Gitlab considers not hiring SREs and Support Engineers in China and Russia
gitlab.com
gitlab.com
Even as a reader, it almost feels as if someone misconfigured the ACLs or I'm reading leaked internal documents, not an intentional decision to make this open. Some of the discussions seem highly sensitive, and yet it seems to work for them.
Thank you, Gitlab, for being so open! I've learned a lot about compliance from just reading this thread. For anyone curious, here's some background on the mentioned boycott laws: https://www.bis.doc.gov/index.php/enforcement/oac
I'm eager to find ways to be a more transparent person at work. I want to eliminate "politics" and "games" where possible and for work to be Wysiwyg.
I hoped that people would use the sentences I proposed on that page but that never happened.
What is helpful is that when people raise a concern I can recognize it more quickly and show them it is clearly my flaw. This doesn’t happen often but it happened last week.
I can understand being reluctant to deal with the full extent of the problem. Somebody from China, with a family in China and subject to Chinese law, does not cease to be a security threat by moving to the USA and getting a green card. This gets awkward.
It really is no surprise that valuable secrets of all types (private key, customer data, trade secret, insider info for trading, etc.) end up in other countries.
I hope we learned our lesson during WW2.
However, discriminating based on exposure to coercive pressure from aggressive and hostile foreign powers is probably OK, even if such exposure is heavily correlated with national origin. The key is that the discrimination must be based on an individual analysis of the applicant and his/her life circumstances.
It's not OK to blanket deny any person of Chinese ancestry.
Denying such a person access to sensitive data or positions might be OK, however, if that person is exposed to coercive threats by, e.g. having family located in a jurisdiction known to use its power over expatriates' families as leverage to recruit sources and agents.
So long as the intent is genuinely to serve a compelling interest in protecting against security threats and the vetting policy is as narrowly tailored as possible to minimizing insider risk from applicants with vulnerability to certain threat actors, I think such a policy could pass ethical and (IANAL) maybe legal muster.
"Your honor, of course my intent was genuine ..."
Therein lies the rub ;)
I accept that I do not qualify for a high security clearance because I’m married to a Chinese national. I don’t think that should have any bearing on any other jobs that don’t require such clearances (nor my wife nor my son should be subject to such restrictions).
They notably did not include "or family".
The expectation presumably being that foreign powers were clearly enough signalled to tread carefully with regards to exerting pressure on government officials.
At high levels, that seems reasonable. At lower levels, where there's less scrutiny and less opportunity for diplomatic redress? "Reasonable" measures seem murkier.
[1] https://www.law.cornell.edu/constitution-conan/article-1/sec...
Not so. The Constitution is very clear on eligibility requirements for the President. A natural born American citizen of Chinese descent who otherwise satisfies the requirements in Article II, Section 1, Clause 5 is perfectly eligible to run for the office. If there is concern about potential leverage foreign states have over that candidate--as there rightly would be if our natural born American had close family in PRC--voters might vote for someone else. My position is that such a motivation on the part of the voters is ethical.
> I accept that I do not qualify for a high security clearance because I’m married to a Chinese national. I don’t think that should have any bearing on any other jobs that don’t require such clearances (nor my wife nor my son should be subject to such restrictions).
First, I agree that your or your son's relationship to a Chinese national should not be sufficient grounds to deny you or your son any given job. My position is that a narrowly tailored policy to reject candidates with high risk of coercion from sensitive positions, or to limit such employees' access to sensitive data, is probably OK. Having close family residing in PRC unfortunately does raise the risk of coercive pressure being applied. If your wife has no surviving close relatives in PRC and she never goes to visit, you and your son should be assessed to have no greater vulnerability to coercion than any other citizen with otherwise similar circumstances (debts, addictions, etc.).
Second, I am curious why you disagree completely, yet accept that your relationship with your wife may disqualify you from holding a government security clearance. That means you accept that the government has an interest in protecting classified information from foreign powers, and that your relationship raises your risk profile. Do you not accept that private companies have an interest in protecting their IP and customer data from theft or sabotage? Or do you not accept that your relationship also raises your risk profile for these positions? Just because a position may not require a clearance does not mean that position is not highly sensitive to a potential insider threat. And unfortunately the PLA's targets are not restricted to intelligence agencies; they target virtually every sector of our economy.
This has to do with companies making their own rules about what is right or wrong without any checks, balances, or voter feedback. Security clearances are actually defined by law, I’m against corporations becoming their own extra judicial entities.
As far as I understand, companies are generally free to make their own hiring decisions, so long as they do not amount to discrimination against a protected class. That limitation, by the way, stems from federal legislation--so companies are very much not extra-legal entities operating without any judicial accountability. If a state or federal Congress decide to further regulate companies' hiring decisions, they are free to do so.
I don't understand what exactly you would like companies to do: Simply ignore potential security risks? Do you have a specific process you advocate should be used to evaluate risks? What different kind of restrictions on companies' personnel decisions would you like to see? Do you just have a problem with a focus on risk from family members in PRC as opposed to a broader vetting process where that is only one risk factor?
> Security clearances are actually defined by law
I am not sure that an exact formula for grant/deny decisions exists in statute. These decisions strike me as inherently subjective, although certain facts are obviously pertinent to the decision. I would be very interested to read the relevant laws and regulations, though, if you'd be so kind as to point me to them.
Companies like Apple and others should be allowed to be concerned about theft of sensitive data just as much as the government. Just because it’s not a matter of national security doesn’t mean it’s okay.
Nobody here is trying to discriminate against a race. The problem is having ties to relatives living under a government that is known for making people disappear. The same would apply for a white person with many relatives there, etc.
Your argument of companies not being allowed to take cautionary steps against a foreign government doesn’t hold water.
They already are, with most disputes being settled with Binding Arbitration rather than via the court systems.
Others have already pointed out though, that a company needs to act in its own interests and one of the things it would certainly find interesting is whether an individual is capable of being coerced into sabotaging/sharing corporate trade secrets.
Source: https://web.archive.org/web/20110113190609/http://feinstein....
I think if Congress tried to pass a law limiting the President's access to classified information, the Supreme Court would likely find it to be unconstitutional.
If large numbers of voters felt that, then they would never get elected.
> nowhere justified by the constitution
The voters are entitled to vote however they like; that's implied by the constitution.
> I accept that I do not qualify for a high security clearance because I’m married to a Chinese national
Then you essentially agree with me.
> I don’t think that should have any bearing on any other jobs that don’t require such clearances
I agree. The question is, which jobs should require such clearances?
Constitutional requirements can also be changed, and it is long past time that we do so. The country has been around for 2.5 centuries, and now has hundreds of millions of people. We wouldn't suffer a shortage of presidential candidates if we required that all 4 grandparents (determined all possible ways) and all descendants and spouses have been born in the USA, along with all living ancestors and descendants of all of those. The job is simply too important to allow otherwise. (this would disqualify the most recent two, along with failed candidates like Romney and Cruz)
For tech companies we shouldn't be quite so extreme, but it also isn't good to ignore the problems.
The wiser among us know historically garbage thinking when we see it.
The thing is, coming from a country that is practicing cultural genocide against various ethnic groups, we can probably take those accusations and survive.
You can rest assured that we did not, I have zero doubt that if there ever was another war at that scale we'd have internment camps for nationals of the enemy before the end of that war.
Yes it is. You know what's also a big no-no from an ethical perspective? Letting China win so they turn the world into a global dictatorship with concentration camps, organ harvesting and ubiquitous surveillance.
Sometimes you have to do a bad thing to prevent a worse thing.
Arguably now the FANGS are now CNI - which is going to suck if your on a H1B or Green Card.
Where an employee's family lives seems like the single most important point to consider...
If you are really concerned about the confidentiality of your data, don't store it unencrypted in some SaaS where every customer service rep has full access to all your data. At that point you're already so vulnerable that exluding potenential employees from a whole country is just pointless security theater that some suit with an MBA thought up to justify his position.
People have to do what the state they live in and belong to orders them to do. That's part of the point of having a state. So if you can't trust a state you can't trust its people either.
> you are really concerned about the confidentiality of your data, don't store it unencrypted in some SaaS
I don't think dissolving the company is on the table.
So, I could say that American is sucks if I think Trump is sucks?
That is ridiculous. The first is that 'state is unauthentic' is a subjective speculation. And the most funny is that the conclusion 'people is unauthentic' is came from your first thought.
I can not say American is terrorist if Hillary wanna burn other country. Am I right?
Zing! Solid line but it misses the point. As with any other data, you can encrypt source code. It's perfectly easy to envision a setup where Gitlab employees in country X can only see plaintext Gitlab data they could already see over the public internet.
Even then, good old corruption of non-Chinese is still possible.
You can’t ignore the fact that the PRC uses those things as leverage against people abroad in order to get information. Until that stops, what are companies and governments supposed to do? Roll over and allow espionage because we’re so tolerant?
There's a growing hysteria in the US about China, which is leading to increasing signs of discrimination and harassment of Chinese people in the US. This sort of demonization of an entire country and the politics behind it (preservation of the US as the world's dominant power by containing China) are very dangerous. The thing that makes it most disturbing is the way people across the political spectrum have bought into the idea of the Yellow Peril, and are now okay with discriminatory policies, the trade war, and challenging Chinese territorial sovereignty.
