Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In a large company, a useful thing to do if something fishy is going on is to go see the company's general counsel.[1] If they didn't know about it, they should be told. Their job is to keep the company out of legal trouble. In many cases they have a legal obligation to do something about it. An attorney will rarely tell you to do something illegal; they can be disbarred for that. If they tell you it's OK, then they've given you legal advice as an employee, which gives you some protection when things come unglued. You're also unlikely to be fired for talking to the company's general counsel.

[1] http://www.slu.edu/Documents/law/Law%20Journal/Archives/Dugg...



I'd suggest following up any conversation of substance with general counsel (or even the likes of HR for that matter) with an email detailing the conversation you just had.

Don't do it in an obtuse manner; let them know in advance that you will be sending it following the meeting, maybe even get them to suggest the wording of it if you aren't convinced of the security of internal mail.

It's easy for either side to forget the exact points raised during a conversation like that, so good for everyone to have a written record.


You might as well just quit if you think HR is there to help you at all. HR is there to protect the company from you.


Corporate counsel != HR.


But wait! The emails are being intercepted by the NSA and CIA...


In the case of NSLs, or UK orders from the security services, it may be illegal to tell anyone who isn't mentioned in the order. Including the company's general counsel.

In the event that you are asked to do something illegal, it may be illegal or inadmissible to mention that you were ordered to do so by the government (Matrix-Churchill trial passim)


Would be interested to hear a legal opinion on this. In the US, you do have a constitutional right to counsel (Assistance of Counsel clause of the Sixth Amendment), generally of your choice.

From my reading of the case law, the crux would be that right to counsel can only be invoked "at or after the time that judicial proceedings have been initiated against him, whether by formal charge, preliminary hearing, indictment, information, or arraignment."

Does an NSL constitute adversarial proceedings? Also, how does right to counsel work with other legal gag orders (e.g. if I'm cooperating to provide information on a criminal case but have been ordered not to inform the targets)?


IMHO you have a right to counsel because as a normal citizen, you can't be expected to actually understand if the letter is valid, legal, etc.

That's actually exactly why we have counsellors.


If you're the CEO or some other exec in receipt of such an order, you're not going to be able to single-handedly implement a backdoor without anyone noticing, even if you possessed the skill to do so in the first place.

The nature of such an order requires you to be able to tell the people who need to do it what it is that you need them to do, even if you can't tell them why.

Additionally, anybody with the power to veto such a change also must be provided with a good reason why they can't veto this one. Your legal counsel needs to understand why the change must happen, so he can respond appropriately to questions from pissed off developers and ensure that your company is complying with the letter of the demand (and no more).


I wonder how they think this is supposed to work.

- CEO gets a Letter. Does the CEO start learning Python/C++/PHP and Cisco configuration? Or does he tell a worker bee "Shhh! And read this Letter" ?

- Worker bee starts making changes to production code and systems. Suddenly he starts needing automated code reviews, and reconfiguration alerts go out when he frobs the firewalls. These changes are indistinguishable from an infiltrator with the worker-bee's credentials and ideally things are set up so that changes are generally shared around, a normal review process, to catch out-of-control worker bees.

- The build lab scripts are modified (by who?) to insert bad code. Oh, but the build checkers catch this ("Hey, we found a compiler bug!" / "Umm, no you didn't..."). Everybody starts handing around links to "Reflections on Trusting Trust".

- Things get even more exciting when the internal monitoring systems discover (say) equipment attached to the network that ain't supposed to be there. "Wot's all this then," says the network engineer, and he yanks the cables to the SkankSec-1000 that someone hot-wired into a rack. "Oh yeah, blue fiber is for NSA, green is for CIA, yellow is for GCHG, and black is for Russians, what else?" He leaves it unplugged. Let's ignore the security camera footage in the datacenter, since this is a thought experiment.

In an environment with self-monitoring for health and intrusion detection, applying changes for user surveillance requires quite a lot of internal cooperation and communication. No wonder the Yahoo stuff looked like a Bad Guy who got in.

We can probably extend the internal defenses to alerting on odd access patterns to sensitive database rows, too . . .


The easiest way is probably to create a bullshit project with a few people. We are only creating a new dashboard for X, this is cost reduction project, etc.

I don't know how Yahoo is organized but if teams works in silos, without any visibility on other teams, it is probably not that hard to introduced changes that are undetected.


In a place where everything is monitored, down to the MAC address of machines and their network traffic, ideally it would be difficult to sneak in a monitor.

Access to critical data should be similarly protected.

These are relatively tame intrusion detection systems that you would have to make changes to in order to remain undetected. That should be really hard to hide.


This is apparently pretty much what happened at Yahoo! when the security team found out the rootkit.


My understanding is that US requests explicitly include a clause that exempts your counsel from the NDA requirement, in that you're permitted to show it to and discuss it with them.

(They, of course, are bound to not share it further.)


That almost has to be the case. Otherwise, I get this "legally binding" order that I don't understand but looks scary, but I can't discuss it with my counsel? How am I supposed to tell the difference between that and a con job?


I'm in a right to work state, so they'll just find something else to fire me for.

Edit: But seriously, I'd take the job loss in a heart beat if my company was doing this crap.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: