I love to see how propaganda works. The top comment even congratulates gitlab.
There is a pattern here where the top comment praises a corporation and the top response is an employee of the company thanking the commenter for the praise.
201–210 of 584 posts
I love to see how propaganda works. The top comment even congratulates gitlab.
There is a pattern here where the top comment praises a corporation and the top response is an employee of the company thanking the commenter for the praise.
Well, that's a "goodbye gitlab" for me.
Earlier quoted context omitted.
Congratulations on taking a step in the right direction, even if it is a very small step. Nobody else seems to take the threat seriously, somewhat excepting defense contractors of course. I can understand being reluctant to deal with the full extent of the problem. Somebody from China, with a family in China and subject to Chinese law, does not cease to be a security threat by moving to the USA and getting a green ca…
I on the other hand think that splitting countries into allies and enemies is stupid. China is a huge country, and excluding a billion people from your company just because their government does questionable things sounds like a pretty bad idea. If you are really concerned about the confidentiality of your data, don't store it unencrypted in some SaaS where every customer service rep has full access to all your data.…
I'm shocked (in a positive way) about the amount of transparency Gitlab provides. Even as a reader, it almost feels as if someone misconfigured the ACLs or I'm reading leaked internal documents, not an intentional decision to make this open. Some of the discussions seem highly sensitive, and yet it seems to work for them. Thank you, Gitlab, for being so open! I've learned a lot about compliance from just reading this…
I am in the US, so can not say, "I disagree with how the Israeli government is treating Palestine and thus don't want to do business with any entity located there."?
It's immoral to discriminate on the basis of fear, prejudice, and rumor. One client can demand that Gitlab get rid of Chinese and Russian nationals today. Tomorrow, a different client can make similar demands - aimed at the nationals of different countries. This makes no sense whatsoever, and will blow out of control quickly. Sanction programs are the established legal frameworks for such things: https://www.treasury…
It's not arbitrary banning from foreign countries on your client's request if there's actually good reasons to take precautions with these nation-states.
And why not? They're a private company they can choose to employ whomever they want as long as they're compliant to local labour laws. There's no "due proccess" in business.
"Finally - it actually looks like Gitlab's security practices are truly lacking. That an employee is Chinese/Russian shouldn't be a consideration - the systems should be tight enough to make sure absolutely no-one has access to customer data without consent - and that any actions taken are logged for auditing. Whenever necessary - pass your employees through a background-check. In sensitive (government) scenarios - restrict to employees with government clearance."
Don't improve HR security practices because you're vulnerable in different ways anyways?
If you as a company simply don't trust the government your employees work under, you cannot trust them with sensitive information, even if they're outstanding trustworthy people.
Earlier quoted context omitted.
Would you consider extending this to other roles? If you remember the Juniper VPN backdoor was so well done it would have likely (or did) passed code review, putting most software engineering in to scope. Additionally would this extend to individuals who are of Chinese or Russian origin? China in particular leans on nationals who are on visas or have family still in country to conduct espionage operations.
It would be strange to not accept code from certain countries since we are an open core company that gets contributions from around the world. There are other ways to prevent supply chain attacks. A difference with data is that there are always multiple people involved before code is merged while data can be extracted by a single individual who has access. Discriminating on origin is likely illegal.
It sounds like you just need to harden your production perimeter. Jump boxes with two-man-rule access and terminal logging. Apply the same practices to data as you do code.
> Discriminating on origin is likely illegal.
You should ask your legal folks about the national security exceptions of Title VII. It sounds like your customer requirements are pushing you in that direction anyway.
Earlier quoted context omitted.
I on the other hand think that splitting countries into allies and enemies is stupid. China is a huge country, and excluding a billion people from your company just because their government does questionable things sounds like a pretty bad idea. If you are really concerned about the confidentiality of your data, don't store it unencrypted in some SaaS where every customer service rep has full access to all your data.…
[flagged]
>China has been using our money ...
The best way is to vote with your money then?
Earlier quoted context omitted.
Congratulations on taking a step in the right direction, even if it is a very small step. Nobody else seems to take the threat seriously, somewhat excepting defense contractors of course. I can understand being reluctant to deal with the full extent of the problem. Somebody from China, with a family in China and subject to Chinese law, does not cease to be a security threat by moving to the USA and getting a green ca…
I never thought I'd see this level of xenophobia becoming widely acceptable in the United States. For everything educated Americans loathe about Trump, the one thing they've taken on board from him is fear of the Yellow Peril - which is probably the most dangerous aspect of his Presidency.
Earlier quoted context omitted.
Well, technically it is discrimination, but not racism. I.e. you can still hire a Japanese developer, and with a Chinese regime change you might be able to hire Chinese developers. However, federal law prohibits discrimination based on national origin. This is a touchy subject, but maybe this no longer makes sense? As burfrog pointed out, a Chinese employee living in America isn't free from Chinese control; the gov't…
It doesn’t matter. As long as a security clearance isn’t required, discriminating based on notational origin is a big no no from an ethical perspective, even if it was legal. I hope we learned our lesson during WW2.
Yes it is. You know what's also a big no-no from an ethical perspective? Letting China win so they turn the world into a global dictatorship with concentration camps, organ harvesting and ubiquitous surveillance.
Sometimes you have to do a bad thing to prevent a worse thing.
Earlier quoted context omitted.
> discriminating based on notational origin is a big no no from an ethical perspective However, discriminating based on exposure to coercive pressure from aggressive and hostile foreign powers is probably OK, even if such exposure is heavily correlated with national origin. The key is that the discrimination must be based on an individual analysis of the applicant and his/her life circumstances. It's not OK to blanke…
I disagree completely. By that reasoning, a presidential candidate of Chinese descent who was a natural born American citizen but had relatives back in china would be disqualified, and that is nowhere justified by the constitution. A private company likewise shouldn’t be able to discriminate on speculative threats alone. What if they had a relative in prison, a hostile coercive environment by any measure? I accept th…
If large numbers of voters felt that, then they would never get elected.
> nowhere justified by the constitution
The voters are entitled to vote however they like; that's implied by the constitution.
> I accept that I do not qualify for a high security clearance because I’m married to a Chinese national
Then you essentially agree with me.
> I don’t think that should have any bearing on any other jobs that don’t require such clearances
I agree. The question is, which jobs should require such clearances?