If the Google calendar is for a personal gmail account, then accessing the calendar details server side is a huge privacy breach.
If the Google calendar is for a personal gmail account, then accessing the calendar details server side is a huge privacy breach.
The fact that Google employees, in this case, may not be considering forming a union at this time is irrelevant. The meetings they are having may prompt them to form one at a later time. Either way, their freedom of association is protected.
Google also has a clause in their employment agreement that says you agree to them putting surveillance software on your devices, company supplied and personal, as a condition of your employment. I asked about that one, got the HR response "Well I suppose you could interpret it that way, but that isn't what we mean." and I said, "Okay, lets change it to say what you mean." and got the "Well we really aren't in a position to change these documents, it would be a mess trying to track a zillion individual agreements." etc etc. That rabbit hole of pushing back and forth leads to "perhaps Google isn't the right place for you." :-)
How would Google even know about your personal devices? That seems to only make sense if you intend to use your personal device for work.
I think it is a good incentive to disconnect from the workplace.
It's definitely a slippery slope though.
"If we already have a privileged app running on people's devices... {insert management-centric ask}"
Lots of people at tech companies use personal devices for work. This includes things like having your work calendar, email, or corporate applications on your personal phone. In my company's case there is some kind of enterprise iOS policy that gets installed as part of onboarding a device to access company systems. This has the ability to enforce a password policy, monitor installed software and software versions, to lock out devices that are running known vulnerable apps or iOS versions, as well as the technical ability to remotely wipe the entire device (never heard of that being exercised). Company data resides on the device (via email, documents, and other means) so it's reasonable for them to want to have some oversight. An attacker could attempt to get into company systems via the device, after all, since it has (some limited) access to my corporate account.
I use my personal phone for work because it's extremely handy to have work email and calendar on my phone, and I don't want to carry two phones.
I invite my personal calendar to any work events that I need to be aware of when I'm not at work.
Otherwise, when I leave the office, I leave work there too. I'm extremely fortunate to be able to do that.
It's tragic that my good fortune isn't an option for many.
Didn't a whistleblower at a car company suggest this...
https://www.theverge.com/2019/3/13/18263757/tesla-elon-musk-...
And if such a a company had that technology then we can only speculate its use is more widespread than imagined.
Maybe this is the only reason remote jobs are not available at these companies... Nothing to do with being onsite just more of a precaution to vet employees before even allowing them to be remote.
So if a company could capture your personal text messages and personal cell phone calls while within an office campus (and no BYOD app installed)... would they use that knowledge to prevent poaching as well?
Be careful.
As for how? It was left unspecified but we speculated they could drop a keylogger or other bit of surveillance kit if you logged into your corporate gmail account from a device where it wasn't already installed. Clearly crooks can do this, it has to be easier when you can sign your downloads and are a 'trusted' vendor.
> So if you read your corp email on your home computer, or access employee only services from your phone or laptop etc
I know literally no Google employees that use Google corp resources from personal computers. Phones are common, but as you're hopefully aware, the security considerations are different.
> As for how? It was left unspecified but we speculated they could drop a keylogger or other bit of surveillance kit if you logged into your corporate gmail account from a device where it wasn't already installed.
Who theorized this? Because it's certainly not a thing that's ever happened. It would be trivial to detect, either as a client, or by looking at the source of Gmail.
No. It is a necessary thing to do and what a legal system ostensibly exists to do.
A slippery slope in what direction? In the direction of too many rules being illegal or too many things that could impede organizing being allowed?
That doesn't mean it's enforceable or that it wouldn't run into statutory limits. Many workplace relations laws are written on a strict liability basis, intent isn't necessary for infringement. So if it has a chilling effect on organising, it's potentially infringing.
Mind you, there's something very rich in Google employees complaining about Chrome being used as a monitoring tool. Look around you, folks. What do you think pays for the fancy cafeteria? It's not hugs and smiles.
I'm generally of the view that knowingly adding unenforceable provisions to a contract should be a crime and/or professional malpractice worthy of being disbarred. It's obtaining advantage through unconscionable deception. Or, less fancily: fraud.
Entirely too much of this kind of thing is allowed to slide by legislatures.
Legal and generally accepted in US jurisdiction. In Germany that would require approval by employee representatives, unlikely to happen in any bigger company. In Finland a somewhat related and highly controversive law was introduced many years ago that it would be legal if registered with data protection authorities. Something like 3 companies registered in a decade. Maybe some did it without registering, but generally this is not deemed clearly acceptable practice.
Google has a big data center in Finland. IIRC they stopped their plans for a Berlin lab after visible anti-Google protests in the neighborhood, but I'm sure they have employees somewhere in Germany. International companies just follow local legislation and practices and there is no problem (most of the time at least, there are examples of failure like Walmart trying to expand to Germany with too much of an American management style and eventually giving up).
Surely, Googlers have separate work and personal Google accounts, and only the former would be used with the Google corporate calendar? Article says that one of the things which triggers a report is booking more than 10 meeting rooms for a single meeting – surely, a Googler's personal account would lack permission to book meeting rooms in their corporate offices, and only their work account would have permission to do that?
Before employee leaves the company, its manager is responsible to get all the company data stored (by leaving employee) on another computer, then IT takes the computer and wipes all the drives, with at least two persons present.