People don't care about people from the ROC, aka Taiwan, aka China*. If people in our extremely polarized political environment are uniting on this, it's because it's a Serious Issue that needs to be addressed.
Any american or european living in either country would similarly be affected by the ban. Untwist your knickers please.
You keep calling it xenophobia even after you've been proven wrong when you claimed this is targetted at green-card holders. You are absolutely disengenuous and have no intention at good-faith discussion.
I then suggest you edit out your erroneous personal attacks.
I’m wondering, can the US government legally issue a National Security Letter to an individual employee that forces them to comply and spy for them?
If they can, does this also mean the employee has no legal recourse since NSLs must be kept secret?
No, because that would be unconstitutional. But the proceedings of objecting to a NSL similarly must be kept secret. There wouldn't be any point to the secret component of a NSL if the recipient could object and hash out the merits of the request in public court records.
Most countries do it by subordinating secret agencies to a military division of sorts, wherein martial courts and security access is already structural. Others choose a more 'civilian' approach subordinated to a parallel chain of command within the citizen government/legislation/judiciary — closer to police, interior dpt / homeland security, etc. (in such cases, army intelligence is usually quite distinct from civilian surveillance).
Which approach is favored historically by a country typically depends on pre-existing constitutional models and principles — notably how the army features relatively to the ultimate civilian chain of command, and how the latter is accountable to the (sovereign) public in the event of treason.
None of this applies in authoritarian regimes where the ruling caste or figure(s) usually answer to no principle (no courts for them, only 'advisors' for they sit above the law) and secret service is almost always directly answering to them, as part of the active coercion of the people (fear of the "enemy within", etc).
I don’t have a link I can share at the moment to prove this (I’ll update this comment if I find one), but at least in the case of an employee with a security clearance, it is my understanding they can be forced to comply with a US Government order without the ability to inform anyone at their employer (including corporate legal staff). I’m not clear if this order would have to come as an NSL or via another channel.
Unfortunately, like most good things in corporate software, it didn't last.
Source: am a former RHEL customer now using Fedora
I am in the US, so can not say, "I disagree with how the Israeli government is treating Palestine and thus don't want to do business with any entity located there."?
No.
That link the parent commenter shared is a very good overview: it basically means that your company will not receive special corporate tax consideration if your company:
Enters agreements to refuse or actually refuses to do business with or in Israel or with blacklisted companies.
Enters agreements to discriminate or actually discriminates against other persons based on race, religion, sex, national origin or nationality.
Enters agreements to furnish or actually furnishes information about business relationships with or in Israel or with blacklisted companies.
Enters agreements to furnish or actually furnishes of information about the race, religion, sex, or national origin of another person.
(e.g. “hey [anti-Semitic company], this competing businessperson is a Jew, if you were wondering”)
In any of these cases, there are exceptions and matters of interpretation.
Whether or not you think this is appropriate for the government, it's not as simple as “you can't engage in a boycott as a matter of personal conscience”.
>Enters agreements to refuse or actually refuses to do business with or in Israel
The link does actually include the penalties, which are far more than just losing special tax considerations. It includes hefty fines and even imprisonment under the TRA. The "just losing tax consideration" part is only under the EAR. I understand that part.
It's the fact that they say I cannot boycott Israel independently.
I'm still confused at how this can be fully Constitutional. Say I care a lot about the Palestinians and object to their treatment by the government and military of Israel. Say I make widgets wholesale for people to resell retail.
So I say, if you buy my product and resell it you make money and your government takes some of that money, as is normal. Therefore, I will not sell to any company that sells this in Israel as I do not want to my product to be used to make money for a government whose actions I condemn. I don't care if you are a Jew, a Christian, an Arab and/or even a Palestinian, if you want to sell my product in Israel and taxes which go to the Israeli government will be collected on that, I'm not selling it to you. Not just certain companies within Israel, all of them. Anyone who sells my product and thus makes money for the Israel government, nope, I'm not doing it.
That's the part I have a problem with. If I don't actively try to stop Israel from doing anything but want to take an active role in not helping them in any way, I'm breaking the law? I don't see if how I want to act independently the Arab League but what I want to do aligns with part of what they want to do, that is a problem? I should be able to not support what I see as a bad actor.
I would note my understanding is that fines for non-compliance have historically been relatively light and therefore, to my knowledge, these regulations have not been seriously tested in court in recent times. (And the article I read suggested there was a causal link between those two facts.)
I have a hard time believing that the government could do this but the way I read it says that if I said:
As a business, I disagree with the human rights violations the government of China is engaged in. I am again Saudis Arabia's ban of alcohol on its residents, its treatment of gay people--including death for simply being gay and the way it withholds rights from women. I also deplore Israel's treatment of the Palestinians, including the demolishing of houses.
Therefore, I will not allow my product to be sold in a way which results in any of these governments collecting tax on it, this supporting the government.
The way this reads, it seems the government can say, "Whoa, you can't to that to Israel though." and ignore the other two. Unfair and prejudicial in my opinion.
> forbidden from … Agreements to discriminate or actual discrimination against other persons based on race, religion, sex, national origin or nationality.
So, to be clear - GitLab can merrily discriminate against Chinese citizens of the US on national origin by themselves, but are breaking the law if they do the same under a joint venture with a non-US entity.
Bonkers.
Disgraceful. GitLab was once an inspiration to me in terms of its openness & culture, but the recent moves around tracking and now this, make it clear that GitLab has been around for too long to stay a hero.
Nice bigotry in a post complaining about bigotry.
Maybe I could have worded it better, but I am referring to American culture and the mindset that when you think 'anti-hero', it's going to be a Russian/Chinese most of the time.
One of the hardest parts of most white collar prosecutions is proving that an action was taken "knowingly and willfully". Unlike other areas of criminal law, most white collar offenses require prosecutors to prove that not only did the person know they were doing the things they were doing, they had to know they were illegal.
Having the party's own lawyer offering legal advice outside the scope of privileged communication is normally windfall enough. Having them do it publicly and in the media's eye is just insane.
It's a good question what one could prosecute out of that and what to gain. There are so many open angles and I don't think there is any precedent with a fully opened company.
One client can demand that Gitlab get rid of Chinese and Russian nationals today. Tomorrow, a different client can make similar demands - aimed at the nationals of different countries. This makes no sense whatsoever, and will blow out of control quickly.
Sanction programs are the established legal frameworks for such things: https://www.treasury.gov/resource-center/sanctions/programs/...
It's disappointing to see the promise of some money making the company go full 180 on its hiring and employment procedures - going as-far as potentially rescinding one employee's offer, and flagging another employee's personal choice to live in a different country as a risk.
The due process here is concerning. Some techbro starts by creating a "we need to block all Russian/Chinese" issue - followed by a bunch of echo-chamber "yessir" comments. When a legal advisor steps in - everyone tries to silence her and convince her it's just an "iterative process".
Finally - it actually looks like Gitlab's security practices are truly lacking. That an employee is Chinese/Russian shouldn't be a consideration - the systems should be tight enough to make sure absolutely no-one has access to customer data without consent - and that any actions taken are logged for auditing. Whenever necessary - pass your employees through a background-check. In sensitive (government) scenarios - restrict to employees with government clearance.
Honest question: Is Gitlab now a company not in a position to say "no"? Investors and potential customers need to know.
Why should the same not be true for something with a damage multiplier the size of github which is basically carrying a big chunk of commercial IP in private repos?
Why should the same not be true for something with a damage multiplier the size of github which is basically carrying a big chunk of commercial IP in private repos?"
I'm all for background checks. Those at-least try to give everyone an equal opportunity - and if you fail them, you'll know why and have a chance to challenge the decision. There is a due process - as opposed to having some random techbro creating "need to get rid of {arbitrary nationality} asap" issues and having a bunch of random employees debating it...
If by having "nationality requirements" you mean "being a US citizen" - then Gitlab will lose 50% of its workforce overnight. The same will be true for many other tech companies. You make it sound like the defense sector is enjoying the strict employment regulations...
I'm not suggesting any national correlation here. I suspect the same is true for Chinese and Russian companies too!
As for the defence sector it is not enjoying it, at least in Europe as the incoming staff into the sector are shrivelling up pretty rapidly.
It's not arbitrary banning from foreign countries on your client's request if there's actually good reasons to take precautions with these nation-states.
And why not? They're a private company they can choose to employ whomever they want as long as they're compliant to local labour laws. There's no "due proccess" in business.
"Finally - it actually looks like Gitlab's security practices are truly lacking. That an employee is Chinese/Russian shouldn't be a consideration - the systems should be tight enough to make sure absolutely no-one has access to customer data without consent - and that any actions taken are logged for auditing. Whenever necessary - pass your employees through a background-check. In sensitive (government) scenarios - restrict to employees with government clearance."
Don't improve HR security practices because you're vulnerable in different ways anyways?
If you as a company simply don't trust the government your employees work under, you cannot trust them with sensitive information, even if they're outstanding trustworthy people.
