Live data from Hacker News

Tesla has used space characters in internal emails to identify leaks

twitter.com

441–448 of 448 posts

Re: Tesla has used space characters in internal emails to identify leaks

#441
post #322
post #34

Earlier quoted context omitted.

I love this story about Agloe, New York - a "copyright trap" that materialised into a real place: https://en.wikipedia.org/wiki/Agloe,_New_York When another map maker put the actual settlement on their maps, the original publishers cried foul, but then discovered Agloe had become real!

Agloe anagram of legal

Are you sure about that?

Re: Tesla has used space characters in internal emails to identify leaks

#442
post #325

Earlier quoted context omitted.

This has gotten me genuinely curious, I wonder what the safest way to get a document like that onto your own device is. Printing it on a work printer doesn't seem ideal, but I don't really know what the best approach is. Maybe emailing it to an outside address or sharing it as a document via Dropbox or similar? Copying to physical storage? All of those seem fairly easy to monitor as well though. If any infosec expert…

Anything done on a corporate machine needs to be assumed monitored. The paranoid approach would be to fully power off the machine, take the hard drive out, then use an independent machine to mount and read the data off that. Now, if they suspect that approach, or they suspect you personally, there will likely be evidence of your hardware tampering. But it would thwart automated mass-surveillance solutions.

Hard drive encryption makes this difficult.

Re: Tesla has used space characters in internal emails to identify leaks

#443
post #325

Earlier quoted context omitted.

Data exfiltration is an extremely dangerous risk in the world of corporate espionage, especially for a company like Tesla that is trying to be first to market with something as massive as FSD. There is no way I would send anything to an external print shop from company equipment; they are almost certainly on top of that as well.

This has gotten me genuinely curious, I wonder what the safest way to get a document like that onto your own device is. Printing it on a work printer doesn't seem ideal, but I don't really know what the best approach is. Maybe emailing it to an outside address or sharing it as a document via Dropbox or similar? Copying to physical storage? All of those seem fairly easy to monitor as well though. If any infosec expert…

> Maybe emailing it to an outside address

Easily detected.

> sharing it as a document via Dropbox or similar

If you use a TLS-inspecting proxy/VPN, this will be detected. Otherwise, it depends on how much monitoring is going on, but at best they could suspect it.

> Copying to physical storage?

At my work, USB drives are disabled by MDM.

You could use transfer the files over SSH. Even if you have an MitM SSH-inspecting VPN, once the SSH channel is established, you could tunnel a second SSH connection through the established insecure SSH session.

Even then, with enough logging, you could detect that all local files were accessed sequentially which would raise a red flag.

There's nothing you can do to prevent insider espionage that wouldn't raise false positives and block legitimate work, but you could at least detect it.

Re: Tesla has used space characters in internal emails to identify leaks

#444

Earlier quoted context omitted.

All this musk-style motivation 101 BS is direct from the CIA's manual on domestic espionage - frustration from within. The means define the ends. If you treat people like shit, or as morons who need BS pressure techniques, you'll get a demoralised company. Treat people well, set them clear targets and say it without fluff when they're slacking. If you can't tell somebody they're not good enough, you cannot help them…

> Stop building ratrace companies They build rat-races because they are all still rats at heart. Endemic crisis of leadership and vision bred men who cannot think outside the maze. No amount of climbing extended their horizons or released them from slavery to money and the misery it brings.

> released them from slavery to money and the misery it brings

Good point. I often wonder what motivates a billionaire to keep making more money. For most it seems like ego, greed, and inability to rethink their life. I suppose they climbed so high by being relentless and not stopping. This is what makes the example of Yvon Chouinard so interesting.

Re: Tesla has used space characters in internal emails to identify leaks

#445
post #424

Hello, Guy who embedded Xbox 360 serial numbers into the Xbox 360 beta dashboard UI to identify leaked pics here - there was a big HN thread on it some years ago. Just to point out, using extra spaces and different ascii space is basic steganography that's been used since WW1 and WW2. Elon brags about using spaces and other "Canary" techniques. Not super complicated Elon appears to send emails in a fixed width HTML f…

This was the first thing this post made me think of. You blew my mind with this back when I was a kid in school. Extremely memorable. Glad to see I’m in good company in this thread.

Re: Tesla has used space characters in internal emails to identify leaks

#446
post #424

Hello, Guy who embedded Xbox 360 serial numbers into the Xbox 360 beta dashboard UI to identify leaked pics here - there was a big HN thread on it some years ago. Just to point out, using extra spaces and different ascii space is basic steganography that's been used since WW1 and WW2. Elon brags about using spaces and other "Canary" techniques. Not super complicated Elon appears to send emails in a fixed width HTML f…

This was the first thing this post made me think of. You blew my mind with this back when I was a kid in school. Extremely memorable. Glad to see I’m in good company in this thread.

Glad to hear you found that post/ thread interesting or mind expanding. Hope your career is going well.

Re: Tesla has used space characters in internal emails to identify leaks

#448
post #420

Earlier quoted context omitted.

I remember coming across these pirated DVDs etc where they had some kind of Academy watermarks from pre release or intros that were supposed to be give aways as to the source path for smoke testing.

Even visibly putting someone's name in a watermark won't always prevent one from getting shared https://waxy.org/2014/01/ellen_degeneres_walter_mitty_screen...

The threat exclusion is usually a very effective deterrent
Post reply on HN