Live data from Hacker News

Gitlab considers not hiring SREs and Support Engineers in China and Russia

gitlab.com

451–460 of 584 posts

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#451

Earlier quoted context omitted.

The ban applies to people living in China or Russia, not on chinese or russians. Any american or european living in either country would similarly be affected by the ban. Untwist your knickers please.

It very quickly escalates to discrimination against Chinese people in the US, as evidenced by the highly upvoted comment I originally responded to. I'm sorry if I get my knickers twisted about people proposing an entire race of people pose a national security threat, but this sort of xenophobia has rarely gone well in history.

Chinese and Russians living outside of China and Russia will not be affected by the ban.

You keep calling it xenophobia even after you've been proven wrong when you claimed this is targetted at green-card holders. You are absolutely disengenuous and have no intention at good-faith discussion.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#452

It's immoral to discriminate on the basis of fear, prejudice, and rumor. One client can demand that Gitlab get rid of Chinese and Russian nationals today. Tomorrow, a different client can make similar demands - aimed at the nationals of different countries. This makes no sense whatsoever, and will blow out of control quickly. Sanction programs are the established legal frameworks for such things: https://www.treasury…

I think you're being a bit disingenuous. It seems you're almost implying Chinese and Russians are being randomly discriminated against for no reason, as if the kind of thing Gitlab is worried about has never happened before. Specifically with people loyal to those two countries. Yes, it is discrimination, whether it is baseless discrimination is much more debatable.

> "It seems you're almost implying Chinese and Russians are being randomly discriminated against for no reason, as if the kind of thing Gitlab is worried about has never happened before. Specifically with people loyal to those two countries. Yes, it is discrimination, whether it is baseless discrimination is much more debatable."

Do you have concrete numbers that prove Chinese/Russian workers are significantly more likely to act in bad faith against the companies they work in?

To quote Gitlab's chief legal officer, @cciresi:

> "The highest risk countries for hackers are: Romania, Brazil, Taiwan, Russia, Turkey, China and the United States (The US ranks number two in hackers according to ABC news). Surely, we aren't going to start restricting employment on all these countries?"

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#453
post #324

Earlier quoted context omitted.

Nationalism has always been high in China ever since the CCP took control. Not being a nationalist would be a good way to suddenly disappear off the face of the Earth. China has always had double standards. They make it hell for U.S companies to do business there. The only thing that has changed is that the U.S has started pushing back somewhat as of late, but things are still currently in favor of China. When China…

>realize that personal liberties, sovereignty and privacy are important to the "west" I think that Snowden showed us that this is not actually true. Things like National Security letters and the PATRIOT act make the US to me, as a European, seem very hypocritical right now.

> Things like National Security letters and the PATRIOT act make the US to me, as a European, seem very hypocritical right now.

These are not even remotely comparable. China is an outright police state. Not saying the United States doesn't have a lot of work to do with regards to personal liberty, but the Government here has nothing close to the iron grip control that the CCP has; they may want it, and what Government doesn't, but they don't have it and a ton of our internal legal mechanisms are designed specifically to prevent it.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#455
post #399
post #384

Earlier quoted context omitted.

And you know this how? https://www.bbc.com/news/world-europe-50259597

Haven't you heard about Russell's teapot? The burden of proof lies on you. For one thing, such isolation of Russian internet would have negative economic effect and it's the last thing Putin needs.

Search the news. No need go to the Mars orbit.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#456

I wrote another comment arguing that this proposal was both racist and discriminatory, which got flagged and deleted without explanation, presumably because I worded it in such a way as to give an example that might resonate more with Americans by using examples of specific groups of people that have experienced oppression in the US. In the interests of quality discussion on HN, I'm going to make another attempt but…

The factor I'd consider is the legal system of those countries: if you hire someone who lives in China, you're adding another country which can compel your employee to against against your company or customers’ interests (as an American company they're already exposed to the U.S. government's powers). Similarly, you're taking on the risk that something like, say, a future iteration of the current trade war would lead to you suddenly being forced to discontinue their employment on potentially very short notice (remember Adobe's need to comply with the Venezuelan sanctions?).

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#457
post #187
post #141

Earlier quoted context omitted.

Would you consider extending this to other roles? If you remember the Juniper VPN backdoor was so well done it would have likely (or did) passed code review, putting most software engineering in to scope. Additionally would this extend to individuals who are of Chinese or Russian origin? China in particular leans on nationals who are on visas or have family still in country to conduct espionage operations.

It would be strange to not accept code from certain countries since we are an open core company that gets contributions from around the world. There are other ways to prevent supply chain attacks. A difference with data is that there are always multiple people involved before code is merged while data can be extracted by a single individual who has access. Discriminating on origin is likely illegal.

> open core company that gets contributions from around the world

The irony...

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#458
One would this the best solution for this would be a Federated structure that would ensure a Chinese Systems administrator could only deal with whatever resources assigned (China maybe) and a US administrator can only work with whatever resources are assigned (U.S customers??). Therefore you can have the separation of data but please everyone.

I am not saying it would be simple to iron out, but it would allow for distrusting customers to all play together without worrying about data compromise.

Just a thought, i read all the comments and they are about politics and such and very few are about a technical solution to work for all.

One can argue only letting a Chinese Administrator work on a subset is again a geopolitical thing, but that point should be moot if other administrators are restricted as well.

Re: Gitlab considers not hiring SREs and Support Engineers in China and Russia

#460
post #419

It's immoral to discriminate on the basis of fear, prejudice, and rumor. One client can demand that Gitlab get rid of Chinese and Russian nationals today. Tomorrow, a different client can make similar demands - aimed at the nationals of different countries. This makes no sense whatsoever, and will blow out of control quickly. Sanction programs are the established legal frameworks for such things: https://www.treasury…

> the systems should be tight enough to make sure absolutely no-one has access to customer data without consent - and that any actions taken are logged for auditing. You haven't really done OpSec have you? There is very little absolutism in defining who gets access to what data. In fact barring nations that have historically shared data with their governments is exactly one step closer to how you would achieve this.…

> "You haven't really done OpSec have you? There is very little absolutism in defining who gets access to what data. In fact barring nations that have historically shared data with their governments is exactly one step closer to how you would achieve this."

When was the last time you've contracted for a serious client? When it comes to tech - you don't implement "OpSec" by blanket banning hiring Chinese/Russian individuals. Disregarding your bizarre definition of "OpSec" - plenty of individuals with Chinese/Russian background are working for companies such as Google/Microsoft/Facebook/Uber - making significant contributions and getting paid vast sums of money for it. Those companies actually invest into background checks, have dedicated security teams, are investing into locking networks down and improving monitoring. It appears that Gitlab simply wants the easy way out, or, they can't afford to refuse the aforementioned client's offer.

Post reply on HN