Earlier quoted context omitted.
> Margaret Thatcher did this in the 80’s to help identify who was leaking cabinet documents to the press. Surely the extra whitespace would disappear in the DTP systems used by the press?
This is why any reputable journalist/leaker takes the information and reproduces it prior to any dissemination (hopefully destroying the original source material).
Tesla has used space characters in internal emails to identify leaks
321–330 of 448 posts
Re: Tesla has used space characters in internal emails to identify leaks
#322Reminds me of the strategy of map companies, that planted tiny errors or fictional streets in their maps, so that they can identify other map companies, that copied their work. https://en.wikipedia.org/wiki/Trap_street
I love this story about Agloe, New York - a "copyright trap" that materialised into a real place: https://en.wikipedia.org/wiki/Agloe,_New_York When another map maker put the actual settlement on their maps, the original publishers cried foul, but then discovered Agloe had become real!
Re: Tesla has used space characters in internal emails to identify leaks
#323It’s called whitespace watermarking and seems to be one of those ideas that keeps getting re-invented. It’s used a lot, particularly in HTML where the rendering hides the identifying spaces. It can help you figure out if someone is scrapping your content.
Re: Tesla has used space characters in internal emails to identify leaks
#324Earlier quoted context omitted.
> So here we are, everyone fantasizing about espionage. Espionage isn't a fantasy, it's very much real. People go to jail for it all the time. The only question is to what degree might a company be affected or targeted. Taking steps to add a reasonable layer of security to attempt to protect costly IP isn't being paranoid at all. Not to mention that in some environments there are legal requirements, a prime example b…
Your particular example wouldn't be deterred from the tactics that Elon says that he used, though. If it's not leaked to the public it wouldn't be seen by those that encoded an identifier into it.
Re: Tesla has used space characters in internal emails to identify leaks
#325Earlier quoted context omitted.
Certainly possible, but also relies on the assumption that this was done on company equipment. When leaking info under a vindictive boss I would think opsec rule #1 is avoid company equipment as much as possible. Even without a printer at home, it's quite easy to send a print job to a local office or shipping store.
Data exfiltration is an extremely dangerous risk in the world of corporate espionage, especially for a company like Tesla that is trying to be first to market with something as massive as FSD. There is no way I would send anything to an external print shop from company equipment; they are almost certainly on top of that as well.
If any infosec experts feel like chiming in I'd love to learn more.
Re: Tesla has used space characters in internal emails to identify leaks
#326Earlier quoted context omitted.
Err, did he find the leaker or just anybody who’d printed that file? Hypothetically one person could have printed it at work while the leaker printed it at home, right?
Perhaps Musk's shoddy logic is what's currently pushing Twitter to the brink!
Re: Tesla has used space characters in internal emails to identify leaks
#327Earlier quoted context omitted.
Honestly speaking, the story sounds somewhat believable to me. They likely misidentified the leaker with that silly analysis and fired them on the spot, would be just the usual modus operandi of musk.
they probably narrowed it down to one person and approached them with the logs and "admit and be fired or don't admit and legal (and all the bad/expensive stuff that comes with that) will be engaged to get to the bottom of it starting with you".
Re: Tesla has used space characters in internal emails to identify leaks
#328Earlier quoted context omitted.
Data exfiltration is an extremely dangerous risk in the world of corporate espionage, especially for a company like Tesla that is trying to be first to market with something as massive as FSD. There is no way I would send anything to an external print shop from company equipment; they are almost certainly on top of that as well.
This has gotten me genuinely curious, I wonder what the safest way to get a document like that onto your own device is. Printing it on a work printer doesn't seem ideal, but I don't really know what the best approach is. Maybe emailing it to an outside address or sharing it as a document via Dropbox or similar? Copying to physical storage? All of those seem fairly easy to monitor as well though. If any infosec expert…
Re: Tesla has used space characters in internal emails to identify leaks
#329Years ago, I worked at a place that attempted this. They were so giddy about it. There wasn’t even a known leak, or, arguably, anything particularly worth leaking. They were just tickled by the idea that they could gotcha anyone who tried to leak something. Then, as now, it strikes me as little more than sad and paranoid Tom Clancy cosplay. I’d like to say I’ve moved on to a place with a culture of trust and faithful…
Yet I can't really fault a company for trying to hold people accountable for breaking their terms of employment.
Re: Tesla has used space characters in internal emails to identify leaks
#330Earlier quoted context omitted.
Certainly possible, but also relies on the assumption that this was done on company equipment. When leaking info under a vindictive boss I would think opsec rule #1 is avoid company equipment as much as possible. Even without a printer at home, it's quite easy to send a print job to a local office or shipping store.
Data exfiltration is an extremely dangerous risk in the world of corporate espionage, especially for a company like Tesla that is trying to be first to market with something as massive as FSD. There is no way I would send anything to an external print shop from company equipment; they are almost certainly on top of that as well.
Now, production cost figures and schedules ...