Tesla has used space characters in internal emails to identify leaks
twitter.com
twitter.com
Then, as now, it strikes me as little more than sad and paranoid Tom Clancy cosplay.
I’d like to say I’ve moved on to a place with a culture of trust and faithfulness, but it doesn’t seem like anyone really trusts anyone anywhere anymore, and recent general infatuation with petty lords of chaos doesn’t seem to be helping.
So here we are, everyone fantasizing about espionage.
No offense intended, but have you considered that maybe you're just surrounded by bad people? I have a reasonable amount of trust and faith in the other people that I work with. If I needed someone to pick me up in the middle of the night from the hospital, I'd trust my coworkers as much as I would trust my wife or friends.
My company is hardly some "golden child", but it generally does right by its staff, and the staff, more or less, does right by the company. Things aren't perfect, but I would say the amount of inter-office trust is about as close as anyone would reasonably expect. Problems pop up, but with a healthy amount of addressing things head on, those problems don't rot and fester.
Need someone to be honest with you about the deadline of an upcoming project? Done.
Need to get a hold of someone off-hours on a three day weekend? Alright, as long as it's something important and time sensitive.
Need realistic feedback about a presentation you're working on. Sure.
It all revolves around mutual respect, camaraderie, and clearly defined roles. When I see an upcoming issue with an area I have nothing to do with, I don't feel the need to fix it "because no one else will", but, I also don't leave it to blow up in someone else's face either. I let the right people know, or tell my boss if I'm not sure who should be involved.
If I had to take a guess, maybe you work for one of those larger corporate type companies with lots of middle managers, office politics, etc.? I'd encourage you to look at getting away from that if it's weighing heavily on your ability to trust others. It's something that I dealt with for a length of time, and once I moved onto a smaller shop, the ability to trust and genuinely rely on others improved quite a bit.
Now I'm at a shop that's miles better than the first. Management probably cares too much, treating labor better than a lot of parents treat their own children. Honesty and transparency are the defaults, a problem doesn't result in blame being passed around, the 5 whys are extended to 6 whys if they seem to point to "this trusted human made a human mistake." We're our vendors' favorite customer - we just got a valued salesman/apps engineer back who'd had his territory switched, he covers most of the region starting 30 minutes south of us but also negotiated a key account exception to keep us on his account. We're also one of our customers' favorite suppliers, they'll happily pay extra because they know we'll build them the Cadillac of machine tools with integrity and quality at each step of the build, and not nickel-and-dime them for support after the fact or ignore them when the machine is out of warranty.
The scary part about this, though, is that the accumulation of loyalty, trust, and social capital that's been very slowly built up over decades could be quite effectively and profitably plundered in an acquisition or by a change in the board or management. They could probably turn the screws and push profit into the stratosphere for 4-8 quarters before our abnormally low turnover turned into abnormally high turnover and customers realized that our culture had changed.
And what’s worse, being a hard nosed asshole is expected behaviour from executives, even if it’s uncalled for or actively harmful to the company.
I knew a guy fresh out of MBA school who proudly told everyone I worked with that if they didn’t like what he asked them to do, he’d sack them. Despite the fact that these people had specific training, were good at what they did, and understood how best to do their jobs.
His attitude really made me think about the value of individuals in a company - and showed me exactly how not to do things in the future.
I just took it for granted, but that environment was a bit of a "silo." When I left that company, and started to interact with today's tech culture, it was ... quite a letdown.
It seems that most executives are fairly sketchy people, these days, and they set a culture that is mimicked by the folks that work for them.
I guess that it's always been like that, but it seems a lot worse, these days.
So consider that your trust, your opinion, is based on the past, and you have no actual idea what will happen in the future, or tomorrow even.
Espionage isn't a fantasy, it's very much real. People go to jail for it all the time. The only question is to what degree might a company be affected or targeted. Taking steps to add a reasonable layer of security to attempt to protect costly IP isn't being paranoid at all. Not to mention that in some environments there are legal requirements, a prime example being aerospace.
We have had the experience of having an employee provide confidential technical information to a multi-billion dollar international competitor. The same competitor that, for as long as a year, bribed top resellers not to feature our products at industry trade shows. Business can be absolutely brutal and, yes, it can be war.
If the secrets being guarded are life or death for the company, then some extra measures may be appropriate. But if they're normal corporate "secrets" the harms of enforcement will be worse than a leak.
* tried to sabotage other employees at random by modifying their letter & leaking it
* tried to sabotage a specific employee by getting their unique copy & leaking it
The risk/reward for a company here seems very poor. I would imagine this blows up in the face of the company often.
