Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Question I've always wondered: Does Google's monorepo provide all its engineers access to ALL its code?

If yes, given the sheer number of developers, why haven't we seen a leak of Google code in the past (disgruntled employee, accidental button, stolen laptop, etc)?

Also how do they handle "Skunkworks" stlye top-secret projects that need to fly under the radar until product launch?



Partial check outs are standard because the entire code base is enormous. People only check out the parts they might be changing and the rest magically appears during the build as needed.

There are sections of the code that are High Intellectual Property. Stuff that deals with spam fighting, for example. I once worked on tooling to help make that code less likely to be accidentally exposed.

Disclaimer: I used to work there, but that was a while back. They probably changed everything a few times since. The need to protect certain code will never go way, however.


The very very important stuff is hidden, and the only two examples anyone ever gives are core search ranking algorithms and the self-driving car.

Even the battle-tested hyper-optimized, debugged-over-15-years implementation of Paxos is accessible. Though I’m sure folks could point out other valuable files/directories.


Former employee here. I remember a third example: the anti-DoS code is hidden. I remember this because I needed to do some very complicated custom anti-DoS configuration and as was my standard practice, I looked into how the configuration was being applied. I was denied access.

Fourth example: portions of the code responsible for extracting signals from employees' computers to detect suspicious activity and intrusion. I suspect it's because if an employee wants to do something nefarious they couldn't just read the code to figure out how to evade detection. I only knew about this example because that hidden code made RPC calls to a service I owned; I changed certain aspect of my service and it broke them. Of course they fixed it on their own; I only got a post-submit breakage notification.


Google3 monorepo source isn't, by policy, supposed to leave the corp network workstations, and can't even be on your corporate provided laptop (except for some edge cases in mobile apps dev). Even during full COVID lockdown WFH we had to remote into our machines. (I worked on embedded stuff and had to compile on my office workstation, scp the binaries home, and flash my device, and repeat. Super slow cycle.)

So, anyways, source code being basically on-premise only and on machines that they can fully audit and control... Would you be stupid enough to "cp -r srccheckout /media/MYUSBSTICK" on such a box?

Also believe it or not they used to have a very open internal culture at Google because the bulk of employees genuinely liked the company and its stated mission and there was a bit of a social contract that seemed to be upheld. Stuff didn't generally leak out of the wide open all hands, even. Past tense.


Google laptops and workstations (anything that can actually access srcfs to get this data) are extremely monitored and controlled.

Very critical stuff (ranking, spam/abuse, etc) can be further protected via silos which lock down sections of the code base (but still allow limited interactions with the build).

Google spent significant engineering $$$ into its development tools and policies (generally building custom with no intent to ever monetize vs buying). I don't see a company today, in this climate, that would emulate that decision.


I don't see a company today, in this climate, that would emulate that decision.

Why not? There are a lot of benefits from owning the tooling and being able to tailor it to do exactly what you want.


It's extremely easy to detect a disgruntled employee making a copy of source code. There's no accidental button to leak. There's no source code on laptops as policy doesn't allow it, with limited exceptions only.

But there was a giant leak a long time ago. It was called Operation Aurora done by China. Legend has it that to this date the Chinese search engine Baidu still uses stolen code from Google.


Within the monorepo there is the notion of "silos" where access to directories can be restricted to groups of people/bots. Though I believe that's exceedingly rare, I've never come across one.


I suspect this is part of the interview process and why it takes so long and so many people.

Character and trustworthiness is extremely important.


The Google interview process is overly focused on algorithm skills and absolutely does not select for character and trustworthiness. In fact the leaks from Google to the news started circa 2017 and in response the leadership basically neutered internal forums like TGIF and memegen. Remember the Damore incident? While Damore was wrong, it wouldn't be as big of a deal if the incident wasn't leaked to the press. It's clear that Google would be a much better company if its interview process actually accounted for character and trustworthiness.

The old article, Three Years of Misery Inside Google, the Happiest Company in Tech is still the best description of what went wrong inside Google: https://www.wired.com/story/inside-google-three-years-misery...


I have interviewed with Google. It's not explicitly tested for but you can be sure the interviewers will have an opinion of your character.

Also, (in the middle of six hours of interviewing) for lunch I lunched with someone completely outside of the particular group I was interviewing for. Rather genial chap and I'm sure his opinion was sought too.

I'm not downplaying the tech questions, I'm saying there's a meta/side evaluation as well.


There hasn't been a lunch interview since the pandemic. Everything is online. The old Google is no more.


Also I don't think Damore was wrong .. or right. He was certainly naive.


Edit - I guess there hasn't been zero leaks: https://searchengineland.com/google-search-document-leak-ran...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: