back

by awnird·12y ago·view on hn ↗
This is incredibly troubling. How can anyone trust GitHub, knowing that non-employees regularly had access to private information?
6 comments
What about de-facto board members? Tom was on GitHub's board, it was/is a small company, I don't get how "founder's wife" is not a suitably trusted position. I mean, clearly a bad call in this case, but hindsight is 20/20, and in my small business the husbands of my co-founders are de-facto employees (And in fact board members with significant proxy voting power, simply by state law of common property).

Edit: I looked it up; California, too, is a community property state. Theresa was absolutely an effective board member.

That's not how community property works. Teresa effectively owned an indivisible half of Tom's Github stock via the community property laws, but this does not make her a board member. Board members are selected by the company pursuant to various legal mechanisms not subject to community property laws because a board position is not a "property."
You should really get a better lawyer.
Most corporate startup lawyers have founder's spouses sign release forms for to clearly indicate that they do not have some claim to ownership or equity.
This.

I just drafted a stock purchase agreement for my business partner and I on our new startup and one of the basic boilerplate additions to the stock purchase / vesting agreement is a spousal agreement to the terms of the purchase.

The communal property law only relates during a divorce were the shares are split up between the couple by the courts. Any decently written stock purchase agreement has a first right of refusal for the company to purchase back those shares in the event of an involuntary transfer.

Well, we don't know that. It's an allegation by one person which hasn't been confirmed as being true by GitHub. And presumably after this incident, if it is true, they'll have better security policies going forward.
This is incredibly troubling. How can anyone trust ${CLOUD_OR_HOSTING_COMPANY}, knowing that ${PERSONS_OR_SOFTWARE} regularly had access to private information?

Be paranoid. Encrypt it if you don't want people to snoop.

In my experience it is pretty common for people who bring work home with them not to be super-meticulous about preventing access to the content of the work by their families. How many people do you know who sound-proof their home office so their wife can't eavesdrop on their business calls?
I think I should point out this is a fireable offense in a number of companies. I work with sensitive information every day. I'm pretty sure if allowed someone outside the company to use my machine for anything, I would be fired.

My dad works for IBM doing mainframe repair and installation. He's seen his coworkers fired for allowing unauthorized individuals to use their company laptops. They've gone even further in the last few years in making unauthorized software a fireable offense.

Granted, two data points isn't a lot but there are companies that have enforced policies to prevent sensitive information from leaking.

I should also point out both my dad and I do significant amounts of work from home and we are both required by our companies to use full disk encryption.

Without going to the extreme of secret+ classifications -- in which case you cannot take things home without a secure home office, and move things between them in secure containers -- I don't think employees are fired for failing to lock their home office against their spouse or soundproofing their office against their spouse.

Which is different from saying that the company would fire them if the spouse used their inside-access to harm the company in any way.

My girlfriend works on disclosure projects at a company you've heard of and who regularly has highly-anticipated announcements. I have no idea what she works on, even when she's working from home in the same room as me[1].

1. http://www.officedepot.com/a/browse/laptop-privacy-filters/N...

I think that people that can and do bring work home are employed in fields where one does not need to be super meticulous about preventing access to the work.
You would think wrong.

Very wrong.

You know a lot of people that bring work home because the living room has better reading light than the SCIF?
No, people bring work home because they need to put in some extra hours, but do not wish to stay at the office until 9PM.
So you know a lot of people that take things out of the SCIF because they do not want to stay late?
Depends on what you mean by SCIF. Coworkers bring confidential paperwork/documents home, and remote access over remote desktop software is blessed. However you might get a phonecall from security if you started downloading lots of confidential data directly to your home computer.
There's a pretty big difference between sound proofing your office and giving your wife unfettered access to the corporate network.
How can you "trust" GitHub knowing that employees regularly have access to private information?
Why does anyone trust _______, knowing that employees regularly have access to your private information?
That's the $BB++ cloud question, isn't it?

In short, many vendors go to great expense to vet, audit, and limit the number of employees who could potentially access customer data. Some will geo-locate physically separate systems under separate administration according to regional necessity.

Disclosure: works for such a vendor.

Sure, but this can only be appreciated if the relationship is large enough to have an explicit non-changeable contract and routine auditing. From any lone consumer's point of view, "cloud" providers are black boxes that will probably try to limit the damage a rogue employee can do, but any methods or promises can change overnight based on business needs.
Especially knowing that x% of those employees will have left the company in 5 years, and y% of those will have taken private copies of customer data with them.
i don't trust them. I simply have no choice.