This is a question of liability. Gitlab's liability, based on whatever internal metrics being measured, would be significantly higher than the potential economic rewards of having employees in sensitive positions in these two countries--at the moment.
Also, on a side note, morality != legality. They're two different things. What is moral isn't necessarily illegal, and vice versa.
There's no need to beat up the strawman "techbro." It seems to me that this was a difficult decision to make and somebody had to make it.
Damned if you do; damned if you don't.
GitLab are considering making this change in order to satisfy the requirements of a potential customer[0] - i.e. the reward is for adding the restriction.
And in turn, making the change itself could increase liability[1] since it doesn't seem to be based on a legal request or existing defensible GitLab policy.
[0] - https://gitlab.com/gitlab-com/www-gitlab-com/issues/5555#not...
[1] - https://gitlab.com/gitlab-com/www-gitlab-com/issues/5555#not...
The thread reads like a case of the compliance arm of the business trying to keep the ship steady and non-discriminatory (which is in-line with GitLab's stated goals, the intent of the law, and likely in-line with their prospects as a long-term global employer), while a sales part of the organization tries to close a deal.
Putting in additional engineering effort to allow the customer to specify their own policy on SRE/support access to data -- which they'd be responsible for defending if there were any questions -- seems like it might be a way forward. Whether the sales team and customer would wait for that is another question.
It's remarkable and very progressive to see this discussion in the open; it's also interesting to note how many side-discussions and different opinions emerge in the comments and in discussion here, while the core communication continues between a small number of participants in the merge request.
So let's just label every employee with a Foreign/Chinese/Russian background as a spy, because a client says so?
And your comment suggests as much - why would opsec about consumer / sensitive data be important unless you expect your employees to act in less-than-fair manner (be that for personal gain, a competitor's gain, a national gain, ...)?
How come we don't see Gitlab re-considering hiring Australians then?
> "And your comment suggests as much - why would opsec about consumer / sensitive data be important unless you expect your employees to act in less-than-fair manner (be that for personal gain, a competitor's gain, a national gain, ...)?"
The defense industry will put you through background checks, demand a security clearance, and won't hire you unless you're a citizen - whilst simultaneously employing some of the strictest security measures available today. Security will stay there long after you've stopped hiring Chinese and Russian individuals.
I can't speak to GitLab specifically, but them restricting Australian hires too has been brought up numerous times in this HN thread. Given the amount of activity on here from their team members and specifically sytse, it would seem likely that they have at least been made aware.
Because no company has asked them to yet. Give it time ;)
The thing that I suspect that most people don't understand about Australia is that the laws don't really mean shit all unless the situation gets very serious very fast.
I know people who have received aa requests who have literally responded with "get fucked mate, why on earth would I do that?" and the response has (for every instance I'm aware of) been "yea, true. it was a bit of a stretch"
It's rather like the Australian constitution, I'm fairly sure I've seen a joke around about it, we have one but like... no one actually cares... if shit really hits the fan I'm sure we'll all go find a copy and figure it out, but otherwise we're doing only slightly less than alright just kinda playing it by ear...
You haven't really done OpSec have you? There is very little absolutism in defining who gets access to what data. In fact barring nations that have historically shared data with their governments is exactly one step closer to how you would achieve this.
> Investors and potential customers need to know.
Says the guy hiding behind a throwaway (new?) account...
When was the last time you've contracted for a serious client? When it comes to tech - you don't implement "OpSec" by blanket banning hiring Chinese/Russian individuals. Disregarding your bizarre definition of "OpSec" - plenty of individuals with Chinese/Russian background are working for companies such as Google/Microsoft/Facebook/Uber - making significant contributions and getting paid vast sums of money for it. Those companies actually invest into background checks, have dedicated security teams, are investing into locking networks down and improving monitoring. It appears that Gitlab simply wants the easy way out, or, they can't afford to refuse the aforementioned client's offer.
Uhh, today? I have about 20 on-going contracts with "serious clients", which include manufacturers, distributors, software companies, etc. What's your point?
> When it comes to tech - you don't implement "OpSec" by blanket banning hiring Chinese/Russian individuals. Disregarding your bizarre definition of "OpSec"
Banning hiring from countries isn't an exclusively isolated tactic for executing OpSec...I'm not sure why you implied that.
> Those companies actually invest into background checks, have dedicated security teams, are investing into locking networks down and improving monitoring.
Those companies all have physical presences in those countries. Gitlab does not. BIG DIFFERENCE.
Do you have concrete numbers that prove Chinese/Russian workers are significantly more likely to act in bad faith against the companies they work in?
To quote Gitlab's chief legal officer, @cciresi:
> "The highest risk countries for hackers are: Romania, Brazil, Taiwan, Russia, Turkey, China and the United States (The US ranks number two in hackers according to ABC news). Surely, we aren't going to start restricting employment on all these countries?"
Except for the fact that state-sponsored hacking and IP theft is a real thing. Your comment reads as naive and extremely uninformed. I would invite you to read the Huawei "Tappy" indictment [1] to understand the lengths that certain nations go to steal from US companies. Here we have a company that is literally offering cash bonuses to their employees for stealing IP.
> the systems should be tight enough to make sure absolutely no-one has access to customer data without consent
If you read the indictment, you'll realize that these rogue employees don't care about audit logging or any punishment that follows as a result of getting caught. In many cases, all they have to do is fly back to their country and they'll be rewarded and regarded as heroes for their loyalty to their country.
[1] https://www.justice.gov/opa/press-release/file/1124996/downl...
As a founder of a tech company based in China, I benefit from US companies blocking Chinese (and Russian) engineers; still I am saddened by this. I hope they could come up with more intelligent policies to protect their OPSEC.
The Chinese government is, IMO, massively over sensitive to any outside commentary or criticism, eg: https://www.abc.net.au/news/2019-10-31/china-warns-australia...
He's more likely to talk about camps in China than he is about the homeless in Los Angeles. One is a problem completely out of his control, another is one he could easily mitigate. You wonder why that is?
As a Westerner, while its important to understand about the nasty side of China is somewhat pointless to endlessly focus on it because its not a problem we have the capacity to solve.
There are issues that we can obtain Chinese buy-in on like climate-change (we all live on this planet) so we should focus on things like this where we can work together so we can forge better ties instead of focusing on what we don't like about each other. Lets not do evil-empire all over again.
Myself, I do criticise my own government, protest on the streets, and also donate money to causes that work in opposition, mostly, to the current government. I've also made business decisions that involve much less interaction with mainland Chinese businesses and customers precisely because I disagree with the mainland Chinese governments way of doing things. Maybe it's cost me some money, but I sleep better at night.
Whether some of the view points are valid in the first place (at least the second or third one) is deeply contested to Chinese. If you're just parroting Western media view points without showing at least some understanding of Chinese view points, you will likely not get any genuine answers.
But, yes, of course the point is that the poster likely isn't doing anything as they are partially funded by the Chinese government, and also are benefiting from all the aggressive actions their government is taking inside and outside of China.
More generally, what's the point of raising these accusations? When you speak to an American, do you demand that they apologize for their government's illegal invasion of Iraq (and the ensuing hundreds of thousands of deaths) or support for Sunni radicals in Syria?
As for what China is actively doing to assert these claims, I suggest you look at a map of which countries occupy which islands in the South China Sea. The PRC is not the worst offender there, by a long shot. Nobody's hands are clean in the matter.
Let's compare island occupation to island-building, island militarization and bullying tactics with vessels. Whatever combination of ways different parties are jostling over trying to de facto claim parts of the Sea, a pretty thorny root of the problem is one actor trying to claim all the marbles.
Like sailing warships or flying military aircraft next to islands that a foreign country claims as its own? US military actions is the South China Sea could be viewed as highly provocative. I can see why China would respond by putting anti-aircraft batteries on the islands.
> Self-interested motivations (TW)
Everyone's motivations are self-interested. Virtually all countries bordering the South China Sea stake wide-ranging claims.
> "We're big and we want it really bad" is not a justifiable standard of resolving resource and territory disputes.
Of course, that's not how China makes its case. It claims that the islands have belonged to China for hundreds of years, and points to various old maps, historical use by Chinese fishermen, mentions in various treaties, and so on. I don't know how strong these claims are, but I try not to get worked up about tiny uninhabited islands. I mostly hope that the situation doesn't escalate, but many sides are capable of escalation - the US, China, the Philippines, Vietnam, and others.
> a pretty thorny root of the problem is one actor trying to claim all the marbles.
Two actors "claim all the marbles" (the ROC and PRC), Vietnam and the Philippines each claim 80% of the marbles, and Malaysia claims 30% of the marbles.
My original question was why any of this is relevant. If we're going to be raising random accusations against various governments, I can think of much more serious issues than some uninhabited islands and rocks, like the illegal invasion of Iraq or the overthrow of the Libyan government.
https://www.nytimes.com/2016/07/13/world/asia/south-china-se... "... the tribunal rejected China’s argument that it enjoys historic rights over most of the South China Sea. "
> I mostly hope that the situation doesn't escalate, but many sides are capable of escalation - the US, China, the Philippines, Vietnam, and others.
