Stop using your work laptop or phone for personal stuff, because I know you are
zdnet.com
zdnet.com
It's remarkable to me how much this has improved my life. It took some getting used to, but when I'm working I focus better on work, and when I'm not I unplug. It seems obvious yet somehow leaving work behind at the end of the day escaped me before.
Also as someone who used to run an IT department, it's shocking the degree that some people fail to realize their work equipment is well works. Personal e-mail on your work laptop, I get it. Your entire collection of photography celebrating the human form in your folder of the company shared drive, why would anyone think that's a good idea?
While I don't have a one for each potential client, I do use a different user for each client, and all data should remain in user space -- which is easy enough to accomplish since I need to maintain matching versions of databases anyway, there is no need to share a single data store.
Not sure how easy it is on other OSes. On Linux, it's easy.
Don't have the need for that, so I've never tested it in practice, though.
... unless you can add multiple iCloud accounts to one phone. I guess I've never tried, because I just assumed you couldn't. Though you'd still have the problem of things like dev builds and all that existing in the same space, and email accounts (on the phone) syncing to the same application without much separation, and all that.
It was a fun gimmicky but I can't say I missed it once I had to start using a Mac.
Gives an answer for how you firewall sensitive data also, e.g. every document you gave me never existed anywhere except in this (potentially encrypted) VM. Easy to delete cleanly.
For some types of development, I find working on a remote server using SSH/Mosh/tmux works really well for me. I am retired now but I used to ask clients to rent a reasonably powerful VPS that we both had access to and just worked on that. I think this gave customers good control over their property (i.e., the work I did on their behalf).
So 6 clients = 6 computers...pardon me Macbooks is your ideal setup?
I hope that was a joke.
I really hope that was a joke.
Then I use firefox for everything client related (their outlook, jira, etc) and just login to my gmail on chrome or brave or something.
That being said, I didn't work myself to the bone. Instead of taking breaks with reddit, checking personal email, or spending time on social networks, I allowed myself long lunches, long walks, naps in the park or at the beach, and other forms of relaxation during the working day. This easy pace allowed me to perform some of the highest quality and most creative work of my career.
I've allowed Slack on my personal phone. It has no permissions according to the Android OS (beyond permission to use the network, which, of course, can't be denied least Google lose ad revenue). I don't think it can wipe my phone. I hope it can't wipe my phone?
It's not that slack can wipe your phone, but that (it sounds like) slack can detect the presence of the company MDM setup which can wipe your phone and lock you out of the app if it is not detected.
Fortunately my work day ends when I leave work and I can just block off time if I am otherwise out of office for whatever reason.
So just share the calendar and isolate the rest? No need to throw the baby out with the bath water, do what works for you
In your work calendar: Settings -> Settings for My Calendars -> Access Permissions -> Get shareable link.
In your personal calendar: Other Calendars -> Subscribe to Calendar
With this, I've managed to remove all other traces of work from my personal phone.
How in the world do you do that? Subscribe to Calendar isn't even possible with Office 365, right? You have to use From URL, to which you give the .ics URL, which Google Calendar normally pulls a couple times a day. Is there a different mechanism you use?
Hahahahahahaha. Good one.
I work at a department that's all about data quality and integrity, and we have super bureaucratic processes to regulate access to data, but you don't want to know how much data lives in Excel files; an issue I'm constantly trying to address.
No internet access at on laptops or only with a sim card which only allows connections to the VPN bastion host etc. Direct Internet on premise is a no-go as well, obviously. So no checking stack overflow if you've got any issues
They still leave infrastructure with default passwords exposed to the internet and implement questionable password policies for their customers... But they do everything they can in order to sabotage their employees!
Maybe make it a point to put your passwords on a sticky note stuck on the monitor prominently on display if $work requires you to change passwords that frequently?
I've been confronted with exactly this a short while ago, and even produced Microsoft's official stance on this (against). But in the end, their argument really boiled down to "but my checklist says so".
Microsoft's [0] first entry of "Common approaches and their negative impacts". With a reference to the FTC website. [1]
[0] https://docs.microsoft.com/en-us/microsoft-365/admin/misc/pa...
[1] https://www.ftc.gov/news-events/blogs/techftc/2016/03/time-r...
https://pages.nist.gov/800-63-FAQ/#q-b05
Q-B05: Is password expiration no longer recommended?
A-B05: SP 800-63B Section 5.1.1.2 paragraph 9 states:
“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”
Users tend to choose weaker memorized secrets when they know that they will have to change them in the near future. When those changes do occur, they often select a secret that is similar to their old memorized secret by applying a set of common transformations such as increasing a number in the password. This practice provides a false sense of security if any of the previous secrets has been compromised since attackers can apply these same common transformations. But if there is evidence that the memorized secret has been compromised, such as by a breach of the verifier’s hashed password database or observed fraudulent activity, subscribers should be required to change their memorized secrets. However, this event-based change should occur rarely, so that they are less motivated to choose a weak secret with the knowledge that it will only be used for a limited period of time.
That said, there is a place for 30-day rotation. That's when the so-called "password" is actually a shared secret for extremely high-value systems. Payment gateways, for example.
Should we even attempt to let the user define such shared secrets? If 30-day rotation is good, surely 30 second rotation is better? Perhaps we can replace such "passwords" with some kind of one time PIN (OTP) or some generated pass phrase only valid for n minutes?
I am all for having transient secrets, but without an extremely well integrated and robust vault they would be unmanageable. Plus asymmetric handshakes are computationally really expensive, so you don't do them all the time.[ß] The 30-day rotation period for these types of secrets is merely a reasonable compromise between "assume all shared secrets will be compromised" and the human factor.
ß: a friend set up a dedicated payment gateway device for a UK challenger bank. For just one card issuer. That thing can supposedly run at 10Gb line rate, so doing asymmetric crypto frequently would murder performance and latency.
Though, to be honest, at this point I believe that humanity should just abandon passwords for all but the most unimportant of things (e.g. your account on some hobbyist forum), at this point they just have too many downsides and most people seem to be unable to handle them properly.
If I have a personal thing during work hours I just block it off on the work calendar. No details, just "Not available".
Anything outside work hours doesn't need to be on a calendar.
In general, if I have a personal appointment, I'm not going to forget about it. Just the act of having added it to my calendar is enough to remember it, without having to look at the calendar. I only ever mix personal events into my work calendar if I there is an overlap with my working hours, everything else is none of my workplace's business, I'll polite decline any meeting that conflicts.
Besides, last-minute meetings are a sign of bad meeting culture.
It would be nice if I could sync my work calendar with my personal calendar, but with all details redacted except for begin, end, and perhaps location.
