Amazon will monitor workers' keystrokes to 'combat data theft'
inputmag.com
inputmag.com
You shouldn't lose all rights just because someone is paying you any amount of money. The company does not own you. You're not a soulless resource that can be used and tossed whenever your boss pleases.
” According to the guidelines, if the use of the Internet and email services is only permitted for business purposes, the employer can check the Internet use of the employees randomly, to make sure that they use it for business purposes only.”
https://www.mondaq.com/germany/privacy-protection/496710/ger...
The employer can look at work emails if it's the last resort (no other means to get the information), they have a reason (like if employee is sick and a customer emailed them directly with important contract data), a member of the work council is present, and it's been cleared by the GDPR person (whatever they're called in English).
Labor laws have been shaped by courts so it's quite confusing, even to Germans. Rulings are often decided by minuscule details that don't appear to be big but often are, so generalizing is hard.
If a customer phone the support directly, are they going to hold the phone for hour waiting for approval? Only after the approval, the support can start reading the work email and decided the next step.
Co worker and manager need to aware of the work progress, just in case the employee is sick or something.
Employee should do their private work on their own devices.
What make email different from phone call?
The company can simply require all customer communication to go through a proper CRM. This way there is no need to look into an employee's personal inbox.
I worked in call center management and saw this play out real time. They made clients wear fitbits and hit metrics to qualify for the cheaper health insurance plan. Workers put the fitbits on drill bits and ran drills to whirl around the fitbit to beat the metrics. Then there was a mass group chat about how to beat the system. Then peoples personal cell phones had to be banned and kept in lockers outside the offices. And around and around and on and on it went. It was literally like Tom and Jerry and everyone was miserable and meanwhile the company wasn't doing well because nobody was focused on getting any high quality work done because of all the distractions and drama over the tracking.
I don't believe this can be represented by KPIs, and therefore doesn't factor into (bad) managements' view of the world.
I'm not a huge fan of this monitoring, but why be so dramatic? You aren't losing any rights here, let alone all rights. You do not have a right to use your employer's computer without your employer's permission.
If you want to do something that isn't monitored, just use your own computer instead of your employer's computer. You should be doing this anyway, keystroke monitoring or not.
These are the same laws that also allow surveillance cameras not only within company properties, but even in public.
You do not have the right to privacy when you are not in a private space. This applies to company computers just the same.
In Europe you generally have a graded expectation of privacy that does not disappear the moment you enter the workspace.
We recognise that people have needs that are not met if you treat them as automatons.
To your surveillance camera point, I live in the UK which is renowned for the number of cameras. If I point a surveillance camera at the sidewalk in front of my house, I'd break the law.
Is this true? So your camera is only allowed to point at your property and nothing else? I don't see how this could possibly be true when you're allowed to take photos in public. Or does the fact the surveillance camera is fixed make a difference?
Thankfully not true in sane countries
https://www.google.com/amp/s/www.lci.fr/amp/societe/video-en...
In short, you definitely have a right to send e.g. personal emails from your work computer and your employer definitely does not have the right to go look into them for instance
I'm not so sure about that. Do large-enough French companies supply their own Certificate Authority to all company computers (like all large corporations)? If so, then they're free to browse/search/store all https communications from any company machine, right?
The assumption is that employers and IT departments will always "follow the rules", but it's impossible to verify something like that. The way corporations would be "caught" would be from huge numbers of whistle-blowers but that's a risky career move for most IT workers.
The good news is IT departments and individuals generally don't care to spy unless there's something really high-value at stake and only then towards very specific "targets". With few exceptions, the vast majority of workplaces tolerate ordinary personal use of corporate computer resources.
Hahaha. We Americans have this little term called "Human Capital"
Human Capital Management.
Another scale up (down) from where you're moving to.
Next step might be rolling HCM into a function of the Finance Department. (moreso).
Which goes to show how correct Marx was, at least from a sociological perspective.
"Resources" can surely mean "assets" (note that the relevant resources are selected...), which is not at all diminishing or ghastly, and also honestly means "what is available to fulfil a need". Implication of «expoitation» (or, even farther, "expendability") is not necessary, though "being used" is surely there - but that is the job itself.
"Capital" implies "investment" - what you invest is the principal, "capital", while the additional returns are the secondary part -, not necessarily that «ownership» that implies a loss of freedom: contractually, you allow your employer to make your work part of an investment. Again, it is the job itself. The capital is what you have invested and returns after having brought fruit: again, they are assets.
Terms have broad semantics, it is never a good idea to interpret with partiality. :)
Edit: I am not denying that some employers may de facto as if interpret "resources" and "capital" dishumanly: I am stating that the fault is not in the jargon.
At first. After a few months, though, he proved himself to be classical politicking a---hole and a horrible bully if you got on his bad side. I take that as a lesson to trust my instincts more.
Though I must admit that design resource is hardcore :) I must try that at the office and look at the reactions.
«Wo is der Azubi?! Sie meinen der Primary Business Solutions Executive Assistant. ...Der is grad kacken.»
I think the trend comes from the globalization of business and trade, so that when parts meet there is no translation of titles but a sort of spontaneous international convention. This avoids questions like "So, what is exactly your job as /Azubi/?".
(Of course, still tongue-in-cheek, it may remain a justified question to ask "What is exactly your job as PBSEA".)
Interesting.
When it arose there must not have historically been anything similar commonly seen.
Could be all previous German engineering success has been best accomplished without anything resembling an American-style HR approach.
After all, today's HR designation took root during the belt-tightening of the '80's under Ronald Reagan, and as we have seen has declined in usefulness from there continuously over the decades.
No translation was given back then either, and that was in the USA :)
I am.
Just thinking everything's great doesn't actually change reality lol
Don't accept that bullshit. Especially if you're a software engineer and have a million opportunities.
I resigned from a big tech company because I refuse to build any weapons, period. I'll always refuse to build them as long as I live. I can easily get hired somewhere else.
Have some self respect and demand to be treated with dignity. To hell with the bosses' intimidation
However, that requires some savings and some political perspective. I understand why someone who just struggles to pay their bills every month "thanks to" their corporate overlord (i.e. "wage slavery" as that is/was called) would not consider it a viable option.
Organize with your fellow workers. Sabotage the company. Make your managers' lives miserable, but do it collectively ;)
Re: theft - they didn't mention theft in their comment (unless they edited it out; why not version control on HN?) but the problem I have with theft is that it allows thieves to gain resources that they didn't develop to earn themselves, that they don't yet deserve - giving them power they don't deserve nor have learned how to wield adequately.
Indeed yes, sabotage is worse than theft.
If the alternatives suck (being poor or a social outcast) or are hard (entrepreneurship) or not that different (another soulless corporate job), how much freedom is there really?
I have no stake in the question, live in France where guns are an exotic thing - just genuinely curious about the limits.
A person can recognize reality while knowing it should be different. Recognizing the need for something to be different is the first step in it becoming different.
Learn to read the OP's sentence as "A person should not be a soulless resource..." - that is often what is meant.
Once healthcare is tied to employment, that is exactly what people are.
Yep, and this marvelous US productivity hack by employers and lawmakers (/s) - of making affordable healthcare conditional to employment - is unfortunately growing around the world. Parallel to this move is the continued commodification of most other resources and relationships.
Employers do pay a portion (usual 50% or more) of the health insurance premiums, but these days it is just another form of compensation, worth somewhere around $200 to $1,200 per family member per month (pretax).
Before ACA, it was true there were cases you simply could not get health insurance without an employer, as you could be denied for a multitude of reasons.
> If machines produce everything we need, the outcome will depend on how things are distributed. Everyone can enjoy a life of luxurious leisure if the machine-produced wealth is shared, or most people can end up miserably poor if the machine-owners successfully lobby against wealth redistribution. So far, the trend seems to be toward the second option, with technology driving ever-increasing inequality.
-- Stephen Hawking, https://www.reddit.com/r/science/comments/3nyn5i/science_ama...
Rough at the time for sure. But few would wish to go back.
> But few would wish to go back.
What does that even mean? I would love to "go back" and deal with things by not just letting the masses starve while people in costumes play god and smell their own farts, which is exactly what they do today. I would LOVE to see see that space exploration and awesome inter-species music festivals we might have in 2021 if the last few millenia hadn't been such pathetic ass.
Do they?
Back in the day when everything was manual I think you could reasonably make a living farming your own land. It was hard work but it was possible.
Nowadays everything is so optimized that margins are razor-thin and the remaining farmers are being squeezed from every side, both from the demand side for their produce (supermarket chains driving prices down) and from the equipment side (John Deere & co intentionally making equipment that's impossible to repair unless you pay them exorbitant prices).
It's clear that, in their super-capitalistic view, if they pay you a salary they own you for 8 hours a day. Property doesn't have rights, so neither do you.
This has been clear for quite some time, but it's reaching exaggerated extremes in recent years.
It's worrying how US companies are expanding so intensely into the EU as well.
Reading about this topic, it seems this is also not legal, especially when limited personal internet usage is allowed as well in the contract.
What's the right way to approach this issue? I guess if someone brings this up, they'll just update contracts and say that personal internet usage is forbidden? It still feels like someone is watching you.
Not to backseat design (ok, to backseat design), but shouldn't it be the case that access would already be scoped to accounts relevant to active tasks, and not every one of the 300M+ active customer accounts, especially without some sort of escalation or break-glass? That rationale for this software is likely invented, right?
"It’d be one thing if these workers were well paid, but they’re not."
quick survey -- this would still be put on the "bad ways to treat your workers" list, correct?
The idea is that you can solve the problem without having to spy in your employees every move, and focus on securing important operations.
If you have to worry about your room mate acquiring all of that, your threat model doesn't allow for remote work as the adversary will bypass the keylogger too.
You are working for a retailer, not the militaries.
You need to have this sensitive data locked down appropriately so that people cannot just unilaterally access it on a whim. There should be an audit trail back to some rationale for access (e.g. support case) that enables access, and if the data is sensitive enough it should use multi-party auth.
Keyloggers are not going to stop someone who is using someone else's computer already - they are WHY they are using someone else's computer!
You'd have to set up a system where the phone tech could not access the account data unless the customer relayed the right name, SSN, or whatever other validation that they were the right person (people forget passwords!). But this means you need to be able to look up an account by some kind of PII, or at least ask the customer to cite some recent purchases (to prove ownership)... in which case the tech has to be able to see the purchases to validate them!
Anyway, I'm sure there's some path here to make it mostly possible, but I don't think it's easy and I'm sure it's a higher-friction customer support experience.
Even better, callbacks on demand mean no hold music. Just waiting time for the call.
agree with grandparent that incoming cold calls would be more challenging in terms of both authenticating the caller (some places I've called just seem to match phone number) and limiting access to information.
This sounds like someone's solving a lack of training with code
We give full admin rights to laptop owners and don’t install spyware. I would be sad if a coworker acted as if their keystrokes were being recorded; thinking that would surely slow them down and make them more careful about pursuing all promising research paths. So I think it’s important for companies that don’t spy to signal that they don’t; the opportunity cost outweighs the marginal security benefit.
In a lot of places, in case of severe signal, like computer reaching out to know malware C&C servers, the computer is taken by IT and investigated - does it really have malware? How did it get on PC? Did it propagate?
This sometimes involves digging through browser cache and history.
So even if you not recorded all the time, you should be prepared that your computer will be taken away from you at any moment and browser history examined. Such is the life in a big company.
We are much smaller and still larger than the median company size in the US: https://www.naics.com/business-lists/counts-by-company-size/
Huh? I've worked at multiple companies that all do very broad device monitoring (it's fairly standard at all large companies) and I don't think I've ever heard anyone express any concern like this. I've certainly never felt this way myself. What "promising research paths" are you talking about? Do your google searches at work frequently involve porn or something?
I get big scary corporate “You’re not allowed to go there!” and get the feeling that there’s now somehow some black marks on my invisible permanent record, because I wanted to read something about Zig or something.
