Live data from Hacker News

Tesla has used space characters in internal emails to identify leaks

twitter.com

321–330 of 448 posts

Re: Tesla has used space characters in internal emails to identify leaks

#321
post #33

Earlier quoted context omitted.

> Margaret Thatcher did this in the 80’s to help identify who was leaking cabinet documents to the press. Surely the extra whitespace would disappear in the DTP systems used by the press?

This is why any reputable journalist/leaker takes the information and reproduces it prior to any dissemination (hopefully destroying the original source material).

See how the Intercept absolutely screwed Reality Winner

Re: Tesla has used space characters in internal emails to identify leaks

#322
post #34

Reminds me of the strategy of map companies, that planted tiny errors or fictional streets in their maps, so that they can identify other map companies, that copied their work. https://en.wikipedia.org/wiki/Trap_street

I love this story about Agloe, New York - a "copyright trap" that materialised into a real place: https://en.wikipedia.org/wiki/Agloe,_New_York When another map maker put the actual settlement on their maps, the original publishers cried foul, but then discovered Agloe had become real!

Agloe anagram of legal

Re: Tesla has used space characters in internal emails to identify leaks

#323

It’s called whitespace watermarking and seems to be one of those ideas that keeps getting re-invented. It’s used a lot, particularly in HTML where the rendering hides the identifying spaces. It can help you figure out if someone is scrapping your content.

Yes and similarly many printers and photo copiers have something called MIC - machine identification codes:

https://en.wikipedia.org/wiki/Machine_Identification_Code

Re: Tesla has used space characters in internal emails to identify leaks

#324

Earlier quoted context omitted.

> So here we are, everyone fantasizing about espionage. Espionage isn't a fantasy, it's very much real. People go to jail for it all the time. The only question is to what degree might a company be affected or targeted. Taking steps to add a reasonable layer of security to attempt to protect costly IP isn't being paranoid at all. Not to mention that in some environments there are legal requirements, a prime example b…

Your particular example wouldn't be deterred from the tactics that Elon says that he used, though. If it's not leaked to the public it wouldn't be seen by those that encoded an identifier into it.

But it would be discoverable and traceable in the case of legal proceedings.

Re: Tesla has used space characters in internal emails to identify leaks

#325
post #265

Earlier quoted context omitted.

Certainly possible, but also relies on the assumption that this was done on company equipment. When leaking info under a vindictive boss I would think opsec rule #1 is avoid company equipment as much as possible. Even without a printer at home, it's quite easy to send a print job to a local office or shipping store.

Data exfiltration is an extremely dangerous risk in the world of corporate espionage, especially for a company like Tesla that is trying to be first to market with something as massive as FSD. There is no way I would send anything to an external print shop from company equipment; they are almost certainly on top of that as well.

This has gotten me genuinely curious, I wonder what the safest way to get a document like that onto your own device is. Printing it on a work printer doesn't seem ideal, but I don't really know what the best approach is. Maybe emailing it to an outside address or sharing it as a document via Dropbox or similar? Copying to physical storage? All of those seem fairly easy to monitor as well though.

If any infosec experts feel like chiming in I'd love to learn more.

Re: Tesla has used space characters in internal emails to identify leaks

#326

Earlier quoted context omitted.

Err, did he find the leaker or just anybody who’d printed that file? Hypothetically one person could have printed it at work while the leaker printed it at home, right?

Perhaps Musk's shoddy logic is what's currently pushing Twitter to the brink!

I’m sure the belief that one can find a technological solution to any problem, including social and organizational ones, wouldn’t help.

Re: Tesla has used space characters in internal emails to identify leaks

#327

Earlier quoted context omitted.

Honestly speaking, the story sounds somewhat believable to me. They likely misidentified the leaker with that silly analysis and fired them on the spot, would be just the usual modus operandi of musk.

they probably narrowed it down to one person and approached them with the logs and "admit and be fired or don't admit and legal (and all the bad/expensive stuff that comes with that) will be engaged to get to the bottom of it starting with you".

You can also easily narrow it down to a time period. Find out when leak occurred and then look at prints shortly before that.

Re: Tesla has used space characters in internal emails to identify leaks

#328
post #325

Earlier quoted context omitted.

Data exfiltration is an extremely dangerous risk in the world of corporate espionage, especially for a company like Tesla that is trying to be first to market with something as massive as FSD. There is no way I would send anything to an external print shop from company equipment; they are almost certainly on top of that as well.

This has gotten me genuinely curious, I wonder what the safest way to get a document like that onto your own device is. Printing it on a work printer doesn't seem ideal, but I don't really know what the best approach is. Maybe emailing it to an outside address or sharing it as a document via Dropbox or similar? Copying to physical storage? All of those seem fairly easy to monitor as well though. If any infosec expert…

It will always be a game of cat and mouse. Your protections for leaking are limited to legal whistleblower protections against retaliation, so odds are anything suggested here will potentially be traceable or suspicious, which may invite further scrutiny.

Re: Tesla has used space characters in internal emails to identify leaks

#329

Years ago, I worked at a place that attempted this. They were so giddy about it. There wasn’t even a known leak, or, arguably, anything particularly worth leaking. They were just tickled by the idea that they could gotcha anyone who tried to leak something. Then, as now, it strikes me as little more than sad and paranoid Tom Clancy cosplay. I’d like to say I’ve moved on to a place with a culture of trust and faithful…

Yet I can't really fault a company for trying to hold people accountable for breaking their terms of employment.

I can. It's a waste of time and easily defeated if anyone realizes. Once secret is known, its easy to frame innocent coworkers by twiddling spaces.

Re: Tesla has used space characters in internal emails to identify leaks

#330
post #265

Earlier quoted context omitted.

Certainly possible, but also relies on the assumption that this was done on company equipment. When leaking info under a vindictive boss I would think opsec rule #1 is avoid company equipment as much as possible. Even without a printer at home, it's quite easy to send a print job to a local office or shipping store.

Data exfiltration is an extremely dangerous risk in the world of corporate espionage, especially for a company like Tesla that is trying to be first to market with something as massive as FSD. There is no way I would send anything to an external print shop from company equipment; they are almost certainly on top of that as well.

Sheesh, Tesla FSD would be even worse than the "secret Coca-Cola formula", no one would even want to be in the same computer with it.

Now, production cost figures and schedules ...

Post reply on HN