A big portion of one of my information security jobs involved looking at employees' browsing history and emails daily. Sometimes to investigate potential misconduct (something dumb like a manager wanting to see if someone's slacking off, or something serious like suspicion of stealing information), but usually to investigate potential security issues (like if we believed a computer visited a malware-associated web page, we wanted to see how the computer ended up there).
In the US, pretty much no one bats an eye that this is considered necessary and normal. Employees who don't want to be snooped on are free to use their personal devices at work, like their phones, which of course we have no access to. But it's considered very normal that if an employer gives you a computer to use for work, that they can inspect that computer and data to and from it. No one has a feeling of their privacy being violated, because there's no expectation of privacy when using someone else's (the company's) property.
For infosec operations people in European countries, how are these things handled? How do you investigate potential breaches which originate from endpoints? Do you have to ask the employee if you can look at their browsing history? What if it's a potential misconduct investigation, where tipping someone off may result in destruction of evidence?
Excellent. Now you only have to remove the expectation of privacy in any situation from the social norms, and another big problem will be solved. You will be able to live under total surveillance without anyone feeling that their privacy is being violated, because there was no expectation of privacy to begin with.
An alternative hypothesis (crazy, I know...), is that the power imbalance in favor of the rich went very far in the US, which means that the poor have no safety net or ability to organize, so they are completely at the mercy of the whims of corporations for survival. And so, they will accept many indignities without bating an eye.
Do people in EU countries expect to use any other of their employer’s equipment for personal reasons?
It's a weird idea that you have to be a complete robot at work and only ever do work things.
But the official position of the company can’t be “everyone use the company’s resources as they see it for personal use”. So it’s best to just say company resources are for company. What if someone gets hurt using company machinery for personal use? In the US, that would be cause for the company’s workman’s compensation insurance premiums to increase. Why would an employer want that kind of headache?
In practice, from doing many of these investigations, no one bats an eye or gives a single shit about what kind of non-work activities you're doing. The visit to the ticket website would just be a few entries in a long list of other web visit entries, which we'd quickly scroll past while trying to find the thing we're actually looking for (usually malware-related traffic).
Every single second that you are working, you know that your employer might be looking over your shoulder. It's like living under a microscope. For me, this is an indignity. Having to work in such circumstances would probably drive me to deep depression.
> Do people in EU countries expect to use any other of their employer’s equipment for personal reasons?
Within reason, sure. I would say that the main value that underlies all EU countries (not that we realize it perfectly, or even get close to it, of course!) is that human beings are the most important thing.
I find mainstream American values increasingly inhumane.
In addition, everyone has a personal computer in their pocket they can use if they want privacy.
I do agree that there should be more requirements to look at data, though. Managers requesting bullshit fishing expeditions to see if an employee is slacking off should be required to submit some sort of evidence before making the request. That never sat right with me, or anyone on my team. But for security issues, there was no question that there was an absolute necessity and justified reason to look at that information.
I'm asking because my concern is maybe European corporate infosec people really aren't managing, here, and are blind to some ongoing major security issues.
Within reason, sure. I would say that the main value that
underlies all EU countries (not that we realize it
perfectly, or even get close to it, of course!) is that
human beings are the most important thing.
American here: I strongly agree. And I don't like giving more power to corporations. They have too much already, and I believe that strong labor movements are one way to fight this.Still, I just... would never feel "entitled" to use my employer's property for personal uses. And I wouldn't have an expectation of privacy. When I care about privacy, I simply use my own device.
Now, let me be clear. The reality of working in America is that people use their work computers for personal uses all day long. Generally nobody cares, as long as you're getting your work done.
And if somebody really needs to do something personal, they can always just whip our their phones. If I was printing out some concert tickets at work, I'd use my employer's printer. Everybody does this. But if I was going to send some sexy messages I wouldn't do it with work equipment.
So, I don't know. I just don't see the problem. There are many many problems with America, and many ways in which Europe does things better IMO. I just don't see this as one of them.
I'm not saying this is always the case in the EU, though. Obviously there is equipment where for many reasons it's absolutely vital that you don't use it for anything personal. I'm not supposed to run a torrent client on the company server, for example. You can't just "borrow" a company car for a personal trip. But when I happen to use the laptop that the company has assigned to me to work on, to do a bank payment, my boss has absolutely no business knowing the details of that transaction.
I would be okay with them knowing I visited the banking site on company time (if I used their equipment, their DNS, etc) but not with decrypting the SSL encrypted data I'm exchanging with the bank or obtaining it in some other way such as a keylogger.
Though again, I'd probably avoid the issue entirely by using my own device and data connection if I didn't trust my employer. (I'm a bit spoiled, working in IT: I'd probably know if my employer was doing shady things with the data)
How did this work? I presume they had a whitelist of Internet banking sites. But, do you really think their whitelist would include every Internet banking site in the world? I doubt it.
Ah, but it's not someone else's device now is it? It's a corporation's device and corporation's have lobbied for laws that specifically prevent individuals for being liable for the colorations actions. If they aren't liable for the actions of said corporation, why should this be treated as two people's opposing rights of property vs privacy rather than a non human entity's property rights vs a humans privacy rights?
This is not an EU-wide regulation. The UK is currently a member of the EU, and this practice is legal in the UK. Employees do not have the expectation of privacy on employer owned equipment.
(Please, lets not devolve into a conversation about Brexit, it's an unrelated tangent)
After all, the rooms belong to Google.