This makes no sense. Why would they tell everyone what their measures were?
_WHICH_ coworker is unknown.
If innovation and brilliant thinking are part of your brand, you actually get higher quality work, sustained over a longer period of time, if you actually back off on the whip-cracking and just give people what they need to produce great work.
You get slightly slower growth, but more area under the curve in the long run.
The labourers would have been enticed by the mix of high-quality food and the opportunity to work on such a prestigious project."
https://www.sciencefocus.com/science/were-the-egyptian-pyram...
I am asking - show me the person who found the better way.
They weren't build by aliens with alien technology? ;-)
SCNR because we are talking about Elon Musk with his space obsession.
Early support for company health insurance, flextime, work-from-home, free coffee breaks, decentralized decision making, etc.
See the HP Memory Project at https://www.hpmemoryproject.org for some of the stories. ("Jim Catlin's Packard Story" and Packard's 11 rules, "Bill Hewlett and the HP Medical Plan" for their anonymous payment for medical bills for an employee's premature baby, etc.)
The padlock story at https://www.hpmemoryproject.org/timeline/john_minck/inside_h... is also pretty well-known, and used as an example of promoting institutional trust.
Packard's support for apartheid profits keeps him definitely on the scale.
[1] Probably better if you were a white male not as subject to the "mixture of machismo and misogyny" of early HP - https://www.hpmemoryproject.org/timeline/barbara_waugh/barba... .
For a (much more) elaborate expansion on this, see the book Drive by Daniel H. Pink.
Putting a OSS lipstick isn't doing any favors to understanding the human nature and how to create a good governance model to keep people happy. I suspect this is never going to be "solved", only solved in one person's views or ideological bias.
OSS projects that have paid developers often manage to avoid much of the pressure that occurs in closed source.
Some OSS projects like the kernel manage to harness companies as way of funding full time developers without giving them too much say in details or deadlines. A feature ships in Linux when it is ready and accepted by the maintainers and Linus not when some manager says it has to ship.
Of course this works far better for large projects that are essentially a "commons" like the kernel, less so for open source projects where most of the developers work for a single company.
That said it wouldn't it be cool have some sort of open source VW Bug. Stainless steel cyberbug, EV for the people. Low tech, curb lasts whole century, ubiquitous parts.
AWS would just fork it, package it as a SaaS, give nothing back to the project and it would then slowly atrophy and cease to exist.
The means define the ends. If you treat people like shit, or as morons who need BS pressure techniques, you'll get a demoralised company.
Treat people well, set them clear targets and say it without fluff when they're slacking. If you can't tell somebody they're not good enough, you cannot help them to be good enough. None of this psychobabble BS where you're constantly second-guessing in a failed attempt to retain them on the rat-race for the rest of their life. Stop building ratrace companies.
They build rat-races because they are all still rats at heart. Endemic crisis of leadership and vision bred men who cannot think outside the maze. No amount of climbing extended their horizons or released them from slavery to money and the misery it brings.
Good point. I often wonder what motivates a billionaire to keep making more money. For most it seems like ego, greed, and inability to rethink their life. I suppose they climbed so high by being relentless and not stopping. This is what makes the example of Yvon Chouinard so interesting.
To give Elon credit, he does try to motivate people. Sleeping on the factory floor, doing more work than his subordinates, inspiring people about grand goals and "anti-bureacratic" philosophy – all contribute to motivation. He sent out an email to Tesla employees that literally said "If a rule becomes a Dilbert joke, then change the rule".
I am trying to steelman Elon's way of governing and personally know several people at SpaceX that are not dying from overwork, but actually happy. I also have a few friends who couldn't stand SpaceX and quit within the first year.
(Thinking of how much the Artemis cost vs. total SpaceX subsidy here, but subsidies are everywhere and look suspiciously like legalised corruption and/or voter manipulation to me even when I like the thing being subsidised).
And Musk is the perfect example of "do as I say, not as I do", as he sends teams into a death march of insane hours, wherever he is, while he's shitposting on Twitter from his multi million dollar house paid for by company funds and pretending he's doing 120 hour work weeks
I recall a story about Jobs tracking down leakers in his own executive suite by telling each of them a slightly different things in private. Not sure if it worked, but it can be a very effective deterrent.
Surely the extra whitespace would disappear in the DTP systems used by the press?
If it must be fictional, try the original superman.
He should have used different stories.
It also might make her suspect misinformation as there are three different values coming to her at once and she’ll have to deduce what’s more likely that all three informants are lying, or misunderstand, or Tyrion fed them bad info.