Settings > Calendar Settings > Access Permissions > Make Available to Public > on the dropdown, pick "See only free/busy". Now you can share the link with your work calendar and it'll show up as indistinct blocks of time.
You can do it both ways, and you'll be able to check your availability for both work-related things and personal things in their own calendar, but contextualized.
Aside from the odd appointment at the dentist or doctor's office, I don't have very many appointments that need to show up in both calendars. Work hours are work, everything else is personal and none of my workplace's business.
If one covers strictly work hours and the personal one is strictly for outside work hours, then no need to check both. Just check the applicable one.
I'm happy that works for you, but for me or anyone else who can be absent minded sometimes, that does. not. work. I need a calendar to remember promises I've made to people about when and where I'll be. Tuesday I'm meeting a friend to catch up in person, Thursday I've got a birthday dinner to go to, there's a show on Friday that I have tickets to. Stack multiple events in a single night if you have a busy social life. That's not a ton of information to remember but human memory is imperfect, and that sort of information is in one ear and out the other for me.
Prior to pocket computers, I'd have a paper datebook to carry around (and lose), but thanks to modern technology, it's stored in the cloud and accessible for me at https://calendar.google.com.
Can't edit original, but what I meant there is that it doesn't need to be on a calendar that work has access to (if the event is outside working hours).
For things on weekends I put those on my personal calendar. But that's clear-cut separation since no work event will ever be there.
The conflict is only for personal events during work hours. For those I put the blank placeholder in work calendar to block out the time.
They had no way of managing private keys, privately or properly at all
They did it anyway, in one instance one person turned in their computer for routine IT maintenance and it was wiped! lol! Its pretty obvious that a person like this only had a passing interest in crypto and never made any backup
Things are so much easier now with hardware wallets that connect to iphone apps
But its shocking how people often have no separation
But I use my own computers for most things. If I had to use a work-issued computer for work things, I'd be more careful about commingling. (I do have a work laptop, but I don't use it for very much.) I also generally keep personal and work email separate--to the degree one can really deliniate personal and work.
Thought maybe I was the only one. Text messaging is enough. Not even using any trendy apps, just a few basic things from F-Droid.
But then when you stop (I got a Huawei phone which cant install most of the corporate things for national security reasons), then wow. When I leave I leave, I do dilletante stuff, eat out with my wife and nobody cares. They just call someome else. I get probably less cookie points at annual reviews but a few rushes at the end of the year can usually compensate.
Stringent security rules and obnoxious firewalls exist because people don’t respect cool rules.
The lines have become too blurred. I work from home, I have one office and one desk. The computer on the desk was purchased by my company but other stuff wasn’t like my mouse or my iPad. I have work Slack on my phone, which is my personal phone. I know I should be, but I’m just not that careful anymore about what I do where.
Granted, I work for a startup. It’s a MBP they had shipped directly from Apple to me. I set it up and configured it myself.
The GitHub Balanced Employee IP Agreement acknowledges that this distinction is arbitrary and unhelpful:
> In California the main difference made by BEIPA is that IP developed with company equipment or relating to the company's business, but in an employee's free time and which the employee is not involved in as an employee, is not owned by the company (but the company does get a non-exclusive and unlimited license if the IP relates to the company's business). This recognizes that from the employee perspective, segregating one's life activities based on ownership of devices at hand or relatedness to an employer's potentially vast range of business that an individual employee is not involved with as an employee imposes significant cognitive overhead and often doesn't happen in practice, whatever agreements state.
- https://github.com/github/balanced-employee-ip-agreement
I hope that more employee agreements move this direction so we can stop trying to enforce this distinction.
I plug the same monitor and mouse into a work computer and a personal computer. This isn’t hard - you can use a single dongle with all of your inputs so you only need to swap one plug. Or you could use some kind of KVM switch.
I understand that startups may not want the expense of buying hardware for their employees, and you might not want to buy your own laptop, but if you end up building something valuable in your personal time, it’s in your interest to keep these things separate. For example, you might work on a side-project which is somehow related to your employer’s business, and eventually decide to quit and start your own company. You’ll be in a more secure legal position if you used your own device for that. You might judge that you aren’t likely do do that, but you should think through the trade-off.
The GitHub agreement sounds like an improvement, but most companies don’t use it. I’m not sure how well it protects your interests. If you’re working at odd hours because you’re receiving notifications on a personal device, while you’re also working on your side-project on a work device, would lawyers agree on what is personal and what is work?
With 2FA being more common in the workplace it just makes sense to have that on the work phone.
As for a RSA token key fob or phone text for 2FA, i prefer the phone as it can also show upcoming meetings and mails.
Though it's easier to forget the phone than your keys i'd say.
...and if you want to have personal stuff on a laptop you should buy your own.
I wholeheartedly agree with computers/systems, and keeping things separate there.. but two phones? Who wants to carry around two phones just for staying on top of slack during _off hours_?
If the company isn't ok with me using slack on my personal phone, then I'll only use slack on the supplied computer during business hours (eg. they get no mobile slack out of me at all). Either that or I find a different job. Life is too short to deal with so many devices and the hassle of it all.
What matters also is that I really like my work. And it isn't forced on me or even expected in the slightest. It's nice when I can pop in when I'm off and help out. If not it's fine too. Flexibility.
For me this works. I understand it doesn't work for many others like yourself. But that doesn't mean it should be made impossible for me (like some countries do, e.g. in France forcing work email to stop after hours).
For example, I am an extreme segmentor (two laptops and two phones, both of which are either off or put away in silent mode when I'm not working; zero work-related stuff on any personal devices).
At the same, my working patterns are very flexible. I just look at my diary first thing in the morning to figure which meetings I need to attend, and plan the rest of the day however I see fit. Going to the gym, for a run, sitting outside to read, running errands or getting a massage in the middle of the day are all completely normal.
I encourage my reports to take a similarly flexible approach to working, regardless of where they are on the segmentor-integrator spectrum (most of them are integrators).
I also want to be fairly compensated, though, and if I'm lying awake at 4am solving the hard problems because I'm so engrossed in my project that I'm dreaming about it, the only really fair compensation is a percentage of the profits. So for me, since nowhere I've worked is willing to contemplate a profit-share arrangement, this kind of work only really works if I own the company.
I prefer to do things whenever I want to do them and not bother with “on” and “off” hours.
Of course, workplaces tend to insist on remote data wipe functionality and that's a big nope from the get go.
The sad thing is, Google could fix this and use their authoritative position to declare it safe: support multiple encryption keys in the secure enclave on a device, encrypt apps associated with different profiles with different keys, and allow registering "work" keys as remote wipeable. Throw in some sort of copy+paste restriction option to satisfy the pedant IT managers who think cameras aren't cheap and common.
>Q: Why not use Island by OasisFeng, the creator of Greenify?
>A: Simply because it is not an FOSS app and it bundles with non-free SDKs. Note that this doesn’t necessarily mean that Island has anti-features like tracking (and I don’t think it has either), it’s just that I wrote Shelter as an FOSS replacement of it. There is no other reason why one would prefer Shelter over Island except for this one.
Work profile requires explicit support from your IT department, but Android also supports multiple user accounts on one device (each gets their own lock screen, home screen, app switcher, notification shade, settings, installed apps, etc), so you could segregate things that way too if you can't get your IT department to support work profile.
I feel like multiple user accounts is an underappreciated feature of Android. I just got an iPad and it's a real drag that you can only have one Apple ID logged in on it, one set of apps, one home screen, etc. Tablets are made to be shared.
Why would I be doing that?
Having entirely separate devices is BY FAR the best thing I have done for my mental health and productivity. Same as other posters here.
If I want to see a friend in the middle of the day, I do it. If I want to take a 3 hour lunch, I do it. When someone 8 time zones away answers a question I asked earlier at my 1AM, and I’m awake and see it, I’m excited to learn the new whatever thing, and may take an hour (or three!) to chat with them about it.
Everything I do in life I have opted into and enjoy. I gain nothing by firewalling some parts of it from other parts.
I have tried every modality of managing work and personal life and this one is by far —- by far —- the best one for me. The notion that there is a work laptop and a personal laptop and naer the twain shall meet is a complete anachronism. It’s fine if that separation helps other people but it actively hurts me.
[1]: https://en.wikipedia.org/wiki/Biopower [2]: https://openaccess.city.ac.uk/8237/8/Review%20article%20-%20...
Wow.. All I can suggest is think through the consequences. Unless you work for yourself or a very tiny startup, your employer is monitoring everything you do and store on the work computer.
You may also get cut off at any moment with zero notice if there are layoffs. If you had any personal content there, you've lost it.
Also, depending on where you live, but it can also mean now the company has a strong ownership claim to anything and everything you do in side projects since it is being done on company equipment.
In that case hopefully not but as seen elsewhere in this thread, for other OSs they can fully own it even if shipped factory direct.
Unless manufacturers are putting these spyware hooks directly into the firmware? Haven't heard of that yet, but those things change.
Well you said personal MacBook, this topic is about work laptop or phone.
These days (sadly) for any non-small company, all work computers and phones have remote control spyware. If you think that's not the case in your large company, you're probably wrong.
At a recent medium size engineering company, I was constantly surprised how even extremely technical engineers in the company didn't realize all the company spyware that is running on their laptop.
I do have MDM on my personal iPhone but that seemed like a reasonable tradeoff in order to easily access work email and files on my phone.
Same rules apply even in that case. If you can't txt/page/slack me on my personal phone, then you don't get me "on-call". I'm _not_ going to carry two phones for anyone ever again (been there, done that, hated it).
And you should be compensated specifically for that on call time. A standard is 1/3 of your on call time out of business hours is credited as PTO hours for 30 minute response.
Or 2/3 of your on call time out of business hours is credited as PTO hours for 5 minute response.
I have no issues carrying the work phone with me during the _working hours_. But off hours I just leave it next to the car keys, so I don't forget to take it with me the next morning. Just because I have a work phone that I didn't ask for doesn't mean I have to carry it with myself or even check off hours. It is useful only to have a toy to play with during the boring face-to-face meetings.
I
Shouldn't the thing _actually be_ "if they want you to have Slack on your phone, they should pay you for availability during off hours"? The phone buying is a basically one-time cost from their perspective.
Slack/Teams on my (personal) phone means I can run an errand in the middle of the day and still be available. I’m happy to use my personal device for it. The alternative is having much less flexibility.
If my employer expected me to be available outside office hours or when not at my computer it would be a completely different story. Like if I was on call. Then I’d demand they pay for my smartphone too.
Where I work we managed to ship thousands of laptops to students homes from the manufacturers during lockdown and but still ensured that they had the correct E-Safety software and configurations on them when they turned them on for the first time.
On iOS however, it can't. iOS won't let itself activate without internet.
How would that work?
We do this for all Macs and iPhones for our employees, we buy them directly through our Apple business portal and it all automatically registers to our JAMF account.
This seems ripe for exploiting for nefarious purposes. With Apple having built it, all it takes is one court order targeting a serial# and it auto-installs full remote control spyware on that mac?
It's not being talked about much, but since companies are okay paying landlords billions, they seem to be shy to pay their employees for use of their homes as offices.
Do you charge your company for your commute to the office?
I can see where you are coming from, but charging the company for office space in your home is a bit over the top IMO - paying for the setup should be sufficient. Additionally, working from home comes with time and money savings for you (unless your answered "yes" to the question above), so it's not like they're using your space with only disadvantages to you. Lastly, renting out the space in your office might come with further drawbacks, as the company could demand more control of the space it is paying for.
Why? What about electricity bills?
> so it's not like they're using your space with only disadvantages to you
Then put it in contract as a home office agreement and not assume that everyone is okay with it.
Travel expenses for your commute are pretty standard. My employer offers either a per-kilometer amount (if you travel by car) or a train subscription, if you travel by public transport.
Companies tend to pay people for their commute here in Belgium. This can take the form of paying your train pass, a reimbursement per kilometre travelled or even a company car + fuel card.
That doesn't cover the hours spent travelling, of course.
This thinking is fascinating. Why do you think company shouldn't be paying for use of someone's property?
I can weather this as a temporary pandemic measure but for some of my early-career colleagues it's a very serious burden.
HARD disagree. Use a separate personal machine and a KVM switch or hub/dock.
I work from home, and I just switch machines. I also have cut off times for when I am allowed to do personal things vs work.
The more you mix play and work, the worse both end up being.
This! Especially with Thunderbolt being widely available n high end machines, switching between computers is easier than it ever was. I have a work Windows machine and a personal Macbook. Switching from work to personal system is a matter of unplugging and changing a single cable.
I too disagree, and aside from that, it's such a defeatist attitude.
It's sensible to separate the two in principle, but the arguments forwarded by the author seem to ignore the actual substance of the issue here: that people ar not machines that can genuinely do "work" and "play" separately and that employers should not have that sort of power in the first place.
The world we should strive to build is not one where security issues are entirely removed from the equation or where employees become perfectly aligned with their employer's business needs, but one where most individuals of the society lead healthy, fulfilling, meaningful lives.
As such, it's not the employees that should remove their humanity from teh workplace, it's the workplace - the employer - that should be take (many) steps back and allow people to be people.
The activity might just be that the laptop connected to the internet, but I'd still consider changing passwords.
I'm sure there are better ways to setup the VPN but it works for what I wanted it for.