Only one of those countries has been building / extending artificially reefs / islands in this area.
Xi lost face over this decision, and just said "tough, we aren't going to abide by it anyway". Hardly the actions of a reasonable government as good world citizens.
> I can think of much more serious issues than some uninhabited islands and rocks
China has deemed it very, very important to seize this area. It's pretty clear why to most people.
> US military actions is the South China Sea could be viewed as highly provocative. I can see why China would respond by putting anti-aircraft batteries on the islands.
You think it's reasonable to respond to freedom of navigation operations (also conducted by other countries than the USA) by militarising islands that aren't even theirs?
China doesn't recognize the tribunal's jurisdiction in this case, since China previously opted out of binding arbitration on territorial issues, as allowed by UNCLOS.
> Only one of those countries has been building / extending artificially reefs / islands in this area.
At the same time, the US has been conducting provocative military maneuvers in the South China Sea. These days, China and the Philippines are cooperating to some extent in the South China Sea. The US has been prodding the Philippines to take a more confrontational approach.
> China has deemed it very, very important to seize this area.
I think there are two issues. They view the sea as strategically important, and don't want to be at the mercy of the US Navy, which could shut down a lot of Chinese trade in the event of a conflict. They also don't want to lose face, and giving in to US demands that they drop China's traditional territorial claims would not go over well among the Chinese population.
> You think it's reasonable to respond to freedom of navigation operations (also conducted by other countries than the USA) by militarising islands that aren't even theirs?
"Freedom of navigation operations" is a propagandistic name given by the US Navy to very provocative military maneuvers in what China views as its territorial waters. I think it's entirely understandable that China puts defensive weaponry on islands it considers its own, in response to perceived violations of its sovereignty by a hostile military.
Those who aren't outright dissidents seem to have an exceptionalism complex where Chinese X is different so no criticism can apply - combined with Not Invented Here syndrome. From what I have heard from those through VPN tunnels they are accutely aware that they aren't anything special.
I’d also suggest there’s a difference between acceptance of bad government action, even if you don’t or can’t actively oppose it, and active defense of such action.
When people criticize China, they are almost universally criticizing the Chinese government, because of their double standards, shady practices, lack of respect for individual privacy/sovereignty, ethnic cleansing in xinjiang.
I love the Chinese people, whereas I hate the Chinese government.
In what way was the parent comment racist?
That right there is exactly the response your government would want you to have. You already 'hate the west', and now even more because of what I wrote? That seems unreasonable to me, and there was not one racist mention in my comment either.
If 'my' government (in Australia) were pulling these kind of stunts in 'my' name, damn right I would be doing something about it. In fact, I already do something about my community's shabby treatment of the First Australians (financially and lobbying wise).
I feel we, the people, have a responsibility to ourselves and other humans, irrespective of country of origin, culture or background, to resist and oppose transgressions by the governments who represent us.
- Joining/founding an underground resistance group
- Distributing anti-government propaganda
- Rising through the ranks of the party until you're influential.
- Emigrating (This won't directly influence your government. But losing skilled workers (I assume you are one) harms the economy, making a revolution more likely.
- If that is not possible, being as unproductive as you can get away with.
- Becoming friends with high-ranking officials, then influence them.
- Protesting. You can technically make sure you won't get punished by setting yourself on fire.
> And you people being racist pos because there is nothing I can do about my gov. Wtf do you want?
No one's being racist here. The entity people don't trust is the Chinese government. Governments act through the people they govern so that distrust extends to your potentially involuntary actions (but not to your character). Note that Gitlab doesn't trust employees living in China independently of their ethnicity.
Criticizing a government apparatus isn’t racist. I don’t know why every single time a westerner criticizes the PRC, they act like we hate all Chinese people.
Nobody here has a problem with Chinese people in general. Hopefully all of us can separate a nation’s people from their government... The problem is with the PRC’s government.
The link this whole discussion is about is about banning Chinese people. Not the government, not even people that work for the government, just "Chinese people in general"
This whole discussion is because of the PRC, and having ties to family members living under the PRC.
The ticket raised on gitlab is specifically about Chinese and Russian nationals, but this would also apply to Australians (they can be compelled, legally, to build backdoors upon request of the government). If I were in charge of a non-trivial company I certainly would not hire an australian national.
This same exact argument would apply for a white person from China who has family or other assets in China, and thus has leverage that can be used against them by the current totalitarian regime.
If the US government enacted a law similar to Australia where we could be compelled to build secret backdoors, then foreign companies probably wouldn't hire an American either.
This really has little to do with race, and everything to do with risk and governments. We would still be discussing a ban on hiring Chinese nationals even if China -weren't- almost completely homogeneous in race; it's basically irrelevant.
Then you should be more pissed off at your own government and screwed up system than the people who are pointing how that the system you live under is screwed up.
I'm not from China and I disagree with the action of the China's government you listed above. However I wonder why this kind of opinion (aka the Chinese should be responsible for their government) is not commonly held against the USA?
The USA had invaded countries based on false pretext, toppling legitimate governments, and supported dictators all around the world. Why then, this "the Chinese are responsible for their authoritarian government" argument was not commonly held against the citizens of the USA, who supposedly live in democracy and therefore better equipped to actually change the situation?
Why do you think it isn't?
The current Presidency has put some of these issues in sharper contrast, but the Iraq war was a total failure of the US media to do their job (IMO).
Nationalists of all stripes get very angry when you point out their nation's crimes. Poland made outright illegal to point out that there were in fact Polish collaborators in the Holocaust for instance. It is true that the country was overwhelmingly the victim and Nazis were responsible but cutting off this self reflection only looks sinister. When 'face' culture is involved it seems to be further. Numerous sister city relationships were ended unilaterally by Japan for acknowledging the "comfort women" - ironically losing far more face internationally. Add in outright totalitarianism under a dictator and criticism is seen as an outright threat.
Using that lens, this is a short-term financially-motivated attempt to change company hiring/access policy, which in turn provides justification for the anti-Western sentiment you mention.
In my opinion this is a restriction that should be the customer's responsibility to enact, if they choose to - which means that GitLab should pause and build access controls which allow the customer to configure (and ideally audit) who at GitLab has access.
What is excellent and commendable is that GitLab is able to have much of this discussion in the open; because at many other organizations, this would all have happened behind closed doors.
China has always had double standards. They make it hell for U.S companies to do business there. The only thing that has changed is that the U.S has started pushing back somewhat as of late, but things are still currently in favor of China.
When China makes draconian laws like this: https://www.chinalawblog.com/2019/09/chinas-new-cybersecurit...
Is it really a surprise that companies that care about their customer privacy would be hesitant in dealing with China? Is it inconceivable that data breaches and unauthorized access of data/systems could happen through Chinese employees? These are some of the things you have to think about.
Maybe the Chinese government should look at the year (2019) and realize that personal liberties, sovereignty and privacy are important to the "west". If China is going to disrespect our important values, than what you are seeing in this Gitlab discussion is bound to take place for companies that are sensitive about protecting their customers.
That's not evidenced by the massive presence of US companies in China. American companies do vastly more business in China than vice versa. Whenever I see these sorts of claims, I ask what specific restrictions or hurdles are being discussed.
But as to your point, some of the things that make it difficult for western countries to do business there is the great firewall, draconian privacy laws https://www.chinalawblog.com/2019/09/chinas-new-cybersecurit...
and subsidies (both monetary and policy) from the Chinese government that make it almost impossible for foreign companies to compete against domestic companies.
> China is a known currency manipulator
The accusation has always been that they're suppressing the value of their currency (in order to boost exports), which would actually mean that their nominal GDP understates rather than overstates the size of the economy. Whether these accusations are true is a different question.
> It's a third world country with vast majority of its citizens in poverty.
It's certainly not a Third World country anymore (technically, this is a misuse of the term "Third World," but I'll go with it). GDP/capita in Beijing, Shanghai and Tianjin (China's 3 largest cities) is about $20k, which puts them roughly on the same level as the Czech Republic, Greece and Estonia, and just slightly below Portugal and Taiwan. Lots of Chinese cities are richer than these three (Shenzhen is at $32k/capita, similar to South Korea). On average, Chinese GDP/capita is about $10k, similar to Mexico and Turkey. That's pretty much average for the world.
There are certainly huge differences between different regions of China (Beijing is way more developed than a random farming village in the West of China), and there's enormous inequality within every part of China, so there are a lot of poor people. However, there are also a few hundred million people living what you would recognize as middle-class lives. That's why you'll see so many Chinese tourists these days at any random tourist destination around the world - they have the money to afford those sorts of luxuries now.
> Vast majority of the people there are not doing well and it's not a prosperous country.
Most Chinese people would agree with you that China is not yet "prosperous." Even the Chinese government officially agrees with you on that. They are doing vastly better than they used to, though, and the country as a whole is no longer poor. It's about average for the world now, but with a high growth rate and some highly developed regions in the East. Whether they make the final push into developed-country status remains to be seen.
You keep saying this sort of thing, but yet, all sorts of foreign companies do booming business in China. The likes of Starbucks, KFC, Volkswagen, Intel, Boeing and Airbus absolutely dominate their respective markets in China. For a long time, Apple was crushing it in China (until Chinese consumers decided the quality/price ratio was too low).
> But as to your point, some of the things that make it difficult for western countries to do business there is the great firewall, draconian privacy laws
The privacy laws you're citing were only just passed about a month ago. They can't have been a hindrance before. The Great Firewall affects every business in China, both foreign and Chinese.
> Just because there are U.S companies in China
It's not just that there are a few US businesses here or there in China. Foreign businesses have an enormous presence in China. It's the most important single market in the world for a very large number of American and European businesses. If that's what business "hell" looks like, I can only imagine how great heaven is.
> The U.S is a much bigger economy than China and that's one of the reasons why you see penetration from U.S companies in China.
It depends on how you measure the size of an economy. In purchasing power parity units, the Chinese economy is larger than the American economy. Going by the exchange rate, it's smaller. The question of which economy is larger is actually ill-defined.
However, the reason why there's greater penetration of American companies in China than vice versa is that the US economy is more developed. There are simply many more leading companies in many sectors in the US. In the late 1970s, China began courting foreign investment, which meant courting foreign companies. Far from making life "hell" for those companies, the Chinese government tried to give them attractive conditions. Many foreign companies invested large sums in China, and made enormous profits out of those investments.
Now, for the first time, Western companies are facing peer competitors from within China, and you suddenly hear cries of how China is taking advantage of everyone. The crazy thing is how all perspective is lost. The massive presence of foreign companies in the Chinese market and the massive exploitation of cheap Chinese labor by foreign corporations are forgotten, and all we hear about are how it's supposedly impossible to do business in China.
If you are ever in China, go into a grocery store and look at the aisles. The main reason why American products are priced at 200%-300% the competition is because of tariffs. Tariffs designed to make ordinary middle class American products only affordable by rich elites. It's a very effective cap on market share.
1. https://data.worldbank.org/indicator/TM.TAX.MRCH.WM.AR.ZS?lo...
This particular case is likely because the usage of deodorant is not a thing in China. The majority of East Asia doesn't have the body odor issue. It's a gene thing.
I think that Snowden showed us that this is not actually true. Things like National Security letters and the PATRIOT act make the US to me, as a European, seem very hypocritical right now.
The patriot act was passed after 9/11 where the people were hurt and scared. There is backlast against the Patriot act too. Besides PRISM was a highly classified program because the people wouldn't be okay with that type of surveillance here in the U.S where the expectation of privacy isn't even a thing in China.
They are two totally different worlds.
You can't deny the hypocrisy here. While our citizens might support him they don't to the extent that they can pressure governments enough to allow him to return home.
First, they've had neighbor surveilling (snitching on) neighbor to control the people since Mao: it's part of the culture and fully accepted because they can't envision another way. They have a saying [ref needed] "Such a people deserve such a government." Now of course the whole tech stack supports it. We're just getting used to ubiquitous domestic surveillance in the West.
Second, because they've further along, they've used their control of information to abuse their power. Tibet, Tiananmen, organ harvesting, and more lately the Uighur atrocities against people of dissent or race. The West is not there but you can see we're blasting down that road now.
These are not even remotely comparable. China is an outright police state. Not saying the United States doesn't have a lot of work to do with regards to personal liberty, but the Government here has nothing close to the iron grip control that the CCP has; they may want it, and what Government doesn't, but they don't have it and a ton of our internal legal mechanisms are designed specifically to prevent it.
We should be able to discuss America's governance failures and problem areas without conflating them with horribly regressive models of governance.
Search "false equivalence". Use Baidu. Or Yandex.
Or since the Boxer Rebellion.
Or since before the Opium Wars. And probably even much earlier.
I ask because my experience across the Western net has been seeing lots of debate. This thread is a good example. I only see Chinese netizens appear in huge angry voting brigades, spamming threads with proclamations, denunciations and flimsy claims.
So I genuinely wonder; does vibrant and open debate take place somewhere? How/where could I see what such debates look like?
You will never see it anywhere on the internet, because from the very beginning your decision has been made. Anything you read will be morphed according to your belief. Anyone pro China on this site is immediately either labeled as brainwashed retards or paid shill. That's why there are no discussions, it's just your echo chamber.
Here we go. "CCP is bad and China is bad, so every Chinese is bad". This kind of logic is not very healthy, it just like saying "Google(Or insert any company here) is bad, let's punish their employees", it will hurt those employees (way) more than it hurt Google.
Put the story into context, if Chinese engineers cannot find a job oversea, they will probably go back to China and contribute to a Chinese company that operate under CCP's rule. Will that be a good thing for you eventually?
I bet CCP is also counting on the rising nationalism in the US as well, to drive Chinese engineers back home with their valuable knowledge.
OP even mentioned that moves restricting hiring in China from US will help their Chinese based company.
> CCP is bad and China is bad, so every Chinese is bad
This is a very unfair summarization of the parent comment. They never implied that conclusion. Yes, the CCP is bad; And they control China and the Chinese people. But that does not say anything about the people themselves other then they are subject to the communist rules. It is a resistance to the CCP privacy practices that brings this change.
Whataboutism?
Do you believe this move is a double standard? If America and the E.U. mirrored Chinese rules and practices for corporate governance, foreign investment, and political involvement in private enterprise, how would that look?
Because short of some effective alternatives, the Chinese government isn't really giving the West much of a choice here.
It's easy to pay attention to difference between people and culture, as noticing difference is what we instinctively do, but it is also beneficial to notice our similarities too. We're all people. Besides minor cultural differences, we all respond in similar ways to the situations we are given throughout life.
>As a founder of a tech company based in China, I benefit from US companies blocking Chinese (and Russian) engineers; still I am saddened by this. I hope they could come up with more intelligent policies to protect their OPSEC.
btw, is it legal to read HN in China?
I don't expect Chinese natives to understand the full story because they aren't exposed to all the wrongdoings of their government and even if they are, they think it's justified because they selfishly believe in supremacy of their own race/country. Even your comment suggests that you have been led to believe US is the "bully". I have heard all the arguments from the Chinese about 100 years of humiliation, Opium wars, and how US did X, Y, and Z "bad things" without ever pausing and stepping out of their own shoes to look at their actions in an unbiased way or learning the truth of the facts. I guess you can't have a meaningful argument when your only sources are your government textbooks and fire-walled internet. Think about that.
https://gitlab.com/gitlab-com/www-gitlab-com/issues/5555#not...
They have a customer that required the personal data they'll give to Gitlab not be handled by people living in Russia and China. Could be a group doing humanitarian or journalistic work.
That's actually an interesting conundrum: you want to hire a company, need to trust it for handling sensitive material, and can't afford it to fall between specific states' hands.
I don't think there is an objective process to do that. I know that USA and France and probably many other countries have laws to authorize seizure of data they consider linked to a variety of vaguely labeled activities (from "trouble to public order" to "terrorism"). You may end up excluding 80% of the world if you use objective criterion there.
https://www.tabletmag.com/jewish-arts-and-culture/culture-ne...
Search for "You were directly involved in the drafting of the original FISA law in 1978."
And this isn't discriminating on nationality or national origin, it is on the nation you currently live in. Employers decide not to hire employees living in other countries all the time, it's the most prevalent choice (i.e. US companies only hiring employees living in the US). I don't see why doing this because a customer you've considered critical has asked for it is any more legally risky that having done it for other reasons, assuming we discount the anti-boycott argument.
This is all with the huge caveat of I'm not a lawyer, just giving my perspective based on how I've seen these laws/regulations applied in the past.
Thing is, even if it is just country of residence, it is still a discrimination on hiring and could very well be illegal unless there are strong legal reasons. E.g. "we have to do things that are illegal under the laws in country X, so we can't hire people there".
I think the main point of her position is that one should have an objective criterion to add countries into a blacklist and that none can realistically been done over privacy issues that would include China and Russia but not USA.
No government would make it illegal for a company to choose not to do business in a non-ally foreign country. Millions of business already don't engage in many foreign countries, by default. Including yours, I bet. Why should they be required to do so?
They speak about revenue, so I'm sure that's not the case. I bet it's a commercial company with sensitive data, probably gov/mil contractor with strict obligations to their customer.
And someone at their management doesn't understand Intelligence 101: they don't reach for your data from the country of origin.
I doubt a mil contractor would add Russia and China but not embargoed places like Iran.
And yes, I think this is a misguided attempt at security. Companies that handled crucial data that need to stay private really should spend the resources on managing these data themselves.
> As such we feel a country block is the most humane solution at this time--especially because it affects zero current employees
<BOLD>See self-reply below, not the case.</BOLD>
Though that is alluded to as a possibility, with complications.
________________________________
Update: My first read was incorrect.
That would seem to apply to current employees in Russia / China who are in roles covered by the block.
Which is kind of A Big Deal.
X: "Current team members"
A: "moving to these countries"
B: "remaining in a role that prohibits it"
X are prevented from BOTH A AND B.
(X may do neither A NOR B)
Or:
X are prevented from (A AND B).