Much more likely to have three independent stories so that the traitors will be revealed even if there are multiples.
In the current scenario, if Varys and Littlefinger snitch then Tyrion won’t know because Cersei will hear Greyjoy and Vale and not reveal what she knows to Tyrion because it conflicts as Myrcella can’t be married to two different groups.
The better scenario would be something like “Myrcella marries Dorne to Pycelle; 1,000 ships sent to Westeros to Varys; I’m appointing Jaime as lord of casterly rock” then each betrayal could be known.
If Varys and Littlefinger snitch in this scenario Cersei will look into ships and casterly rock and reveal the betrayers to Tyrion.
I found it odd because they weren’t really pertinent and seemed really unique that I’ve never heard of anyone else with the condition.
I suspected he did this to try to determine who they can trust when he would remark that people were liars or not trustworthy and one time a coworker told me a completely different weird detail about them.
I never got a chance to ask them about this technique before we stopped working together.
Because I can't figure out how this would be helpful in any other context.
I never revealed the info because it was said in confidence. But we weren’t really that close so it stood out to me.
My example was made up but the actual factoids were about medical issues and bodily functions. It wasn’t creepy or anything just not something I would want widely known.
But also very interesting!
Funny when you would see devices pop up on the internet with these little things, and wonder who lost their contracts/jobs/etc/...
When Palm was creating the Pre, we had some security dude come to our lab to show us how to securely store, transport, test and inventory devices. It was crazy.
https://waxy.org/2014/01/ellen_degeneres_walter_mitty_screen...
Fictitious or fake entries are deliberately incorrect entries in reference works such as dictionaries, encyclopedias (including Wikipedia), maps, and directories. There are more specific terms for particular kinds of fictitious entry, such as Mountweazel, trap street, paper town, phantom settlement, and nihilartikel.
https://en.wikipedia.org/wiki/Fictitious_entry
In cartography, a trap street is a fictitious entry in the form of a misrepresented street on a map, often outside the area the map nominally covers, for the purpose of "trapping" potential plagiarists of the map who, if caught, would be unable to explain the inclusion of the "trap street" on their map as innocent. On maps that are not of streets, other "trap" features (such as nonexistent towns, or mountains with the wrong elevations) may be inserted or altered for the same purpose.
Supposedly, even today, Apple will assign employees (especially new ones) fake projects in an effort to weed out leakers.
https://www.pcmag.com/news/genius-we-caught-google-red-hande...
I guess engineers at Google have too short of tenure to actually remember the precedent.
Did you read the link?
Hell, even a re-encode/format change, or stripping of format info can moot the entire premise.
I welcome Musk to demonstrating his own psychosis/neurosis. It doesn't really speak to any fundamental cleverness.
Furthermore, were I a journalist receiving such material, I'd damn well make sure to change how I communicated it enough to neutralize attempts at such watermarking, simply because I know people are pre-disposed to such acts as he did.
In fact, if you're going for maximum Discordian Malcontent high score, and you're confident you're operating under such scrutiny, neutralize a copy you leak, then carefully orchestrate the planting of false trails to keep the spook wannabes chasing their tails, which can end up blowing back on the orchestrator for waste of resources. This works better with a larger team though where Spartacus dynamics start kicking in. Sample size 1 tends to leave sufficient metadata from neutral parties to rehome in on a common perpetrator.
This is why labor organization scares the living shit out of people like Musk, and other large holders of capital/abusive management types. Info asymmetry, fear, and disunity are some of their most potent weapons.
Wisdom tends to prevail on the side of "don't do shit somebody'd find leak worthy, and you won't have this problem".
We used EMC's Team Rooms, and it was quite fun to run a full-text search across our tenant a few months later.
https://www.nytimes.com/1988/09/03/world/soviet-aide-admits-...
In contrast, the classified maps were remarkably detailed:
"Why Every Map of China is Just Slightly Wrong"
https://en.wikipedia.org/wiki/Agloe,_New_York
When another map maker put the actual settlement on their maps, the original publishers cried foul, but then discovered Agloe had become real!
Very fitting, if people weren't sure if it 'be or not be'.
You can report the location to Google as "bad data" and they'll delete it, but then a totally different fake location will re-appear in its place a few days later.
https://londonist.com/2015/11/london-trap-streets
Tangential: Are A-Z guides still a thing? I still have my old one from many years back when I lived there.
Recipient A then clicks reply-all, now everyone has copy that was personalized to A. They might even notice subtle differences between them.