You could be fired tomorrow, and your access to your hardware revoked instantly. Apple devices, in particular, allow IT to remote lock your laptop. Whatever you had stored on the drive is lost to you, available to your employer, and you can't do anything about it.
Don't mix business and personal hardware.
That sounds like a massive privacy and security issue. Do you have more information?
https://support.apple.com/guide/mdm/mdm-overview-mdmbf9e668/...
If the user owns the machine, then there must be authorization and the MDM has much more limited, privacy-preserving scope.
No, you can't. The employer has proof of ownership because they buy the machine.
[1] https://support.apple.com/guide/server/intro-to-profile-mana...
Co-usage is just a thing these days. A little trust in your employees is also important. Usually these profiles just mandate some basics like password complexity, disk encryption and they set standard settings like WiFi and printers so you don't have to bother figuring all that stuff out. And it will install applications you need and security stuff.
And don't forget, a password complexity profile on a Mac will apply to all accounts created on it. Even ones created by the user. Many things work like this, on a machine level. It's more about establishing a security baseline than tying the users' hands.
Having work emails/chat/etc on my phone has been a great benefit -- it means I can be untethered from desk but not miss anything important.
The company just says "your new job is to stare at the login screen until HR can schedule a meeting with you."
Not according to the comment I was replying to.
Employed or not, your access isn't under your control.
Certainly if a machine is stolen I’d expect it to be remotely wiped. Same with a phone.
If you have hardware that isn’t under an mdm system though that’s different.
Though I would prefer to see stricter separation like Android Work profile on computers too.
As for what happens if your Chromebook is stolen and you've not selected the option to lock it when the lid is closed, Workspace/GSuite accounts can be remote wiped, personal ones cannot. Perhaps with the upcoming Workspace Individual plan, remote wiping of personal accounts will be possible too.
It's something I'm not worried about in general given our work policies and practices. I just travel with a personal MacBook or Chromebook.
Personal Apple devices are closest to the definition of "PC".
Yet my multi-user Linux desktop system is called a "PC".
(I'm technically not on call but on practice it's messier)
As for me, I’ve done the two-laptop thing when traveling since 5y or so. It’s actually worth it for other reasons too - having your only computer have a hardware failure or be stolen in the jungle is no fun. If both are of the same make you could even boot one’s drive off the other in a pinch.
For all the “what about X?” questions in this thread... you will figure it out easier and faster than you think once you force yourself to change habits.
Solvable with wake-on-lab.
- 1 MbP for my actual job. I’m not admin. I can’t even trigger a update.
- 1 MBP to access the parent company system. Like … 1 a month. ( it has a vpn client that I can’t install on the first one … that’s all )
- my personal laptop. Because I can’t do shit beside working on the two first.
It’s ridiculous
I used to do this in earlier times when personal use was still a very dark thing (in our company it has since become normal - at least web browser stuff). In the days I carried a ThinkPad T42 I would just slip the HDD caddy out and stick in my own at night in the hotel.
Later on I ran my own macOS on a company mac from a USB 3 HDD. Just hold option when booting. You can even encrypt both to secure them from each other.
Luckily these days I don't have to bother with any of that anymore. But they weren't too bad options as long as you don't need both environments at the same time.
What’s annoying me is to have to carry 2 work laptop.
Oh well :)
But good tips.
So I’ll keep those others in the closet
(next to the flux capacitor)
Just one of the many ways that dual-use is becoming more common. And OSes are increasing their abilities for it too. Mobile OSes are already great at separation. Windows is coming along slowly with Windows Information Protection and Azure Information Protection. Mac has user enrolment but it's in its infancy, sadly.
You can also be compelled by the courts to surrender a device that holds information relevant to a civil or criminal matter. For example sending text messages to a coworker on your personal phone about how you are going to coordinate your efforts to block someone's promotion.
They monitored the living bejeezus out of my work equipment, and wouldn't let personal equipment (including phones) connect to the corporate network.
It was pretty overboard, but my company was seriously paranoid. It actually caused problems. For example, we wrote optimized C++, and optimizing on a monitored system is...difficult; especially with some of the custom gnarlyware we got from companies like Intel.
It also meant that I never worried about mixing my personal work with company work. If I had personal equipment at work, I would use 4G/hotspot. Not ideal (so I didn't really do anything more than check emails at work). It also allowed me to get to some of the banned sites (the company had a nasty habit of banning exactly the kinds of sites that optimizers like to read).
Another benefit was that I left my work equipment at work, so I couldn't easily be roped into doing out-of-band work. I had a great excuse.
It was annoying, but fine with me. I think the company went way overboard in their paranoia, but it was their company, and they got to set the rules. I have never had any interest in causing issues with them, so I was careful not to do anything that would step on their toes. They pretty much returned the favor.
In addition, he had PCMCIA cards (this was before thumb drives) that contained classified data and were used in the unclassified desktops and/or laptops.
Later I gave that laptop to someone to learn to code on and now they're a full-time software engineer.
In all fairness, I suspect me buying 2 laptops every 3-4 years instead of one laptop over the same period is a small environmental impact compared to other things (air travel, dietary choices). But it also seems like that's not a reason for me to ignore its impact. And the aggregate cost of many people having 2 laptops instead of 1 is probably worth considering.
I thought about ways to only have one device (running my personal "machine" as a VM on my work laptop or vice versa) but couldn't come up with anything cleanly satisfactory.
Today I don't even want my personal phone connecting to corporate wifi. I work with these cats, I know how they think. So yes, two devices please.
This goes against corporate policy, but it’s a good reason to not trust any wifi you don’t control.
I’m a two-decvicer. It increases the lifespan of my personal computer. And, more often than not, when I have left a job, employers have let me keep the old laptop, saving me from buying a new personal one. Honestly, are you really telling me you’d not own a personal computer? This sounds extremely trusting towards your employer, and puts you at a lot of risk depending on their policies and philosophy.
It wasn't technical aspects of VMs per se, it was how to use them while still keeping things separate. If I had my personal machine as a VM on work baremetal, then in principle the personal VM wouldn't really be isolatable from work because if they had a keylogger then it would capture all input.
Edit: To be clear, I don't think that my employer uses keyloggers. But if the purpose was to keep personal and work separate, I didn't think a personal VM on a work machine really provided enough separation.
I didn't carefully investigate the reverse (having my work machine be a VM on top of a personal laptop) partly because MacOS is easiest for a work machine and I didn't want to mess around with trying to run MacOS in a VM.
> This sounds extremely trusting towards your employer, and puts you at a lot of risk depending on their policies and philosophy.
That's exactly why I didn't go down that route.
But one thing I found which is great is setting up my work and personal laptops next to each other on a laptop holder and doing everything through external monitors.
