Apple explicitly asks employees to merge their personal and work accounts
twitter.com
twitter.com
> During a discovery thing 3yr ago, legal forced me to hand-over all my texts. They refused to let me delete anything, even "fully personal," even when I said "by fully personal I mean nudes." They said they're in their "permanent evidence locker
This doesn't sound like company policy, and more like they were subpoenaed or otherwise compelled to hand over communications.
> Another interesting Apple tidbit: the company tells employees to link their personal iCloud accounts if they need to collab with colleagues when they start. When they leave, they're asked to hand over their laptops w/o wiping them and give managers access to work systems.
I'm not sure how to parse this. Do you need to link your personal accounts with family photos and whatnot? Or can you just create a separate iCloud account just for work, to collaborate with coworkers?
I'm a firm believer in separating work and personal accounts. I usually try not to even log into email from my work computer if I don't need to, and I always use a spare phone for work if a company requires admin access or remote management tools of any kind. That said, reading these tweets I'm not really sure if Apple is asking employees to breach this separation. I'd just create a separate Apple ID for work and use that for the "personal" account that I'm supposed to merge. That's a separation I'm still comfortable with.
Nope. You can create a separate iCloud account just for work. I did that during my time there. I always maintained a separate work phone, and used work icloud account for that. The folks complaining are the ones who just didn't do that, and added 'work data' on their personal account, which ofcourse they will have to hand over if subpoenaed.
Even if there was zero explicit or implicit force in place, the circumstances can still be non-obvious.
If you get handed a MacBook, you're basically forced to work with an iCloud account. And the fact that making the mistake of using your own one in the high-pressure situation of a first day in a massive company is apparently a non-reversible decision that hands over data that was created before and outside the employment definitely points towards Apple abusing their position of power here.
Trust me, Apple legal would rather not dig through your personal information to find nuggets to hand to opposing counsel during discovery.
But if there's work information in your personal account, and Apple is legally compelled to go through accounts with work information as part of discovery... what's going to happen?
The only victims I can possibly see here are those employees that had to review nude images inappropriately stored on a work computer.
Apple absolutely does not require that you use your personal iCloud account on your work machines, and any professional should know that it is inappropriate to browse, share, or store nude photos (of anyone) on company-owned hardware, and should never have placed their colleagues in a position of having to deal with those images.
Apple should be in the position to instruct new employees to create an icloud account for work alongside explaining that the computer they are handed must be turned in at times. The employees aren't the only ones with responsibility here.
Maintaining a modicum of personal responsibility is not asking for very much here.
In fact, I’d say it’s the bare minimum professionalism requires.
You don’t own your company-provided equipment. This is explained by Apple, in addition to being a patently obvious fact.
If you personally choose to misuse company equipment, that is something you are personally responsible for.
Adults trying to shift blame back to Apple is a remarkable abdication of a simple responsibility. If they cannot exercise good judgement in such a straight-forward case, I question whether they can be expected to operate professionally in the work-force at all.
It’s part of the on-boarding at my company (which happens to have formerly been at the same location Apple’s HQ is now).
Yeah it feels like something is definitely missing here. If it's some kind of legal discovery, it's no shocking that the person cannot delete "personal stuff" before they hand it over, that would basically render pointless whatever they are doing with the phone.
Or just quit the company if they ask you to hand over a personal device.
Usually your employer would prefer that you not hand over your personal device. Because the other party is looking for some sort of "smoking gun" where employees admit that they think some corporate behavior is bad or breaking the law. The penalties for not cooperating here are bad enough, though, that companies will generally cooperate. And the situations where it's a personal device are relatively rare, usually it's just corporate devices.
Quitting the company doesn't change anything. You can still be subpoenaed after you leave the company and the court can force you to turn things over.
Source: I'm not a lawyer but I have had my communications subpoenaed from my time at both Google and Facebook and I have complained to many corporate lawyers about how stupid these rules are while they politely explained to me how the system works
Company should have no right to your family communications.
I never use text.
If you delete something that the court has ordered you to turn over, they can and will charge you with contempt.
Again, this isn’t your employer doing this. Your employer would love if you didn’t turn over anything, but they are legally required to cooperate and will get in a lot of trouble if they don’t do their part.
That way if ordered by the legal system you'll only actually have at most 1 week of personal data and none of it will be text.
You won't be deleting anything after their request, you will just hand over what you have, which is incidentally not much.
Wiretapping laws prevent courts from getting your voice records, at least in CA.
If personal devices were not subject to legal discovery, every company would just have all the executives only use a personal device for all communication, and suddenly they are immune to discovery?
some people use their personal phone for work email, etc. and miss the fact that that makes the phone basically a company property - i.e. the company can wipe it remotely, etc.
Wrt. Apple requiring to not wipe out laptop before returning it i wonder how do they enforce it. In more than 2 decades i have never returned laptop without wiping it and wonder what can change that, if any.
Exactly. OP wrote it was a "discovery thing". Discovery is a legal process for gathering evidence in a lawsuit. All relevant business records are discoverable, even if they're stored on employees' personal devices.
Apple doesn’t expect you to use a personal iCloud account, and is very clear about warning you about sharing /storing personal data on work systems.
I have very little sympathy for someone that used a personal account containing nudes on a work device.
That was a work-inappropriate choice with entirely predictable results.
Who is "legal"? Corporate legal? They no right to your personal phone. Even if they were subpoenaed, they could only ask you to hand over data on corporate devices, not your personal one.
The only people who can get your personal device are a search warrant from a court.
When the company is subpoenaed, they aren't going to give you the chance to delete data from "evidence". This is probably what happened here.
I created a completely new consumer iCloud account and used that. I never did anything remotely "personal" on that machine, and after I left Apple I never used that iCloud account again. In fact I don't even remember my password for it.
I went so far as to carry two iPhones, one personal and the other "corporate," and I only ever used my "corporate" iPhone with Apple employee apps. I never even connected my personal phone to the campus WiFi; I used wireless data for that phone the entire time I was there.