I know I’m not going to be fired for something like that. What I don’t know is if some higher up just looks at some roll-up without digging or understanding, the kind of scenario that could come up in something like, for example, layoffs.
Definitely has a chilling effect for me personally.
If I want to look up example of string operations in C I might Google "c strings" or "c strings examples". Incidentally, in similar fashion to G-strings, a C-string is a type of lingerie.
If I'm doing quick graphics adjustments I don't want to bother the art department with I might use the fantastic GNU Image Manipulation Program and do a search for "gimp tricks" or "gimp tutorials". Incidentally, as anyone who's seen "Pulp Fiction" might know, a gimp is a type of BDSM gear. Definitely not savory for work.
This is why, much as I'm concerned about personalized searches, it's kind of non-negotiable for me that to function as a professional software engineer I should be logged-in to my Google account. It's the only way I can be sure not to get results from, say, Victoria's Secret.
In practice, companies only have humans look at IT use if there's a security problem or a performance problem.
Over here, when a company would do that and use it against me, I would sue them for privacy breach. Employee rights are very well protected in western Europe.
Use a VPN, that way if you good off on your phone during the day at least they can only see how many bytes you're using and when
Queries to sensitive DB endpoints are what you want to keep an eye on.
Whilst that’s probably still true, I now also wouldn’t want to work somewhere like that if the “prize” for being accepted is to be treated like a machine or worse.
Being a contractor seems like a much more honest bargain. You pay me and I make something for you.
How I do that is my business as long as it meets the spec.
Now I'd rather keep a simple job and work on side projects that interest me than working at a FAANG.
I just don’t want to wear one of L. Bob Rife’s headsets to get that. :P
Here’s a recent report on one of the companies that counts Apple as its customer monitoring employees by video. [1] Apple in this instance responded that it prohibits such monitoring.
[1]: https://www.macrumors.com/2021/08/09/workers-complain-about-...
There’s an entire suite of software companies that have been building this stuff for twenty years, companies like Verint.
That's already two decades back.
I remember back when I started out in the 2000s. I worked at a call center here in Bangalore. The breaks were one 35 mins(lunch), three 15m breaks spread over the shift, which most people took to use rest rooms. Many times you need to call the floor manager, and they turn it down. You need to hold your rest room emergency until they let you go to the toilet for 15 minutes. You got penalised if you over shot the 15m rest room break.
They even had metrics like resolve rate, calls per day, escalation count, data collection metrics(if you made 3 mistakes entering the user email, you were fired) etc etc.
I remember being in the bursars office and someone was complaining that they registered for a class and it didn’t show up. The woman working there spun her screen around and said “here are all you keypresses from last week, you clearly didn’t register.” Now with so much more computing power/networking and storage everything is stored..but I wonder if they’ll ever look?
Makes a great target for hackers though.
stopped buying from them a long time ago, I encourage everyone else to do the same.
Hung out chit chatting with management and reading books / creating static websites with Notepad++ (no outside software allowed) when the call volume wasn't too high.
Googling "pac man" yields the pac man doodle, which I played so much (google obviously wasn't blocked but a lot of sites were).
Why are companies like Amazon constantly kicking the shit out of the lowest paid employees!?
For some in the upper ranks, applying the whip to lower ranks is the carrot.
Not really. Which do you think is a larger increase in total income?
- Bottom 50% of all wages increase by 5%
- Top 1% of all wages increase by 20%
Average Bottom 50%ile wage = 46K USD. 5% increase = 2.3K Multiply by 50 = 115K
So the 20% increase in top 1%ile represents a 3X increase in total income when compared with bottom 50%ile.
Our current wage growth of ~3% combined with inflation of ~5% means that real wages have been falling at about 2%.
https://www.cnbc.com/2021/07/27/wages-are-rising-but-has-inf...
The WSJ added:
> Average weekly earnings since January are up $15.59, but with inflation surging to levels not seen since the early 1980s, real weekly wages are down $8.99, the largest real-dollar drop in wages since Bureau of Labor Statistics data were first collected in 2006. By comparison, real wages have fallen more in the past seven months than they rose in the final 27 months of the Obama presidency.
https://www.wsj.com/articles/inflation-government-spending-w...
