9 ms·
It's immoral to discriminate on the basis of fear, prejudice, and rumor. One client can demand that Gitlab get rid of Chinese and Russian nationals today. Tomo
by 490d0aff0ee8 7y ago
It's immoral to discriminate on the basis of fear, prejudice, and rumor.
One client can demand that Gitlab get rid of Chinese and Russian nationals today. Tomorrow, a different client can make similar demands - aimed at the nationals of different countries. This makes no sense whatsoever, and will blow out of control quickly.
Sanction programs are the established legal frameworks for such things: https://www.treasury.gov/resource-center/sanctions/programs/pages/programs.aspx https://www.treasury.gov/resource-center/sanctions/programs/...
It's disappointing to see the promise of some money making the company go full 180 on its hiring and employment procedures - going as-far as potentially rescinding one employee's offer, and flagging another employee's personal choice to live in a different country as a risk.
The due process here is concerning. Some techbro starts by creating a "we need to block all Russian/Chinese" issue - followed by a bunch of echo-chamber "yessir" comments. When a legal advisor steps in - everyone tries to silence her and convince her it's just an "iterative process".
Finally - it actually looks like Gitlab's security practices are truly lacking. That an employee is Chinese/Russian shouldn't be a consideration - the systems should be tight enough to make sure absolutely no-one has access to customer data without consent - and that any actions taken are logged for auditing. Whenever necessary - pass your employees through a background-check. In sensitive (government) scenarios - restrict to employees with government clearance.
Honest question: Is Gitlab now a company not in a position to say "no"? Investors and potential customers need to know.
- m0xte 7y agoIf you look at the vetting processes in the defence sector they have strict nationality and background checks. Why should the same not be true for something with a damage multiplier the size of github which is basically carrying a big chunk of commercial IP in private repos?
- jiofih 7y agoI think that last paragraph is suggesting that GitLab could simply reject such clients - or better, direct them to the self-hosted plan where they have full access control.
- m0xte 7y agoThat's a fair point for sure.
- 490d0aff0ee8 7y ago> "If you look at the vetting processes in the defence sector they have strict nationality and background checks. Why should the same not be true for something with a damage multiplier the size of github which is basically carrying a big chunk of commercial IP in private repos?" I'm all for background checks. Those at-least try to give everyone an equal opportunity - and if you fail them, you'll know why and have a chance to challenge the decision. There is a due process - as opposed to having some random techbro creating "need to get rid of {arbitrary nationality} asap" issues and having a bunch of random employees debating it... If by having "nationality requirements" you mean "being a US citizen" - then Gitlab will lose 50% of its workforce overnight. The same will be true for many other tech companies. You make it sound like the defense sector is enjoying the strict employment regulations...
- m0xte 7y agoThe issue is not necessarily the background checks but the fact that you can be compelled by the state you reside in after the fact. For example the state could target known employees of GitHub after they are employed and checks passed. I'm not suggesting any national correlation here. I suspect the same is true for Chinese and Russian companies too! As for the defence sector it is not enjoying it, at least in Europe as the incoming staff into the sector are shrivelling up pretty rapidly.
- swongel 7y agoLol, our employees who have access to sensitive data cannot be citizens of: - A country the country our company is based in is currently in war with. - A communist dictatorship known for pressuring its citizens into stealing IP/corporate secrets abroad. It's not arbitrary banning from foreign countries on your client's request if there's actually good reasons to take precautions with these nation-states. And why not? They're a private company they can choose to employ whomever they want as long as they're compliant to local labour laws. There's no "due proccess" in business. "Finally - it actually looks like Gitlab's security practices are truly lacking. That an employee is Chinese/Russian shouldn't be a consideration - the systems should be tight enough to make sure absolutely no-one has access to customer data without consent - and that any actions taken are logged for auditing. Whenever necessary - pass your employees through a background-check. In sensitive (government) scenarios - restrict to employees with government clearance." Don't improve HR security practices because you're vulnerable in different ways anyways? If you as a company simply don't trust the government your employees work under, you cannot trust them with sensitive information, even if they're outstanding trustworthy people.
- droidno9 7y agoCompanies don't make decisions based on morality. This is a question of liability. Gitlab's liability, based on whatever internal metrics being measured, would be significantly higher than the potential economic rewards of having employees in sensitive positions in these two countries--at the moment. Also, on a side note, morality != legality. They're two different things. What is moral isn't necessarily illegal, and vice versa. There's no need to beat up the strawman "techbro." It seems to me that this was a difficult decision to make and somebody had to make it. Damned if you do; damned if you don't.
