TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How to safely collaborate with team member (temp) in China?

5 点作者 tsenkov大约 2 年前
A person goes to China for a month, visiting family and they want to continue to collaborate with team while there.<p>VPN seems to be a no-brainer, but even in that scenario - VPN&#x27;s allowed to operate in China, most likely collaborate with the Chinese government?<p>Is there a secure way to get access to company data and systems of a western company while traveling in China?

4 条评论

hayst4ck大约 2 年前
You could set up your own VPN and if it works great, if it doesn&#x27;t that&#x27;s life.<p>I think the question that&#x27;s more important is how big of a target are you? If you&#x2F;your company&#x2F;your co-worker are all ultimately nobodies, then it probably doesn&#x27;t matter.<p>If you have highly desirable state secrets or advanced tech, then from a technical perspective you&#x27;re probably out of luck.<p>Your problem might not even be the connection, but the device connecting.<p>Chinese (PRC) people will almost all have WeChat on their phone. It&#x27;s not hard to imagine keeping a list of all Chinese citizens in the US who come back to china, catch messages that say &quot;I have to work for several hours&quot; and launch a targeted attack with Pegasus like software.<p>A border agent could say &quot;your data or else.&quot;<p>If you buy an iPhone in China, that data, like complete backups, is probably open to the Chinese government probably unencrypted. I am not sure what happens when a person who bought an iPhone outside of china and brings it to china, or who sets their locality to PRC.<p>A password vault could be compelled to be opened.<p>So to answer your question, first we have to understand what you have of value and what your threat model is.<p>From an ultra paranoid perspective, no physical device with privileges should enter China and even the employees personal devices shouldn&#x27;t have anything company related like 2fac codes.<p>From a completely practical perspective, connecting to a vpn on a laptop while tethering through a &quot;state approved&quot; vpn is probably fine.<p>I think most valley companies would give completely new devices for e-mail and meetings and maybe local development, but completely restrict prod access, then destroy those devices when the employee comes back, but maybe I misremember.
评论 #35706615 未加载
comprev大约 2 年前
Serious question - is the staff member _that vital_ to the company by which they cannot be unavailable for one month?<p>The first thing I&#x27;d do is involve a lawyer familiar with working for a western company in &quot;hostile&quot; environments and involve InfoSec for a risk assessment.<p>Coincidentally I know of a Chinese citizen, living &amp; working in EU (western employer), who needs to be in China for 1-2 months for medical reasons. He casually (well, naively) believes it will be no different to working remote in EU, and therefore not a problem for his employers.
hnthrowaway0328大约 2 年前
From my understanding companies in China can apply for non-blocking Internet so people can visit Google&#x2F;Youtube&#x2F;etc. freely. However, if your concern is that the general Internet in China is not safe enough (monitored), I&#x27;m not sure what solutions can solve that. Maybe there is some end-to-end encryption software that you can use?
评论 #35700814 未加载
tsenkov大约 2 年前
Does anyone know if Amazon Workspace hosted in Tokyo, could be accessed from China? Latency to AWS Japan would likely be one-of&#x2F;or the lowest from China to an AWS datacenter?