Ouch. Presumably this would have been MDM?
I've never understood why phone makers make this possible for non-device-owners, as it seems like a gigantic foot-gun. To say nothing about the ethics involved.
Ouch. Presumably this would have been MDM?
I've never understood why phone makers make this possible for non-device-owners, as it seems like a gigantic foot-gun. To say nothing about the ethics involved.
They will not wipe your personal phone or your personal profile on your phone. This is completely avoidable and shouldn't come as a surprise.
The only brief moment of this being acceptable was Samsung phones being able to have completely split personal/corporate profiles across 2 sims in a single phone and have 2 copies of each app, but that seems to have died.
If your employer is managing the device you're choosing to also use for personal data, it's 100% your fault and 0% surprise when it backfires on you.
If you work in tech and don't have a separate work phone+laptop and personal phone+laptop, you're either a founder or an idiot.
The answer should be nothing but there's a moral hazard wherein employees can't do much about it without limiting their career.
A contractor can deduct work expenses from income, a phone is just one item on a long list of things that will be deducted.
If there is corporate information on a device, it would be a breach of their fiduciary responsibility not to manage that device and have the ability to remotely wipe that data.
I don't think, in a legal sense, that's true. It feels like it comes from the same mindset that corporations have a "fiduciary responsibility" to their shareholders to always put profits above all else; in fact, there's nothing in corporate law or financial regulations that requires that at all.
The IT department has responsibility for network and systems policies and company-owned equipment, and it's perfectly reasonable for them to have the ability to wipe data on that equipment or set policies that disallow personal devices on company networks at all. But they have no requirement -- and I would argue no business -- to wipe a non-company device just because someone added a corporate email account to it.
Does that make it marginally more likely that someone could keep corporate email that they weren't supposed to? Sure. But there are other legal ways of handling that which aren't destructive to non-company property. No one would argue that a policy of "if you take physical work home, upon termination the company can set fire to your house to ensure all copies are destroyed" is enforceable.
If my personal calendar and work emails are being copied onto your device, you better believe the GDPR data protection regulations apply.
The house example is ridiculous. The point is if you commingle the data in ways such that the endpoint protection software no longer supports delineating the corporate data, then the user (employee/contractor) has opted into that situation with eyes wide open.
> Computing devices need to be protected from loss or theft through mobile device management capabilities, such as remote wipe and kill. A lost device could be the weak link in the data protection chain, leading to a data breach based on information stored on the device or accessible through still active user credentials. Enforcing certain settings in order for a device to connect to the network at all – such as local encryption, password complexity, the presence and currency of security software, and the removal of the local administrator account – will be an essential part of protecting the organization within the GDPR framework.
[1] - https://www.actiance.com/wp-content/uploads/2017/03/WP-GDPR-...
> If you commingle the data in ways such that the endpoint protection software no longer supports delineating the corporate data, then the user (employee/contractor) has opted into that situation with eyes wide open.
You're assuming the user has been given a clear understanding of the situation, and frankly, I think you're letting the IT department off the hook here. They need to either provide protection that can prevent "commingling" to their satisfaction, to grant a comparable level of trust to users with personal devices that they do in other aspects of conducting business (which was the real point of the example you didn't like), or just to ban personal devices.
DLP (data loss prevention) software should be present on any personal computing device that can store company data, which will be a requirement of their cyber-security insurance policy, a requirement of the various audits they surely undergo, and probably also a requirement of GDPR.
It's providing strictly more choice and flexibility to their employees and contractors to allow them to host company data on their personal device, the obvious trade-off being made when you install the DLP endpoint software on your phone and grant it permission to remote-wipe your device if necessary.
If the company required their employees/contractors to use their personal device for company business, this would be an entirely different discussion. In California, the employer is required to reimburse employees for using their personally owned device for company business - i.e. required to pay for the cost of a phone and the service plan.
Employees choose not to buy a second phone and get paid for their service plan on their personal phone for convenience, and to save themselves the cost of a personal plan. Some choices are not strictly good, but include pros and cons which are individual's responsibility to weigh.
I think it's a safe assumption that anyone choosing to install the DLP agent on their personal phone, particularly at a company like Google, does so fully informed of the responsibilities that come with that decision.
Personal devices are excellent attack vectors if allowed on the internal network unmanaged. The alternative is not accessing internal resources, email, etc., unless the employee is given a company-owned device.
If they are directly contracted with Google or a sub-contractor through another company they should purchase an additional phone for this purpose. Both the phone and the service would be considered a business expense for tax purposes.
If they are a direct employee of another company then that company should be providing a phone for this purpose. If Google or their employer won't provide a phone for this purpose than neither considers it a requirement for the job and they should not worry about it.
I'd call that a quality of life improvement. Why are contractors required to be available 24/7? I've never experienced that as a contractor, nor would I agree to it.
If it's so important that it must be done during my personal time then my manager can call me and request as much.
Remember pager duty and overtime pay? Doesn't that seem quaint now that many people seem to have accepted that they must make themselves available at all times?