- jka 7y agoThat was roughly the reading of this issue that I assumed initially too, but in fact the liability/reward situation is reversed here, I think. GitLab are considering making this change in order to satisfy the requirements of a potential customer[0] - i.e. the reward is for adding the restriction. And in turn, making the change itself could increase liability[1] since it doesn't seem to be based on a legal request or existing defensible GitLab policy. [0] - https://gitlab.com/gitlab-com/www-gitlab-com/issues/5555#note_237506130 https://gitlab.com/gitlab-com/www-gitlab-com/issues/5555#not... [1] - https://gitlab.com/gitlab-com/www-gitlab-com/issues/5555#note_239385982 https://gitlab.com/gitlab-com/www-gitlab-com/issues/5555#not... The thread reads like a case of the compliance arm of the business trying to keep the ship steady and non-discriminatory (which is in-line with GitLab's stated goals, the intent of the law, and likely in-line with their prospects as a long-term global employer), while a sales part of the organization tries to close a deal. Putting in additional engineering effort to allow the customer to specify their own policy on SRE/support access to data -- which they'd be responsible for defending if there were any questions -- seems like it might be a way forward. Whether the sales team and customer would wait for that is another question. It's remarkable and very progressive to see this discussion in the open; it's also interesting to note how many side-discussions and different opinions emerge in the comments and in discussion here, while the core communication continues between a small number of participants in the merge request.
- 490d0aff0ee8 7y ago> "Companies don't make decisions based on morality." So let's just label every employee with a Foreign/Chinese/Russian background as a spy, because a client says so?
- hkai 7y agoIf it makes no sense whatsoever, why do you think it makes sense to some other people?
- rossmohax 7y agoDirector of Compliance raised very similar concerns in the discussion over there, it's funny (not really) to see how our good old friend Paul (CFO) stomps over it again
- arkitaip 7y agoGitlab's CFO Paul Machle is becoming a liability to the reputation of the company.
- deleted 7y ago[deleted]
- mbesto 7y ago> the systems should be tight enough to make sure absolutely no-one has access to customer data without consent - and that any actions taken are logged for auditing. You haven't really done OpSec have you? There is very little absolutism in defining who gets access to what data. In fact barring nations that have historically shared data with their governments is exactly one step closer to how you would achieve this. > Investors and potential customers need to know. Says the guy hiding behind a throwaway (new?) account...
- 490d0aff0ee8 7y ago> "You haven't really done OpSec have you? There is very little absolutism in defining who gets access to what data. In fact barring nations that have historically shared data with their governments is exactly one step closer to how you would achieve this." When was the last time you've contracted for a serious client? When it comes to tech - you don't implement "OpSec" by blanket banning hiring Chinese/Russian individuals. Disregarding your bizarre definition of "OpSec" - plenty of individuals with Chinese/Russian background are working for companies such as Google/Microsoft/Facebook/Uber - making significant contributions and getting paid vast sums of money for it. Those companies actually invest into background checks, have dedicated security teams, are investing into locking networks down and improving monitoring. It appears that Gitlab simply wants the easy way out, or, they can't afford to refuse the aforementioned client's offer.
- mbesto 7y ago> When was the last time you've contracted for a serious client? Uhh, today? I have about 20 on-going contracts with "serious clients", which include manufacturers, distributors, software companies, etc. What's your point? > When it comes to tech - you don't implement "OpSec" by blanket banning hiring Chinese/Russian individuals. Disregarding your bizarre definition of "OpSec" Banning hiring from countries isn't an exclusively isolated tactic for executing OpSec...I'm not sure why you implied that. > Those companies actually invest into background checks, have dedicated security teams, are investing into locking networks down and improving monitoring. Those companies all have physical presences in those countries. Gitlab does not. BIG DIFFERENCE.
- el_cujo 7y agoI think you're being a bit disingenuous. It seems you're almost implying Chinese and Russians are being randomly discriminated against for no reason, as if the kind of thing Gitlab is worried about has never happened before. Specifically with people loyal to those two countries. Yes, it is discrimination, whether it is baseless discrimination is much more debatable.
- 490d0aff0ee8 7y ago> "It seems you're almost implying Chinese and Russians are being randomly discriminated against for no reason, as if the kind of thing Gitlab is worried about has never happened before. Specifically with people loyal to those two countries. Yes, it is discrimination, whether it is baseless discrimination is much more debatable." Do you have concrete numbers that prove Chinese/Russian workers are significantly more likely to act in bad faith against the companies they work in? To quote Gitlab's chief legal officer, @cciresi: > "The highest risk countries for hackers are: Romania, Brazil, Taiwan, Russia, Turkey, China and the United States (The US ranks number two in hackers according to ABC news). Surely, we aren't going to start restricting employment on all these countries?"
- president 7y ago> It's immoral to discriminate on the basis of fear, prejudice, and rumor. Except for the fact that state-sponsored hacking and IP theft is a real thing. Your comment reads as naive and extremely uninformed. I would invite you to read the Huawei "Tappy" indictment [1] to understand the lengths that certain nations go to steal from US companies. Here we have a company that is literally offering cash bonuses to their employees for stealing IP. > the systems should be tight enough to make sure absolutely no-one has access to customer data without consent If you read the indictment, you'll realize that these rogue employees don't care about audit logging or any punishment that follows as a result of getting caught. In many cases, all they have to do is fly back to their country and they'll be rewarded and regarded as heroes for their loyalty to their country. [1] https://www.justice.gov/opa/press-release/file/1124996/download https://www.justice.gov/opa/press-release/file/1124996/downl...