That said, I don't recall ever being asked to merge my personal and work accounts. It's just that if you want to do any personal stuff with corp hardware, it's much more convenient to just use your personal Apple ID when you provision the hardware.
This is the way. Carry two devices.
Separate personal/work devices. Never connect personal to corporate network. Never send messages between personal and work. Never give out personal device # to colleagues.
Assume that everything on your work device is logged and monitored. Don't do vacation research, medical research, social media, Spotify, anything personal at all on your work device. Ever.
That's quite extreme. What is your threat model?
Company surveillance (of their employees) is very real and unlike 'google reads all my emails' they actually can and do and it is a person they actually know whos private information they are viewing. I dont even need to get into the chance of every piece of information being in a lawsuit or get into the lack of any controls around data retention etc to be worried.
First step IT would take when I dropped my phone in 'because they had to run the update' - they would open my photos and take a look through. Second step - they would go to the deleted photos and have a look through. It was done as part of any company-mandated review of the device but out of personal 'curiosity'.
Every private message on teams etc was logged and routinely reviewed by a compliance team and often escalated to line managers - the team doing so knew everything professional and personal going on in the place. Who was getting hired, fired, promoted, working hard, slacking. Who was sleeping with someone, depressed, happy, gay, straight, having kids, getting divorced, getting a nose job, getting a vasectomy etc.
So whats the threat? I have nothing to hide, I am popular, a hard worker, not having an affair with the intern, so they are not going to trawl through looking for any dirt to diminish or fire me. There is little value in this information beyond gossip, but a permanent record remains all the same. For me there is little extra effort required to phone home from my phone rather than the recorded office line and that way the call wont be listened to by the guy in compliance.
Here in Germany I think gathering many of these facts would simply be illegal.
That said, when I have worked outside the region or in less regulated positions - the intrusion into particularly email and written communications is the exact same. When you leave an organisation in particular, you do reflect on how big a trail of information you have left behind in their hands.
This is also exactly why I always check all the paperwork for "personal usage" of the devices and services provided by the company (email and stuff). If there is nothing about it, I send my mom a random cat picture from my work email (always outside of office hours, in other cases it could be a contract violation). Why? Because if it's not forbidden, you are implicitly allowed to and after at least one private message was sent by the account, it's legally like a private account.
If your employer snoops in the account, it's a massive privacy violation (Datenschutzgesetz and DSGVO/GDPR) and a strong case in employment law. Never needed it, but it's better to be safe than sorry.
I dont think I have ever worked under an IT policy that was anything but 'for work use only' - although that didnt stop me from taking great pleasure at seeing how many work emails were used to sign up for sugardaddie etc whenever they leaked. I was never too fussed - having two phones, two emails, two laptops etc doesn't bother me in the slightest. You lose access to the work phone number / email / storage when you leave anyway so it's really of no use.
I have even come to like the physical separation of work and personal, there are times each needs more than 50% of my attention.
Extreme surveillance from your employer would unnerve you.
Your remediation is:
Firewall between work and personal.
Is that a reasonable restating?
Threat model is straightforward: I have no expectation of privacy on my work devices. I do not want my employer entangled digitally with my personal life.
A threat model would be (albeit an absurd one):
I will be fired and blacklisted if an employer determines how many personal emails I send a day
Yes, but I feel like a major takeaway is that you should never ever do that
1. You absolutely have the choice to make a separate iCloud account for work, you just can’t make it with an @apple.com email. 2. It’s true that you should not wipe your device when you quit. 3. We were instructed to avoid using iCloud for anything work related. They recommended turning everything iCloud related off on your work computer except for FindMy. 4. None of the claims in the tweet sound familiar to me, but Apple is a big org.
My impression is that they need you to have an iCloud account for tracking the location of the device with FindMy, but technical/legal limitations prevent that from happening through your work email.
(Obviously thoughts are my own, I do not speak for the company)
It's a big company though, so possible that policy varies.
0: https://support.apple.com/guide/apple-business-manager/what-...
IIRC, they did iron out the problems eventually, and finally came-up with a semi-decent UX for normal (non-MSFT) people that had an Office 365 ("Organizational account") with the same e-mail address as an MSA - but I think internal MSFT accounts still have issues? My information isn't up-to-date fwiw.
FWIW, I never had access to any "real" internal resources via my new @outlook.com MSA address - the only things it did have access to was things like MSDN Subscriber Downloads[1] and as a backup/recovery e-mail address for my @ms org account.
[1]: Oddly enough, I retained access to the MSDN Subscriber Downloads area, including full ISOs and Product Keys for about 2 years after I left the company, I only lost access because that was when they moved everything over from "MSDN Subscriber Downloads" to "My Visual Studio" which changed everything.
[1] Why would a customer need to merge two accounts? Because originally Apple accounts were just for iTunes, associated with your email address.
Then they started cloud services like file storage, email, calendars, etc, and those accounts were tied to your Apple provided email address.
Eventually they made it so that iTunes and cloud used the same accounts, but those of us who had both iTunes and cloud before that ended up with two accounts. And since your devices can only be signed into one at a time, if we were not extremely careful we ended up with some of our app and music purchases on one account, and some on the other.
This is an ongoing pain in the ass. It would be much much nicer if Apple provided a way to delete one of the accounts and move all the purchases to the other, but they have not done so despite receiving numerous requests to do so.
Sometimes you get lucky. It turned out that all I had on the Apple addressed account was a couple of "purchases" of free apps plus some paid for storage. It was easy just to repurchase those free apps on my original iTunes account, purchase cloud storage for that and delete the other account from my password manager so I can't ever accidentally log in to it. But many people have a lot of non-free app and music and video purchases on both, and so are stuck keeping them both active.
