Live data from Hacker News

Elon Musk emails employees about 'extensive and damaging sabotage' by employee

cnbc.com

601–610 of 627 posts

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#601

I don't want to be the conspiracy guy, but if I read the email the opposite way, I found out that the message is the sabotage first (yes), but the second point about ramping up the production to 5k is the second subject. I'm asking the question if this email could be a stunt to inform the investors their production state, to inform about the delays, etc. ? Simply wondering.

I very often notice how Musk will write or tweet in an ambiguous enough way that most people will read different messages out of him.

My own speculation is that he does this intentionally not to lie, but to catch people out with "gotchas". It's a hedge against both failure and success.

I caution against over-interpreting anything he says until the details are made very specific.

An aside for example, one time I told a customer "I'll see what I can do" - what they heard though was closer to "ok I'll sort it out for you", and weren't too pleased when later on we weren't able to resolve it in time for them.

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#602

Isn't this the plot in one of the episodes of Billions? If you are short a stock and a billion dollars is on the line, there are people you can pay who will "ensure" that a company fails and you win your B+ bet.

I believe it's a plotline in any film or TV series featuring gangs or mobs.

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#603

Short sellers lost over $1 billion dollars on one day a couple weeks ago. Money talking, bullshit walking..... https://www.cnbc.com/2018/06/06/shorts-against-teslas-stock-...

$1 billion sounds like a large number, but how many people was it spread across and what percentage of their portfolio was it?

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#604
post #294

There's something really sad about all the people who are claiming that Musk has developed deep psychological problems in recent months. Do they really think these claims are going to stop people from buying his cars, or stop big companies from hiring SpaceX to launch their satellites into orbit? Or that it will cause the megafactory to be a total failure? I think what we are seeing here is speculators who have bet d…

Prediction: they will raise new capital. Because if not, prediction 2: bankruptcy at the end of the year. Reasons: widely reported ginancial status of Tesla, based on official publications.

What if Musk supplied the required capital himself?

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#605

Earlier quoted context omitted.

This is the closest that I've ever felt the need to call someone an idiot on the internet. Both boosters' feeds were fed from the same booster, i.e. we were seeing the same image twice. That is _not_ fake.

The footage itself was real video from a real camera, but the announcers said the footage was something different than it actually was. The YouTube _recording_ of the livestream was also edited after the fact without any mention that it no longer reflected the originally broadcast. While technically not 100% fake, I think at the very least it would be fair to call that misleading. If this is the closest you've ever c…

> I think at the very least it would be fair to call that misleading

You imply intent. There was no intent to deceive.

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#606
post #28
post #21

Earlier quoted context omitted.

My company only allows authenticated users to commit changes. Even pull requests on our public repos get scanned and reviewed before human review. And pull requests are infrequent enough that unknown users usually involve some interaction. It seems like if an organization is allowing randos to push changes, they would also allow randos with valid pgp to push changes as well. So the investigation would change to “Who…

What you might not realise is that the author of a commit is not related to the (authenticated) user who pushes. You couldn’t merge changes from multiple people otherwise. Signed commits do fix this although you have to be careful about your threat model. Lots of software (e.g. gitlab) will prevent alice from pretending to be bob but will not protect you against server compromise (because public key directory and sig…

What I mean is that making fake author accounts and then merging with an authenticated account shouldn’t help a malicious actor. Any competent project will be interested in the accounts contributing.

Maybe my org is just simple but if “John Doe” started submitting pull requests and prepend merged them, it’s me on the hook and there are people interested in who John Doe is. And in my org, even John Doe needs a network credential so even their local git instance (which I’ve never seen anyone use) would need a credential.

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#607

I made this same comment on the other discussion. I find it concerning that one person was able to push malicious code to 'production'. To me, this suggests that Tesla, a company building highly sensitive software, does not employ basic branch policies. How is is it that these changes could have made it through a code review process and get deployed? If a company like Microsoft or Google announced that a disgruntled…

If they really had access to credentials for multiple accounts, then I don't see why they could not +2 their own code commits. Provided the code still builds and passes basic functional tests, I doubt anyone would see this.

Could it be that folks started looking at code commits when vehicles started behaving badly?

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#608
post #79

Earlier quoted context omitted.

Are we really saying that Tesla, a company building highly sensitive software, is not employing basic branch policies? How is it that these changes could have made it through a code review process and deployed to 'production'? What I take away from this is that one malicious actor was able to single handedly deploy malicious code and that there were no processes in place to stop this. That is a far more worrying issu…

Not sure if it changes your point at all, but the changes were to the manufacturing operating system, not the car OS. I'm not familiar with manufacturing but I imagine there are a ton of different systems and perhaps not all are as secure as the other. I recall reading they needed some paint improvements, so perhaps they changed something there. I don't imagine they would have software controlling paint totally locke…

Most manufacturing machines run G-code. Simply changing one of the G-code values (text editing) would cause the machine to make parts incorrectly, and this would screw up things down the line. https://en.wikipedia.org/wiki/G-code

on my Haas mill, the code is directly editable by the operator. On my robots, the code is 'taught' by moving the arm and telling the machine that the new location is the updated. It is routine to have to adjust minor things in the robots, the operator would have to have access to do their job.

I had a welder put a washer under a sensor on my robot one time, making every weld 1 mm in the wrong spot. We couldn't figure it out and ended up reprogramming the entire setup, 8 hours, to fix it. A week later I noticed the washer, put there by a guy who I fired for bad attitude a week before. Once I had found the washer, I had the choice of going back to the old code, or leaving it with the new code.

I left it with the new code. I didn't have another 8 hours to waste to fix the fix.

Even tiny companies like mine can have sabotage. Why not Tesla?

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#609
post #580

Earlier quoted context omitted.

"Defense" seems to be a strange choice of word here. And seriously, iPhone isn't just a phone, seriously?

Yeah, defense as in defending an argument. > And seriously, iPhone isn't just a phone, seriously? Not sure how old you are, but if you want just a phone look at feature phones, seriously ;)

Certainly older than Tesla. Or Apple, for that matter.

By the way, any feature phone is much better than iPhone as... a phone, you know, to call people and stuff. Even as smartphones Apple products aren't unicorn magic. Neither are Teslas. Riding in one, they can barely compete with a mid-range Hyundai.

Re: Elon Musk emails employees about 'extensive and damaging sabotage' by employee

#610
post #84

I made this same comment on the other discussion. I find it concerning that one person was able to push malicious code to 'production'. To me, this suggests that Tesla, a company building highly sensitive software, does not employ basic branch policies. How is is it that these changes could have made it through a code review process and get deployed? If a company like Microsoft or Google announced that a disgruntled…

This is a very naive comment. There will always be a small handful of engineers that can push the button to move code into PROD or even change code in PROD live. Ideally, with mature controls, the people in this list is short. But to jump to the conclusion that Tesla doesn't use good practises is very short sighted. Who's to say that external parties didn't target this person specifically because of their role/influe…

This is a very naive comment

No, not for a company doing what Tesla does. In the environment I used to work in, that would have been flat out impossible. No change would have been allowed that did not follow process unless an explicit and documented exception was made.

Even if you did manage to commit code to the release trunk without review, every single change to the codebase was checked before the release process started in order to verify that the right process was followed. If we ever found a change that no one could find paperwork for, it would be reverted.

So, yeah, it's possible if you want to do it badly enough.

Post reply on HN