Live data from Hacker News

Gitlab considers not hiring SREs and Support Engineers in China and Russia

gitlab.com

21–30 of 584 posts

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#21

I'm shocked (in a positive way) about the amount of transparency Gitlab provides. Even as a reader, it almost feels as if someone misconfigured the ACLs or I'm reading leaked internal documents, not an intentional decision to make this open. Some of the discussions seem highly sensitive, and yet it seems to work for them. Thank you, Gitlab, for being so open! I've learned a lot about compliance from just reading this…

Thanks! We try to be transparent by default and even when it is difficult. I think the OP is a good example of something that is hard to be transparent about because the decision isn't obvious and it takes discussion to come to the best conclusion.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#22
post #11
post #7

Earlier quoted context omitted.

Correct, this block would be for two functions (Site Reliability Engineer and Support) and we currently have no people in that role in China and Russia. Please note that we're still discussing this change. We work out in the open so you can see us working on it. I hope that people appreciate the difference between that and what you would see in a non-transparent company (probably nothing, they would just not open up…

I appreciate that Gitlab discusses this in open, the only real disappointment that it's so one sided.

How is it one sided. They are actively providing info on a third party website. Others can weigh in if they choose. That's up to them

Although they will probably choose to hack them instead

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#23
post #18

See https://gitlab.com/gitlab-com/www-gitlab-com/merge_requests/... for more discussions. Here's one from sytses (CEO/co-founder) > @cciresi this is a request from a customer considering using GitLab.com. @mmcb has more context on the why. We should probably add that to the MR. Probably the US government or something like that?

>Probably the US government or something like that? The requirement to block some class of people off from some customers is nothing new, and back at Sun there was separate Sun Federal which was dedicated for such clean business. GitLab's approach (and i think it is just a start of the trend in the industry, time to get rid of the accent :) while theatrically good isn't practically efficient. A Chinese or Russian res…

It seems obvious to me that the kind of pressure to which you are referring is not limited to family. It would be easy enough to threaten a high school boyfriend. Or the family of your child's former best friend. Or a former co-worker. Or any friend. Or even a complete stranger.

Extortion can be effective well outside family lines.

And, of course, extortion is equally effective on USians, Brits, Indians, Nigerians, or anybody else.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#24

See https://gitlab.com/gitlab-com/www-gitlab-com/merge_requests/... for more discussions. Here's one from sytses (CEO/co-founder) > @cciresi this is a request from a customer considering using GitLab.com. @mmcb has more context on the why. We should probably add that to the MR. Probably the US government or something like that?

I'm not sure I've ever 180'd on a compliance practice as quickly as I have with GitLab's compliance policy repo transparency. When I first stumbled across it during the telemetry situation last week I thought they were nuts. Absolutely nuts. But reading through this thread and the one posted last week it seems like an incredibly effective approach. People from all areas of the company, not just legal/compliance are g…

This one actually makes me scared for Gitlab. I feel like their exposing themselves to a lot of extra liability by making these discussions public.

For instance - it's been suggested (I don't know if rightly or wrongly) that they have a customer who asked them to do something that would violate the US boycott laws. I'll assume that it is the case that they've been asked to violate these laws.

According to a plain reading of a document someone linked here [0] that means they are required to report the request to the US government. I'll assume that it is the case that they are required to report it too, even though I'm not a lawyer, and that's not really an authoritative source.

> The EAR requires U.S. persons to report quarterly requests they have received to take certain actions to comply with, further, or support an unsanctioned foreign boycott.

If they don't (because they forgot, because they disagree with that interpretation of the law, because they don't want to piss off the customer, etc) they now have a public facing record of them violating the law. Even if the assumptions are wrong (they likely are) and they aren't violating the law, someone might decide they are and it might result in lengthy/costly legal battles.

How many other examples like this probably live in that repo for anyone to see?

[0] https://www.bis.doc.gov/index.php/enforcement/oac

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#25

Probably an idea to throw Australia on that list - https://www.zdnet.com/article/whats-actually-in-australias-e...

I'm surprised we (Australia) aren't already on more of these lists.

After having this discussion with my manager and colleagues (the conversation with my manager was in my interview process where I bluntly stated if I was asked to comply with anything from this law, I'd immediately resign, my manager also agreed). Everyone I've spoken to agreed we'd immediately resign since it was the only potential option to protect our selves as employees and our employers.

Edit: I'll need to spend a little more time looking into the Assistance and Access Laws. The following article attempts to downplay some of these concerns:

https://www.homeaffairs.gov.au/about-us/our-portfolios/natio...

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#26
GitLab wants to be "on the right side of the law" when things get stickier . . . plus China and Russia both have State supported hacking (US does too, probably all 5 eyes countries), but if they have to choose between Allies or Axis powers - - it's a pretty easy choice for the side that is more stable, that does not actively promote organ harvesting of live humans, less obvious police state and their money is accepted everywhere . . .

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#28

Probably an idea to throw Australia on that list - https://www.zdnet.com/article/whats-actually-in-australias-e...

I'm surprised we (Australia) aren't already on more of these lists. After having this discussion with my manager and colleagues (the conversation with my manager was in my interview process where I bluntly stated if I was asked to comply with anything from this law, I'd immediately resign, my manager also agreed). Everyone I've spoken to agreed we'd immediately resign since it was the only potential option to protect…

[deleted]

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#29

Probably an idea to throw Australia on that list - https://www.zdnet.com/article/whats-actually-in-australias-e...

I'm surprised we (Australia) aren't already on more of these lists. After having this discussion with my manager and colleagues (the conversation with my manager was in my interview process where I bluntly stated if I was asked to comply with anything from this law, I'd immediately resign, my manager also agreed). Everyone I've spoken to agreed we'd immediately resign since it was the only potential option to protect…

> I'd immediately resign

You are assuming that is actually an option. There is nothing to suggest the current Australian government would not prevent you from resigning until the task had been completed. This is the same government currently attempting to make it illegal to boycott businesses that are damaging to the environment.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#30

Probably an idea to throw Australia on that list - https://www.zdnet.com/article/whats-actually-in-australias-e...

I'm surprised we (Australia) aren't already on more of these lists. After having this discussion with my manager and colleagues (the conversation with my manager was in my interview process where I bluntly stated if I was asked to comply with anything from this law, I'd immediately resign, my manager also agreed). Everyone I've spoken to agreed we'd immediately resign since it was the only potential option to protect…

Since National Security Letters exist, blocking all employees from the US would also be logical. Same for running anything on third-party hardware.

There needs to be a more effective response than Hari Kiri.

Post reply on HN