At my desk I have an adjustable laptop holder which holds my work and personal laptops, as they're both macbooks switching between my work and personal laptop is as simple as unplugging a couple usb-c hubs, plugging them into the other laptop (the port is 1 inch away), and pulling out my other keyboard.
This sentiment is a typical early 2000s mindset. It no longer works in this world where the line between business and private lives have blurred. And it wasn't just the pandemic that did that, this has been going on much longer.
Who wants to bring 2 laptops on a business trips? Or 2 phones for that matter? Computing is flexible in the age of the cloud. Mobile OSes are really good at separating personal and private data (think of Android's Work Profile and iOS's User Enrolment). Personal computers (either Mac or Windows) don't do this as well yet, but at least they're a hell of a lot more secure with everyone enforcing disk encryption now.
But we should remember that technology is there to serve us. If the tech can't deal with our increasing mix of private and business, we'll just have to make it better at that. Telling people not to do it just won't work.
I have one exception: Installing personal apps on a work computer is not really OK (unless the application has already been approved for work too). On mobile this is fine because of the more rigid separation.
PS: This is not just my opinion, it's the company's policy. We explicitly allow personal use (including apps) of mobile devices and most personal web usage on company laptops (though blocking malicious sites and stuff that's not really "business oriented" :) ). We do block some things like sideloading on mobile. Our devices are still secure because we enforce what's important (like decent passwords, full disk encryption). Our users are happier because we don't treat them like children. We're happier because we don't need to approve every taxi app anymore that a user would want to use on their work phone during a business trip. We just make sure their apps can't access the work apps. On mobile this works really well and on PC/Mac it's in the works.
It's a give and take. The early 2000's us-against-them BOFH total lockdown thing just doesn't fly anymore.
So the approved usage is more-or-less only the web browser? If the user can make do with that for their personal stuff, they would probably be happier with a tablet anyway. If they can't, then, well, they need two laptops.
In other organisations I'm sure those IT policies remain, but certainly in my part of my organisation I have a vanilla desktop, which replaced my vanilla laptop (haven't used it for 3 years). There's a corporate laptop (which is vanila OSX with MDM), but more and more corporate services are available on web and I haven't used it for over a year.
I haven't paid for a mobile phone since I got my first work phone in 2006 (when phones were just for phone calls and sms). Most people in my organization that had phones back then (we tend to stay in the same company for life) are still one-device people.
So yes, from an organisation point of view, it's an antiquated mindset about control over worker drones.
In my experience, it's younger people who didn't join or get to a point where they had a work phone until after the smartphone revolution, that tend to carry two phones - a personal one and a work one.
Of course I do my personal coding on my own machine because of ownership/legal issues.
But replying with Gmail to my plumber or drawing my new kitchen using the CAD software on my work laptop or writing the invitations to the neighborhood barbecue if it’s more convenient? I’m just going to assume nothing bad will come of it.
Sensitive data, competing business, security risks, sure. But that’s pretty rare. Convenience easily trumps it.
Separating work and personal machines also improved my WFH experience. When I shut down my work laptop, I put it in the drawer and the work day is done. Whatever happens, I will have to deal with it the next morning. And to avoid that, no deployments at about 1h before I leave so I don't get dragged into hot-fixes. If it's an urgent fix and it's end of day, I just stay a little longer, at least I have more control that way and no phone calls interrupting my evening.
There has been at least one high profile case over the last few years over people who didn’t do that.
As you might be able to imagine, this happens pretty often.
If you have a good relationship with your boss you can do that, in the company we all manage our own devices, meaning that the operating system and stuff is decided and installed by whoever uses the computer (Linux, Windows, macOS, whatever you are more practical, that is also an advantage since we ensure you can develop a project on all platforms). Also we have basically have all admin access on everything personal and everything that is shared (shared computers in the office, network equipment, servers, etc).
I could not see working on a place where I have to pay attention on what I do on a particular device if not they will punish me. To me it doesn't really make sense, the computer that I'm using is mine till I use it, of course if I change job that computer will be formatted and used by another person.
There is this concept but to me it only slows down work. If I have to do something personal related on the desktop at work I do it on the desktop, similarly if I'm at home and I have to do a fix on a production system I do that on my personal laptop, or I answer a Teams call from a coworker from my mobile phone.
Get this, Charlie; get this, Charlie! It's cookies... Cookies! Oh, the humanity!
Never ever put anything personal on a work laptop. I recommend remote desktoping to your personal machine and doing all your personal stuff on that machine, so you get the best of both worlds.
I don’t see why anyone would do anything else.
“This guy was browsing incel forums from this time to this time”
Which court in what land uses that information?
Sounds kind of mythical, especially since I’m sure there’s an army of other people on idiot forums like that who are nonetheless performing fine.
EDIT: Okay, you guys hit me with sufficient downvotes that I’m rate limited so I know the predominant view is different.
Fine. I’m not a lawyer, but I’ll tell you this. If some rando IT dude is going through folks’ computers after they quit and I find out, I am quitting your company and telling everyone. I have never done that to anyone reporting to me and no company has ever done that to me. I can’t believe you’d accept these work conditions. Wild.
"This guy was conducting illegal business using the company's network"
"This guy was running his own mining rig on company servers"
It's not hard to think of actual cases that happen.
Y’all are playing me if you think that.
That said, I agree with the commenters that I wouldn't want to work somewhere that did this as a matter of routine. I always have my work laptop encrypted with a key only I know and I have not (yet) been forced to give work root access for management. I'm always confident handing in my laptop that they couldn't find anything even if there was something.
Are you a lawyer?
> Which court in what land uses that information?
That seems like a question for the legal department, not for the IT department.
You're doing this thing that smart people do (I know because I do it myself if I'm not careful) where you way overstep your area of expertise. It's not a good look, avoid the trap.
However, that's just not the world we live in. From the perspective of an employer, you can make your choice to behave ethically regardless of the legal implications, and that's a choice that I would laud you for. But from the perspective of an employee, you shouldn't assume that your employer will behave ethically: on the contrary, I would always assume that your employer is going to go through your computer when you give it back. You can fight that if you want, but that's not the hill I would choose to die on, as there are much worse privacy violations going on.
If you want to see how bad things have gotten, freeze your credit, sign up for credit monitoring, and then start applying for jobs, and see what happens. About 75% of jobs I've applied for in the last few years have tried to pull credit reports--and you can't really stop them as long as they do a "soft" credit check (freezing credit doesn't block this).
Every large company I've worked at or heard of it's pretty much assumed that IT may monitor everything you do on their machine. Everyone knew this. Which is why you don't use the company laptop for personal use.
I have been using my work laptop quite heavily for personal use and I would prefer not to stop honestly.
