Live data from Hacker News

Elon Musk emails employees about 'extensive and damaging sabotage' by employee

cnbc.com

531–540 of 627 posts

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#531

Earlier quoted context omitted.

But somebody has access to the signing keys/signing process. And somebody has access to the production machines. Etc.

Yes, but that changes the scenario from a "small handful of engineers" that can all do it unilaterally, to needing at least one person from N different teams to collaborate. And in my specific case, the group with the singing keys is also the group paid to tell us "no" whenever a release is blocked by process reasons.

My guess is that most people with access to signing keys or prod environments would have enough skills to code in some sabotage bugs before deployment or siphon off some data, so a lone devops person with (physical) access could probably a lot of harm just by themself.

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#532

Earlier quoted context omitted.

I'm baffled at your lack of imagination, but: keyloggers, unlocked terminals, API token sniffing from cookies, reactivated old accounts, changing the reviewing account id in the database, …

I'm baffled at your lack of imagination What does being rude add to the discussion?

Sorry. This was the polite phrasing I came up with…

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#534

Earlier quoted context omitted.

> If someone actively tries to circumvent the policy or the process, odds are that most software shops would fall victim to the same thing. Too often the focus is entirely on outside attacks, with little consideration given to insider attacks. Previous job was at a cyber security firm. We'd routinely come under attack from criminal and, we believed, occasional nation state attacks as our researchers attributed a few…

> Then you'd come back from lunch and find the mantrap doors propped open, or someone left a workstation unlocked with root access to something important, or random guests just wandering around. It's a miracle we never were compromised by a disgruntled employee (of which there were many). Maybe not the most technical solution to this, but one of my previous employers had a workplace culture of setting the desktop bac…

I worked at a place that did something similar. If you walked away from your unlocked computer, when you came back you might find you'd sent an email to everyone in the office saying that you're buying lunch today.

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#535

Everyone's reaction to this seems to be "He is crazy / paranoid". He gave very specific examples of things this person did. If you were someone with a large position against Telsa, or a competing manufacturer, or an oil / gas company finally picking things up after a terrible oil price collapse, yeah maybe it makes sense to go mess things up subtly enough that the company slips a little bit closer to bankruptcy? I'm…

> Everyone's reaction to this seems to be "He is crazy / paranoid". He also investigated "sabotage" when a SpaceX rocket exploded in 2016. > or a competing manufacturer, or an oil / gas company finally picking things up after a terrible oil price collapse This is borderline ridiculous. Are you really convinced that Tesla is on the verge of upending the entire energy world? That any minute now they are going to put Bi…

> Outside of the coastal elites or tech junkies, Tesla is practically unknown and is a rounding error to competitors.

Tesla outsells BMW, Audi and Mercedes' flagships in their home market - https://www.cnet.com/roadshow/news/tesla-outsells-bmw-audi-m...

Tesla Model 3 Outsells BMW, Mercedes Equivalents in California - The Model 3 is the best selling mid-size premium sedan sold in California in the first quarter. - https://www.thestreet.com/investing/stocks/tesla-outsold-bmw...

It seems it would be healthy for competitors to take note of this "rounding error"...

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#536

Earlier quoted context omitted.

I think you misunderstand. Even with code review policies, there is still a short list of people who can push to production without going through code review. Not from a policy standpoint but from a security and access perspective.

The chain we had in ${BIGCORP}: Programmers: read-write to repository Staging team: read-only on repository, read-write to test servers and staging zone Deployment team: read-only on repository and staging zone, read-write to production It wouldn't prevent malicious code going out but at least would require a chain of cooperation between employees, which would be harder to achieve.

You generally can't stop someone with administrative access to production from running something that didn't come from your normal process/VCS.

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#538

Earlier quoted context omitted.

> Then you'd come back from lunch and find the mantrap doors propped open, or someone left a workstation unlocked with root access to something important, or random guests just wandering around. It's a miracle we never were compromised by a disgruntled employee (of which there were many). Maybe not the most technical solution to this, but one of my previous employers had a workplace culture of setting the desktop bac…

I worked at a place that did something similar. If you walked away from your unlocked computer, when you came back you might find you'd sent an email to everyone in the office saying that you're buying lunch today.

Yeah, this is funny, but a bad idea. You getting on somebody elses workstation, under their login - what happens if they are doing bad shit to the company? Now you have to explain why you were seen on their workstation.

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#539
post #475
post #439

Earlier quoted context omitted.

Someone has to be responsible for managing people and organising access to the appropriate machines for them to do their job, if it isn't their manager then who is?

You can manage people and organize access without actually having the ability to gain access to their credentials. In fact, that's how it's supposed to work in safety-critical environments.

This is how it works in normal software companies too. I never see the credentials for my employees.

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#540
post #517

Earlier quoted context omitted.

> The best counter argument you have is sarcasm? Yeah, I was tired and irratible when I wrote that. As quotes, it's actuly true: his small but extremely vocal 'cult' following is a big problem. I still don't agree with most of what his most strident critics say. I think he's being unusually straightforward in thought and communication.

Fair, I have definitely done the same thing. Friends?

Friendly at least! (:
Post reply on HN