CEO Catches Stranger After Hours, Prompting Espionage Charges (wsj.com)
An anonymous reader shares a report: Samuel Straface thought he was the last one out the door one recent evening at the medical-technology startup he leads in suburban Boston. But as he passed a glass-walled conference room on the second floor, Dr. Straface says he saw a man he didn't recognize, sitting by himself in front of two open laptops and a tablet device. He continued walking a few steps toward the exit, but then, feeling uneasy, he turned back (Editor's note: the submitted link could be paywalled; alternative source). The man was later identified as Dong Liu, a dual citizen of China and Canada. And his after-hours computing at Medrobotics is at the center of an economic-espionage case brought by U.S. prosecutors. Mr. Liu is in federal custody, charged with attempting to steal trade secrets and trying to gain unauthorized access to the company's computer system, prosecutors said. If convicted of both charges, he could face a maximum sentence of 15 years in prison. "Mr. Liu adamantly asserts his innocence and we fully expect he'll be exonerated after a careful review of the evidence," said Robert Goldstein, Mr. Liu's defense attorney. The U.S. attorney's office for the District of Massachusetts declined to comment on the case beyond details in court records. Before his arrest, police said Mr. Liu told them he was there to discuss doing business with the company -- but Dr. Straface says no one had scheduled a meeting with Mr. Liu.
"The man was later identified as Dong Liu, a dual citizen of China and Canada."
As a non-American this Dong is obviously a victim of racism -- which only exists in America -- and should be given an award for liberating information that wanted to be free from the clutches of evil racists like that CEO who DISCRIMINATED against Dong by using his brain.
You never discriminate against Dong.
[P.S. --> If that fucker had been a Russian then executing him on the spot and using it as indisputable proof that Trump committed treason in the election would be cool though. Xenophobia is only bad against some foreigners based on political convenience after all]
AntiFA: An abbreviation for Anti First Amendment.
I don't understand why we have paywall-ed links on the front page.
https://beta.theglobeandmail.c...
If you must moderate, please moderate as irrelevent, not something bad, because I'm sure someone will find this interest
A couple of sources that aren't paywalled:
https://execsecurity.com/news/...
http://www.cetusnews.com/busin...
They will be less likely to cheat next time.
"Mr. Liu told them he was there to discuss doing business with the company..."
Yes. Obviously. Exactly like a fox goes into a hen house to "do business" with the chickens.
I've calculated my velocity with such exquisite precision that I have no idea where I am.
But I think it's pretty clear from some of the stories about Chinese espionage that the only way we can disincentivize civilians from doing stuff like this is to completely upend their existence. Ex charge this guy with economic espionage, violating the Computer Fraud and Abuse Act and whatever else, then throw everything from criminal trespass to theft of services (if he's on the company's network).
Honestly, if you are in a field that is competitive enough where others would want to copy your work, you should at least take the proper measures to ensure that somebody cannot just walk in the building and access your data. Your drives should be encrypted at the very least.
Anons need not reply. Questions end with a question mark.
And it's all part of the new Cold War III we're in right now.
Security is a myth. Computer security doubly so.
-- Tigger warning: This post may contain tiggers! --
Came here to post that he wouldn't have got a second look if he was wearing a hardhat and reflective vest. Yes, even on the computers.
"When information is power, privacy is freedom" - Jah-Wren Ryel
Yeah both links supplied by the editors are paywalled. I found this though:
http://www.cetusnews.com/business/CEO-Catches-Stranger-After-Hours--Prompting-Espionage-Charges.HJg30svCq-.html
Am I the only one who can foresee the best newspaper headline: "Chinese Dong caught 'doing business' behind Laptop" I'm just saying...
... PERFECT name for a porn-film body double.
- First they ignore you, then they laugh at you, then ???, then profit.
You cannot get dual citizenship with China. Is this article accurate/believable?
https://www.csoonline.com/arti...
As the article stated, the CEO (Straface) was the last one out of the building which implies it's late (7pm? 8pm?). Regardless, if you're in an office to meet with someone and you notice that no one else is around after 2.5 hours, that's usually a sign that your meeting has been canceled!
Looking at the title I read it as CEO was caught downloading "Stranger After Hours" as a TV show being leaked online.