I believe my intentions are pure and to provide value, I understand world is not perfect, but I would not want to work for an employer that needed to monitor me.
Lastly, the companies or specific malicious admins might simply not care about the legality and still monitor you - either for company reasons or simply to stir through your data. If they have admin access to your computer, it's simply not your computer.
But it is stupid to allow any old IT staff to do so, and this thread is a good illustration of why: because most IT staff do not have the discipline or smarts to keep what they learn sufficiently confidential. Allowing IT staff to browse the files of other staff at will can lead to other HR problems such as harassment or even blackmail, or loss of corporate reputation if people post embarrassing stuff in, say, a public HN thread.
The ability should be exercised only under the supervision of a lawyer, which limits bad behavior and creates attorney-client privilege for discussions of what might be found.
I worked at a place that did have good 'secrecy' around most monitoring. While I was one of three people outside of Infosec that managed to find out that someone was let go because they were caught exfiltrating client/employee PIFI... I'm pretty sure nobody who was possibly compromised got informed.
This was a place that was so concerned with image that the handbook was about as strict as what my Sister had to deal with when teaching at a Catholic school. Image was everything to them.
Sure it’s company hardware, and you get to do this shit but damn that shit would be like “I gotta get out of here” if I heard IT was scanning people’s browser history for sucking at their jobs.
EDIT: The lawsuit thing makes this even worse. If I even heard that someone was suing their employees for poor performance I am like straight up blackballing that company and all of its damn subsidiaries as places to work. Like my friends would know, my family would know, friends of my family would know. I’m sorry, this is straight up unacceptable to me.
Unless this guy was sexually harassing people, I'm curious how this is going to protect anyone from any kind of liability.
>you should remember that the laptop belongs to the company and you have zero rights to privacy on it, so conduct yourself appropriately.
Yes, but as others have mentioned, just because the company has the right to do that doesn't mean it's either ethical OR good. No one here was asserting the right to privacy on company owned hardware.
I Never have work email on any other device but works.
I do not know how it works in your country, but anything that you discover of his personal life becomes a liability for the company. If he had AIDS and now you get that knowledge and it leaks, you may find the company fined for big money. In Europe, again and again, companies are forbidden to use any knowledge gained spying on employees.
What reason would you have to investigate an employee that is leaving the company anyway? Unless it has some contractual impact and your company HR/legal department is aware, there is no reason. "To see what the employee was doing" is not a legal reason.
I strongly agree that IT needs ethical education. That you have access to some information does not mean that you have the right to access it or that it is moral to do so.
>What reason would you have to investigate an employee that is leaving the company anyway? Unless it has some contractual impact and your company HR/legal department is aware, there is no reason. "To see what the employee was doing" is not a legal reason.
In our case, we would and could never investigate someone for any reason besides HR and/or legal explicitly requesting it for a specific reason and telling us what they wanted us to look for and why. "Fishing expeditions" weren't permitted. (There were a few occasions where such fishing expedition requests did come from them, and our managers would push back and basically professionally tell them to fuck off.)
I'm not sure of any specific laws or liabilities, but I'm sure we also would (and should) have likely been sued if we discovered some sensitive personal information about an employee and that information then leaked. If we inadvertently stumbled across personal things like that during the course of a specific investigation, we would always ignore it and not make any record of it. We didn't care about someone's personal life and didn't intentionally ever look at anything related to it.
Due to the nature of the investigations, it was often unavoidable that we'd end up seeing something at least somewhat personal, even if it's just some random website they habitually browsed appearing multiple times in their browsing history.
So, we would never look at an employee's computer or network traffic "just to see what they were doing" or just because we could. That would definitely be extremely unethical and unprofessional, and if management discovered any of us doing that we surely would and should have been fired. However, I'm not sure if there are actually any laws against that in the US if it's disclosed in the employment contract.
Well, an obvious one is "did we fire him for cause or will we have to pay more unemployment"...
Because that is the smart thing to do. I got to purchase my laptop when I left the company, and they still wiped it out before handling it. It protects them and it protects me. I do not want access to any company resource, it can only hurt me. And they are not interested anymore on what was in the laptop either.
Fortunately that idea was beaten to a bloody pulp by the HR team before it got off the ground. But you would not believe the mall cop mentality in many companies.
Edit: I see the printing part. I guess I was more shocked at the call out to MapQuest.
Not to mention the roadside assistance and towing coverage. I take long roadtrips too. The couple times that AAA has saved me make all the yearly dues worthwhile. E.g., once they arranged a 300-mile tow from a small coastal town back home; it took less than an hour to setup and didn’t cost me a dime. The alternative would have been paying next-day air freight on a Mercedes alternator and battery, and staying another 2 days to get the work done.
(Because, in Germany, even if you're an ADAC member, you'd be hard pressed to find an ADAC-affiliated office to pick up a map from...)
The bottom line is that if you're having a problem and you're in an automobile (doesn't have to be yours) AAA will do their best to help you solve that problem.
Unlimited, free, high-quality paper maps are just another perk. Walking in to a member branch and walking out with maps is just the beginning: a AAA employee will help you plan out a road trip, and make what's called a TripTik, which is a custom spiral-bound route map, with various sorts of amenities you can choose pointed out for you.
There are campgrounds as well. It's truly remarkable how much AAA offers.
However, I would caution you that some of the benefits that used to come from being an AAA member have been severely curtailed. The towing benefit, in particular, now has quite a few restrictions on it.
It's saved my bacon a few times at this point. Basically a (large and unwieldy) cell phone I can pull out when my main driver falls dead.
Pro tip: install ride share apps on the tablet in advance, because in a serious UX fail, Uber and Lyft both want you to receive an SMS code to activate accounts. I was lucky that time, that getting my iPhone out of airplane mode at 1% battery wasn't enough to trigger forced shutdown.
Lyft doesn't even have a separate app, but Uber actually offers an iPad-native experience, but is unable to activate you without SMS. Which, along with standard voice calls, is the one thing a data plan associated with a phone number won't let you do except from the primary advice.
(Well, that or Pi 400, but I worry how well the Pi 400 would hold up for travel, or about getting a hotel room with no easy HDMI on the TV)
Of course regular taxis are also still a thing ;)
When I lost my phone in Madrid, and realized that I have no way to call a taxi, since I was staying in a residential area where you don't see taxis in the streets.
My Spanish was barely sufficient to explain my predicament, and I lucked out because a random convenience store clerk called me a taxi from his phone.
Which reminds me: in case you didn't notice, there are no more payphones. In 2001, I could walk up to one, and use one of them Yellow Books to do anything you could do one the phone.
Today, you need to have a smartphone to do many basic things.
There are still some payphones here too, but most of them have been vandalised, that's true.
