don't understand the point of pretending that Russia et al can't get into Gitlab whenever they want to. They can. Air-gapping isn't going to slow them down.

> They can. Air-gapping isn't going to slow them down.

Two points here. First of all, failing to acheive absolute security is not a justification for ignoring best practices.

Second, this isn't air gapping. It is preventing a bugged laptop from sitting in on conference calls and meetings for the next year or two until it gets aged out.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#143

I'm shocked (in a positive way) about the amount of transparency Gitlab provides. Even as a reader, it almost feels as if someone misconfigured the ACLs or I'm reading leaked internal documents, not an intentional decision to make this open. Some of the discussions seem highly sensitive, and yet it seems to work for them. Thank you, Gitlab, for being so open! I've learned a lot about compliance from just reading this…

I used to work for a company that had a public Jira bug tracker (security related bugs were hidden). I imagine a lot of customers had the same feeling you had: listing all bugs in a release, their status, the discussion around them, it was all there. Very transparent and very appreciated.

Unfortunately, like most good things in corporate software, it didn't last.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#144

Doesn't this directly imply non-US entities should have severe reservations about American SREs and Support Engineers?

That is just whataboutism. China has a long demonstrated history of using its intelligence services for the benefit of domestic corporations, as well as exploiting its citizens working overseas to aid in the same.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#145

Earlier quoted context omitted.

I disagree completely. By that reasoning, a presidential candidate of Chinese descent who was a natural born American citizen but had relatives back in china would be disqualified, and that is nowhere justified by the constitution. A private company likewise shouldn’t be able to discriminate on speculative threats alone. What if they had a relative in prison, a hostile coercive environment by any measure? I accept th…

> By that reasoning, a presidential candidate of Chinese descent who was a natural born American citizen but had relatives back in china would be disqualified Not so. The Constitution is very clear on eligibility requirements for the President. A natural born American citizen of Chinese descent who otherwise satisfies the requirements in Article II, Section 1, Clause 5 is perfectly eligible to run for the office. If…

> Second, I am curious why you disagree completely, yet accept that your relationship with your wife may disqualify you from holding a government security clearance.

This has to do with companies making their own rules about what is right or wrong without any checks, balances, or voter feedback. Security clearances are actually defined by law, I’m against corporations becoming their own extra judicial entities.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#148
post #143

I'm shocked (in a positive way) about the amount of transparency Gitlab provides. Even as a reader, it almost feels as if someone misconfigured the ACLs or I'm reading leaked internal documents, not an intentional decision to make this open. Some of the discussions seem highly sensitive, and yet it seems to work for them. Thank you, Gitlab, for being so open! I've learned a lot about compliance from just reading this…

I used to work for a company that had a public Jira bug tracker (security related bugs were hidden). I imagine a lot of customers had the same feeling you had: listing all bugs in a release, their status, the discussion around them, it was all there. Very transparent and very appreciated. Unfortunately, like most good things in corporate software, it didn't last.

Red Hat has a public Bugzilla with (almost) all the open bugs in their software.
Post reply on HN