Live data from Hacker News

Gitlab considers not hiring SREs and Support Engineers in China and Russia

gitlab.com

181–190 of 584 posts

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#181

Deleting everything I have on gitlab and leaving this racist platform

So, give any quote from the link or elsewhere that in any way shows the reasoning for this consideration is based on how much they don’t like Chinese people or how inferior they are as a race. People keep throwing around the racist label even when it’s absolutely clear that it’s not about race. It’s about the Chinese and Russian governments and how they operate. These are legitimate informational/operational security…

>It’s about the Chinese and Russian governments and how they operate

Have you ever thought that Russian government consists of Russian people? Same with Chinese

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#182

Well, the answer to that is simple. #boycottgitlab I am working at a European company where the amount of Russian engineers is constantly increasing (similar thing happens in many of the bigger companies nearby). And they prove to be quite ok. So since today I will speak strongly against use of Gitlab in my workplace should such a talk begin.

I think you are confusing them having something against Russia(gov) with Russians(people). They also clearly state that current employees will not be affected. Reading the motivation behind it and the possible dangers it would pose to their clients. I think it's very reasonable not to continue having sensitive data be available in Rus & Chi.

What would you do in this case?

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#183
post #148
post #143

Earlier quoted context omitted.

I used to work for a company that had a public Jira bug tracker (security related bugs were hidden). I imagine a lot of customers had the same feeling you had: listing all bugs in a release, their status, the discussion around them, it was all there. Very transparent and very appreciated. Unfortunately, like most good things in corporate software, it didn't last.

Red Hat has a public Bugzilla with (almost) all the open bugs in their software.

Public for their paying customers. Which is fair enough, but it’s also nothing particularly unusual.

Source: am a former RHEL customer now using Fedora

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#184

Well, the answer to that is simple. #boycottgitlab I am working at a European company where the amount of Russian engineers is constantly increasing (similar thing happens in many of the bigger companies nearby). And they prove to be quite ok. So since today I will speak strongly against use of Gitlab in my workplace should such a talk begin.

If anything, I'll start doing exact opposite. So since today I will speak strongly in favor of use of Gitlab in my workplace should such a talk begin.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#185
It's immoral to discriminate on the basis of fear, prejudice, and rumor.

One client can demand that Gitlab get rid of Chinese and Russian nationals today. Tomorrow, a different client can make similar demands - aimed at the nationals of different countries. This makes no sense whatsoever, and will blow out of control quickly.

Sanction programs are the established legal frameworks for such things: https://www.treasury.gov/resource-center/sanctions/programs/...

It's disappointing to see the promise of some money making the company go full 180 on its hiring and employment procedures - going as-far as potentially rescinding one employee's offer, and flagging another employee's personal choice to live in a different country as a risk.

The due process here is concerning. Some techbro starts by creating a "we need to block all Russian/Chinese" issue - followed by a bunch of echo-chamber "yessir" comments. When a legal advisor steps in - everyone tries to silence her and convince her it's just an "iterative process".

Finally - it actually looks like Gitlab's security practices are truly lacking. That an employee is Chinese/Russian shouldn't be a consideration - the systems should be tight enough to make sure absolutely no-one has access to customer data without consent - and that any actions taken are logged for auditing. Whenever necessary - pass your employees through a background-check. In sensitive (government) scenarios - restrict to employees with government clearance.

Honest question: Is Gitlab now a company not in a position to say "no"? Investors and potential customers need to know.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#186
post #126
post #66

Earlier quoted context omitted.

Probably in relation to this: https://www.chinalawblog.com/2019/09/chinas-new-cybersecurit... Whether it's real or not or even likely to be effective, there's a chilling effect and businesses are obviously concerned to be raising the issue of Chinese-based employees with GitLab.

Oh, China is finally following US policies on full takes. Not entirely unexpected. The difference is that China observes their borders, whilst the USA does full takes everywhere they can, which is everywhere in the west.

What is a full take, what do you mean by US policies on full takes, and can I also have a source on US performing full takes everywhere in the west? Thanks!

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#187
post #141
post #7

Earlier quoted context omitted.

Correct, this block would be for two functions (Site Reliability Engineer and Support) and we currently have no people in that role in China and Russia. Please note that we're still discussing this change. We work out in the open so you can see us working on it. I hope that people appreciate the difference between that and what you would see in a non-transparent company (probably nothing, they would just not open up…

Would you consider extending this to other roles? If you remember the Juniper VPN backdoor was so well done it would have likely (or did) passed code review, putting most software engineering in to scope. Additionally would this extend to individuals who are of Chinese or Russian origin? China in particular leans on nationals who are on visas or have family still in country to conduct espionage operations.

It would be strange to not accept code from certain countries since we are an open core company that gets contributions from around the world. There are other ways to prevent supply chain attacks. A difference with data is that there are always multiple people involved before code is merged while data can be extracted by a single individual who has access.

Discriminating on origin is likely illegal.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#188

It's immoral to discriminate on the basis of fear, prejudice, and rumor. One client can demand that Gitlab get rid of Chinese and Russian nationals today. Tomorrow, a different client can make similar demands - aimed at the nationals of different countries. This makes no sense whatsoever, and will blow out of control quickly. Sanction programs are the established legal frameworks for such things: https://www.treasury…

If you look at the vetting processes in the defence sector they have strict nationality and background checks.

Why should the same not be true for something with a damage multiplier the size of github which is basically carrying a big chunk of commercial IP in private repos?

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#189

Well, the answer to that is simple. #boycottgitlab I am working at a European company where the amount of Russian engineers is constantly increasing (similar thing happens in many of the bigger companies nearby). And they prove to be quite ok. So since today I will speak strongly against use of Gitlab in my workplace should such a talk begin.

I think you are confusing them having something against Russia(gov) with Russians(people). They also clearly state that current employees will not be affected. Reading the motivation behind it and the possible dangers it would pose to their clients. I think it's very reasonable not to continue having sensitive data be available in Rus & Chi. What would you do in this case?

I believe, that I am capable of discerning those things :)

Though I suspect that we are over-thinking. Imagine Germany, 1935. “Company X will stop hiring Jews as it deals with stuff important for the military”. And the society be like, “thank you, company X, we are positively pleased with your transparency and shmamparency”.

Are you crazy, people?

I think, that Gitlab is the one that confuses Chinese, the people and Chinese government, let’s say.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#190
post #91

I think one of the reasons should be that Gitlab does not have many enterprise customers in China and Russia. Native Chinese or Russian speakers are not needed for Support.

Russians and Chinese could not care less but gitlab. They have progressed so much in the last years, they have their own gitlab systems. Demonizing Russia and China for bad practices and not doing any introspection on yourself is hypocritical. US suppremacy is over. Get on with it
Post reply on HN