The employees there apparently kept scores (on a white board?) to make her want to quit the job [1]
[1] https://twitter.com/ashleygjovik/status/1427351298920239106
No matter who is in the wrong here, this is some A-grade toxic shit. This is unacceptable even for kids let alone adults.
https://www.ashleygjovik.com/ashleys-apple-story.html
Edit: I don't understand her endgame. She's not going back to work at Apple after the negative publicity she's been generating. She probably doesn't care because she's in law school and will be graduating soon. Is her goal to negotiate a generous settlement? The negative publicity reduces the value of her settlement. (Companies will pay for an NDA as part of a settlement, but only if the damaging info isn't already public.) Is she pursuing some naive, idealistic notion of justice? Or is it all to establish "cred" for her future legal career?
I'm sure it's not because of the money, it's purely a political motivation. That's what she wants to do in her life.
I understand it, I also take all the chances I have to bash the government, out of pure hatred.
I wonder that because I worked there for years and anything remotely like what she claims was implausible when I was there, and would have been immediately corrected with impunity had such occurred.
I mean there's security all over and they're not in a managerial chain, so something seems very difficult about her claims to me.
In saying that, maybe she did have some entirely crazy people around her. Evidence would be stronger than conjecture, and I hope she has some if such happened.
Would you happen to have a link handy? I don't mean to be adversarial. That screenshot is just so incredibly outlandish that it comes across as something from an overdone movie and I honestly find it difficult to take at face value.
Basic human decency and social norms aside, I just can't comprehend what manager would fail to recognize something like that committed in writing as a huge legal liability.
> I admit I looked it up thinking "this can't possibly be real, no one would leave that paper trail".
> I was wrong.
That is why said that no matter who is at fault here, this act of public score keeping is still not ok.
I have no reason to doubt that she's telling the trust from her perspective, but that being said, there are always two sides to a story.
> In saying that, maybe she did have some entirely crazy people around her
To be honest, reading her published tweets/documents, she mostly appears to be someone who complains to HR about everything. Judging by the way her managers "dismiss" her complaints with (attempted) humor (refill whiskey bottles with fruit color and water, suggest which NERF gun she should buy, etc), i'm guessing she's been at it for a while. The sign that her managers purposely leave her out of important meetings could also be a signal that "she's more trouble than beneficial".
Not saying she was wrong (or correct) when she complained, but it would certainly explain some of the hostility being shown by her team members. Reading the parts she complains about it actually sounds like a really nice and accepting/inclusive workplace, and a place i would love to work. Planning a NERF war, and your managers only concern is if you're too loud to disturb other teams :)
In any case, she has published multiple (redacted) confidential documents, so i wouldn't get my hope up for a big settlement.
It seems strange that she happens to be also the victim of organized workplace harrasment at Apple. And again, the authorities (internal Employee Relations) refused to help, and tried to cover it up…?
Either she’s the most unlucky person… or maybe it’s all in her head? Take a look at her website documenting her “ordeals” at Apple [2] To me, it looks like the scrapbook of a paranoid schizophrenic who meticulously collects “evidence” on their “gangstalking”… Just look at this tweet [3] where she talks about fighting Apple, Northrop Grumman (!) and the Irvine Company, and tell me with a straight face that she’s not a wacko.
[1] https://sfbayview.com/2021/03/i-thought-i-was-dying-my-apart...
[2] https://www.ashleygjovik.com/ashleys-apple-story.html
[3] https://www.ashleygjovik.com/uploads/1/3/7/0/137008339/publi...
I agree with the point of your comment but this particular post is regarding employees and seems like this has been in place for 3 years at least (tweet mentions it).
I started moving away from Apple a few months ago, much before this Apple CSAM debacle. This is a pretty big move for me because I am a developer who makes apps for both iOS and MacOS, so I pretty much need Apple software for work.
No longer buying iPhones or Macs. I was planning on upgrading to the Mac Mini with M1 chip later this fall but now I plan on building a hackintosh instead. I also no longer recommend Apple devices to friends/family.
I got myself a cheap android phone which I have de-googled myself. I got this Android phone ($190 USD for a very good phone - 8GB ram, 12gb space):
https://www.amazon.com/UMIDIGI-Unlocked-4150mAh-Capacity-Sma...
I use Firefox for YouTube on it with the following add-ons:
1. uBlock Origin
2. Video Background Play Fix add-on
This allows me to use YouTube as a background playback music player. And if needed, I use YouTube-dl to get the audio files and put them on the phone.
You can check out several tutorials to de-google an android phone.
If you don't trust Apple, why build a Hackintosh and run Apple software?
Looks like it's work related. Although perhaps they could just treat it as a work device and use personal devices for everything else.
I’ve been using it sparingly, but intend to make a full time switch pretty soon. Having a phone with less capability and a focus on privacy will I think help make my phone less of a mental zapping appendage and more like the useful tool I remember these things being way back when.
I guess I’m arguing why even bother with a full replacement? I know everyone else seems to be all in on mobile/leaving a modern app ecosystem feels like getting left behind, but maybe everyone else is wrong. Maybe it’s better to just step away from all the ultra modern attention grabbing bricks of pure unadulterated dopamine and switch to a hacky little portable computer when you need to look something up, or text someone, or call someone, or work on some text document you have or whatever.
If you have a phone with even a crappy browser you have access to a ton of modern functionality anyway if you want it, minus all of the notification hell.
However, I would recommend it only to the most determined people because many things don't work well.
Forget GPS navigation. GPS does not get the correct location most of the time, AGPS only works through a hacky bash / python script. There is no good gps app anyway.
The sms app on phosh is crashy and does not yet support MMS for which you have to use another hacky script (but I'm working on an alternative app).
The phone often needs to be rebooted due to the modem sometimes not waking up. Calls are not high quality. No built in way to have a reliable alarm if the phone is not plugged. Photos are bad. The phone is generally slow for many modern web apps targeting more powerful hardware.
The phone takes time to wake up for a call.
I would not want to experience an emergency requiring to call someone.
The phone is not waterproof so it will likely break if it takes a good rain.
