Live data from Hacker News

Ex-Google engineer charged with stealing trade secrets

apnews.com

401–410 of 497 posts

Re: Ex-Google engineer charged with stealing trade secrets

#401
post #193

If any of you get this far down, one thing that caught my eye is that Google said they had analyzed this guy’s network traffic after locking his laptop, confirming various things. If you work at a large company like Google, every packet on their employee access network is recorded and indexed for forensic purposes. This is not something Google would talk about publicly, but it’s standard practice in any company that…

This is standard practice in all big companies. Everything is tracked and recorded. If you want to say something to a colleague that you don’t want management to know - use your personal phone and talk at a coffee shop or bar in person.

Re: Ex-Google engineer charged with stealing trade secrets

#402

Chinese or not, this guy is a thief and violated rules of being honest. He also kept a high profile in China and did that on purpose for fame and fortune. Shame on him - Said a Chinese

[flagged]

Yeah sinophobia is an easy trap to fall into. Though I would assume there is analogous sentiments on Chinese platforms.

Re: Ex-Google engineer charged with stealing trade secrets

#403

Earlier quoted context omitted.

> It didn't work out for them that well. They couldn't last more than 6 months at any one company I don’t understand what you are saying here. How many months does one need to stay to hover up the trade secrets / IP? In software engineering you get access to the repos on day one, but even in other industries I guess what you don’t have access to after 6 months you won’t have access to realistically ever. > eventually…

I have a strong distrust for authority, but even I would report espionage and IP theft of this sort. Downloading a movie doesn't bother me. Running a site for others to download movies doesn't bother me. But being a snake to go defraud a company to steal the hard work of others so your own illicit company can turn a profit off said labor by others irks me. Do your own R&D. Did you ever consider doing raising a red fl…

If anything is going to unite two groups of people who are “naturally” on opposite sides of a political spectrum, it’s going to be stopping treasonous activities.

I airquote naturally because it’s obvious that foreign interference is at play, based on the laissez-faire attitude towards this sort of thing by some groups.

Re: Ex-Google engineer charged with stealing trade secrets

#404

Earlier quoted context omitted.

> It didn't work out for them that well. They couldn't last more than 6 months at any one company I don’t understand what you are saying here. How many months does one need to stay to hover up the trade secrets / IP? In software engineering you get access to the repos on day one, but even in other industries I guess what you don’t have access to after 6 months you won’t have access to realistically ever. > eventually…

I have a strong distrust for authority, but even I would report espionage and IP theft of this sort. Downloading a movie doesn't bother me. Running a site for others to download movies doesn't bother me. But being a snake to go defraud a company to steal the hard work of others so your own illicit company can turn a profit off said labor by others irks me. Do your own R&D. Did you ever consider doing raising a red fl…

> Running a site for others to download movies doesn't bother me.

> being a snake to go defraud a company to steal the hard work of others so your own illicit company can turn a profit off said labor by others irks me.

I'm sorry, I really don't understand this. What part of the second statement doesn't apply to the first?

Re: Ex-Google engineer charged with stealing trade secrets

#405
post #193

If any of you get this far down, one thing that caught my eye is that Google said they had analyzed this guy’s network traffic after locking his laptop, confirming various things. If you work at a large company like Google, every packet on their employee access network is recorded and indexed for forensic purposes. This is not something Google would talk about publicly, but it’s standard practice in any company that…

It's SOP in all companies, not just those facing sophisticated threat actors - there's a reason EDRs like Crowdstrike and SentinelOne are massive players now.

As someone who has worked at companies, it sure as fuck is not. Unless you are a very valuable company or you make money with data/software, ain't nobody got time for that.

Re: Ex-Google engineer charged with stealing trade secrets

#407

[flagged]

This crosses into a slur (edit: I don't mean an ethnic slur. I just mean, in this case, a negative generalization about a large class of people) and you can't do that on HN. We ban accounts that do, so please don't do it again. We've already had to warn you about this once: https://news.ycombinator.com/item?id=37580266.

https://news.ycombinator.com/newsguidelines.html

Re: Ex-Google engineer charged with stealing trade secrets

#408
post #193

If any of you get this far down, one thing that caught my eye is that Google said they had analyzed this guy’s network traffic after locking his laptop, confirming various things. If you work at a large company like Google, every packet on their employee access network is recorded and indexed for forensic purposes. This is not something Google would talk about publicly, but it’s standard practice in any company that…

It's SOP in all companies, not just those facing sophisticated threat actors - there's a reason EDRs like Crowdstrike and SentinelOne are massive players now.

It absolutely has to be more nuanced than "there's exabytes of pcaps somewhere" because cloning repositories, pushing branches, backups, these things would basically end up being nasty amplification attacks against the ability to store this data. And block dedupe can work for some storage loads, but it's not solving this problem, especially when that git clone came over ssh or https.

Data from employee devices all being captured and stored? That seems plausible. All data on the corporate network? Less so to my naive mind. I'd love to hear exactly how that works and what kind of retention exists for it.

What seems far more likely is that there's a rules engine that can see all the traffic and makes a decision about if it trips an event to be logged or looks strange enough to be captured (along with some amount of surrounding context, if possible).

Re: Ex-Google engineer charged with stealing trade secrets

#410
The guy was allegedly stealing all that using Google Drive. I find such moronic behavior really hard to believe. Literally, there’s no illusion of privacy at Google while using company hardware, let alone company services. This has become quite clear after the Levandowsky fiasco - some of the things disclosed there were surprisingly invasive far in excess of what you’d normally expect
Post reply on HN