Whether or not remaining in one of these countries and MOVING to a role that prohibits it is included in the prohibition is unclear.
Someone's future transfer may hinge on that.
I've danced this dance at a previous company when we had an employee working from a country of interest for an extended period of time. They were air-gapped from our systems and it worked because they submitted everything by pull requests (the original way, sending git patches by email). They didn't have access to our CRM or any customer systems because several of our contracts - not just with governments but also major multinationals - prevented employees in certain countries from having access.
Even when I traveled to the same country I used a burner laptop that was decommissioned when I returned. When we EOL'd laptops in the office they'd go in the burner pile to have one last holiday abroad before they were wiped again and sent to a local charity.
So, someone in, say, QA or documentation, looking to head into SRE or Support, would be unable to if they presently reside in China or Russia.
Meanwhile, if the government can just arrest you and say "change this repository and you go free", it's essentially free.
Security isn’t absolute, it’s layered. The harder you make it for the adversary, the more it costs the adversary (eg: potentially burning a zero day), and the more chance there is of detection.
Can Russian intelligence get into Gitlab? Probably. Are measures that make it more expensive liable to deter them? I think so.
Two points here. First of all, failing to acheive absolute security is not a justification for ignoring best practices.
Second, this isn't air gapping. It is preventing a bugged laptop from sitting in on conference calls and meetings for the next year or two until it gets aged out.
Their employment being dependent on them residing within specific locales is not the same as "prevention". It's an incentive scheme, afaik.
Please note that we're still discussing this change. We work out in the open so you can see us working on it. I hope that people appreciate the difference between that and what you would see in a non-transparent company (probably nothing, they would just not open up a vacancy in the offices in that country).
Additionally would this extend to individuals who are of Chinese or Russian origin? China in particular leans on nationals who are on visas or have family still in country to conduct espionage operations.
Discriminating on origin is likely illegal.
It sounds like you just need to harden your production perimeter. Jump boxes with two-man-rule access and terminal logging. Apply the same practices to data as you do code.
> Discriminating on origin is likely illegal.
You should ask your legal folks about the national security exceptions of Title VII. It sounds like your customer requirements are pushing you in that direction anyway.
The irony...
It could affect present employees who are in other roles, located in China or Russia, from moving to a covered role, whilst continuing to reside in China or Russia.
Edit: I've provisionally gone with "Gitlab blocks hiring SREs and Support Engineers in China and Russia". If that's wrong, or if anyone can suggest a more accurate and neutral title, we can change it again.
Maybe substitute "not" for "blocking" as well since that seems clearer.
https://www.zdnet.com/article/whats-actually-in-australias-e...
After having this discussion with my manager and colleagues (the conversation with my manager was in my interview process where I bluntly stated if I was asked to comply with anything from this law, I'd immediately resign, my manager also agreed). Everyone I've spoken to agreed we'd immediately resign since it was the only potential option to protect our selves as employees and our employers.
Edit: I'll need to spend a little more time looking into the Assistance and Access Laws. The following article attempts to downplay some of these concerns:
https://www.homeaffairs.gov.au/about-us/our-portfolios/natio...
You are assuming that is actually an option. There is nothing to suggest the current Australian government would not prevent you from resigning until the task had been completed. This is the same government currently attempting to make it illegal to boycott businesses that are damaging to the environment.
Also, the proposed anti-boycott rules have been widely criticized as unconstitutional, unworkable and ludicrously against the conservatives free speech pronouncements. Unlikely they would get support from Senate cross bench.
That's the good(ish) news - the bad is that restraints on the passing of bad law are generally pretty weak in the absence of a hostile Senate. This is particularly true with the current feeble opposition, and even more so given the general atmosphere of cowering obeisance that the major parties have allowed (or encouraged) to develop around any legislation involving the word 'security'.
The problem is not really that you couldn't resign -- it is that the company would hire replacements that would get the job done. The company executive would be compelled to.
Albanese (and his forgettable deputy Marles) have so far been a disaster for the ALP.
There needs to be a more effective response than Hari Kiri.
Sure, it would be, especially for companies located in neutral countries, but since US influence is so strong everywhere almost all over the world that's also practically impossible. "Every animal is equal but some animals are more equal than others"
https://www.bmwi.de/Navigation/EN/Home/home.html https://www.bmwi.de/Redaktion/DE/Publikationen/Digitale-Welt...
China and Russia obviously have their own systems, but many other countries some some element of national control which is less obvious. Japan certainly has a mature native cloud capability, although it would be highly disruptive to move everything to it.
Its like plans to be 'cloud agile', it doesn't work unless you deploy to both every time, and you probably just double your cost and bugs for deployment ops. So the tendency will be towards cloud balkanization. Which could really suck, or it could force a path away from proprietary APIs towards standards, which will suck in a different way.
I think it's just the usual "Australians not realizing they live in a bubble", and kindly warning the rest of the world about laws or practices that have already been in place in our countries for twenty years.
(2) In English, both hari kari and hara kiri are accepted spellings (the word came into English before modern, maybe even standardized, transliteration, and the source language doesn't natively use the Latin alphabet.)
(3) But, in any case, you are right that it is misspelled.
I'm also an Australian living overseas, have worked on many sensitive projects that would be of interest to the Australian government and its masters, and I'm quite prepared to give up my nationality over this issue.
Australians will never be afforded an opportunity to overthrow their government, nor will we get the revolutions our demonstrations hope for.
In the case of Chinese-based employees the assumption is that anything they did would go through Chinese Government controlled networks (there's VPN ban even for foreign businesses) and likely result in your intellectual property being shared with your Chinese-based competitors. Not to mention their access being potentially compromised and used.
If an Australian-based employee complied with a letter, they could destroy your business reputation when it got out, even if you threw them under the bus. Probably the main reason Australian employees are still given latitude is that committing compromised code into the codebase would require involving everyone who could possibly see that code change.
> In e-group on Monday October 15, 2019 we took the decision to enable a "job family country-of-residence block" for team members who have access to customer data.
I don't think there's a need to explain what's wrong with this idea, there are a lot of sane comments on this thread explaining this just okay.
On a side note, I really like how company transparency saves them from making wrong decisions final. I think that this initiative will be dropped just like the recent third-party tracking issue, and I wish more companies were as transparent as this one.
This is partially the goal of such moves and will accelerate the rise of discrimination. Thus, one should not quit despite the situation.
edit: what bothers me is that at least by some senior staff members these employees are already considered second-class citizens as otherwise this initiative wouldn't even be discussed, and I wonder how comfortable it will be to continue working with these people now.
There are employment laws which prevent companies from discriminating against people based on factors such as race, sexual orientation, religion, physical appearance, age, marital status, and other things over which they either have no control or which are not relevant to their job. These laws are in place for good reason and most people (myself included) support them.
It is my belief that a company policy prohibiting the hiring of people based on any of the above attributes would be wrong, and probably illegal (depending on the jurisdiction).
The question then comes down to whether refusing to hire someone based on either their nationality or the country in which they live (in the case of a remote company) is wrong in the same sense as the above factors. My argument is yes. The fact that someone lives in China or Russia does not, by itself, make them an untrustworthy person, any more than someone living in the United States, Germany, Japan, or the UK.
At the request of several customers, GitLab is proposing a policy which discriminates against people based on their naionality/country of residence, which I would argue is almost (if not equally) as bad as discrimination based on the other factors I've mentioned, and should be opposed for the same reasons as a policy which prohibited hires who were of a particular race or sexual orientation.
If anyone wants to flag this comment, you are of course free to do so. But I would much prefer, and I think we could all benefit from, a coherent discussion of the flaws in my argument.
There's no reason to believe it's different in any other countries, in particular countries that have a an obvious confrontational stance against "the west" and are at least semi authoritarian.
So a person maybe a "nice/trustworthy person" but because of such laws, working with a person from a country equal granting access to your internal infos to the whole country this person is a citizen of.
Furthermore, the whole point of anti-discrimination laws are to prevent judgement based off traits that cannot be changed. Where you live is not the same thing as your skin color. Imagine if someone refused to change their password and only used 6 characters for it. It’s a security protocol to force a change there. I’m viewing thing more similar to that than similar to racial discrimination, given that gitlab is not saying they won’t hire Russians widely.
This is very true. People are getting very caught up on discrimination without taking into account all of the "acceptable" forms that happen all the time. If you're a violent felon, you are likely going to be discriminated against when looking for a job in child-care. Yeah, this is an extreme example, but it's a form of job discrimination most people see as reasonable. Like-wise, people are discriminated against all the time in jobs for things like lack of qualification or lack of relevant degrees, etc., and again most see this kind of discrimination as reasonable. The kinds of discrimination that aren't reasonable are things like no hiring somebody because of their race because there isn't any reasonable connection between that fact and their ability to do job.
The question here isn't whether it is discrimination to not hire those who live in Russia or China, the question is if the underlying premise that those people are more of a data liability than other people. I haven't read the entire thread, but so far I haven't really seen much discussion on this point, just lots of people saying the policy is outright racist (even though I believe the policy only affects people who currently live in those countries regardless of race rather than not hiring people of Chinese/Russian descent who live elsewhere).