The on-screen time is not great though you can buy spare batteries which can largely change the game. Remember to set the sleep timer to 30s, which you need to do using the command line if you use Phosh, it helps a lot.
A smoother transition could be to use a degoogled android phone, maybe with MicroG for cell/wifi based location and only using free software (from F-Droid). But you'll still rely on proprietary blob.
I only ever used open source apps on Android and always refused to use apps like WhatsApp & its friends, which helped the transition to the PinePhone.
On the flip side, the PinePhone is getting better every day and the ability to just buy a spare battery and a battery charger and swap them as needed without any tool is really nice.
I typed this message on the PinePhone by the way. It's far from horrible despite my comment.
edit: what I want to say is, wanting to migrate to free and privacy-friendly software is probably a good thing, but increase the chance it will work by not making it too hard. On the desktop, Linux distributions are delightful to use, free software phones are still pretty much work-in-progress unfortunately. The gap between a degoogled Android phone and a PinePhone is huge, probably way bigger than between an iPhone and a degoogled Android phone.
Forget global positioning specifically, shouldn't a good OpenStreetMap atlas application without automatic positioning be feasible, if not presently available? Today it might feel like caveman technology, but it's not that long ago that having a high quality up-to-date world atlas that fits in your pocket would have been considered a considerable marvel. That such an atlas might also tell you exactly where you are at all times is icing on the cake.
Well, you have those options which work well enough to be usable (you don't have pinch zoom, Gnome Maps takes a while to load, openstreetmap.org does not fit very good on mobile, both require an internet connection):
- openstreetmap.org
- GNOME Maps
Then you have Pure Maps. It allows offline maps using OSM Scout Server [2]. It seems good, however it overheats my PinePhone and crashes probably out of lack of resources. So I don't use it. It could be because of Flatpak, but I'm not sure.
As for how to build a good alternative, I see these possibilities:
- contribute to Pure Maps to make it more lightweight. Maybe it's just a matter of building native packages for distributions like Mobian and Manjaro.
- Look whether KDE has a good app for that. They have Marble on the desktop but I'm not sure there is a mobile version that works well yet so porting this to mobile could be a way. KDE apps are generally very high quality though Marble could use some refinement.
- using C++ and Qt/QML with its Map widget, and find a way to use OSM Scout Server to provide the tiles. Actually, Pure Maps is a QML app.
- build a minimal web page showing a Leaflet or a MapLibre widget, connected to a backend built using a compiled language like C++ or D, itself connecting to OSM Scout Server to provide the tiles. Or to OSM Scout Server directly if it is possible.
The last option is probably the most lightweight solution, provided you probably have a browser already running on your phone. I'm not saying this out of my ass by the way, I'm building an SMS app using Svelte for the user interface and D for the backend connecting to the modem and managing the SQLite database. It's way faster than chatty. Maybe don't use React though, this is heavy (Mattermost works but is almost unusable, Element (Matrix) works way better but you still feel latency everywhere).
I would not seek for WASM apps though. Those generally require big and heavy runtimes to be loaded in the browser for questionable benefits, with no way of sharing those runtimes with other apps. I would rather look for native apps, or Web apps with lightweight frontends which can actually be quite fast if done well.
I'm a huge believer in disabling any form of push notification. Nobody's software is entitled to my attention, I'll use it when I feel like it, not when it nags me for attention like a petulant toddler. I don't know how people tolerate their phones pinging, flashing, and buzzing all day like a pinball machine that's been very personally crafted to extract as much attention from your day as possible.
A little off topic, but since social media seems to be the main driver of this "phones as a personally crafted distraction" I'd love to see what a social network that's not actually deeply antisocial would look like. No push notifications, no filter bubbles, no politics, no "nudge" messaging from governments and other organisations aiming to subtly change people's behaviour, no creepy advertising pushed to a perverse degree. Just give me a place with a good chat client, a way of asynchronously keeping in touch with people in my life in that long range between "good friend" and "stranger" (seriously even the Facebook walls of 2008ish would do), and just enough non-obnoxious adverts to cover costs and make a reasonable profit. Oh yeah, and you should always be able to pay a small monthly fee to be rid of ads if you want to.
Ask HN: What Apple alternatives are you switching to? https://news.ycombinator.com/item?id=28220968
More likely that they never were for privacy and injury used it as a marketing ploy, putting on the mirage of being pro-privacy.
The real question and concern is what happens once laws start getting passed that run counter to this. And that then won’t be just Apple’s problem at that point.
Lol, no.
and tell me what's not about privacy with this? The alternative is upload everything unencrypted to providers who then scan there, which is how everything else works.
I don't need to read your marketing manual when there's no getting around the fact you are normalizing on-device scanning on personal devices and automated secret reporting to the authorities, which means iphones have now become adversarial.
Used to be that there was a clear delineation between a customer's device and a cloud server. Not anymore with Apple "privacy".
At least with Google I know that if I don't upload the photos to them, they're not scanning my device.
Just as a point of fact, there is zero point to encryption if Apple is able to access everything on icloud, which they can, because Apple doesn't allow you to do backups using a key that only you know.
That's just another one of Apple's penny-pinching scams so they can upsell customers on extra icloud space for backups which are also "encrypted", yet Apple can read everything.
Real privacy would mean real encryption, but then Apple couldn't do their upselling scam and also couldn't secretly scan all your personal stuff.
That's exactly how it should be. If a service provider wants to scan unencrypted documents for legal or PR reasons that's completely understandable. If instead they want to provide true E2EE and risk ending up in court with the regulators, that's also fine.
E2EE with black box on device scanning, however, is an absolutely terrible idea. It misleads regular people who almost certainly won't understand what's really going on. It's easily subverted by various governments as a condition of doing business. It blurs the line regarding ownership and unlawful search, thereby eroding future expectations of civil rights.
Apple should just be honest about the fact that they aren't comfortable providing a full E2EE solution for various regulatory or political reasons.
This is just ever so slightly better than the worst of everything.
No real encryption, on-device scanning and scanning on Apple servers. "For privacy", WTF!!
I can't see any reason to implement a scanner in this way other than at least having E2EE as a possibility under consideration. They knew there was the possibility for PR backlash. Doing it on device also adds significant complexity. Meanwhile scanning on upload is a very common and well accepted (both legally and socially) practice.
On its own the current approach is all downsides and no upsides so there has to be something else going on here. Wanting to market iCloud as providing full E2EE is obvious and fits perfectly.
We can only recognize the current situation, not a hypothetical future one.
I for one think it is unlikely that Apple will willingly lock themselves out of that mountain of intoxicating user data.
I believe their privacy stance is just marketing. There's countless examples of them not caring about real security issues, eg https://sneak.berlin/20201112/your-computer-isnt-yours/
Even if they do ever implement true encryption - not E2E between customer and Apple - personally I wouldn't trust it because of the unauditable on-device scanning/snitching.
> The alternative is upload everything unencrypted to providers who then scan there
No, the alternative is to not do any scanning.
EDIT: The devices are cheap too, but aren't slow. Typical cost is less than $250 including both the device and software license. The software is mostly open source, but there are a few licensed components. It is possible to use Sailfish without the proprietary bits for free.
Always create new accounts for anything work related -- GitHub, Apple ID, whatever.
Don’t install work apps on your personal phone. Don’t enrol your personal phone in corporate MDM. If they want you to use a device for work, ask them to give you one.
Don’t do personal stuff on your work devices. Don’t do side project work on your work devices. Only do work for your employer on your work devices. Turn it off when you’re done work and leave it off until you start work the next day.
Be very clear on all your contractual obligations related to this before you start a new job. Ask to see ahead of time all the paperwork they will ask you to sign, so there are no last-minute surprises (“oh, you want to own anything I create outside of working hours?”).
Firewall yourself to protect yourself.
Edit: One more: don’t use corporate WiFi with your personal devices
Never accept terms that give your employer control over anything you do independent of work that doesn't affect your performance at work. There is nothing in it for you and the only reason it would be of value to them is if they intend to abuse it.
And it's not about being fearful. It's about realizing that the relationship between you and your employer is often adversarial. They want to pay you as little as they can get away with for the most work possible. You want the exact opposite. Otherwise why would you have to "negotiate" for a higher salary when you were hired?
> why would you have to "negotiate" for a higher salary
Why not?
It's also worth noting that using personal accounts for professional purposes can confuse things. Personally, I forward any email that my supervisors inadvertently send to my personal account to my work account so that everything is archived and is in one place. Given the amount of filtering of some services (e.g. email) correspondence sent between internal accounts also tends to be more reliable. I have seen situations where dozens of employees did not receive a vital message since it was either sent to a spam folder, or simply dropped, since almost everyone found their personal email provider more convenient.
The concept here is that if you learned something new at work and then implement it into your own private projects, the company wants that project since they paid for your time learning new something. Also, NDAs and other forms of copyright and what not gets weird.
To me, the gold standard of how to do this is how Woz handled the creation of the first Apple computer. He took it to his employeer multiple times being told they did not claim any ownsership on each occassion.
This is not how the law works if you’re in California at least. They’ll still get you for other things if you work at a large company, but not for that.
If there's value for the other side to present the boob pictures as evidence in trial (e.g. in an attempt of character assassination), it will be rather hard to have them not passed around in court now that they're part of the "evidence locker" (as they call it) even though there were 100% personal and unrelated.
Whose lawyers? The plantiff's? Or the defendant (Apple)'s?
And it seems common at a ton of companies.
No account switching on the website, no easy way to use multiple SSH keys to access multiple accounts when using Git.
I’m on a mobile device so excuse the vagueness, but if there’s interest I can provide some resources and go more in depth.
Host personal.github.com
HostName github.com
User git
IdentityFile ~/.ssh/id_rsa_personal
then clone from git@personal.github.com/x.git for personal stuffThanks for the assist fnord77!
`sshuttle -r my-cloud-server 0/0` for a poor man's vpn
`ssh some-enterprise-server` for when the server has a user unfriendly domain name that you don't want to bother remembering
`git clone git@github-personal:myusername/somerepo.git` when you want to clone using your personal key from GitHub.
There is the caveat, though, that you may have some nested dependencies that will use the plain ole every day host name in which case things will break for you. It rarely comes up, though, in my experience.
Also, if the submodules are public, the plain host will work fine because it doesn't matter what key you authenticate with.
[includeIf "gitdir:/home/john/corp/**"]
path = .gitconfig-corp
And then ~/.gitconfig-corp: [user]
email = john@example.com
name = John Doe
[url "git@github.com-corp"]
insteadOf = git@github.com
Now all repos under the path /home/john/corp/ will use that config. Then you can put a new host in your SSH config: Host github.com-corp
HostName github.com
User git
IdentityFile /home/john/.ssh/corp_github
This way you can have different e-mail address and name in your commit messages as well.Due to the nature of git you can't scope it via GH URL (you can have many remotes in the same local repo). Though you can still manually rewrite when you add a remote with just the SSH config change, e.g.
git clone git@github.com-corp:corp/foobar.gitBut again, it's just personal preference.
You can make notification emails related to the business org repos go to your work email, while all other notification emails go to your personal email.
When you fork a business org private repo into your account, it stays attached to the business org. Other members of the org can push to your fork of that repo but not your other personal or open-source repos. When your account is separated from the org, you lose access to your fork.
If the business org requires extra SAML/OIDC through their central auth service, you can still access your personal and public repos without doing it.
So yeah the business still has to remember to disconnect you from the org when you leave the company, but that's still true if you make a new github account anyway?
Without actually reading the ToS properly, I imagine you're good if your org is paying for your seat in their org (as opposed to a free org, but if it's a company with private repos I'd assume it's the case). That'd be reasonable.
If reality is that you actually meed individual billing for each individual account, that would be kind of crazy and I hope that's not the case.