Which in typical fashion, I dropped off just under the deadline, so the office was closed.
Oh did I mention that no there aren't regular taxis on this island anymore? I should have mentioned that first.
As typical I became the guy who could help coworkers fix basic PC stuff quick. I didn't mind this as I got to know my coworkers and really just did simple things for just our small team.
One guy calls me over to help him with why he couldn't open some images on his computer. I fix the file association and ... yeah it's porn.
A little while later a guy brings in an old digital camera (back when they had some weird proprietary formats for images). Yeah his daughters were taking pics of them standing by the highway flashing traffic as it goes by.
Nothing ever came of any of it, but here I was thinking loading a bunch of mp3s on my computer was a bit dicey....
I'm not sure people's attitudes have changed that much in the following decades.
The same people installing SolarWinds and requiring you use Outlook with 10 different comprised extensions will be the first to try blaming their employees for installing Docker or kubectl because it wasn't approved software yet you were brought in to be the container expert.
I suppose you could wrap it with Windows sandbox[1] if you're paranoid.
[1] https://docs.microsoft.com/en-us/windows/security/threat-pro...
If they buy you internet, they are tracking it. If they provide you with a computer, they are tracking every click and pointer movement.
Keep work computers and personal computers separate and that includes all methods of IO.
I used to work for a Fortune 10 company, and they retroactively changed their approach to personal data on company computers. Yes, does it sound illegal? Very much NOT so, but they totally got away with it.
....Except there was an accidental malformed script that wiped all the user folders and backup data. Ever wonder what happens to a SAN when every disk shits itself for a few days?
I'll never really know what the outcome of the malformed script was except there was no retroactive application of corporate rules because the thing the rules were meant to apply to simply didn't exist anymore.
Coincidentally, it was also the same day that I quit and decided to work for myself.
"Malformed script"
You meant this as an exaggeration, right?
If not -- How exactly are they doing this? Every click and pointer movement is less useful without the corresponding screen capture.
The only work thing I have on my personal phone is Slack, and that's with auto-DND outside work hours. If there's an emergency, you can call me.
As far as I am concerned, I am your paid consultant, and I will grant to you far more valuable information (via source control or shared docs) over the course of our shared engagement than you will ever grant to me. When you are no longer able or willing to pay me, all of it will disappear in a plume of smoke, like crumbs on a dirty plate.
Whatever you may think about the fairness of these, there are consequences to your actions. With regards to work, laws and policies don't adjust based on what you believe. (They are based on what you do or don't do.)
As for asymmetries of power, that’s up to you to assess for yourself and your own well-being, as to what you’re willing to cede to someone else. Don’t be weak.
And-by the same token (no VPN pun intended)-if your employment relationship is not based on some degree of trust, you’ve already lost.
> Don’t be weak.
I think I know what you mean. The key word to me is "assess", as in "be mindful" of the gap between your goals and reality, your options, and the likely consequences.
Since this kind of aphorism ("Don’t be weak.") can be interpreted in many ways, I like to elaborate. In this context I would say:
* Know your legal rights
* Be proactive, protect yourself, have back-up plans
* Understand the pros and cons of your options; e.g. standing up for yourself. The downsides may involve employer friction and perhaps legal cost and lost wages. The upsides may be deferred and quite uncertain.
* Pick your battles.
Beyond the individual dimension, raising awareness, organizing, and collective action go a long way towards promoting employee rights. These improve the "menu of options" available to individuals dealing with organizations that tend to benefit from a power imbalance.
P.S. VPN = Valiant Pun Noticed
I've never seen crumbs on a dirty plate disappear in a plume of smoke. Maybe I'm missing out?
Are you in the habit of nuking your plates?
When I started needing specific apps for work, I also got a work phone. I don't think my employer is doing anything creepy, and now I know if I'm wrong about that, it is contained and severed from my everyday phone.
But that's an expensive option.
Are you saying you personally purchased a phone for use as a work device? That's completely bonkers to me. I have a personal phone and a work phone, but I definitely don't pay for the work phone out of my own pocket. I even made them order the case and screen protector I put on it.
When installing any software such as applications, or as developers, dependencies for your programming language of choice you're always at risk of installing something that once executed would for example grab your ssh keys and push them to a server somewhere, or all your environment variables, etc,etc.
So, if that happens when doing normal work, it sucks, it's bad, but you were doing your job the best you could.
What I think it should be unacceptable is for this to happen when you're working on your own side projects or your personal stuff.
To avoid this, as everyone suggest, don't use your work laptop, but if you do (example: while traveling, or because your work laptop is more powerful, etc) just create a separate user account on it. Just this simple thing will provide a lot more security and protect your company from a lot of security issues.
The back looks like this, to give an idea of scale:
https://www.refurbishedcomputerslaptops.com/wp-content/uploa...
What a lovely little platform, especially for $100. That’s a price point that makes hardware replacement easy to stomach. It also freed up my MBP for personal stuff only.
Being a desktop it also means I have to “go to the office” to do work stuff. Bliss.
If you do consulting for multiple customers, then you may be able to create a different user account per customers, so there's some separation among your customers' information.
If you're able to use thin clients, then you may be able to create separate user accounts on the servers, so any files stay fully on the servers and never download to your local computer.
When you use multiple user accounts, you're having the operating system help separate things per account, such as each account's credentials, profiles, logins, histories, cookies, caches, etc.
Maybe it's sending personal texts or emails from your work phone, editing personal documents or photos on your work laptop, or joining a virtual happy hour with friends from your work tablet.
So... I agree with much of this article. However, the above is silly and undermines the point. Basically living with these devices should not be a concern any more than faxing personal health expense forms using the company fax machine. Or using the cheap pen from the office supply room anywhere.Should you do projects with company resources? No. But that is not exactly a slippery slope. Don't pretend it is one.
On the other hand, some habits form slowly. Sometimes bad habits creep in when you are in a hurry or lazy.
It depends on many factors. Many people find value in setting rules that seem too strict for others. Know yourself and choose accordingly and/or adapt to your workplace as necessary.
At large, I also think that this means some things can't be codified. Such that some activities are highly dependent on expected duties of the employee.
As an example, as a security guard, if on the job you think up a good movie script and get it written, I don't see any argument that you thought of it while at work compelling. Even if you jotted notes throughout the day. If you are a staff writer for a studio, I'm sure the case is different.
So the same here. It is not a slippery slope. Nor is it a uniform field. And, in general, I suspect I would side with individuals over corporations way more. Probably not exclusively, but predominantly.
Edit: not that I think your advice is bad, really.
I'm not sure I'm following how your comments got here. Do you intend to make the above broad assertion ("we shouldn't, as a society, accept that some things are wrong")? To put it another way, are you arguing in favor of moral relativism?