Edit: WP has the Tesla story with the counsel forwarding his copy to everyone in a new mail (presumably trying to be helpful?) So not a case of reply-all disease
Watermarking added by the mailing-list manager software?
Email round two: A REPLIES ALL to their individually-watermarked copy of the email, delivering it to ALL employees (or some nontrivially large sample), by which B AND EVERY OTHER RECIPIENT now contains A's watermarked copy.
Email round three: B OR ANY OTHER RECIPIENT OF A's REPLY ALL can now leak A's watermarked copy of the email. Watermarking NO LONGER identifies the leaker.
Likely the To: line is some sort of mailing list in this case. The mailing list watermarks when redelivering to everybody. The To line remains unchanged. A reply-all causes one copy to be leaked (but it might be re-watermarked, depending on configuration...) Edit: A reply further down says it was actually a forward which does seem more likely, but nothing about the original setup is impossible.
That is indeed the precise and exact point.
https://en.wikipedia.org/wiki/Canary_trap#In_popular_culture
"After a series of leaks at Tesla Motors in 2008, CEO Elon Musk reportedly sent slightly different versions of an e-mail to each employee in an attempt to reveal potential leakers. The e-mail was disguised as a request to employees to sign a new non-disclosure agreement. The plan was undermined when the company's general counsel forwarded his own unique version of the e-mail with the attached agreement. As a result, Musk's scheme was realized by employees who now had a safe copy to leak."
Guy who embedded Xbox 360 serial numbers into the Xbox 360 beta dashboard UI to identify leaked pics here - there was a big HN thread on it some years ago.
Just to point out, using extra spaces and different ascii space is basic steganography that's been used since WW1 and WW2. Elon brags about using spaces and other "Canary" techniques. Not super complicated
Elon appears to send emails in a fixed width HTML file in a lot of cases, which gives you some extra options with ascii characters on line breaks for steganography. Using a tool I wrote a decade + ago to find inserted line breaks in images - here was what I pulled out from a screenshot of Elon's email to employees from earlier today.
https://twitter.com/cullend/status/1593022922603786240/photo...
I expected it to be super old but there must be old people with printers.
I get annoyed when companies expect me to print stuff at home. I prefer companies to assume that no one has a home printer and plan for it by including return labels and whatnot.
[0] https://metafacts.com/home-printer-trends-in-the-us-tupdate/
I have to admit, it turned out to be pretty cool. I hadn't used a printer in years for anything personal, and it turns out you can print professional-looking glossy photos for like 15 cents each between ink and glossy photo paper. Now we have a ton of nice family photos all over the walls, and I printed out a selfie from my WoW character when our guild killed some raid boss together and mixed it in with the other pics
Also, printers at home are incredibly useful. I'm surprised more people don't have them. Especially now that online shopping (and therefore online returns) are so much more common and require printing return labels.
As crappy as modern printers are, they provide an oversized amount of peace of mind for me.
...what year is this? Like, I have some questions:
1) Why keep hard copies of documents created electronically when there are so many more redundant, more secure, and more convenient ways keep the electronic versions themselves?
2) What in God's name are you putting on your tax forms that warrants being that paranoid about who sees them?
Well, it includes social-security numbers for starters, and may also include bank account routing information (where to send the refund check, or withdraw in case of extra payment needed).
2) As an American example, ask Trump, he really doesn't want to release that information for one reason or another. Simply put trying to figure out other peoples security and sensitivity sensibilities is not something you have all the details on and are making vast assumptions.
There are still much more convenient and technically superior methods than using physical paper copies if that is your concern.
> ask Trump, he really doesn't want to release that information for one reason or another.
Using "unscrupulous, if not criminal, activity" as an example in this instance doesn't seem like the best argument.
Any digital record has a huge number of failure modes. For security you'll want to encrypt, when encrypted you'll now have another piece of data you need to secure and backup. You have to ensure the backup services are secure. If any of these become insecure how do you trace the insecure accesses? If it was accessed from overseas what do you do about it?
Criminal activity is common, but lets go with something that would be criminal in one country and not in another... This gets very messy with cloud services where some other government can request the information. With a safe you have to get the local government to sign off on a warrant.
I haven’t seen a home printer since I moved out. In all these years I’ve only needed to use a printer once (sheet music when I was learning piano).
It’s just not that common to use paper anymore, aside from school projects.
