Live data from Hacker News

Tesla has used space characters in internal emails to identify leaks

twitter.com

351–360 of 448 posts

Re: Tesla has used space characters in internal emails to identify leaks

#351

Years ago, I worked at a place that attempted this. They were so giddy about it. There wasn’t even a known leak, or, arguably, anything particularly worth leaking. They were just tickled by the idea that they could gotcha anyone who tried to leak something. Then, as now, it strikes me as little more than sad and paranoid Tom Clancy cosplay. I’d like to say I’ve moved on to a place with a culture of trust and faithful…

> They were so giddy about it. This makes no sense. Why would they tell everyone what their measures were?

Well, they didn't tell everyone. I was simply, as they say, familiar with the plan.

Re: Tesla has used space characters in internal emails to identify leaks

#352

Earlier quoted context omitted.

Yes. But they'll say that anyway, even if you publish the document in full. This is why a trusted free press matters, and why authoritarians work so hard to undermine it.

A trusted and free press huh. In what works of fiction can I read about those?

Fox News is mostly fictional stories about the free press.

Re: Tesla has used space characters in internal emails to identify leaks

#353
post #23

Earlier quoted context omitted.

Margaret Thatcher did this in the 80’s to help identify who was leaking cabinet documents to the press. I recall a story about Jobs tracking down leakers in his own executive suite by telling each of them a slightly different things in private. Not sure if it worked, but it can be a very effective deterrent.

It's pretty well known that map makers do this, adding non-existent small localities to detect when someone is blindly copying their work.

Yes, it is a fascinating topic:

Fictitious or fake entries are deliberately incorrect entries in reference works such as dictionaries, encyclopedias (including Wikipedia), maps, and directories. There are more specific terms for particular kinds of fictitious entry, such as Mountweazel, trap street, paper town, phantom settlement, and nihilartikel.

https://en.wikipedia.org/wiki/Fictitious_entry

In cartography, a trap street is a fictitious entry in the form of a misrepresented street on a map, often outside the area the map nominally covers, for the purpose of "trapping" potential plagiarists of the map who, if caught, would be unable to explain the inclusion of the "trap street" on their map as innocent. On maps that are not of streets, other "trap" features (such as nonexistent towns, or mountains with the wrong elevations) may be inserted or altered for the same purpose.

https://en.wikipedia.org/wiki/Trap_street

Re: Tesla has used space characters in internal emails to identify leaks

#354

Reminds me of the strategy of map companies, that planted tiny errors or fictional streets in their maps, so that they can identify other map companies, that copied their work. https://en.wikipedia.org/wiki/Trap_street

Google still does this! They seem to use some sort of generative neural net to produce fake names, descriptions, and even reviews for the trap locations. You can report the location to Google as "bad data" and they'll delete it, but then a totally different fake location will re-appear in its place a few days later.

I worked once with a contractor who did not have a physical location for their business. They simply worked out of a minivan which they drove to wherever they were needed. But they pretended, to google, yelp, and probably others, to have a business location.

Re: Tesla has used space characters in internal emails to identify leaks

#355

Years ago, I worked at a place that attempted this. They were so giddy about it. There wasn’t even a known leak, or, arguably, anything particularly worth leaking. They were just tickled by the idea that they could gotcha anyone who tried to leak something. Then, as now, it strikes me as little more than sad and paranoid Tom Clancy cosplay. I’d like to say I’ve moved on to a place with a culture of trust and faithful…

Indeed. For example, Musk fancies himself a champion of "hard work" but what he fails to realize is that humans have not actually merged with robots yet, and we still have human needs. If innovation and brilliant thinking are part of your brand, you actually get higher quality work, sustained over a longer period of time, if you actually back off on the whip-cracking and just give people what they need to produce gre…

To produce great work you also need some pressure. Otherwise people will get real lazy very quickly.

Re: Tesla has used space characters in internal emails to identify leaks

#356

Earlier quoted context omitted.

I need to print return stickers for Amazon in EU.

Interesting. I’m germany we love paper but amazon returns work without the need to print a label at home.

In Austria you do need to print the label. How dos returning without a label work? I mean how does the post know where to ship the package?

Re: Tesla has used space characters in internal emails to identify leaks

#357

Earlier quoted context omitted.

It's pretty well known that map makers do this, adding non-existent small localities to detect when someone is blindly copying their work.

I used to work in a laboratory where we tested pre-production cell phones (this was before the iPhone...). Different OEMs would send us sample devices with different fonts on the keypad, or with little blemishes on the keypad, or would put little subtle cosmetic changes to devices to catch leakers. Funny when you would see devices pop up on the internet with these little things, and wonder who lost their contracts/jo…

I remember coming across these pirated DVDs etc where they had some kind of Academy watermarks from pre release or intros that were supposed to be give aways as to the source path for smoke testing.

Re: Tesla has used space characters in internal emails to identify leaks

#358
post #91
post #81

Earlier quoted context omitted.

Recipient A gets their personalized copy, as does recipient B Recipient A then clicks reply-all, now everyone has copy that was personalized to A. They might even notice subtle differences between them.

But how did recipient A get a personalised copy if the mail with that copy was sent to a list of recipients? Edit: WP has the Tesla story with the counsel forwarding his copy to everyone in a new mail (presumably trying to be helpful?) So not a case of reply-all disease https://en.m.wikipedia.org/wiki/Canary_trap

Email round one: individually-watermarked copies are delivered to individually-addressed individuals. More elaborate systems might watermark such emails en-route, though that's ... less likely. A and B each wind up with individually-identifying copies of the email.

Email round two: A REPLIES ALL to their individually-watermarked copy of the email, delivering it to ALL employees (or some nontrivially large sample), by which B AND EVERY OTHER RECIPIENT now contains A's watermarked copy.

Email round three: B OR ANY OTHER RECIPIENT OF A's REPLY ALL can now leak A's watermarked copy of the email. Watermarking NO LONGER identifies the leaker.

Re: Tesla has used space characters in internal emails to identify leaks

#359
post #61
post #25

Also worth noting that this did not work out, because their general counsel accidentally replied all to the email, giving everyone in the company a safe copy to leak.

"Reply-all" suggests that the same mail went to a set of recipients, but doesn't the watermarking strategy require each recipient to have their own unique copy?

doesn't the watermarking strategy require each recipient to have their own unique copy?

That is indeed the precise and exact point.

Re: Tesla has used space characters in internal emails to identify leaks

#360
post #265

Earlier quoted context omitted.

Perhaps it wasn't an exact byte match, but close enough to only 1 print job size within a reasonable time frame.

Certainly possible, but also relies on the assumption that this was done on company equipment. When leaking info under a vindictive boss I would think opsec rule #1 is avoid company equipment as much as possible. Even without a printer at home, it's quite easy to send a print job to a local office or shipping store.

Ironically, we had an employee appear to exfiltrate data through a print shop. They almost got away with it unnoticed.

The USB stick they used to make the transfer contracted ransomware from the public terminal, which put everyone on high alert when it was next introduced into the corporate network.

Post reply on HN