The US needs to make China aware that this state sponsored economic terrorism will no longer be tolerated. I vote that every time there is a theft of US technology, we VOID $10 billion (minimum) of US treasuries held by China. Make it $50 billion if it is a military contractor. If they want to steal our technology, they are going to pay out the ass for it. If they run out of US debt, start putting a 1% tariff on all goods imported for a year, per incident. Watch companies start to flee China as the cost of producing goods there to import to the US skyrockets while the Chinese economy craters.
We cannot survive as a nation with the parasite of China continuously stealing our manufacturing, manipulating trade deficits and now stealing our technology. We either have to change or we are going to collapse.
And to all you globalists out there rooting for the US to fail, I hope you like living under a jack booted dictatorship with zero freedom and can speak Russian or Mandarin, because that is what will happen to you about 10 days after a US collapse.
If you disagree, please post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like
(IMAGINE THE FOLLOWING IN ALL CAPS) We stayed overnight in a medical-technology startup! BIG MISTAKE... youtube.com/tfil
The article I found on it (not WSJ) didn't give a time but it sounds like it was fairly late, and this guy is sitting alone in a conference room with multiple devices downloading files from the corporate network. I don't think the "I was just there for a meeting" defense is going to go very far.
This is horrible security on a number of levels...
Physical - How does an unauthorized person even get past the reception lobby and into a conference room? For Pete's sake people, don't let strangers wonder around the office by themselves. It's dangerous on sooo many levels.
Network - What kind of network security do you have? NOBODY, including your own employees should be able to just walk in and plug something into your network and get anything beyond an internet connection (if that). Personally, I'd dump any rouge device that pops up on my corporate LAN into purgatory. No connection for you! Beyond the "guest" network, I'd require authentication for network access.
If this story is true, this company has some serious security holes.
"File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
Source https://www.bostonglobe.com/me... (paywall link) (disclaimer, I work for The Boston Globe)...
Did you mount a military-grade, variable-focus MASER on an unlicensed artificial intelligence?
I'm curious what security camera footage, if any, will reveal about the defendant's arrival and movements through the building.
If he took advantage of the bustle at the end of the workday to slip-in and then hid for a time where he would be unlikely to be stumbled upon then he's screwed.
Do not look into laser with remaining eye.
Except...they caught the guy. Might actually help us learn more about how the Chinese do economic espionage, because they got his computers, too.
15 years max sounds on the light side. But it's Federal, which means no parole. This is totally theoretical, anyway, since if Dong is convicted, the Chinese will immediately arrest and convict a random US diplomat and then swap him for Dong.
It's just common curtesy to break into a company and take up residence in the meeting room. That way you'll be instantly available to reschedule at your business partner's leisure.
How does an unauthorized person even get past the reception lobby and into a conference room?
I've worked at plenty of companies where the receptionist is the last one to arrive in the morning (9:30-ish) and the first one dashing out the door (4:00-ish). Don't forget that the reception area is also unguarded during lunch and frequent pee-breaks.
The problem here is that this is a state actor being caught out. The effective kinds of penalties in this situation would be tantamount to self harm. That is, the only thing that would stop China from doing this would be to cut economic ties with them. Of any kind. And that is literally cutting our nose off to spite our face. We and by this I mean the global community are tied too deeply to one another economically to try and isolate a nation as large and as prosperous as China currently is. It's also of dubious use as a way to change regimes. Look at N. Korea or Iran for examples. While Iran has seen some positive democratic reforms in the past decade, it was only after a certain amount of trade was normalized that it happened.
The only level one has left then is an individual one. To make it too costly for an individual to be caught to make it worthwhile. In order to make this effective, one would have to up regulations so that your own country's infrastructure and business practices are able to catch them. Which isn't going to happen while the current political regime reigns in DC. If anything, President Stupid is going to make it easier for this to happen for his Russian buddies who are busy doing the same thing China is doing, just in different industries.
Here to confirm it does work. I have actually done the same. Pulled it off last week to keep a project moving along rather than waiting 6 hours for the actual person in hard hat to show up.
Linkedin says the company has 113 employees listed. If they really are that size (they were described as a "startup") then it's very realistic their security is that informal/lax.
Caught him? After he likely had 2 hours of unfettered access? AND the CEO admits that he just about didn't do anything...
Sure, they caught him, but it seems like they got lucky. If you are counting on getting lucky for your security systems to work, you have a security hole big enough to fly a fully loaded 747 though upside down....
