It didn't work out for them that well. They couldn't last more than 6 months at any one company and I think eventually gave up and went back home.
It didn't work out for them that well. They couldn't last more than 6 months at any one company and I think eventually gave up and went back home.
Sure, some algorithms there might save you some time, but its often the design and the data where the money lies (what this guy focused on).
Clone google's repo and you'll likely struggle forever to get anything of substance running on a rando vm/docker/etc. not to mention about spinning the entire stack with interconnected services, certificates, shitty code, and layers upon layers of hacking that can only be resolved by relying on the tribal knowledge on whomever built the darn thing.
Compared to that - detailed design docs, a team of motivated Chinese dudes/ettes with some monetary support from the local party, and you can have a close-enough copy running natively on the Alibaba cloud in a few months.
Or maybe useful for security exploits.
The design from a design doc can be replicated at almost any company. The actual code is specific to the company and their exact stack.
The company's business position is similarly hard to duplicate. You can understand a company's current capital, customers and money flows. Your new company has to either outcompete for those same flows or create or capture alternative flows, and do this with different capital. Having, say, the entire source code for FedEx doesn't make it easy to launch a competitor. It's practically irrelevant compared to the network of capital investments, corporate goodwill and contracts, etc.
I don’t understand what you are saying here. How many months does one need to stay to hover up the trade secrets / IP? In software engineering you get access to the repos on day one, but even in other industries I guess what you don’t have access to after 6 months you won’t have access to realistically ever.
> eventually gave up and went back home
But according to what you said that was their plan all along. So in what sense did it not “work out for them”?
Some repositories needed to do your work, sure. Not necessarily all, and the more interesting work may not be available to just anyone who joins.
If it's a company like Google, you may not even end up at the group you interviewed for.
You need some level of intelligence and knowledge to know what is worth stealing and what to do with it.
Getting a major with the sole purpose of industrial espionage and then telling people about it indicates a lot about the person in question.
I've been at my company for almost 20 years. I have a lot of access, but if I was told, "go find some trade secrets." LOL, not a chance. The haystack is far too big and I don't even know what I'm looking for. Someone who has been at the company 6 months barely knows where the bathrooms are.
I was more like, giving the direct competitor the code would more be like industrial sabotage for their sake. What could they possibly do with it. They would waste fte years dechiffering it instead of doing something useful.
But nah, rather keep your own engineers in the dark about secret plans and road maps.
I worked out quite well though, since the engineers did their thing withoit knowing what the higher ups wanted.
Because it is not your intention to do so. Think about how one can live a whole life locking and unlocking locks without ever accidentally lock-picking one. Yet they can be picked, and often quite easily if that is your goal.
If you are serious about it you don’t just bumble around randomly until a trade secret hits you on the head. You can ask yourself: what can that company do nobody else can? You can even ask this question before joining a company and thus selecting the right target and the right position to get access to it.
Did you ever consider doing raising a red flag? If so, why did or didn't you?
I airquote naturally because it’s obvious that foreign interference is at play, based on the laissez-faire attitude towards this sort of thing by some groups.
Yet, the vast majority of both camps still think of themselves as american. Neither group will take kindly for others to present themselves as american, to then proceed steal from other americans for the benefit of non-americans.
We are all part of the same macro-tribe after all.
The capitalists running the companies are the common enemy. Nationalism is a tool, not something to be into once the nation is strong. Sad that people still care about being patriots or whatever when the companies are only paying you a wage while they make profit and keep all control of all the work and means of production.
> being a snake to go defraud a company to steal the hard work of others so your own illicit company can turn a profit off said labor by others irks me.
I'm sorry, I really don't understand this. What part of the second statement doesn't apply to the first?
Presumably the more valuable the IP, the harder it is to access.
Interviewing for a job with the prior stated intent of pilfering their IP is fraudulent.
The IP theft is a private concern. The national security implications are public. What OP describes seems worth criminal investigation.
I mean obviously if the said person did pilfer, or attempted to pilfer, it would be illegal.
But is there any law against interviewing for a job, while having a prior statement of intending to pilfer? Or in a more general sense, interviewing for a position while previously saying that they intend to breach the contract?
I'd imagine that there could only be ground for a lawsuit if 1) a contract has been signed, and 2) the stated activity has at least been attempted.
This would be like someone specifically (not vaguely) stating their intent to commit a violent crime and then spend months preparing for it. Yeah, law enforcement, please definitely follow up on that one.
Your average web dev probably isn’t familiar but navigating this is a routine consideration in deep tech.
ofc, like in any security-related field, many are LARPing instead of practicing, and that's a different issue.
A "real" national security background check requires support and sponsorship from a national government, and governments don't provide that casually to anyone that asks. If a startup finds themselves with national security customers, there is no requirement for the startup to go full-on Secret Squirrel but governments will calibrate their trust in the startup by how seriously the startup takes security and how diligent they are when vetting employees. It does not involve everyone getting a security clearance, which would not be possible anyway if the startup works with multiple national governments.
I find the opposite situation is more common in practice: startups that find themselves in the national security space are often naive about what constitutes a baseline level of security, vetting their employees, and the pervasiveness and character of espionage programs.
It is important to recognize that national security considerations are starting to affect startups that never go anywhere near national security customers due to escalating concerns and increased rigor around software supply chains. You may not have an interest in national security but national security may take an interest in you. This has ramifications for many software business models.
https://www.bis.doc.gov/index.php/policy-guidance/deemed-exp...
OP...you should definitely report this to the FBI.
If you try to hire a hitman, the FBI will definitely investigate even though no crime has been committed.
It most likely wasn't a Handler/MSS type espionage.
It was most likely trying to grab IP to found a domestic competitor, and raise a Seed round from local government accelerators like those Beijing and Hangzhou have.
You wouldn't have to be a delusional braggart to want to tell a friend this. Most spies are not going to be as much of a compartmentalized lunatic like Robert Hanssen or someone at that level.
It's similar to the Israeli program in the 90s (who's name I'm blanking out on EDIT: Yozma I before it was privatized) because just like China in the 2000s-early 2010s, there wasn't a notable private sector VC industry yet.
Quite an allegation... any reference to them sponsoring/encouraging stealing IP or am I misreading and you simply meant it's a government sponsored startup accelerator program?
Israel never recognized American software or pharmaceutical patents, and most countries do some form of Industrial Espionage (France is fairly notable in the space as well [4]).
The wildest cases tended to be back in the 1990s, when Israel was trying to build a domestic armament industry, notably by stealing American IP and selling it to the Chinese [0][1][2][3] (most modern Chinese weapons systems today are based on that IP transfer in the 1990s).
This largely ended by the mid-late 2000s when the Israeli tech industry was much more established, and Ehud Barak (edit: Olmert - mixed up his surname and the Barak middle scandal) getting arrested on corruption charges, heralding the end of Israel's Wild West days in the tech industry.
Also, Tiannammen Era sanctions from the 1990s forced Israel defense companies to pivot to India, which doesn't allow vendors to sell SKUs to India which Pakistan and China have access to, and would leverage French and Israeli SKUs based on American designs.
I highly recommend reading this GAO report from the 90s [3]
[0] - https://www.jstor.org/stable/2538128
[1] - https://www.nytimes.com/1993/10/12/world/israel-selling-chin...
[2] - https://www.jstor.org/stable/1149008
[3] - https://www.gao.gov/assets/t-osi-92-6.pdf
[4] - https://www.politico.com/story/2014/05/france-intellectual-p...
Also, not to nitpick, but would appreciate publicly accessible articles… from the abstracts I can only assume these are summaries made in the 90s of pre-90s shenanigans
EDIT: saw now the edits with 3-4, will look at when I have time (thanks!)
Yep. Brainfarted and merged Olmert and the Barak missles corruption case
> summaries made in the 90s of pre-90s shenanigans
Hence why I wrote "the Israeli program in the 90s".
It's significantly less egregious nowadays (imo de facto non-existent due to how integrated the Israeli innovation system is with the American system now and how simplified FDI is in Israel compared to the 80s-90s)
> appreciate publicly accessible articles
Internet based news wasn't really a thing until the post-Netscape era.
All you're stuck with are archives of print news or government articles, especially because this kind of behavior largely ended by the 2000s.
> EDIT: saw now the edits with 3-4, will look at when I have time (thanks!)
No problem! And like I mentioned before, most countries do this in some form to help domestic champions (eg. India and Pharma IP, France and Defense IP, socialist era Israel and Defense IP, 1970s-80s Japan and electronics IP, China and Defense+Software IP).
If a country allows almost 100% FDI, there's no reason for industrial espionage in that specific sector because foreign champions become integrated with domestic ones. Hence why Israeli and Indian companies don't steal hardware designs anymore because most Americans companies have design centers there that are closely integrated with domestic champions.
Few examples just for Airbus every few years you get report of US spying: * https://www.dw.com/en/airbus-fires-16-over-suspected-german-... * https://edition.cnn.com/video/news/2015/05/01/airbus-spying....
The main difference is DGSE would explicitly attempt to steal American IP and then provide it to Thales or Dassault.
If they were, just about every single private sector company globally would be guilty of IP infringement, let alone Public-Private Partnerships like the ones I mentioned.
And if you don't like that, you can sue them in the special intelligence court where the evidence cannot be revealed, the proceedings are secret, and the judges are very unbiased.
so, is there a clear line between: steal trade secret, and applied learned experience in new company the way everyone does?
some call that a positive initiative. cross training between departments or some such corp speak is used so people can "fill in" or just have a better understanding of the other departments so you can possibly work better with each other or come up with novel solutions for someone else.
companies that silo everyone off and prevent open discussion between groups are horrible places to work. ask Oppenheimer.
There may be some grey, but copying information in writing is pretty clearly over the line.