7 ms·
> The agent said Tan handed the flash drive over to the US company, and the firm found that the deleted files would have allowed his new employers to recreate t
by yerich 8y ago
> The agent said Tan handed the flash drive over to the US company, and the firm found that the deleted files would have allowed his new employers to recreate the product in question. The files had been deleted from the flash drive the day before Tan resigned, the affidavit said.
Call me confused, but I don't really see a crime here? The defendant turned over the data before his resignation and is not accused of actually making an attempt to transfer or sell the data to another party, or conspiring to do so. The only accusation is that he had some files that weren't part of his job to have, apparently. But presumably the internal corporate system allowed him access to it and thus he obtained it without breaching any computer system. Perhaps his workplace policy barred him from downloading files onto a USB drive. But is that considered theft?
- abrawill 8y agoWhy were they on the USB drive is what I’d like to know.
- pfortuny 8y agoWell, if the documents contain trade secrets... You may see them on your boss’s desk and read them and memorize them. That does not make your making a copy of them (even from memory) right or lawful.
- baybal2 8y agoI think that's the second Micron case. An exec reports "phone stolen," phone found in his "collaborator's" locker who accidentally shoved it into her bag along with other papers on the table. Both the exec who reported theft and his "accomplice" are send to jail, and a "national security" case just sprung up from two completely unrelated cases thanks to prosecutor's creativity. Same thing here: 1. Apparently they found that he simply had "weird files" on his flash drive. 2. He had full right to access them. 3. He deleted "weird" files he had rightful access to, and voluntary surrendered the physical medium upon his resignation. On the sole premise of him deleting "weird" files, he was accused of espionage, with the charge constructed from nothing but tangents, but no "corpus" to "habeus."
- marcoperaza 8y agoWhen you work somewhere, you end up having access to all sorts of stuff. E.g. through the issue tracker, you might be able to see things about projects that are supposed to be secret (as in company-secret, not government-secret). If you resign and your usb drive has a bunch of deleted files about that stuff, that has nothing to do with your job, that’s a reasonable basis for serious suspicion. You don’t need a smoking gun of a crime to be suspicious that a crime may have been committed. Suspicious facts are plenty to start investigating, and a mountain of “circumstantial” evidence can even be enough for a conviction. I don’t know anything about this case, and I’m not accusing this guy of anything, but your line of argument is wrong.
- baybal2 8y agoIt is your line of argument is wrong, patently wrong. That's all about accusing a man of murder without proving that the person being murdered is dead. That's unjust, and is a joke of justice, and most fundamental legal standards of criminal law jurisprudence. Man, who taught you all that?
- perennate 8y agoIn the U.S., the defendant can only be convicted if the evidence proves guilt beyond a reasonable doubt. Hongjin has not been convicted yet, so I don't follow the logic in your comment. The criminal case process has only just started and we have not seen the full evidence yet, and there has been no determination by the court system on whether or not he is guilty. I think there is some confusion because of the differences in the judicial process between the U.S. and other countries like China. I'm not saying the U.S. judicial process is perfect, but I think it's unreasonable to attack it before a verdict has even been issued.
- mdorazio 8y agoThat's not how criminal investigation works, that's how a witch hunt works. In order to be a legitimate criminal investigation, the first part needs to be that an actual crime was committed, then suspicious activities are used to justify an investigation and possible conviction based on evidence. Otherwise, police could just run around arresting people because "that guy looks suspicious", search all their stuff and activities for something possibly illegal, and then say "look, we were right all along".
- mac01021 8y agoHow much did that company recover of the files? Is it possible that tan deliberately deleted them in such a way that they could be recovered forensically? That might save him from getting caught, and his "handler" overseas could even have recommended it. But who knows... This article doesn't provide enough information to make a good guess at what was going on.
- baybal2 8y ago1. He surrendered USB sticks he used inside the company upon resignation. 2. They found confidential files there, but nothing he had no right to access to 3. They found out that he deleted "weird" files the day before he quit the company. He could not have ever exfiltrated that data to begin with as he gave the drive back to Philips.
- mac01021 8y agoI'm not saying he stole data or even did anything wrong. But he could certainly have copied data off the USB before deleting it.
- baybal2 8y agoWELL, the main question: WHY THE HECK did he report on himself??? The charge pretty much says that he voluntarily contacted his supervisor and asked what to do with that USB stick. And there, the parallel with Micron case gets more startling: the alleged "spy" was the very man who said that his cellhpone was missing. Then the police found the cellphone in his coworkers locker. The coworker accidentally put his phone into her back along with papers on the table. Then the police searched his phone, and found out that "he happened to be a spy" on very similar circumstances.
- arcticfox 8y ago> WHY THE HECK did he report on himself??? I mean, he deleted the files first. It's reasonable that he thought that was sufficient; given the code I've seen from some scientists, scientist != computer expert. The innocent explanation is that he was cleaning up company property before returning it, but I expect that will play out in court.