This instantly qualifies you as "available 24/7"
I'm too young to remember, but I have a few years of working experience under my belt now. The amount of people that greenlight everything a supposed authority demands of them just baffles my mind. I'm not even mad if a company tries to maximize their gain on the expertise that I bring to the table. That's just the game: You work for what's in your best interest, I work for mine. But when you push back against a perceived worsening of workplace conditions and the people not supporting you are your colleagues, because they somehow see themselves as being on the same side as the boss... I'm kind of sad about the social achievements people are willfully throwing away in the hopes that they themselves will 'make it' one day
And by the way, this is coming from someone who loves his job and has a good relationship with his boss. Doesn't mean I have to be delusional about what's going to happen when push comes to shove
I'm not convinced you have any knowledge of how things actually work in Google, but my point is that you can give me a ring if something requires immediate attention. If you don't provide a company phone I'm not using mine instead.
They can make a non-corporate device have a work profile with Google Apps Device Policy, and only that profile will be purged if the device is wiped by a Google Admin.
They didn't require contractors to bring their own computers and phones to the office if they were needed for their work.
I'm sure Google could afford that as well as to manage it...
The moment my company announced a requirement for having to install a corp policy enforcement application on my personal phone if I wanted to have access to the corp account (a reasonable request, in terms of company policy/security) was the moment I stopped having corp account on my phone (or any phone for that matter). It's been working fine for years.
I've done this.
You are absolutely right.
My understanding is that Google can't see the personal stuff. But it doesn't matter that much to me, personally, if they can (I'm not doing any exciting corporate activism, anything illegal, etc.). At least, it doesn't matter more than a couple grand a year plus the inconvenience of two phones. I'm not saying everyone should feel this way, and obviously some people value privacy more than I do, but that's the trade-off that makes sense for this idiot.
You signed something at work that "all data in google owned devices are property of google". Period.
This is the same as using your company-provided computer for something else.
> My understanding is that Google can't see the personal stuff.
You are completely wrong.
First they have access to all your text and calls, since they own the mobile plan you are connecting trhu.
Second, the "device administrator", keyword: device, can wipe out the entire device, not just one account.
> But it doesn't matter that much to me, personally
So why comment on a thread where this is the topic?
Good point about also owning the phone plan. But since I use Google Voice for everything (personal account) I'm not sure how much of that they can see (in their capacity as owners of my phone service), and like I said, I'm not doing anything interesting. If Google really wants to see my call logs of wife, wife, friend, mother in law, wife, wife, wife, dad, friend, etc. it's not worth thousands of dollars a year and an extra phone in my pocket to prevent it.
Same with laptops - if one decides to use work laptop for personal use its their choice at their own risk, but it doesn't become their personal laptop in any meaningful way. Even if hardware would stay after employment ends, every reasonable company would wipe it clean with some deep format & clean image of OS.
If it's set up to entirely manage the device, then yes it will get fully wiped (we do this for corporate-owned device).
A personal device can access our environment if requested (they have to sign an agreement form, explaining what we can or cannot do) and a work sandbox will be created, in which only the apps installed in this sandbox will have access to corporate data (ex: you'll have a copy of Gmail, Hangouts, Drive, etc in the sandbox).
In the situation of a personal device, a wipe will only remove that sandbox, leaving the personal data untouched.
Of course, if the user does have their Cloud backup enabled to automatically shunt photos, they're at risk of using the phone in a work environment and accidentally storing proprietary info in their personal account.
The fact the camera UI doesn't really allow you to choose what account you're snapping photos under makes the whole arrangement lose-lose, and this is a really easy failure mode for a user to find themselves in if they don't see it coming.
Sounds like a lose-lose and I'm a strong believer in that if a company the size and as wealthy as big G wants a contractor to make use of a device to accomplish a task for them, they can provide the device and do what they will to it afterward and then re-purpose it for the next round of business. This isn't a new operational pattern, and I've never experienced otherwise. They don't need to buy new, just keep a supply of devices for contractors.
If photos would be put in the area that doesn't get wiped, any idea what the quote is about?
In either situation, the corp has the ability to remotely wipe the device and enforce other policies on said device.
This should be abundantly clear to anyone who works in Tech.
I believe that on newer Android devices, the option is to wipe your work profile only, but on devices that don't support it, yes, MDM lets you wipe the entire phone. My own employer just rolled out an MDM option that gives them the ability to wipe my personal phone (this is my personal iPhone, acquired before I joined the company, not a corporate perk or anything) in exchange for being able to use native apps like Slack instead of doing everything inside a work-specific specialized browser. I'm steadfastly refusing to install it, and I'm on the older config with the work-specific app until it stops working.
She could have just as easily lost her phone in a car, or had it break. So this seems entirely irrelevant.
And yes, of course Google wiped her phone: if you're not actively working there, you're not allowed to have access to your past business emails that have been cached, photos of whiteboard drawings you took at the end of meetings, offline copies of strategic Docs, Sheets, and Slides, etc. and other resources that are stored on your phone.
If you use the same device for work and personal, this is just what happens.