I've also yet to find a superior UI to printed pages for running RPGs. Books are great, iPads are great, laptops can be OK, but for the core material you need for a given session, there's nothing in the world I know of that beats ~20-30 pages of printed notes and excerpted bits of PDF books & some randomly-generated junk from the Web for each session, so you have only expected-to-be-relevant info in it. Nothing better when you're actually at the table. I mean, you could do the same thing writing it by hand if you have very neat handwriting, but being able to mix together your own notes and e.g. NPC template-blocks, custom maps, and commercial material pulled from books, is awesome and saves tons of time when prepping. You can achieve something similar with just an iPad, but it's still slower and more awkward to actually use—though I do have other things I use tablets for at the table, that they excel at.
why would anyone have more than one at home?
I think anyone who wants to write potentially career limiting things should exercise basic common sense like not using work computers and printers, removing fingerprinting elements, etc.
In the future I expect more to do stuff like cut and paste between programs to alter the font and spacing before sharing.
Or, of course, don’t leak proprietary information. There are whisleblower protection laws for illegal material that can be revealed. But leaking random company stuff, I think leads to less info being shared by the company to employees.
It's not retaliation if they fire you before you make the disclosure...
And why Snowden had to do an illegal act to reveal.
But I think these scenarios are totally different from these Twitter leaks where there’s no whistleblowing or illegal activity revealed.
But I think there are tons of examples where the law worked and whistleblowers were protected and even financially rewarded, https://www.phillipsandcohen.com/successful-cases/
If your final target was Notepad or similar, it should drop all the metadata. But in that case, just start with Notepad.
or, he stayed up for two days until he got it exactly to match by tweaking his approach a little at a time, and actually matched it to the right person. Honestly, he seems like he'd do this.
And in a large company, how many ~1 page letters get printed? What are the odds that there is only a single match in the entire company?
I take this story similar to the binary coded space story: more likely to be apocryphal and promoted to deter future leakers than true stories about catching them in the past.
I have my own story about this: In the early 2010's I had a boss that loved to call us and check in every day. We were a remote team and he had anxiety that we were all larking off. I later learned his technique was to open the dropbox admin tools to see the location of someone before calling them. "So, BarelySapient, where are you working at today?", he'd ask in a cheerful tone. But in reality, he was testing employee truthfulness. Every call. He later fired one of my co-workers when they reported to be working from home, but dropbox reported them somewhere in the Florida keys....
There is no way I would send anything to an external print shop from company equipment; they are almost certainly on top of that as well.
If any infosec experts feel like chiming in I'd love to learn more.
Easily detected.
> sharing it as a document via Dropbox or similar
If you use a TLS-inspecting proxy/VPN, this will be detected. Otherwise, it depends on how much monitoring is going on, but at best they could suspect it.
> Copying to physical storage?
At my work, USB drives are disabled by MDM.
You could use transfer the files over SSH. Even if you have an MitM SSH-inspecting VPN, once the SSH channel is established, you could tunnel a second SSH connection through the established insecure SSH session.
Even then, with enough logging, you could detect that all local files were accessed sequentially which would raise a red flag.
There's nothing you can do to prevent insider espionage that wouldn't raise false positives and block legitimate work, but you could at least detect it.
Now, production cost figures and schedules ...
The USB stick they used to make the transfer contracted ransomware from the public terminal, which put everyone on high alert when it was next introduced into the corporate network.
Basically all it would tell you is the number of word documents with approximately the same amount of text were printed, plus or minus about a paragraph. Letters aren't frequently printed and the contents of the leak would almost certainly limit the number of suspects to a small handful of people. It's not hard at all to believe that in a group of ~50 people and a time window of ~1 week you might only have one even close match.
Or have a printer at home on stand-by for your leak press releases. If I were Musk, I would have fired him/her not for being a snitch, but for his/her sloppiness and overall carelessness and lack of discipline.
Networked printers store a lot of information about what is being printed.
Not a bad idea for initial filtering, I think, but I doubt it would hold up in court on itself.
I’m sure between various version there is difference in what is produced.
Unless you can ask word for the equivalent of a postscript ?
They likely misidentified the leaker with that silly analysis and fired them on the spot, would be just the usual modus operandi of musk.
It is a difficult task, anyways.
The Musk detective work is described by Vance in a footnote:
“Musk would later discover the identity of this employee in an ingenious way. He copied the text of the letter into a Word document, checked the size of the file, sent it to a printer, and looked over the logs of printer activity to find one of the same size. He could then trace that back to the person who had printed the original file. The employee wrote a letter of apology and resigned.”
This leaves me a with more than a few questions:
1. Why would this email/letter have been printed out? It's short, informal, and did not seem to contain any corporate materials that would require access from a work computer. Surely, this would be better sent as an email from a personal computer? All I can think of is that the employee did print some kind of private company information (perhaps as proof?) to send to Valleywag. But wouldn't this mean that the print-job sizes wouldn't match since there would be printed materials not made public? It seems beyond insane to physically mail a tip to a gossip site that was built around emailed tips.
2. If this was sent as a physical letter, why would the quote in the article contain the typos? Why would they even take the time to type up the entire letter when the article summarizes every single point that the Tesla employee mentioned? Shouldn't they have taken some care to not verbatim reproduce text that could have gotten their source into trouble? I will say that the minimal journalistic standards employed by former Gawker-network sites provide convenient explanations to these questions, so these aren't particularly damning.
3. Is this really all the text that was sent to Valleywag? The quoted part of the letter provides no salutation or signature. Sending this text exactly as quoted as a physical letter seems bizarre, even for an anonymous tip.
4. Would the sizes of the files sent to the printer even match up considering the document metadata? This actually seems somewhat plausible.
5. Would the print-job really be the best way to figure out who the leaker was? In October 2008, before the letter was written, Tesla only had 363 employees[3] and may have laid off a few dozen of them before this letter was written. This employee claims to have joined in 2004. A Wired article from 2006[4] mentions a meeting of 30 Tesla employees and board members in December 2004. It seems like there are a very small number of people who could have been the potentially leaker. How many of those people were using the corporate printers the day after the mentioned all-hands meeting to print a single page document?
--------
I imagine that this story was told to present Musk as smarter than everyone else while also threatening disloyalty, which seems to be a frequent Musk bugbear. The bit about the caught employee writing a letter of apology and then resigning (amidst large-scale layoffs at Tesla in 2008!) also seems a little too cute, in a chain-email-atheist-professor-humiliated-by-freshman-Albert-Einstein kind of way.
--------
[1] https://www.theatlantic.com/technology/archive/2018/06/elon-...
[2] https://www.gawker.com/5071621/tesla-motors-has-9-million-in...
[3] https://www.latimes.com/archives/la-xpm-2008-oct-25-fi-tesla...
https://web.archive.org/web/20221116003941/https://www.wired...
Still a reckless way to identify the leaker, there's plenty of reasonable doubt if all they have to go on is the size of the document that was printed.
Given that Musk is not the most reliable narrator, to say the least, I'm skeptical of this story. I'm sure he sees plenty of utility in appearing omniscient to frighten potential leakers.
We then take the output of this and transcribe it over an old HAM radio to a friend in China. He lives on a farm, so he then dictates it to a chicken who writes it in the sand. He quickly takes a picture before the wind erases it.
He then contacts a US media publisher under the name 'Whu Lee K', and they print it as is! What a wonderful time to be alive.
It seems incredibly naive to print out a leak letter from work.
sounds like this was likely an internal report (which would have been printed at the office as part of one's work), which later made its way to the media, rather than some letter stealthily written and sent to the media (which would have been unlikely to be printed at the office)
It's also the CEO of the company taking time from the shareholders to hunt down and hurt someone.
Don't work for people like this.
Like other commenters, I find it hard to believe that this actually happened.
I read the book but did not remember that part. So, I searched it. You almost wrote verbatim. What are the chances a leaker(s) would print before leaking? Very low or none. So, that practice has very slim chances of success. The one in the tweet is a bit better. But has a escape route. Either - try to grammatically correct or paraphrase - it before leaking.
Always found it ironic that their own products (gmail/chrome) gave away their attempts at steganography.
discovered by accident that Google was doing steganography in their e-mails
https://freedom.press/news/sharing-sensitive-leaks-press/
https://mashable.com/article/leaking-hacking-data-nsa-anonym...
Advice for future leakers:
1. Ask your co-worker to forward you that email (because you "accidentally deleted it"), and diff to your copy, so you know if your employer is cosplaying as the CIA.
2. Retype everything before leaking or leak crappy photos of documents on your screen (or better yet, both).
3. Leak to a journalist and make them promise to only describe or quote the documents you're sharing, and not sure the literal files. A lot of this CIA cosplay won't work without access to the leaked file.
The difference is that in the 360 dashboard they used "decorative" rings to encode the information.
They managed to prove in court that google actually took their texts by embedding a Morse code. They used ' and ` as Morse characters in their lyrics to mark their property.
However, as far as I know, they lost the case anyway because the judge rules that the lyrics doesn't belong to the lyrics page, but to the song owner.
[0]: https://www.golem.de/news/vorwurf-von-genius-com-google-soll...
With ithreat, there is someone checking who doesn’t care about your reddit use.
