As the follow-up tweet says: "Completely independent of the specifics in this instance: get a second device before installing an employer's config profile on your personal device"
As the follow-up tweet says: "Completely independent of the specifics in this instance: get a second device before installing an employer's config profile on your personal device"
I'm with you though... If an employer wants to manage my device, they can provide the device.
The first of these could sometimes have implications for ownership of personal projects created using the device, which was one of many reasons I picked the second option, but it was absolutely permitted at least for any case where the company cared about you having mobile account access.
I even saw a guy using the code review site on his mobile, on BART. That was dumb from the standpoint of infosec, usability, and mental health, but shows how much is possible in the browser.
"""BeyondCorp began as an internal Google initiative to enable every employee to work from untrusted networks without the use of a VPN."""
Disclaimer: Googler, opinions my own.
Seriously, they could be logging your exact location, remotely activating the camera or doing any number of disgusting things.
Requiring the use of a spy should not be a factor in an employment setting, of course we're seeing this is the case and it is very offputting.
Thankfully not something I need to worry about though.
Installing an app that relays GPS and camera may be possible, but permissions need to be granted by the user explicitly- the MDM server cannot grant those permissions.
Google has in my opinion the better approach with work profile. Only give the MDM control and visibility over the work area and nothing else.
Apple has started heading into this direction with User Enrolment but it's not sufficient for most companies as it only allows built-in apps to be used for both work and personal data. And it requires Apple account federation which is problematic.
> Microsoft does the latter, so it wouldn't surprise me if Amazon does likewise.
Not true (source: current MSFT employee). More detailed explanation below, as neither former nor latter describes MSFT accurately.
So, for most teams and positions (there are many exceptions), you don't get a dedicated work phone. So yeah, if you want to access work stuff on a mobile device, you need to install MSFT MDM on your personal phone, and they will, allegedly, be able to control stuff on it (depending on the device itself and how MDM is configured).
However, there are no requirements to do it. You can simply not install any work-related stuff on your phone, so you won't need an MDM. I simply don't access any work resources on my personal phone. If I need to do work, i open my work laptop. If they want me to use work apps on mobile and be accessible, they should provide a company phone for this.
There have been zero conflicts around it on my end, even after multiple years of working there on multiple different teams. Not once have I even got an implied request from anyone (managers, colleagues, etc.) to be accessible on mobile (except for when I am on-call, but for that, they just need my phone number, not any specific apps installed on my phone, and everyone knows it) or any questions about it. Everyone is totally cool with people not being glued to their work apps on their phones on their own free time.
But you are correct, those who choose to use work apps have to give MDM permissions to their personal devices or buy a dedicated device for that (exceptions apply, because there are some teams that provide dedicated work phones). However, unless it is required for the job to be able to use work apps on your mobile device, I think it is fair if they don't provide a work phone. Makes it easier for me to not check on any work stuff during the weekend.
It turns out that I can use our 2FA app without MDM, on my personal. And nowadays, I rarely use slack or email from mobile, and I don't get calls.
I am pretty strong in the "don't put company stuff on personal devices" camp. Even if they don't control your phone by policy, they do technically. They put root certs on the device, and though they can't see individual app data (depending on config) they can see a list of installed apps, and enforce certain baselines.
If you, as an employee, don't want to remove TikTok I believe you will have that right, it's just that you won't be able to access company emails from that device.
Now, whether or not that leads to a company phone or you having to look for another job, depends on the individual and how important that individual is to the company.
Perhaps I'm projecting a little, but: please don't feel like you're stuck there. It's an illusion more often than not.
Of all the hills I am willing to die on, getting another phone isn’t one. Especially if they provide a credit for your cell phone.
https://www.teamblind.com/post/Amazon-Cell-Phone-Reimburseme...
I personally just bought the cheapest $60-80 Android phone from a random Amazon seller.
It falls under the category of providing your own resources to do your job, and that territory enters socioeconomic discrimination territory real quick.
But for engineers and other office workers at tech companies?
As a practical matter, people have to buy lots of things to do professional jobs that they wouldn't need to buy without those jobs. In this day and age, if you want a second phone, buying a few year old phone is cheap as is adding another phone to your existing cellular account in most cases.
And, seriously, complaining about having to spend a few bucks for something you need at work is equivalent to circumstances around Indian treaties in the US?
Of course I do have other apps directly related to work... I guess those aren't an issue if I had TikTok?
I am too. Many years ago at my employer, someone fat-fingered a command and wiped every single iPhone/iPad that an employee had configured to connect the company email system. Even after restoring a backup, the devices would just wipe themselves again unless the owner managed to remove the MDM profile before it reconnected to the internet. A good fraction of my coworkers were affected.
I'm not giving anyone access to do that to my personal data.
After that I've never allowed an employer to control my personal devices. Not that I actually did before, didn't know activating that stuff had so bug implications. I just wanted the calendar on my phone.
For me, it's a minor inconvenience at best, not a death sentence.
If it does get to the point where I need to have access to my company email, I will have a separate device.
That being said, if my phone was erased, it would only be a slight inconvenience, I can restore from backup.
This was all much easier in the blackberry days for them to control
And indeed, that was Blackberry's big sales pitch.
BYOD creates many, many wonderful consequences, however it also has tradeoffs, and those tradeoffs are not for the faint-of-security.
He never got one, because as he said, if they have your number they'll call you, if they don't then they'll solve their own problem. Looking back on it now, it was prescient advice.
So what... Sometimes I go to the shop or bank during the day. Or even a walk to the beach if it's not so busy. They're paying me to do a (global) job, not to sit at my desk between 9:00 and 17:00.
Personally I love this flexibility. And I don't feel like I work more than 40 hours, I don't even count them but I doubt I do, especially if I omit the time I spend during "working hours" reading hacker news or other stuff. My work is my hobby anyway.
I do think people who like having fixed work times should have the opportunity to have them. But I also think people like me should be able to work like this without it being considered a bad thing.
If Amazon doesn't provide me a work phone, they can eff right off in attempting to dictate what I put on my phone.