I used to think people were paranoid about this stuff until I ran a big email system. Most big companies have a department in compliance or counsel that reads your mail, either in response to a complaint or randomly depending on the industry.
Accused of sexual harassment? Your JDate and Match emails support the idea that you’re lonely. An external entity thinks somebody embezzled money? Your late credit card notice projects that you have money woes.
I’m a complete outlier in how conservative I am with this stuff and I’m nowhere near as fastidious as the HN gold standard.
They read the email of your personal email account if you use it in the company-owned phone? Or they read the email of your company email account?
In other words, when you say 'This. +100', what do you mean by 'This'? The parent comment raised many points and I'm confused as to which one you're referring to.
Edit: To be clear, it's my fault because I'm new to these things and I don't understand them well.
yes, if you read your personal email on a corp device, then there's a good chance corp is reading your personal emails. and 100% yes, the corp can/do read your corp email. they are required to keep copies of every email sent by employees, so just assume at some point some corp lawyer can/will be reading them.
Required by who? (Sorry, I'm not so knowledegable about these things)
Edit: search "email retention laws" for more precise rules and specifics
No, but the point is they can. And if there is anything they feel they need to protect themselves, they can investigate. Most corp employees are just too damn busy avoiding doing their regular tasks to be bothered to snoop other employee emails. Yes, I agree that it's not like someone is just tasked with reading all email every day. The point is that they can and do when necessary. Once they start reading, they have no idea where the trail ends so they will be reading a lot.
It all comes down to the same thing stated here multiple times, don't send any messages on corp equipment that you wouldn't want to see read aloud in front of your manager/boss or worse a courtroom.
Some companies sample mail and flag for manual inspection.
For you conducting any personal business on work devices, it is pretty easy for employers to get tools that can detect and even capture that activity. That ranges from grabbing files on the device to periodically or continuously recording screen content.
For conducting personal business on work services, that is trivially searchable with O365 or Google Workplace. Some industries (banking, finance) are required to retain all mail and sample it for policy violations. Sometimes contractors are roped into doing this by contract terms. Sometimes dating coworkers becomes a problem when you communicate on work systems in unexpected ways — anything you do is essentially public.
For conducting business on personal devices, employers cannot generally search through your content. (Unless security or other products are present — for example Crowdstrike or similar EDR tools will log most executable launches) But, if evidence exists that you use personal stuff for business and there is a litigation event or investigation, you can be compelled by a court to turn over your personal gear. That risk depends on what you do for a living and for who. (For example, a government employer may have an inspector general with police subpoena powers, if you are a decision maker in a company, a civil suit may focus on something you said or didn’t say)
All-in-all, the best policy is to keep work away from your personal business and vice versa within reason. The meaning of “Within reason” depends on your circumstances. The issues for a unionized white collar worker at a factory are different than an at-will financial analyst at some big bank.
Thankfully that's illegal herearound. And I work in finance.
There certainly are automated controls on all communication systems and all mails (and relevant phone calls) are recorded and retained. This being a regulatory requirement.
I'm also pretty sure that there's pattern detection software running on those systems to flag potentially problematic communications.
But indiscriminate email monitoring is illegal without a very good reason (suspected fraud, circumvention of regulatory or compliance requirements, etc) is illegal.
This still doesn't mean that I would mix the personal with work on my personal device but I'm glad there are such protections in place.
How much would you even notice this these days, with everything synced to the cloud?
It’s undoubtedly more secure to maintain perfect separation between work and personal information contexts. It can also be expensive and annoying, and may not be worth it for everyone. It really depends strongly on the employer and one’s relationship with them.
you havent worked in sales.
you learn to never put anything questionable in writing. Most people dont even hint at things, just not worth the risk.
drinking create plausible deniability of what you said or what was remembered. information spreads deals get closed. and im talking about things that are perfectly clean but may not apear that way if written.
sort of like in person you can say “grab me a burrito” but if you write it as a request its hard for it to not come off as demeaning.
If they do it's the stroke of a key to make it a ToS violation for employees to have any personal, privacy. Which seems to be their endgame for everyone. Their issue with facebook google etc is that it's not apple doing it as far as I can tell.
It might be the only way things start heading in the right direction.
Hopefully an exec gets caught up in a CSAM hash collision fiasco.
Can't you use a VPN and the guest network and be essentially OK?
I've seen people fired for watching DVDs at work. Conversly people watching youtube a lot and nothing happening. Early in the web days an admin assistant came to me because they clicked on something on the web and a bunch of pron windows started popping up. She panicked and turned off her computer and was wondering if it was safe to turn back on or would she be fired. It was safe, and nothing happened to her.
Someone at a job complained I was reading the news on the web to my boss, when that was my habit at lunch. That was fun.
I am not super religious about, but I do have boundaries. It is mostly like you said. It is all great until it isn't and employer is building a case against you.
My company last year demanded we have MDM to access email. So now I don't read emails outside of work hours.
I assume there's decent reasons behind such mandates, but net net all it does is alienate many people.
(I mean any dangers at the account/permissions/privacy level - separate from "having two separate accounts might be better for work/life balance" sorts of concerns.)
Personally, I like knowing that my personal GitHub credentials stay only on my personal devices and my work credentials stay only on my work devices. I never have to worry about the two mixing and any problems that might arise.
More annoying can be commit signing, but this is actually something GPG has baked right into it - I issue and sign a new key with my work email address while I'm there, and when I quit revoke the key as superceded (and set the expiry to roughly my contract renewal period/performance eval period).
The real problem is corporate IT doesn't understand encryption or signing beyond how their vendors pitch it too them as "secure" so trying to extend any of this to actually support business processes is a losing battle.
So far, the only problem I've ever had with separate accounts (including contributing to FOSS) is one time (once!) somebody selected the wrong email alias to review a CL. That took all of (literally) 10 seconds to fix.
I don't want to carry two phones. I'm part of a team that owns some responsibility for fixing things that break in the night. I find it freeing to be able to reply to a Slack or Outlook email while I'm with my kids at the playground.
