Live data from Hacker News

Gitlab considers not hiring SREs and Support Engineers in China and Russia

gitlab.com

151–160 of 584 posts

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#151
post #135

Earlier quoted context omitted.

There are a lot of countries.

there are about 250 or so. it's not hard to make a complete list and drop the few undesired ones.

The point is that those 250 countries all have different legislation and cultures. The only concern is not "we don't want the Chinese government to have access to user data". That's the only concern for Gitlab (well that and not violating US laws in regards to who they can do business with), but it is not as simple for many other companies.

Going from a whitelist to a blacklist is hard because you need to either individually vet every country and decide if they're ok, or you need to just assume a lot of countries are ok.

Going from a blacklist to a whitelist is obviously trivial.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#152

I'm shocked (in a positive way) about the amount of transparency Gitlab provides. Even as a reader, it almost feels as if someone misconfigured the ACLs or I'm reading leaked internal documents, not an intentional decision to make this open. Some of the discussions seem highly sensitive, and yet it seems to work for them. Thank you, Gitlab, for being so open! I've learned a lot about compliance from just reading this…

I also learned a lot and some of the employees made great points. I’m wondering, can the US government legally issue a National Security Letter to an individual employee that forces them to comply and spy for them? If they can, does this also mean the employee has no legal recourse since NSLs must be kept secret?

> If they can, does this also mean the employee has no legal recourse since NSLs must be kept secret?

No, because that would be unconstitutional. But the proceedings of objecting to a NSL similarly must be kept secret. There wouldn't be any point to the secret component of a NSL if the recipient could object and hash out the merits of the request in public court records.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#153

Earlier quoted context omitted.

> discriminating based on notational origin is a big no no from an ethical perspective However, discriminating based on exposure to coercive pressure from aggressive and hostile foreign powers is probably OK, even if such exposure is heavily correlated with national origin. The key is that the discrimination must be based on an individual analysis of the applicant and his/her life circumstances. It's not OK to blanke…

I disagree completely. By that reasoning, a presidential candidate of Chinese descent who was a natural born American citizen but had relatives back in china would be disqualified, and that is nowhere justified by the constitution. A private company likewise shouldn’t be able to discriminate on speculative threats alone. What if they had a relative in prison, a hostile coercive environment by any measure? I accept th…

Constitutionally speaking, the President does not require a security clearance; the President ex officio has unlimited access to classified information. If there are concerns the President may be vulnerable to foreign influence, the constitutional processes to address those concerns are election and impeachment not security clearances.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#154

Probably an idea to throw Australia on that list - https://www.zdnet.com/article/whats-actually-in-australias-e...

I'm surprised we (Australia) aren't already on more of these lists. After having this discussion with my manager and colleagues (the conversation with my manager was in my interview process where I bluntly stated if I was asked to comply with anything from this law, I'd immediately resign, my manager also agreed). Everyone I've spoken to agreed we'd immediately resign since it was the only potential option to protect…

As an Aussie living & working overseas I'm still not sure if it applies to me and makes me a liability? I know they can't enforce it unless I go home but I will someday

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#155

I understand the basic issues involved here. Both countries are doing very odd things when it comes to information and privacy. However, I feel like making this a "country issue" is really not exactly the right horse to ride on. Rather, I think it should be stated due to the security policies of these governments, we are banning them as information safeholds at this time or something of the sort. Then, the issue is L…

But the problem isn’t storing information in these countries in this case. It’s how these are known to coerce nationals with ties to the homeland into spying for them.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#156
post #148
post #143

Earlier quoted context omitted.

I used to work for a company that had a public Jira bug tracker (security related bugs were hidden). I imagine a lot of customers had the same feeling you had: listing all bugs in a release, their status, the discussion around them, it was all there. Very transparent and very appreciated. Unfortunately, like most good things in corporate software, it didn't last.

Red Hat has a public Bugzilla with (almost) all the open bugs in their software.

It used to be open for most things. Doesn't seem to be that way for at least the last 6 months or so (may more).

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#157

Deleting everything I have on gitlab and leaving this racist platform

So, give any quote from the link or elsewhere that in any way shows the reasoning for this consideration is based on how much they don’t like Chinese people or how inferior they are as a race. People keep throwing around the racist label even when it’s absolutely clear that it’s not about race. It’s about the Chinese and Russian governments and how they operate. These are legitimate informational/operational security concerns that can’t be waved away with "well, it’s racist to protect ourselves, so we just won’t".

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#158

Earlier quoted context omitted.

In china, not from China. The former is easy to justify, and would affect even Americans of non Chinese descent. The latter would be incredibly difficult to justify, and could easily be seen as unwarranted discrimination.

Well, technically it is discrimination, but not racism. I.e. you can still hire a Japanese developer, and with a Chinese regime change you might be able to hire Chinese developers. However, federal law prohibits discrimination based on national origin. This is a touchy subject, but maybe this no longer makes sense? As burfrog pointed out, a Chinese employee living in America isn't free from Chinese control; the gov't…

Are we seriously going 9066 here?

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#159
Well, the answer to that is simple. #boycottgitlab

I am working at a European company where the amount of Russian engineers is constantly increasing (similar thing happens in many of the bigger companies nearby). And they prove to be quite ok.

So since today I will speak strongly against use of Gitlab in my workplace should such a talk begin.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#160

Doesn't this directly imply non-US entities should have severe reservations about American SREs and Support Engineers?

Perhaps if they are Chinese or Russian and work closely with their nation's government or military, but in that case I imagine they probably are already taking whatever precautions they can to limit access by Americans.
Post reply on HN