5 ms·
> Nvidia did hire him precisely for his previous experience at this rival company, on the very same project that the two companies were partnered on, which is t
by juunpp 3y ago
> Nvidia did hire him precisely for his previous experience at this rival company, on the very same project that the two companies were partnered on, which is the same project that Nvidia hired him for.
Yes, this happens all the time.
> There is no argument to be made that Nvidia wasn't aware he'd be coming with secrets.
This is not a logical conclusion from the above. Hiring for the exp is fine. Hiring for the trade secrets obviously is not. No serious company would do the latter, esp a company the size of Nvidia.
- devmor 3y ago[flagged]
- takinola 3y agoRisk is always balanced against reward. I doubt Nvidia is culpable here not because I have some strong belief in their morality but because I trust they would not take stupid tradeoffs.
- Retric 3y agoThe exposure was unexpected so the risk was likely perceived as low. That said, the discovery process could clear NVIDA.
- actionfromafar 3y agoThat puts a lot of faith in a lot employees.
- margalabargala 3y agoIMO this is more of a "don't ask don't tell" thing. I'm sure there was never an explicit agreement that the employee would bring trade secrets, but they can promise to be able to build for Nvidia what was built at the last company, and Nvidia could say "yes I want that", and not audit the new employee's dev environment.
- FirmwareBurner 3y ago>IMO this is more of a "don't ask don't tell" thing. I assure you isn't. If your company (in the law abiding west) has any suspicion you're using another company's illegally obtained proprietary IP, they won't see you as some hero doing God's work and put you on the promotion track wile closing a blind eye to what you're doing, but they immediately ask you to delete everything and every trace related to that. Foreign IP is radioactive and they don't want to get sued because you're bringing some source code and PDFs from their competitor, which might not even be that useful for them anyway. There were even cases of companies ratting out their employees they found using IP they stolen from their previous employers and getting them arrested, because if you stole IP from their competitor what's stopping you from also stealing from them? >not audit the new employee's dev environment Audit how? Against what? Stolen foreign source code you don't have? That's just not realistically possible to audit every employees work and accurately determine if they are or not reusing source code they stolen form a competitor, especially if the employee doing this is careful to change or redact what he's checking in. Only thing you can audit is against FOSS code that is public, but not if it's stolen proprietary code and the employee made sure to not check-in anything giving away the origin of the original IP holder. They didn't catch this guy until he got sloppy and made this huge blunder. You can never secure everything and audit everyone, especially if you want people to get any work done and not feel violated, so everything boils down to trusting employees they won't steal from you, and trusting the legal framework and law enforcement they'll do their job when in need, so you just have everyone sign NDAs and hope for the best.
- winocm 3y agoA thought that came to me recently in the shower: Isn't all knowledge effectively based on previous knowledge, and by extension, experience? i.e: A programmer knows how to do X, leaves a company to do Y, where Y is in the same field of work as X. Doesn't X still affect the programmer on a subconscious level and henceforth, their thoughts indirectly?
- jfim 3y agoYou can bring your expertise in X without the source code that does X. The former is legal, the latter is not.
- FirmwareBurner 3y agoBringing knowledge is one thing, which is legal, but stealing source code and design files from your employer to copy it to the systems of their competitor where you now work is a completely different thing which is illegal. Companies want your knowledge, not you bringing proprietary IP from their competitor to work, as they know that's a very expensive lawsuit waiting to happen.
- wombatpm 3y agoBut what if I have an idemic memory?
- FirmwareBurner 3y agoThen you'd be able to draw and type out everything from scratch directly on your employer's PC and not have to download it via USB drives or email, like this guy did.
- chii 3y agoSo if you obtained an idemic memory via installing a camera, flash drive and io ports into your brain? How or why is the mere transport method of information the distinction between infringement of IP vs not?
- zik 3y ago> No serious company would do the latter It happens literally all the time: [1] https://www.theguardian.com/technology/2019/aug/27/anthony-levandowski-google-trade-secrets-theft https://www.theguardian.com/technology/2019/aug/27/anthony-l... [2] https://www.theverge.com/2022/8/22/23317502/xiaolang-zhang-pleads-guilty-trade-secret-theft-xpeng-self-driving-car https://www.theverge.com/2022/8/22/23317502/xiaolang-zhang-p... [3] https://www.justice.gov/usao-ma/pr/former-engineer-sentenced-possessing-stolen-semiconductor-trade-secret https://www.justice.gov/usao-ma/pr/former-engineer-sentenced... [4] https://apnews.com/article/korea-samsung-china-copycat-semiconductor-bfdf3ad9f817f646d0d47294f62e334f https://apnews.com/article/korea-samsung-china-copycat-semic... [5] https://www.reuters.com/technology/twitter-may-face-difficulties-showing-meta-stole-trade-secrets-2023-07-07/ https://www.reuters.com/technology/twitter-may-face-difficul...
- beardedwizard 3y agoThis proves individual employees routinely steal trade secrets; yes, they do. It does not prove that the companies they join (US public companies in the United States anyway) willfully use it. Think about the large scale conspiracy required to keep something like that secret from an entire company.
- mcpackieh 3y agoThere's no need to rope conspiracies into this. The structure of incentives in corporate environments have people in the company not looking for something they don't want to find. Managers would rather not know about violations and be able to tell their boss that their team are pros who got the job done fast, than investigate their reports for violations and quite possibly find a big mess that needs to be cleaned up. Point is, shit that shouldn't happen routinely does happen anyway. "That wouldn't happen because it would be illegal" is generally bullshit.
- juunpp 3y agoCompanies of this size have routine code audits that would find copyright infringements of this sort. If the employee literally brought in source code files and not even change the name of the directory like it was highlighted here, it'd have been caught. The audit is also not conducted by the manager, but a third party. There is no possible way this would fly unless the individual intentionally stripped the source of copyright notices (the individual's fault), or the source code was just sitting on their laptop and never acted upon, etc. So I think the question (and I'm not a lawyer...) is whether Nvidia conducted such audit and to what extent (if any) the other company's source code was merged into theirs (versus just sitting on the laptop).
- Guthur 3y ago[flagged]
- bsder 3y agoAgreed. NVIDIA has always been a no holds barred competitor willing to push the boundaries of both truth and legality.
- fnord77 3y agoAnd nobody at NVDA noticed when the employee pushed several GB of code into NVDA's repos?
- juunpp 3y agoWhere is the proof that the source code was merged? The article only mentions that former employees caught an eye of the source on the individual's computer; it does not mean the source code was merged or acted upon.