I see the above advice all the time, but I can't help but think it only relates to an IC with no career ambition, no outside responsibility distractions (kids schedules), that's 100% committed to 9-5 life and has little opportunity for big promotion based on being part of a chain of ownership for things that are customer facing.
Personally, I've mostly worked at small companies (my preference), and have ambitions. I have a healthy work/life balance, but also don't want my products to fail and occasionally want the flexibility to help my colleagues while AFK.
In the end, the above advice is very popular, but I just see a jaded burnout mercenary in a company with tens or hundreds of thousand employees.
Ah, so you're willing to trade privacy for convenience.
You can spend as much time on work as you want, but you only get so much time with your children. OP's point is that you should guard the time you have and spend it wisely. Personally, I find carrying a second device and keeping things separate part of maintaining a healthy balance between my work and my personal time.
I also don't want my personal devices or projects tied up in some corporate legal proceeding, so I keep them separate for that reason as well.
I hadn't even done anything wrong but it made me hella uncomfortable thinking about my work or the cops getting their hands on my laptop. It just feels too personal.
I had to file police reports and everything, and ultimately it was never found, but I still hate the idea and sometimes think about where that laptop ended up.
when employees are on the clock, there are protections established for both employee and employer. if someone is injured while on the clock, workers comp is at play as well as corp insurance. if someone is working off the clock and injury occurs, shit storms are coming. if you were clocked out and working because company expects it, you can sue them. if you were doing it on your own to be "a good employee", you can get the blame.
in terms of coders, say you're off the clock and you accidentally truncate a table while connected to production when you thought you were in dev. if you're off the clock, you can actually be accused of "hacking" and doing a malicious act by the corp. if you were on the clock, then they would have a harder time with those accusations.
on the other end, i've worked for companies that were very good on the on clock/off clock recognition. if you were on a paid vacation and the company needed you to answer a call or respond to email, they would credit you that vacation day back even if it only took 5 mins. i miss that company. best work/life balance company i every worked.
Also what's a class traitor? it's not like I'm working so hard not to become filthy rich. All my colleagues are doing the same.
Abusive employers classify many de facto line workers as overtime-exempt, often illegally, and workers should not be complicit in this. An employer who tried to treat a unionized industry the way programmers are treated would be laughed at.
> Also what's a class traitor? it's not like I'm working so hard not to become filthy rich. All my colleagues are doing the same.
Sure, but remember that you're not actually a "temporarily embarrassed millionaire" - you most likely have much more common interest with your colleagues than with your bosses. When you find yourself in a prisoner's dilemma situation, remember that the correct metastrategy is to cooperate with people like you and with people who will cooperate themselves, not with a group that's well known to select for sociopathy.
A guy won Nobel prize proving your quality of life or happiness does not improve above 75k. Thats what you need.
And in IT you dont need to do unpaid overtime or sacrifice your time with family to get to 75k. Everything above that and you are doing it on purpose cause you value money over family and personal relationships. And that is your choice. But that is not healthy and that should not be norm.
And if you need your workers to work 16h a day with unpaid overtime but they are refusing your workers are not lazy you are incompetent CEO. Or just evil level of greedy.
A rough off-the-cuff calculation is that $75k is roughly double the median US income. If the same rough estimate is applied to SV, that’s about $110k. I bet that’s much much lower than many SV/HN would suspect for a happiness threshold. If you can’t find a way to be happy on double the median income, it implies the system is rigged to make an awfully lot of people miserable.
The problem is often not that happiness isn’t possible, but that we compare ourselves to our peer group to calibrate our expectations. As Roosevelt said, comparison is the thief of joy.
Might want to introspect on that a bit.
I haven't called anyone lazy.
I talk about class issues and economic justice a lot, but nobody owes prior allegiance to a particular class in a way that you can call them a traitor, unless it's some extreme example like a union official being willingly corrupted by a corporate fat cat - in which case a person is reneging on a promise they made, not some unilateral obligation.
You might not like or disapprove of someone's work/life choices or values, this person's certainly don't appeal to me as expressed. But someone's failure to share my values does not in any way make them a 'traitor'. That sort of assumption of mandatory loyalty and cultish denouncement isn't any kind of socialism or liberation; you cannot bully people into freedom.
This is an asinine and immature way of doing politics and I urge you grow out of it.
As I said, I don't think much of this person's choices or attitudes, but you can't betray that which you never signed up for to begin with.
As I said, I do have a healthy work life balance. I also have responsibilities to my family and to my colleagues, and balancing those is difficult. Especially during a pandemic with no child care - I'm full time working and full time parenting.
Can you empathize with that?
If you're working overtime and on-call outside of work hours then no, you don't. That's not healthy and there's no way to make it healthy. You talk about "owning" responsibility for fixing this thing if it breaks, but real ownership is two-sided - do you have a meaningful equity stake (token stock options don't count) in whatever that system does so that you're getting the upside as well as the downside?
If you're choosing to spend your life and health on something you actually own, fair enough, it's your funeral. But if you're a worker then it's not your job to deal with that. I can understand that as a parent you're vulnerable, you don't want to lose your job, and when the bosses say the business wouldn't be viable if they had to pay for a proper night shift (or whatever rate it would take for them to get enough coverage from you and your colleagues voluntarily taking those shifts - funny how the biggest fans of "free markets" don't seem to like being on the receiving end) then it's hard to stand up to that. But doing free favours for the bosses is like paying Danegeld - once you start it will only get worse.
You keep talking about responsibility to your colleagues, but what you're doing hurts them a lot. That's where my anger comes from.
I am working a more flexible schedule where I handle some details from my phone AFK and work dedicated hours at times that fit better with family obligations.
I actually believe setting that expectation helps my colleagues.
And again, I work at small companies by choice. If we fail a product, the company may fail, then we are all out of a job.