They don't. You need to adjust your frame of reference to who is the "device owner" here.
The history to this is that smart phones were originally bought by employers who were concerned about the security of their data on said phones. Or at least concerned enough for BB to upsell them on the capability to remote wipe. In Enterprise IT sales you tend to evolve a bewilderingly large set of marginally useful features because each one was used to clinch some large sale over time. Remote wipe would have been one of these.
Fast forward to the introduction of "consumer" smart phones (first WM5, then iPhone 1.0, Nokia S60, ...) those guys entered a market already dominated by BB with the aforementioned huge set of Enterprise features. In order to make inroads into the market, they implemented a subset of the BB feature set. Remote wipe was in that subset. This is because for a period in history you couldn't sell a phone to businesses if it didn't have remote wipe.
The last evolutionary stage was when people mostly started to own their own devices: users wanted the convenience of carrying just one device while Enterprises wanted to keep as many of their vast set of features as they could. The compromise was that device vendors shipped the phones with remote wipe disabled, however if the device is connected to an enterprise data source (e.g. via Active Sync), then it is programmed to ask the user to opt in to remote wipe. The choice is between : you get Enterprise data on your phone and also allow the Enterprise to remote wipe; or you pound sand.
Separating "personal data" from "Enterprise data" was a final tweak on this arrangement, although it wouldn't surprise me if devices have a hard time supporting "don't wipe personal data" since the wiping is done by discarding a volume encryption key (for performance reasons -- you don't want to take 5 min to wipe the device while a hax0r is also trying to exfil the data).
Of course from the present day perspective this all looks very odd, but it came about through a series of quite logical steps, like how you make a Duck-Billed Platypus..
Source: I was involved with implementing remote wipe (server side) for all the various phones though this epoch.
As to the ethical question, under some ethical systems, voluntary agreements without coercion are by-default ethical. My employer doesn't force me to install a work profile. They're happy to supply me with a separate phone if need be. But I voluntarily take on that risk for the convenience.
I also don't freak out if there's a window open in my bedroom when I'm changing. The chances are small anyone wants to take a peek, and if they do it's not much skin off my back.
So, maybe there are just different kinds of people? The kind that irrationally think everyone is interested in snooping on them, and the kind who have more important things to worry about.
But I do have my own phone anyway. We even have a separate wireless network for private devices and guests that is not subjected to any filtering or security screening. All that is really worth having 2 devices in my opinion.
There are also a lot of security benefits if work phones are only used for specific tasks and are locked down as much as possible.
On the other hand, having to manage two devices would be a daily tax. So, yeah, I'm happy with my choice, but I'm happy to accept more information if you have other things I've not thought of.
It can be annoying, or not. Depends a lot on personality, type of work, boss etc.
A lot of people have a phone for work separate from their personal phone...Still, there is a perfectly reasonable middle ground, Google could have requested the employee backup the phone before wiping it since they knew or had reason to know there was personal data on the phone.
This was mostly out of laziness; I have relatively low patience for doing lots of fiddly configuration on a new device, and don't like the bother of setting up a second account on my phone whenever I get a new one. The only real downside is when I go to a meeting, forget which room I was going to, and need to get out a laptop or go back to my desk to figure out where I was going.
But it's done wonders for my work-life balance and just not thinking about my job when I'm not actually working.
That would reduce the amount of notifications I get from work after-hours. I still don't check them, but having them out of sight would be nice.
Furthermore, companies like Google have worked hard to blur the lines between their employees' personal and professional lives. I'm not particularly sympathetic to them suddenly drawing hard boundaries when it benefits them.
Get a second company phone like anyone with a sliver of opsec intelligence does.
Many years ago ago, at my first tech job, the employer provided a smart phone as part of work/on call responsibilities. (This was still around the era when smart phones were just blossoming as useful devices). Every other employee there decided to use their company phone as both their personal and professional device, while I opted out for what are very obvious reasons. I had my phone and I had the company phone; the latter was only on my person when professionally necessary.
It was common sense then, and it's common sense now. You always keep professional and personal assets separate.
(Fun fact worth noting: not too long ago the company decided to either boot personal usage of company devices, or stop providing those phones altogether. Can't say that I didn't warn them.)
(2) https://support.google.com/work/android/answer/6191949?hl=en
If it was added with option (1), the GSuite owner can wipe your entire phone. With (2), I believe only the work profile can be wiped.
If it was an iPhone, I'm not sure the controls for managed devices (I don't think it has a work profile type isolation).
Also I think that there are Android models that don't support a separate work profile.
That's why Wells Fargo can literally break into random people's home, destroy every possession they have, and get zero criminal charges[0].
[0] https://abcnews.go.com/Business/wells-fargo-mistakes-home-ne...
My own employer has us sign an additional document (an addendum to my employment agreement) to get email/calendaring on our personal devices.
(Also my employer is in a regulated industry - trading - where if we talk about work-related stuff on personal devices that don't go through work's logging proxy, the SEC can start digging through my personal text messages in an investigation, in some fashion. I don't know precisely how this works legally, and I hope to never find out.)