It has nothing to do with "untrustworthy" and everything to do with "will be coerced without anyone even breaking the law".
I don't know if that will change your mind, but it's an important difference, it's not a judgement of the people but of the state they are living in.
This came up because of a client request.
Your question about whether people from other countries can be considered trustworthy is completely irrelevant.
The fact is, organizations exist that are at polar odds with governments that exist today. It is not unreasonable to, for example, have a 'Uyghur Oppression Awareness Group' require that all of their data be handled by NOT-CHINA. It has nothing to do with Chinese people, or their ethnicity. It has to do with the fact that if an employee is able to access their data, and the government has an incentive to take that data, the government can easily force that person to hand over that data.
This exists in many countries, Russia, China, USA, Australia, UK, the list is very long.
Your argument is flawed because you're arguing the wrong point. The trustworthiness of an individual is not relevant in any capacity.
The threat model isn't "Russian developer who wants to support their family." The threat model is "Russian government." I agree with and support the laws prohibiting discrimination against people for race, religion, etc., but I don't think this is related to any of the criteria you cited. As far as I can tell, GitLab is enthusiastic about promoting diversity [0]. It's based on country of residence; Americans living in Russia would be blocked and Russians living in America would not. Frankly, I think they should consider putting Australia on the list too [1].
It's not an issue of discrimination based on race, sexual orientation, religion, physical appearance, age, marital status, or ethnicity.
[0] https://about.gitlab.com/company/culture/inclusion/ [1] https://www.bbc.com/news/world-australia-46463029
It isn’t even as simple as worrying that foreign national employees can be coerced by their home nation police or state security services — anyone subject to policies like Gitlab’s who is local to your business but who has family or assets abroad that can be used to effect duress, or who can be blackmailed in some way elsewhere, would need to be vetted.
Australian law is likely to have little impact on what an SRE or support engineer might be able to do. Australia having an established practice of recruiting and placing enterprise surveillance moles would.
China and Russia have some history with this latter. Though one might say similarly of the US and Israel, as two examples.
To my eye, american companies are becoming more and more like chinese companies in the amount of control governments can extort on them and that is highly troublesome.
Or, What about if one of their employees is married (or wants to get married) to a legal resident of one of these countries? How far removed does the employee have to be from this risk? And how much of an impact on their (and their family's) civil liberties could this have?
I imagine Gitlab would have a similar but less restrictive policy, "don't bring a work laptop <with credentials that gives you access to one of these roles> to China, ...".
I don't see why a policy against residing/working in China would care about who you are married to or where they live.
Until Su's ageing parents back home succumb to ill health and she decides that the family need to move back to China to care for them for maybe one or two years - perhaps longer.
Bob then has to make the choice between (a) resigning his job or (b) being forced into a long distance relationship with lots of travel between China and the US, or (c) divorcing his wife.
When company policy gets in the way of important life decisions, I think it is a dangerous line to walk.
If Bob wants to move to China, where the company doesn't have an office, he's going to have to resign or take a leave of absence.
This decision on Gitlab's part would be moving their incredibly generous "you can work from anywhere you want except places where we legally can't let you like Crimea and Iran" to a nearly as generous "you can work from anywhere you want except places where we legally can't let you like Crimea and Iran, and places that are known to coerce people into spying for them like China and Russia".
Most companies operate on a whitelist of places where you can work (where they have offices), not a blacklist. Even many remote companies operate on a whitelist (e.g. "Remote, US only"). Really, I'm amazed they feel that they can operate on a black list approach at all and not accidentally violate tons of local laws.
MSFT just recently won a 10B cloud deal from the DoD, perhaps the purse is still open there?
Going from a whitelist to a blacklist is hard because you need to either individually vet every country and decide if they're ok, or you need to just assume a lot of countries are ok.
Going from a blacklist to a whitelist is obviously trivial.
Whitelist with 3 countries: I have vetted three countries, and know my employees can operate in those countries legally without issues.
Blacklist with 3 countries: I either need to vet 247 countries to ensure my employees can operate there legally, or I am just assuming that those 247 countries are fine without actually doing the due diligence.
Again, going from a blacklist of 3 countries to a whitelist of 247 countries is obviously not an issue. You're operating on the same data. The issue is going from a whitelist of say 3 countries and then not going to a reciprocal blacklist of 247 countries, but a much smaller blacklist of 3. This is what Gitlab has effectively done in OC's estimation. That either means you vetted those 244 extra countries that are now on your "whitelist", or you're making a lot of assumptions.
You forgot D that gitlab is actively discussing which is a role change while staying with the company.
Do one or the other, please. Otherwise you're not doing either very well.
Security clearance background checks will cover this sort of thing. For sensitive government contract work, clearances are generally required for the relevant contractor employees.
For non-government customers who still have these concerns, I’m not sure there’s a good answer. I guess you could define your own clearance process and run similar background checks - many of the government’s own background checks are done by private investigators already.
Second this
According to customer requests that their sensitive information not be placed in a situation where it could be relatively easily accessed by state actors ... serves the customers interest.
That’s not contradictory, except in the most superficial sense of “but we have open arms for everyone”.
> There is an unacceptably high risk that these nations may apply pressure to individuals living within their borders with sensitive data access (based their role at GitLab). It is our concern. And it is the stated concerns of several customers.
The discussion is actually pretty significant, as they sort out how they might manage the _customer demand_ that is creating these hiring blocks, and in turn, how that is reported and tracked.
I don't see this as a purely "done deal", it's a company having very important discussions in the open that most would just default to "restricted". All this transparency is a great source for others to learn from.
Going a bit deeper, it seems to be a specific demand by a potential client. Can make sense for activists, journalists, humanitarians. Makes sense for gitlab to push back too though.
https://www.chinalawblog.com/2019/09/chinas-new-cybersecurit...
Whether it's real or not or even likely to be effective, there's a chilling effect and businesses are obviously concerned to be raising the issue of Chinese-based employees with GitLab.
Every US company must hand over any customer data held anywhere, by any subsidiary or joint venture, on earth at the request of the US government.
I wonder how the HN crowd feels about that? There was a lot of talk recently about how companies should not sacrifice their values and kowtow to the demands of large clients.
As a company that values freedom of movement and is remote first, this prevents their employees from moving to where they want. Does this also mean they can’t vacation there either?
No, the post is fairly explicit about what the proposed block is.
While I agree with the position that companies should avoid trading ethics for short-term profit, this is a move I hesitate to condemn - the cost is fairly minimal (their remote-first position is still quite generous), and there is much to be said for the increase in privacy and security this provides their customers.
Am I the only one who thinks that both China and Russia have spies who are not native Chinese or Russians? And are people really naive to believe that a stupid decision like this would prevent China or Russia from trying to obtain the information they need (if they really want it)
> @cciresi I appreciate your position. Please be aware there is an active, time-sensitive contract negotiation linked to this matter. And you need to advocate to the DRI that the company walk away from that contract in order to enact your proposal.
https://gitlab.com/gitlab-com/www-gitlab-com/issues/5555#not...
Well now, that's interesting.
> @cciresi this is a request from a customer considering using GitLab.com. @mmcb has more context on the why. We should probably add that to the MR.
Probably the US government or something like that?
It's a bit of a chicken/egg situation - is there a strong culture of compliance because of the transparency or does the strong culture of compliance make transparency a non-issue? Whatever their secret sauce I think Wall Street could use some.
For instance - it's been suggested (I don't know if rightly or wrongly) that they have a customer who asked them to do something that would violate the US boycott laws. I'll assume that it is the case that they've been asked to violate these laws.
According to a plain reading of a document someone linked here [0] that means they are required to report the request to the US government. I'll assume that it is the case that they are required to report it too, even though I'm not a lawyer, and that's not really an authoritative source.
> The EAR requires U.S. persons to report quarterly requests they have received to take certain actions to comply with, further, or support an unsanctioned foreign boycott.
If they don't (because they forgot, because they disagree with that interpretation of the law, because they don't want to piss off the customer, etc) they now have a public facing record of them violating the law. Even if the assumptions are wrong (they likely are) and they aren't violating the law, someone might decide they are and it might result in lengthy/costly legal battles.
How many other examples like this probably live in that repo for anyone to see?
The requirement to block some class of people off from some customers is nothing new, and back at Sun there was separate Sun Federal which was dedicated for such clean business.
GitLab's approach (and i think it is just a start of the trend in the industry, time to get rid of the accent :) while theatrically good isn't practically efficient. A Chinese or Russian residing here with some family back at the Motherland is susceptible to the same pressure in the loving, yet firm hands of the Motherland as if s/he were residing there her-/himself. So the next absolutely logical and necessary step for GitLab on this path is to block all Russians and Chinese who has at least some family back there. Giving that there may be other ties too and the hassle to verify (to which degree of relationship?), simply blocking all those nationals would the natural and practically efficient way.
Extortion can be effective well outside family lines.
And, of course, extortion is equally effective on USians, Brits, Indians, Nigerians, or anybody else.