"File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
Am I the only one who keeps reading the CEO's name as Scarface? Because we know how that guy welcomes unexpected visitors, by introducing them to his little friend.
The Quirkz Handbook of Self-Improvement for People Who Are Already Pretty Okay
Check your math; that doesn't even work in long scale.
Momentarily, the need for the construction of new light will no longer exist.
Is there an engineer here who can honestly say they've ever traveled with that full a panoply of recording media on them? Oh, wait, he wasn't an engineer either. He said he was a lawyer...
Whatever he was doing, it wasn't engineering as I know it, and he seemed almost comically concerned about being able to record data no matter what media hardware he bumped into on his trips (or even if none were accepted, he had camcorders).
Add to that his cover story when challenged involved name-dropping an out-of-town engineer, and then the CEO himself (the last was clearly a lie), and there aren't a lot of other conclusions one could come to.
I'm assuming they have also gone through the server logs to determine what his activity exactly was. If it was late (as it sounds like it was) and he was downloading a bunch of material off of file servers, then that's sure going to look like data theft to me, if not outright espionage. They may throw the harder charges at him and then accept a plea deal. At least the guy was caught, so that's something, but it also suggests that the company needs to work with their security to make sure it isn't just an almost-accident that catches someone doing nasty things on the company network.
The world's burning. Moped Jesus spotted on I50. Details at 11.
With the uniform, badge, hardhat and clipboard, he could walk into any boarding to look at electrical closets and no one would question him.
I can do you better than that. In a prior lifetime, I was a janitor. I learned that if you look dirty, harried, purposeful, and carry a mop and a big ring of keys on your hip (that part may have changed since then), you become entirely invisible and can wander anywhere without being challenged.
I figure they'll swap him for yuan, dong is Vietnamese.
"So long and thanks for all the fish."
You're assuming he was Asian. It doesn't say that anywhere. It says he was a citizen of China and his name was Liu. He might be black. Please don't be such a racist. See how that works?
The CEOs who got paid well to sell out the company are almost as guilty as the Chinese.
It's right in line with a career building move for denizens of the C-suite (CEO, COO, CFO, CTO, ...) that is often attributed to the teachings of the Harvard Business School (though graduates of other business schools have also been seen to execute it). It works like this:
1. Join the company as the new, or turnaround, CEO (or whatever). Get a big package of stock options (a "free" leveraged investment that pays off drastically if, and only if, the stock price rises.)
2. Dump the R&D and other preparation for future products (and any personnel working on them). Perhaps also make some cuts in customer support for current products, cheapen the product, cut infrastructure maintenance, etc.. This drastically cuts expenses while not (initially) affecting revenue, boosting the "bottom line" of the financial statements.
3. Announce the big boost in profits at a few quarterly reports and the investor/financial media phone conferences. The stock price soars, as does the executives' reputation as a corporate administration wizard.
4. Select a successor (sucker), leave the company, and cash out the stock options. (PROFIT!) Of course cashing out when leaving is viewed as prudent, since the company will now be run by somebody else the way THEY feel like running it.
5. Rinse and repeat at your next company. Meanwhile, your successor is in charge, and catches the blame, when the house of cards collapses.
The scam depends on the benefits being immediate and the damages, though bigger, being delayed.
Moving production to China (or some other offshore sites), with its far lower costs but track record of expropriation of trade secrets (which takes a while to spin up into a competing product) has exactly the same structure.
Of course it's a breach of fiduciary duty for officers of a corporation to do this. But they can make it LOOK like they're being responsible by taking advantage of the drastically lower production prices to "maximize investor value".
Until enough investors catch on to this, and both the markets and stockholder meetings shift to make this a losing strategy for executives (or regulators pick up on it ditto), expect it to continue.
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
I'm more surprised with the venue that he chose in which to work, especially if he managed to get onto the company's wireless network and to reach sensitive stuff.
It's almost amateurish to actually sit there. He could have set up an old laptop with both an integrated Wifi controller and a PCMCIA Wifi device and used it as a wireless bridge into their network, set up shop somewhere that wasn't company premises, and then just formatted the old laptop once he was done, abandoning it in place. Hell, he could have even left it in the conference room sitting in a corner next to company equipment and probably no one would have paid it any mind, and may have even disposed of it for him ("what is this still doing here? I thought we got rid of these, must've missed one") and no ne would have been the wiser.
Do not look into laser with remaining eye.
The backup link is also paywalled.