The Musk detective work is described by Vance in a footnote:
“Musk would later discover the identity of this employee in an ingenious way. He copied the text of the letter into a Word document, checked the size of the file, sent it to a printer, and looked over the logs of printer activity to find one of the same size. He could then trace that back to the person who had printed the original file. The employee wrote a letter of apology and resigned.”
This leaves me a with more than a few questions:
1. Why would this email/letter have been printed out? It's short, informal, and did not seem to contain any corporate materials that would require access from a work computer. Surely, this would be better sent as an email from a personal computer? All I can think of is that the employee did print some kind of private company information (perhaps as proof?) to send to Valleywag. But wouldn't this mean that the print-job sizes wouldn't match since there would be printed materials not made public? It seems beyond insane to physically mail a tip to a gossip site that was built around emailed tips.
2. If this was sent as a physical letter, why would the quote in the article contain the typos? Why would they even take the time to type up the entire letter when the article summarizes every single point that the Tesla employee mentioned? Shouldn't they have taken some care to not verbatim reproduce text that could have gotten their source into trouble? I will say that the minimal journalistic standards employed by former Gawker-network sites provide convenient explanations to these questions, so these aren't particularly damning.
3. Is this really all the text that was sent to Valleywag? The quoted part of the letter provides no salutation or signature. Sending this text exactly as quoted as a physical letter seems bizarre, even for an anonymous tip.
4. Would the sizes of the files sent to the printer even match up considering the document metadata? This actually seems somewhat plausible.
5. Would the print-job really be the best way to figure out who the leaker was? In October 2008, before the letter was written, Tesla only had 363 employees[3] and may have laid off a few dozen of them before this letter was written. This employee claims to have joined in 2004. A Wired article from 2006[4] mentions a meeting of 30 Tesla employees and board members in December 2004. It seems like there are a very small number of people who could have been the potentially leaker. How many of those people were using the corporate printers the day after the mentioned all-hands meeting to print a single page document?
--------
I imagine that this story was told to present Musk as smarter than everyone else while also threatening disloyalty, which seems to be a frequent Musk bugbear. The bit about the caught employee writing a letter of apology and then resigning (amidst large-scale layoffs at Tesla in 2008!) also seems a little too cute, in a chain-email-atheist-professor-humiliated-by-freshman-Albert-Einstein kind of way.
--------
[1] https://www.theatlantic.com/technology/archive/2018/06/elon-...
[2] https://www.gawker.com/5071621/tesla-motors-has-9-million-in...
[3] https://www.latimes.com/archives/la-xpm-2008-oct-25-fi-tesla...
https://web.archive.org/web/20221116003941/https://www.wired...
It is a difficult task, anyways.
They likely misidentified the leaker with that silly analysis and fired them on the spot, would be just the usual modus operandi of musk.
And in a large company, how many ~1 page letters get printed? What are the odds that there is only a single match in the entire company?
I take this story similar to the binary coded space story: more likely to be apocryphal and promoted to deter future leakers than true stories about catching them in the past.
Basically all it would tell you is the number of word documents with approximately the same amount of text were printed, plus or minus about a paragraph. Letters aren't frequently printed and the contents of the leak would almost certainly limit the number of suspects to a small handful of people. It's not hard at all to believe that in a group of ~50 people and a time window of ~1 week you might only have one even close match.
I have my own story about this: In the early 2010's I had a boss that loved to call us and check in every day. We were a remote team and he had anxiety that we were all larking off. I later learned his technique was to open the dropbox admin tools to see the location of someone before calling them. "So, BarelySapient, where are you working at today?", he'd ask in a cheerful tone. But in reality, he was testing employee truthfulness. Every call. He later fired one of my co-workers when they reported to be working from home, but dropbox reported them somewhere in the Florida keys....
There is no way I would send anything to an external print shop from company equipment; they are almost certainly on top of that as well.
Now, production cost figures and schedules ...
If any infosec experts feel like chiming in I'd love to learn more.
Easily detected.
> sharing it as a document via Dropbox or similar
If you use a TLS-inspecting proxy/VPN, this will be detected. Otherwise, it depends on how much monitoring is going on, but at best they could suspect it.
> Copying to physical storage?
At my work, USB drives are disabled by MDM.
You could use transfer the files over SSH. Even if you have an MitM SSH-inspecting VPN, once the SSH channel is established, you could tunnel a second SSH connection through the established insecure SSH session.
Even then, with enough logging, you could detect that all local files were accessed sequentially which would raise a red flag.
There's nothing you can do to prevent insider espionage that wouldn't raise false positives and block legitimate work, but you could at least detect it.
The USB stick they used to make the transfer contracted ransomware from the public terminal, which put everyone on high alert when it was next introduced into the corporate network.
Or have a printer at home on stand-by for your leak press releases. If I were Musk, I would have fired him/her not for being a snitch, but for his/her sloppiness and overall carelessness and lack of discipline.
or, he stayed up for two days until he got it exactly to match by tweaking his approach a little at a time, and actually matched it to the right person. Honestly, he seems like he'd do this.
Networked printers store a lot of information about what is being printed.
Not a bad idea for initial filtering, I think, but I doubt it would hold up in court on itself.