An interesting point. Many of these assessments are arguably subconscious and/or inculcated.
Some philosophies aspire to as few fundamental guiding principles as possible. Such a structure tends to improve self-consistency.
Other philosophies allow a broader mix of principles, sometimes in tension, which require considerable subjective discussion to untangle. Perhaps one could say these philosophies value human discussion as a core principle from which meaning is constructed.
That said "these philosophies value human discussion as a core principal" really resonates with me. I don't like policies that are designed to be enforced without the people involved interacting with each other in some form. Again, yes there are some straw men that we should burn down when they appear, but I have a hard time with policies pushed in a "zero tolerance" fashion.
I'm pretty sure you mean "some things shouldn't be codified". I'm not trying simply to nitpick; I think using the word "should" signals very clearly that you are making a value judgment, not a judgment of what is possible.
Here's how I'm interpreting your words: "There are many employee behaviors that employers want to promote that are too nuanced or complex to codify". I have a lot of concerns with such a statement:
1. I've seen a lot of people make such a statement because they are unwilling and/or unable to design policies. Some people want perfection, and the messiness and complexity of the real world bothers them. Instead of embracing and managing this uncertainty, they retreat to the false dichotomy of "if we can't do it perfectly, we shouldn't try it at all".
2. I find the statement implies the wrong goal. The goal isn't perfection; rather, the goal is to make policies that *improve* relative to *the next best alternative*.
To design policies and assess performance toward such goals, I like to use a combination of systems thinking, probabilistic reasoning, and realistic models of human behavior.
This also depends on your role. If you have a leadership role, you will likely see that not designing and advocating for policies is an abdication of your responsibilities. In short, no matter how imperfect, you have to make a decision. To quote a movie title, you can't be neutral on a moving train.
Agreed on doing things to try to move the needle in a better direction. I will disagree the minute things land in a "zero tolerance" bucket. Yes, there are easy straw men that can and should be burned down. Nuance and discretion abound, though.
So, I probably do not disagree with the method for making policies you are describing. I'm also probably more comfortable with the idea that many policies are ultimately to be questioned, as well.
That's why I created BenkoPhone (currently Australia only :)
Most of the time, I have two X servers running, so I don't even to login/logout, I can switch from one to the other anytime.
I now have three laptops, two iPads and two iPhones on my desk all day though. Which is a complete fucking pain. Some days I wish I did something else for a living.
In the case of the Microsoft Company Portal app, and enrollment in InTune, a separate work enclave is created, at least today. The enclave is fully controlled by your company's InTune policies, but your personal enclave remains untouched. It's how MDM should be.
edit. It seems like they can remote wipe IF they are using Office 365 with an MDM (like Intune): https://docs.microsoft.com/en-us/microsoft-365/admin/basic-m...
However I just have Outlook and Teams installed. No MDM like discussed here: https://www.reddit.com/r/Office365/comments/l5n70u/if_i_inst...
Here's a screenshot showing that Outlook is not authorized to remote admin my device. So I should be fine: https://i.imgur.com/K5T4DBK.png
I kicked everything off my phone. They can buy me a phone if they want to control it.
I know it's easier to have 2 laptops (one for work, one for personal stuff), but I can't ignore the convenience factor. For example, I have text notes on tech/programming that I have made since college, and I refer to it often while at work. It's easy to copy/paste in single laptop. Recently, I've been using Synergy so I can run 2 separate PC, so it does help a bit.
1. It starts with an anecdote about a CIA director in the mid 90s. Umm, yeah, if you have access to top secret info, I would be very careful about mixing work and personal content.
2. It talks about how much of a pain it can be if you have to wipe your personal data off your laptop when you return it. I may be somewhat unusual for the HN crowd but not for the population at large but virtually all the data I care about lives on a few cloud services, and backing up a few trivial files (like my updated zsh config) is easy.
I just always have one personal Chrome window for any personal stuff, and a separate Chrome window with my work account. Totally easy to keep things separated that way.
Don't think you don't have that. Do you work with any personal or internal company data? Do you have access to systems that contain them? I.e. Databases, Backup Servers, internal portals with company-only announcements ...
Sure, you probably don't work with data classified as top secret, but being implicated in the release of personal data or internal data, especially if it helps the competition or influences the stock price, will get you very quickly in really hot water.
> I may be somewhat unusual for the HN crowd but not for the population at large but virtually all the data I care about lives on a few cloud services
... as well as your local files (Dropbox & Co.), your browser cache and your OS cache. Maybe your password store. Just because the data is not mainly stored on your device does not mean that nobody will access it. Also, people do run data recoveries on these, especially when you did not have time to prepare for this ("This laptop is under investigation, we take it right now, please report to HR").
The server has 24 cores, 32GB/1TB, and I can't see what an equivalent AWS instance would cost monthly. But it's easily more than $25. The PowerPro (8vCPU 32/175) is $148 monthly.
This is especially true of companies with sensitive contracts, data, or relationships where they have all kinds of reasons to want to cover their butts. They may intentionally ignore you doing something you shouldn't, just to silently build a case and keep it in a back pocket.
It’s not isolating data though.
This can give you a really hard time of resetting services if you change work and can't carry the phone number with you.
The replacement is on backorder now for 2 months and no firm shipping date has been given yet. There is a chip shortage, a global logistics backlog, etc.
So, I'm using the work machine.
It can be done, but it would be a massive hassle, a massive security problem (or set of them), etc. etc.
I was hoping the article would say something interesting or compelling - some new way to look at this old issue. Nope.
Of course, my employer is not strict about this and doesn’t care much. I realize other employers might see this otherwise.
Even just an innocent mistake in scrubbing logs for personally identifiable information could bleed information to the other side.
Here's what I do, as a compromise. I know it exposes personal data.
* Any personal projects are managed in the cloud on an EC2 instance. Personal development is remote via SSH. Only local artifacts are ssh keys
* I have a separate chrome profile for personal. All personal activity is in that profile.
* With few exceptions, I avoid storing personal files on the device itself. Personal files go into the cloud / google drive.
I know that my cookies and browser history are being recorded, but I haven't yet found a reasonable way to avoid personal access on my work device.Any tips?
I don't store files though: they are only accessed though the browser.
I also refuse to install any software on my phone that I'm not comfortable with. For example, outlook wanted permissions to remote wipe my phone and a lot of other skeevy stuff. That's not going to happen. I've heard of some employers asking to install tracking applications on their employees phone, that wouldn't fly either.
Not doing so make leaks a matter of time.
Or a ransomware invading your work laptop and encrypting your stuff.
Or your creepy IT guy figuring out the stuff you post on amazon or having access to your nudes or whatever.
Alas, the stories I can no longer share on the Internet like it was the 90s.