But, The 1-2 blend of insider threat programs having the access and wfh productivity suspicions increasing makes me think mgmt will poke under the hood in these logs beyond I-threat concerns at some point soon.
I do if I see double spaces.
Or is it about printed documents?
Only if you tried to select them one by one would you become aware. But that's not what people usually do when they C&P a block of text
That said: not sure how they will look in a text-only (no WYSIWYG) editor or a mail client set to display raw text.
The luxuries of living in iso-latin-1, I suppose.
Mutt just shows them all as spaces...
(back when forums were still a thing)
> ... first draft of the report, I came up with an idea to make each one unique."
> "They've been doing that for years," Holmes noted. "All one must do is misplace a comma here and there. Easiest thing in the world. If the newspeople are foolish enough to print a photograph of the document, we can identify the leak."
> "Yes, sir, and the reporters who publish the leaks know that, too. They've learned not to show photographs of the documents they get from their sources, haven't they?" Ryan answered. "What I came up with was a new twist on that. Agents and Agencies has four sections. Each section has a summary paragraph. Each of those is written in a fairly dramatic fashion."
> "Yes, I noticed that," Charleston said. "Didn't read like a CIA document at all. More like one of ours. We use people to write our reports, you see, not computers. Do go on."
> "Each summary paragraph has six different versions, and the mixture of those paragraphs is unique to each numbered copy of the paper. There are over a thousand possible permutations, but only ninety-six numbered copies of the actual document. The reason the summary paragraphs are so -- well, lurid, I guess -- is to entice a reporter to quote them verbatim in the public media. If he quotes something from two or three of those paragraphs, we know which copy he saw and, therefore, who leaked it. They've got an even more refined version of the trap working now. You can do it by computer. You use a thesaurus program to shuffle through synonyms, and you can make every copy of the document totally unique."
> "... Say we send this memo to the same people who received the other memo — well, we don’t have to include anyone in this room — you’re in on it — but we’ll send copies to every one of the others. Each copy of the new memo would be exactly the same, except for one word. In each memo there would be one word not in the others. We would keep a record of the person to whom we sent the memo — and beside his name we would jot the unique word that was in his memo. Do you see what I’m driving at? When the memo goes out, the person here who is betraying us will pass it on word for word to de Vroome, isn’t that so? Your informer in de Vroome’s headquarters would learn of it and report back to you. Since no memorandum would be precisely the same as the others, because of the single word change, you’d look for the different word in the memo de Vroome received and be able to find out the person who had passed on his copy of the memo. You'd know your traitor."
On a separate note, I'm sure that by now he's pretty much destroyed the entire culture there. So, while many folks will hang around for now, since economy, but most are possibly thinking of leaving. In the end only the most desperate will be left there, so yeah, pretty hardcore.
However it will add almost invisible markings onto the paper itself, such that the page can be linked to the actual printer, exact timestamp and username of the person who printed.
That only happens on color printers. It is called Machine Identification Code (https://en.wikipedia.org/wiki/Machine_Identification_Code).
Supposedly the reason is to trap currency counterfeiters.
Black and white printers do not add such dots.
If it is the same content for all users receiving the text, then you can just retype the text (not copy/paste) into a different file. Of course, authenticity comes to question if you whistleblow by doing this.
cat file.txt | perl -C63 -pe '$_ = join("\n", split(//, $_));' | sort | uniq -c
I've found lots of errors that way: BOMs in the middle of a file, different kinds of dash, quotation marks or brackets that don't match, ...
You can do this easily enough on MacOS simply by taking a screenshot, pasting it into Preview, selecting the text with its automatic OCR, and copying.
Of course you still need to worry about whether line lengths are varied per-recipient, or even the wording of the e-mail itself. But the above will at least take care of glyphs.
cat document | tr -dc '[A-Za-z0-9.,!@$%*()/?" -]'After a series of leaks at Tesla Motors in 2008, CEO Elon Musk reportedly sent slightly different versions of an e-mail to each employee in an attempt to reveal potential leakers. The e-mail was disguised as a request to employees to sign a new non-disclosure agreement. The plan was undermined when the company's general counsel forwarded his own unique version of the e-mail with the attached agreement. As a result, Musk's scheme was realized by employees who now had a safe copy to leak.[4
Everyone who read the tweet or commented here at this current point in time.
Not sure most people who might be future leakers of classified stuff and targetted by this trick will be aware of it.
Companies: Protect your developers, not your code!
If you find a corporate document with a lot of weird sounding word choices and ordering ... it's probably just written by someone not great with the language.
(English -> Turkish -> Hmong -> Xhosa -> English)
Seriously if you’re doing a hiding in plain sight technique like steganography the last thing you should do is boast about the fact you’re doing it.
Before that tweet the thread is talking about an email Musk sent:
> Scoop: Elon Musk just sent an email to all staff outlining "Twitter 2.0", writing it will"need to be extremely hardcore". Long hours, high intensity.
> People need to click "yes" to confirm being part of this by 5pm ET tomorrow, else they get 3 months severance. [...]
Hah, "Click here to agree to a toxic workplace, or be fired"...
"The authoritarian relation between the one who commands and the one who obeys rests neither on common reason nor on the power of the one who commands; what they have in common is the hierarchy itself, whose rightness and legitimacy both recognize and where both have their predetermined stable place."
https://blogs.law.columbia.edu/uprising1313/files/2017/09/ar...
Issues around service conditions regularly go all the way to Congress and get resolved quickly and sometimes expensively, because the alternative is being unable to recruit or retain personnel, and that would be disastrous for a military that's already having a tough time doing both.
Let's not justify abusive leadership. There's never a need for it.
Hierarchy has its own failure modes. Into the valley of death rode the six hundred ..
Also, militaries do have to care about what the lowest ranks think. Not only to maintain recruiting in places without conscription, but also to avoid fragging in places that do have conscription:
"""Fragging is the deliberate or attempted killing by a soldier of a fellow soldier, usually a superior. U.S. military personnel coined the word during the Vietnam War, when such killings were most often attempted with a fragmentation grenade,[2]
…
The high number of fragging incidents in the latter years of the Vietnam War was symptomatic of the unpopularity of the war with the American public and the breakdown of discipline in the U.S. Armed Forces. Documented and suspected fragging incidents totalled nearly nine hundred from 1969 to 1972.[5]""" - https://en.wikipedia.org/wiki/Fragging
While I am confident that Musk's behaviour is merely close to average USA industrial employment norms and this is just us techies being shocked by what that looks like (for example, while there are stories about Amazon running out of people interested in working there, I've not heard that about Tesla, SpaceX, TBC, or Neuralink), this latter scenario is one of the possible failure modes I foresee with actually trying to colonise Mars with Starship, as there just isn't an easy way out if/when things go wrong 40 million miles from alternative employment/governance.
12 year olds can be such piece of shit sometimes, cant they just be grateful they get paid 2c and got selected for the special 36 hour shift to make shoes for us?
It’s also far more likely to happen at a company that is a media darling where everything it does gets documented in papers around the world.
So naturally there’s tons of outside pressure for information to leak compared to typical orgs.
It attracts Elon devotees. It remains to be seen if they can be as good as regular SWEs. I highly doubt it
Tesla has pushed the "we do it to bring amazing things to your car!"...quietly distracting people from the "...we fuck things up so often we're constantly having to patch your car" man behind the curtain.
Once you’re several years into owning a car, the outdated software really starts to show. Especially on mid-2010s cars where CarPlay and Android Auto weren’t a thing, you’re held back by really old shitty software that will never be updated.
That is one thing that Tesla has, without a doubt, got right. And you can tell because most major manufacturers are also going to an OTA update system, even though it obviously costs far more in infrastructure and completely re-engineering their existing systems to support it.
A lot of money, perhaps? I'm not familiar with Tesla compensation levels, but this is the only reason I can think people may have to cope with this guy.
> A lot of money, perhaps?
They work there for the mission, not the money.
Tesla pays 100-150K USD for new grad SWE including stock options/RSU. For AI, it’s about 150-200K.
Or you can drive 15 minutes to Google and a SWE gets 200K and AI gets 200-250K. Or “sell out” and work in quant finance for 400-500K new grad SWE as a 22 year old.
So no, people do not work at Tesla/SpaceX for the money.
I have many friends at Tesla, Neuralink, SpaceX, and they complain how little they are paid, how they have no free time, and how they hope the name brand on their resume gets them a higher paying job some day. Looks like they bought Elon’s bullshit.
Like SpaceX, only the motivated will agree. That's a requirement for turning Twitter into a SpaceX or Tesla scale success.
3 months of severance, after a good 6+ month run of lame duck employment where the whole company didn't really do anything. I could take my time and buy a nice house out in the Midwest, then pick up an easy remote job for $100-150k
I guess it's a different story if you dumped your life savings into a down payment and now you have to keep up with an $8000 Bay Area mortgage though
You're not buying a house of any kind (let alone nice) with 3 months severance after taxes and day to day living expenses.