Same here. I was pretty surprised they sent an apologise email few days ago
Saying sorry after actions you made, show how they care about their users
You gotta lower your ideals of freedom if you wanna suck on the warm teat of China. (c)
I commend the transparency of debating it in the open, but I suspect it'll get hard to maintain reasonable discourse once the issue hits mainstream headlines and becomes sensationalized.
The suggestion does feel like a giant cudgel. I get there are genuine concerns, and I don't have better ideas to offer. I can't help feeling bad for legitimate future job applicants who will feel discriminated against. I'm sure if a bad actor wants to do something adversarial, they'll find ways around it (like agents in a non-banned country).
It used to feel like attitudes of major world powers were slowly converging (Russia got some democrazy, China started to open up its economy, tolerance seemed to be growing). Now it scares me how fast they're diverging. Politics is seeping deeper into tech, and it's going to get more fervent. Curtailing trade is loosening the ties between disparate cultures (https://www.cato.org/publications/commentary/peace-earth-fre...).
The internet was supposed to connect us all and help bring us closer together. What happened?
I am not saying it would be simple to iron out, but it would allow for distrusting customers to all play together without worrying about data compromise.
Just a thought, i read all the comments and they are about politics and such and very few are about a technical solution to work for all.
One can argue only letting a Chinese Administrator work on a subset is again a geopolitical thing, but that point should be moot if other administrators are restricted as well.
But off topic, I’m wondering how many companies have similar policies that nobody knows just because they don’t have “open-source” policy.
Sadly recruitment process is polluted with many hidden policies and while we appreciate and expect honesty and transparency from applicants, the recruiters themselves aren’t anything close to honest and transparent.
Namely, how to maintain your overall organization and software-stack while internally isolating data-flows and rules which are unique to different jurisdictions.
Even if today it's some potential client expressing general concern, tomorrow it might be something you can't simply ignore, like an EU privacy law that must be complied with to avoid dropping a bunch of customers. (Or a demand by Elbonian officials for an account that lets their secret police snoop on Elbonian business, but hopefully that one would be resisted.)
https://gitlab.com/gitlab-org/gitlab-runner/issues/4119 (Gitlab CI/CD jobs finishing midway with Success)
Have you ever thought that Russian government consists of Russian people? Same with Chinese
It’s hilarious and depressing to see people using their freedom of speech to defend China, a place that suppresses any and all criticism in absurdly draconian ways.
As a Chinese I'm actually very disappointed at Gitlab. I think anyone wouldn't be happy if one's country is banned from the company. And I also think some people just worry too much about people in China. Actually, ordinary people in China are not so oppressed by the government. And ordinary developers from China is just as ones in America. Few of them will steal data from the company.
Which clause of which act, or which executive order specifically prevent Gitlab from recruiting non-enemy state person?
Everyone get what they want, in long term?
Tomorrow they will ask GitLab to inject backdoors and GitLab will implement that as well?
It is probably happening in other US tech companies at this time affecting those who want to get lucrative DoD and government contracts.
"Gitlab considers" is the new "British scientist" news headline.
/sarcasm (just in case)
Then they came for the Chinese, and I did not speak out— Because I was not a Chinese.
...
I am working at a European company where the amount of Russian engineers is constantly increasing (similar thing happens in many of the bigger companies nearby). And they prove to be quite ok.
So since today I will speak strongly against use of Gitlab in my workplace should such a talk begin.
What would you do in this case?
Their motivation, should they apply it to UK, US, Spain and France, should lead them to forbid having employees from those countries as well.
As a Swede, I would not like my gitlab sensitive data to be in the hands of US gov.
If you really believe national security agencies do not apply pressure to any tech employees just because they are X citizens of their X country - you need to mature a little bit more, perhaps read Snowdens book and look into what happened with Wikileaks.
This way you may end up justifying terrorist attacks against American citizens coming as a retribution for the foreign policy and military adventures of the democratically elected American government.
But not hiring devs that are maybe trying to get away from those places? As a dev and an immigrant myself I could not just stay silent about that.
I am european and I think you're being pretty stupid. You celebrate that the company you work for hire people in Russia rather from where you live. You seem to fail to realize that if all companies in your country would do that you would soon find yourself out of a job since there is always some place cheaper.
No one is saying russians aren't knowledgeable or good at what they do. Maybe you should read what they actually write instead of simply projecting your straw man ideas onto them.
For one thing, such isolation of Russian internet would have negative economic effect and it's the last thing Putin needs.
They are afraid that the governments of China and Russia could easily force people who live in those countries to give up data. That is a valid concern since that is happening in China.
I know how it affects the economic. Just look at where stuff is produced. It's hard to find things that are produced in Europe or the states. You may say that this is a good thing but I disagree, the same thing could easily happen with software and that would be a dark day in my opinion.
I don't care if that would make me "poorer" in the sense that I can have less material goods. It would still be a better world in my view and better for the environment. I rather pay more for something produced in the EU than to have something shipped from China just to save a few bucks.
> I rather pay more for something produced in the EU than to have something shipped from China just to save a few bucks.
Protectionism works quite contrary, so you do not support it anyway :)
This is happening even WITH protectionism like customs and tolls. Chinas government subsidize stuff like steel production which makes it hard for companies like SSAB in Sweden to compete with them since they sell their steel cheaper than the cost to produce it.
How shall countries protect themselves from countries that act like that without protecting their market? It's extremely naive to think that countries that are rough dictatorships will play fair and nice.
EU should have A LOT higher customs against countries like China. Trading with them on a fair level gives them too much economic control which is good for us in the short term but incredibly bad in the long term.
That is why south park can make an episode like "Band in China" today because we have already given them a lot of control.
In order to effectively support customers, you need to make a decision into how much visibility you'll give customers. Alternatively, you give your support the even more unfortunate circumstance of needing to request sensitive data.
SREs need to be able to work with hardware and software and by virtue of needing to take decisive action are in a similar situation.
kinda crazy, how different audiences get very different reactions.
Imagine if governments worked like this? Holy hell. This is what Assange should have aimed for instead of getting involved in geopolitical intrigue.
The National Intelligence Law of China, passed in 2017, demands that all its citizens "support, assist and comply with works on national intelligence", aka proactively collect intelligence for the regime. (Article 7)
(《国家情报法》第七条 任何组织和公民都应当依法支持、协助和配合国家情报工作,保守所知悉的国家情报工作秘密。 )
This also explains why Huawei devices SHALL be excluded from core communication networks of the free world.
Additionly, unless Jingping 11th go off from his power, the nation should simply be considered another Soviet Union, or even worse, the Nazi.
This is why I refused to obtain a DoD security clearance when my job needed me to: I go to Russia to visit my family every 2-3 years, and I don't want to be in any way valuable to their intelligence services or the like, nor do I want to put myself or my family in danger.
All of the above is in spite of me having spent most of my life in the US by now.
IMO a better solution is for nobody to have permanent access, and granting it on as-needed basis, with a full audit trail. It's not perfect, but it's a heck of a lot better than the ineffectual geography-based blocking that you are implementing.
I assume Gitlab lacks the sophistication to do this split of user data access vs other business operations.
Gitlab runs an open source company, so I don't understand why they are so concerned about China and Russia. Is it for anonymous/confidential customers?
Given the current australian law changes, the rampant israelian IT spy sector and despotic Belarus position on human rights, it's surprising that they only mention China and Russia. This whole debacle doesn't look good and makes one to loose all faith in Gitlab.
China and Russia are known to put pressure or watch/listen on nationals who work in key positions in foreign companies.
As US allys Australia, Israel don't pose the same threat. A lot of information that could be gained would be available through the US government and shared with the those parties if there was a need.
https://en.m.wikipedia.org/wiki/Jonathan_Pollard
https://www.google.com/amp/s/amp.theguardian.com/world/2019/...
There are definitely Chinese and Russian spies but there are spies from many countries besides those. The question is why are you singling out those countries and why now.
The reason is that there is a Cold War brewing between the US and China and this company has become an agent of that war.
The seems to be a propaganda war against China brewing in the US. I last saw this level of jingoism when Bush Jr decided to take over Iraq on the pretense of Saddam Hussein supposedly having nuclear weapons. All the TV network anchors were pushing for war and pushing the supposed threat. Later we find out it was all lies.
Why those two countries specifically? In Russia you can get imprisoned for a variety of political/strategic reasons if you refuse to cooperate. China implemented there own internet for spying.
When you visit these countries you are advised to buy new devices and throw them out on return to avoid backdoors.
General Powell misleading the UN and TV networks was based on having chemical weapons. Nuclear weapons is the fear with Iran. It was believed because the UN weapon inspector Hans Blix was being railroaded with fake traffic jams and other tactics preventing him from investigating. After he pulled out and Sadam had a history of using these types of weapons on his own people, it made the claim easier to accept without more proof.
The same is true of Australia, the USA, and the UK - these nations have no issues with imprisoning each others citizens if it behooves them - i.e. if the individual chooses not to cooperate with the military-industrial-pharmaceutical complex.
China or Russia would not pose any threat if they managed to completely infiltrate US institutions, because they would be, at this stage, the US greatest allies. Sure, China might try to constantly drag the US into pointless wars in Asia, but again it would be fine because it would be to defend the interests of China, the greatest ally.