Given that Musk is not the most reliable narrator, to say the least, I'm skeptical of this story. I'm sure he sees plenty of utility in appearing omniscient to frighten potential leakers.
Still a reckless way to identify the leaker, there's plenty of reasonable doubt if all they have to go on is the size of the document that was printed.
I’m sure between various version there is difference in what is produced.
Unless you can ask word for the equivalent of a postscript ?
We then take the output of this and transcribe it over an old HAM radio to a friend in China. He lives on a farm, so he then dictates it to a chicken who writes it in the sand. He quickly takes a picture before the wind erases it.
He then contacts a US media publisher under the name 'Whu Lee K', and they print it as is! What a wonderful time to be alive.
I think anyone who wants to write potentially career limiting things should exercise basic common sense like not using work computers and printers, removing fingerprinting elements, etc.
In the future I expect more to do stuff like cut and paste between programs to alter the font and spacing before sharing.
Or, of course, don’t leak proprietary information. There are whisleblower protection laws for illegal material that can be revealed. But leaking random company stuff, I think leads to less info being shared by the company to employees.
And why Snowden had to do an illegal act to reveal.
But I think these scenarios are totally different from these Twitter leaks where there’s no whistleblowing or illegal activity revealed.
But I think there are tons of examples where the law worked and whistleblowers were protected and even financially rewarded, https://www.phillipsandcohen.com/successful-cases/
It's not retaliation if they fire you before you make the disclosure...
If your final target was Notepad or similar, it should drop all the metadata. But in that case, just start with Notepad.
It seems incredibly naive to print out a leak letter from work.
sounds like this was likely an internal report (which would have been printed at the office as part of one's work), which later made its way to the media, rather than some letter stealthily written and sent to the media (which would have been unlikely to be printed at the office)
It's also the CEO of the company taking time from the shareholders to hunt down and hurt someone.
Don't work for people like this.
Like other commenters, I find it hard to believe that this actually happened.
I read the book but did not remember that part. So, I searched it. You almost wrote verbatim. What are the chances a leaker(s) would print before leaking? Very low or none. So, that practice has very slim chances of success. The one in the tweet is a bit better. But has a escape route. Either - try to grammatically correct or paraphrase - it before leaking.
I expected it to be super old but there must be old people with printers.
I get annoyed when companies expect me to print stuff at home. I prefer companies to assume that no one has a home printer and plan for it by including return labels and whatnot.
[0] https://metafacts.com/home-printer-trends-in-the-us-tupdate/
I have to admit, it turned out to be pretty cool. I hadn't used a printer in years for anything personal, and it turns out you can print professional-looking glossy photos for like 15 cents each between ink and glossy photo paper. Now we have a ton of nice family photos all over the walls, and I printed out a selfie from my WoW character when our guild killed some raid boss together and mixed it in with the other pics
Also, printers at home are incredibly useful. I'm surprised more people don't have them. Especially now that online shopping (and therefore online returns) are so much more common and require printing return labels.
...what year is this? Like, I have some questions:
1) Why keep hard copies of documents created electronically when there are so many more redundant, more secure, and more convenient ways keep the electronic versions themselves?
2) What in God's name are you putting on your tax forms that warrants being that paranoid about who sees them?
Well, it includes social-security numbers for starters, and may also include bank account routing information (where to send the refund check, or withdraw in case of extra payment needed).
2) As an American example, ask Trump, he really doesn't want to release that information for one reason or another. Simply put trying to figure out other peoples security and sensitivity sensibilities is not something you have all the details on and are making vast assumptions.
There are still much more convenient and technically superior methods than using physical paper copies if that is your concern.
> ask Trump, he really doesn't want to release that information for one reason or another.
Using "unscrupulous, if not criminal, activity" as an example in this instance doesn't seem like the best argument.
Any digital record has a huge number of failure modes. For security you'll want to encrypt, when encrypted you'll now have another piece of data you need to secure and backup. You have to ensure the backup services are secure. If any of these become insecure how do you trace the insecure accesses? If it was accessed from overseas what do you do about it?
Criminal activity is common, but lets go with something that would be criminal in one country and not in another... This gets very messy with cloud services where some other government can request the information. With a safe you have to get the local government to sign off on a warrant.
As crappy as modern printers are, they provide an oversized amount of peace of mind for me.
I haven’t seen a home printer since I moved out. In all these years I’ve only needed to use a printer once (sheet music when I was learning piano).
It’s just not that common to use paper anymore, aside from school projects.
I've also yet to find a superior UI to printed pages for running RPGs. Books are great, iPads are great, laptops can be OK, but for the core material you need for a given session, there's nothing in the world I know of that beats ~20-30 pages of printed notes and excerpted bits of PDF books & some randomly-generated junk from the Web for each session, so you have only expected-to-be-relevant info in it. Nothing better when you're actually at the table. I mean, you could do the same thing writing it by hand if you have very neat handwriting, but being able to mix together your own notes and e.g. NPC template-blocks, custom maps, and commercial material pulled from books, is awesome and saves tons of time when prepping. You can achieve something similar with just an iPad, but it's still slower and more awkward to actually use—though I do have other things I use tablets for at the table, that they excel at.
why would anyone have more than one at home?