Check out the BLS (bls.gov) for the latest data and hope it doesn't get worse.
If Amazon wanted to keylog its employees, they'd just create a keylogger for that purpose, not repurpose this thing.
This land grab is only possible in societies with no countervailing forces, either in government, judiciary, journalism, business world or civic society. Alas the US is very nearly such a failed society, as evidenced by its still smouldering Trump period. This is disastrous for the Western world in general (and Europe in particular) which for decades has simply followed the US lead in tech.
Tech is not just another cog in eternal societal struggles. Things are coming to a head. The challenges are compounding and the sustainability of our entire (eco)system is at risk. Tech should be at the forefront of shaping healthy social contracts to help us transition to a viable state. It is one of the few levers left that have a positive range. Instead it is abusing and eroding the most vital ingredient of a healthy society: trust
To paraphrase: Monitor your own keystrokes and combat soul theft. Make sure you program the kind of future you want to live in.
Honest question, I assume this isn’t covered by two-party consent of recording. Are there any legal frameworks covering employee monitoring in the US or on the state level?
Is it different if alerted on violation as opposed to a manager browsing their employees activity on a whim?
The moment I discovered this, I stopped using teams to talk to my manager/teammates about my frustrations or concerns. I ask them to speak on the phone or face to face.
All the messages on Exchange Online and Teams are logged and can be searched through by an admin, that's to be expected.
It's not logging keystrokes of other apps.
For example: if you use a macro tool to stay "online" on teams, the admins/managers/etc know.
However, now I wonder if it's all overblown, just like other shit in the media.
Surely, no one in their right mind would work in such conditions. It could be decent or at least acceptable.
Wonder how it compares to a small company where your manager watches everything you do and yells at you for a typo.
His COO later stopped taking meetings in the office because the CEO would sometimes sit and watch and listen in to the office from home.
To be specific, I’m referring to the first dystopian half of the book. I suppose the people at the top of Amazon are gradually entering the utopian second half.
This may not be the best solution to protecting data, but it's a hard issue to solve.
Stuff like SIM swapping and recent Twitter hacks come from insider threats. Consumers want companies to protect them (i.e. the consumers) from insider threats. How are companies supposed to do that? Monitoring the speed of typing is one not-particularly-invasive way to do that.
TL/DR: Don't eat the sausage if you can't stomach how it's made.
Amazon is losing 3% of its hourly employees each week, an incredibly high rate that means the e-commerce giant experiences 150% turnover a year
https://www.syracuse.com/business/2021/06/report-amazon-chur...
She’s monitored doing everything including the time it takes to read management emails and going to the toilet.
She puts up with being treated like crap because she thinks the job has prestige.
When the book was first published that all sounded hilariously preposterous. These days it’s almost standard. :(
However, if you’re working at an employer-provided work device, your practice is a wise one.
That's why stuff like this exists.
So assume this happened to Amazon one time and cost them a ton of money.
Do they sit back and just hope it never happens again?
Do they somehow selectively choose which employees to monitor?
Don't get me wrong. I would love to live in a world where everyone can trust everyone else but that's a fairy tale.
That would be a sane approach. Indeed, if there's "data" to guard, then one just properly secures it and allocates access to it. If "theft" happens, then there's access log.
If data is ubiquitous that everyone should be able to access it, then it's hardly data to "guard". In any case, it makes more sense to monitor access to data, not just a sea of keystrokes... unless the concern lies with something other than the data.
If you can't trust someone to be an employee in a position where they have access to your systems, they should not be in that position.
Normalizing the surveillance state is the chilling part. It’s just that the corporation is state entity, not the government.
To your point, the reason we have bad cops is that we have problem people that carjack, rape and the like, so we therefore have cops. If people really didn’t want bad cops, they wouldn’t crime.
But I doubt Amazon has lost much money from the looks of it.
Criminal insiders that prey on the customers are a more interesting target, but I suspect they are in different unmonitored areas.