- gralx 8y ago> ... The defendant turned over the data before his resignation ... The FBI affidavit contends Tan deleted the confidential data before leaving the U.S. company, not that he turned the thumb drive over to them. The charges suggest Tan kept the drive after leaving the company, though the article doesn't say so explicitly. Correction: The affidavit does say Tan turned the drive over to them, and of his own initiative, after he was escorted from the company's premises. See paragraph 17 of the affidavit that user baybal2 links to below.
- baybal2 8y agoNo, he gave up the drive and everything he had from company's IT for review. They are very purposefully avoiding mentioning that, but logically you can't conceive of how they can review the thumb drive without him willingly giving it to them first, nor that he had authorised access to such data in the first place. The charge says nothing about his accessing the data unlawfully, other than saying that he had "no reason" to access it, and it being outside of his immediate responsibility. https://www.justice.gov/opa/press-release/file/1122851/download https://www.justice.gov/opa/press-release/file/1122851/downl...
- gralx 8y agoFair enough. I assumed the parent's source was OP's article.
- perennate 8y agoI think you're misunderstanding the process in a criminal case. The affidavit that you linked to explicitly states: > This affidavit is intended to show merely that there is sufficient probable cause for the requested warrant and does not set forth all of my knowledge about this matter. The full evidence will come out in a court case, and a decision on whether or not he is guilty will be made based on that full evidence. He has only just been charged and the court case has not started yet.
- jgowdy 8y agoAs dguido posted below, the details are a bit different than the tiny pair of sentences you're basing your analysis on. > On 12/12/2018 at approximately 10:30 a.m., Tan contacted his supervisor, advised he was resigning from Company A, and gave his two weeks' notice. Tan told his supervisor that he was returning to China to be with his family as he is the only child to aging parents. Tan told his supervisor that he did not currently have a job offer, but was negotiating with a few battery companies in China. > Tan's resignation prompted Company A to revoke his access to company systems, and conduct a Systems Access review of Tan's computer activity. > That review confirmed that Tan had accessed hundreds of files, including research reports. The reports included not only how to make Product A, which, according to Company A, is a complicated and technically difficult process, but also Company A's plans for marketing Product A in China and in cell phone and lithium-based battery systems. These files included information that Company A considers to be trade secrets and outside the scope of Tan's employment with Company A. The review revealed Tan downloaded restricted files to a personal thumb drive. In the course of his regular duties and responsibilities, Tan should have used his company issued laptop. Tan did not have authorization to use a thumb drive to download Company A files. Tan's supervisor confirmed that nothing in the downloaded files was within Tan's area of responsibility. Further Company A confirmed, through Tan's supervisor, Tan did not have a work related need to access or download the restricted files.
- deleted 8y ago[deleted]
- ams6110 8y agoHow does this actually work? Does Windows keep a log of files accessed or copied? Or does the company install additional security software that audits this?
- ganoushoreilly 8y agoThere's lots of things in play, system logging, storage/file share logging, network traffic logging, authentication logs etc.
- reaperducer 8y ago
- pointillistic 8y agoI sometimes feel that people who comment here of the Chinese spying stories are the Chinese agents. First comment is always dismissing the story. Is anyone at HN looking where the comments originate?
- mistrial9 8y agoraise your hand if your un-advertised Linux server is attacked daily from China
- mountainofdeath 8y agoIf you want to see something, install MySql on a AWS EC2 (or any host for that matter), turn on verbose logging and open it to the public internet. I saw thousands of Chinese bots trying every way to get root access
- mroche 8y ago(ノಠ益ಠ)ノ彡┻━┻ Every. Damn. Day. Particularly at the university, I was setting up a GitLab box that wasn’t supposed to be externalized (didn’t realize at the time that LAN utilizes the public addresses instead of NAT). 90K ssh attacks in 3 days, vast majority from the east Asia area. Luckily none made it through. Learned my lesson (and firewalld) from that experience. Nearly had a panic attack from that (first time setting something up like that). The above was from my naive days before I started getting more deeply involved in sysadmin and networking work. It’s still incredibly annoying to log in to systems with “There have been 173 failed login attempts since the last successful login.”
- Teknoman117 8y agoWhen I set up my first gateway/router server for the first time, I was truly shocked to see how much traffic comes in searching for vulnerabilities. I knew it happened, but the frequency was wholly unexpected. SSH requests for root, SMB traffic, etc. every second or so.
- hatersgonnahate 8y ago
- cavanasm 8y agoThere's an FBI affidavit linked in another comment that mentions a search warrant found additional copies of the data at his home, and that he'd been in regular contact with a Chinese competitor, who offered him a job and ~$60k US signing bonus based on vaguely phrased information already provided.