GitLab Considers Ban On New Hires In China and Russia Due To Espionage Fears (zdnet.com) 41
GitLab is considering blocking new hires from countries such as China and Russia over espionage fears. "There is a general train of thought that both Russian and Chinese intelligence agencies might use the same blueprint and plant agents or coerce GitLab staff into handing over data belonging to western companies," reports ZDNet. An anonymous reader shares an excerpt from the report: Eric Johnson, VP of Engineering at GitLab, said discussions on banning new hires from the two countries began after enterprise customers expressed concerns about the geopolitical climate of the two countries. If approved, the hiring ban will apply to two positions; namely Site Reliability Engineer and Support Engineer, the two positions that handle providing tech support to GitLab's enterprise customers. Johnson said these two support staff positions have full access to customers' data, something that companies had an issue with, especially if tech support staff was to be located in countries like China and Russia, where they could be compromised or coerced by local intelligence services. Johnson said GitLab does not have "a technical way" to support data access permission systems for employees based on their country of origin. "Doing so would also force us to confront the possibility of creating a 'second class of citizens' on certain teams who cannot take part in 100% of their responsibilities," Johnson said.
The new "hiring ban" is not yet final. Open conversations on the topic started last month, and are scheduled to end November 6.
The new "hiring ban" is not yet final. Open conversations on the topic started last month, and are scheduled to end November 6.
oddly India is missing from that list (Score:2)
Re: (Score:2)
Sadly, they do not pay full attention. Bringing Windows into a nuclear plant is about as stupid as you can get. 'Blue screams of death' has real meaning for those situations.
Re: (Score:3)
Use of Windows in life-threatening situations like medical or power has always been a EULA violation.
Re: (Score:2)
Parts of it do (the ABS brakes for example). But Android is only used for the infotainment system which only has a I2C link to the car's control system.
Re: (Score:1)
If I were to pick a top five nations that use spies, India wouldn't be in there.
China, US, Russia, North Korea, Israel ... probably in that order, with Russia ahead if you want to talk about spies-per-capita.
Re: (Score:2, Interesting)
Re: (Score:2)
Re: (Score:1)
Github originally never took these sorts of rhetorical steps
What does that have to do with GitLab?
Re:this smacks of pandering. (Score:4)
I know it's traditional to not RTFA. We've even seen some pioneers not reading the summary. Where can we go from here? That's right. We're not even going to read the article's title! It's a brave new world of not reading Slashdot.
Re:this smacks of pandering. (Score:4, Informative)
...changing your corporate policy to match a federal policy is just corporate desperate virtue-signalling.
That looks more like a problem with the corruption in your government than any problem with Microsoft.
"Pandering" (Score:3)
...but Microsoft, their current owner, has been known for more than 3 decades to pander to Washington in order to curry favour with the party-du-jour.
It's not "pandering" to recognize that the Chinese government uses every worker in the West essentially as espionage agents, and its policy is to hoover up as much IP from the West as it can from those workers, scientists, and technicians.
Re: (Score:2)
somebody is getting smarter, BUT... (Score:3)
One of the most important issues is that a number of Indian coders have actually worked closely with Russia.
Re: somebody is getting smarter, BUT... (Score:2)
Yeah, and what is up with the article talking about them compromised by their own intel services? Would the NSA (if you are American) have to blackmail you into working for them, or would they have to ask and write a check? Compromising is what they do in other countries.
"There is no cloud ..." (Score:3)
"There is no cloud. There are only other people's computers."
Re: (Score:2)
"There is no cloud. There are only other people's computers."
Often times "other people" are large corporations. And "Computers" are servers with lots of storage capacity. But yeah.
Re: (Score:2)
If they're in the U.S., that would be illegal (Score:4, Informative)
blocking new hires from countries such as China and Russia
If GitLab is hiring for positions in the U.S. with this policy, then it is in violation of federal law that prohibits hiring discrimination based on national origin.
However, if it is merely refusing to hire people in those countries to work in those countries, then no so much.
Re: (Score:2)
Yeah it is pretty much blatant racism and prejudice, they should not even have said it, it looks really bad. Even it is relatively likely, especially with huge growth in tech and quality of life in Russia and China and less motivation to risk life and limb in trigger happy USA.
Although the US government could simply create security passes for high tech jobs that companies could align with and require employees to obtain and then it is the governments fault.
M$ are just being dicks though because of course
Re: (Score:3)
GitLAB
Re: (Score:2)
Re: (Score:2)
No nation has to work with, hire, look after another nations citizens...
Re: (Score:2)
None of which has anything to do with my post.
Re: (Score:2)
blocking new hires from countries such as China and Russia
If GitLab is hiring for positions in the U.S. with this policy, then it is in violation of federal law that prohibits hiring discrimination based on national origin.
However, if it is merely refusing to hire people in those countries to work in those countries, then no so much.
I was going to rant that this is a replica of the Federal hiring policies which have brought us gems like the FBI Russian analyst adverts: https://www.fagain.co.uk/node/... [fagain.co.uk]
After READING THE ARTICLE, I can't rant. Bummer. What gitlab did is the normal policy and it mirrors similar policies run by nearly all countries, including the Russian themselves. Actual customer support positions referred to in the article are always limited to specific countries and in many cases additional vetting. F.E. you cannot s
What a shallow argument! (Score:1)
GitLab is considering blocking new hires from countries such as China and Russia over espionage fears.
So [dangerous] hackers can only be geographically located in Russia or China?
No wonder the USA is slowly losing its clout. The Danish just scoffed at the US - going ahead with approving Nord Stream 2 despite all threats the USA threatened...
Re: (Score:1)
No it's not. Like it or not, we're in a cold war. If it were racism, this would extend to american citizens of chinese or russian ancestry, but it doesn't; it's explicitly a ban on foreign nationals.
pointless (Score:2)
why would you host... (Score:3)
Re: (Score:2)
You can monitor your own employees. If you outsource your services, you typically can't control your contractor's employees. The best thing to do is not to outsource, you can run a local instance of GitLab which I do regularly for 'sensitive' applications.
No issue. They can have our code (Score:2)
It's so bad it will destroy their country like it destroys our company.
Oh by the way, we accept pull requests.
But ... but ... but (Score:1)
That's WACIST!