My view remains that if you're going above and beyond then that shouldn't be just to avoid the downside - you should also be getting a proportionate piece of the upside. For a small software company skilled workers are often bringing most of the value to the table, so you should have a corresponding ownership stake (I don't mean that purely rhetorically - from a friend who works at a consultancy that's structured as a cooperative it sounds like it's very much a "normal job" in practice).
Of course in a more capital-intensive business, or if you're blitzscaling, then maybe the owners are bringing something else to the table that you couldn't replicate with just a gang of programmers. But in that case capital is almost always a part of what they're bringing, and that means the company should be in a position to be paying what things cost.
Neither did Hilary Clinton
Playing soccer together, reading to them, playing a board game, doing a joint Lego construction project, learning them to skate, etc. That's spending time together. It doesn't mix well with work.
It is if you actually play with them while there.
I’ve been promoted several times while having separate work and personal phones.
Yes I feel like a right prick pulling two phones out of my pocket - I mitigate this by not being the kind of person who sits down and places their phone on the table face up at dinner.
As for the suggestion that the seperation or work/personal is a sign of less ambition, that you somehow care less about work than your personal life - my work phone is set to ring 24 hours a day, my personal phone vibrate only. There are times where I am not keeping my work life from getting in the way of my personal life, but keeping my personal life from getting in the way of work.
Watching someone go to check their work slack on their phone only to have their attention dragged away to group chats with friends on competing attention apps gives me pause to consider. At the end of the day, whatever works for people, I have found what I think works for me.
In general, as a remote worker, having Slack on my personal phone allows me to work less and more efficiently. It gives the illusion that I am always working, whereas I'm actually working only when I want to and am most effective.
I also work remote, in a different time zone to my team who communicate mainly on slack. I would never consider installing it on my phone.
Yes, it is possible that somebody will send me a message when I’m not at my machine. They’ll get a response the next morning I’m in.
To me, that’s just the most basic form of boundary setting. If I’m not at work, I’m not working. Being remote doesn’t change that.
I've known people who are very driven and can't unplug, who later on end up being very resentful of their own careers because they've structured everything around pleasing others and never saying no.
Why does cooperate IT need to own your tech just for you to be reachable.
This may be slightly more controversial, but I would extend this firewall to conversations with coworkers --- don't tell them anything that could be used against you either, i.e. mentions of personal projects or accounts. I keep a clear "no real name" policy for personal things which are publicly visible --- including HN --- which avoids the delicate situation of people I know who have had their employer complain about stuff with their name on it, in their personal life, that someone else had found and didn't like.
100%. If a company wants me to install an app they'd better provide the phone.
> Edit: One more: don’t use corporate WiFi with your personal devices
Yep, thankfully we don't need to do that anymore with 4G/5G
Leaving a job is hard enough without having to disentangle a bunch of devices and accounts. If an employer wants the security of MDM, just have them provide you the device. Otherwise, it's your device, and you can be responsible for deleting the company related content on it when you separate.
I always refused. My attitude was, like you said, if you want me to carry around a device connected to my work, then you need to pay for it.
But my main reason why though was knowing that managers preferred staff to put work email etc on personal phones, not due to the cost of buying devices for employees, but because it blurred the lines between personal and work domains. You can switch a work phone off at 6:00pm and turn it on again at 9:00am. With a personal phone you have to set up do not disturb profiles and stuff like that to achieve the same separation because you aren't likely to turn it off in the evenings. Admittedly, it's not the hardest thing in the world to setup - but still a bit more effort that just being able to hit the power button.
I still had to deal with the extreme annoyance of having my personal number passed around the company without my permission.
I am issued a MacBook Pro and iPhone from my employer. The IT dept. configured them to connect to our corporate infrastructure: Exchange, MS365, VPN, Dropbox, Slack, printers, etc.
IT did not issue me a corporate iCloud account. I can add my personal iCloud account to these devices if I want, and then I’ll get all my music, messages, etc. on them. Convenient! Or, I can use my work email to set up a new clean iCloud account and use that instead. I know from conversations that a lot of my colleagues add their personal iCloud accounts to corporate devices, especially phones.
Based on the comments elsewhere in this thread, it seems the weird thing at Apple is that @apple.com email addresses can’t be used in iCloud. Which makes it a bit trickier for Apple employees to set up a new clean iCloud for work.
Your goal is to not have to repurchase your music, apps, etc., but not commingle your personal photos and messages. You can do this with iCloud family child accounts.
To use “your” stuff you paid for on a “work account” they ask you to set up using alternative email address, you can make the work account be a family child account.
Then the work account can use purchases etc., and you control its access even if work attempts to take it.
Employees got a free upgrade to the higher tier of iCloud service (the 1TB of storage or whatever). There was also an iCloud@Work program rolled out a few years ago that was like a "behind the firewall" version of iCloud services. It was an approved means to share confidential company docs like shared Notes (in the Notes app) or iWork documents.
What was never clear was the level of integration of personal iCloud documents (photos, iWork, etc) and the @Work ones on the back end. No one gave you a straight answer if you asked if opting in for the @Work stuff allowed Apple to riffle through your photos or personal documents in iCloud.
I always assumed opting into the @Work stuff granted Apple back door access to everything in your iCloud account.
The back and forth between the two parties is enough to give you a headache.
1. https://twitter.com/ashleygjovik/status/1428509942927872000?...
Color me real skeptical that she is telling the truth here.
I can’t imagine the legal department endorsing this.
Yes it costs money and is mildly inconvenient.
Having your personal life vacuumed up into legal discovery changes that attitude quickly.
Also seeing what IT might be logging out of your laptop is sobering.
I think a lot of people miss the R&D part. Clue.
Apple does not mandate that you use your personal iCloud on your work device. You can absolutely make a fresh account (from a new Gmail or something) and use that to sign in, and then throw it away once you have left. Some employees do this: it's possible, but fairly difficult.
However, it is also true that many (dare I say most?) employees do sign into their work devices with personal Apple IDs. Why? Because there are several fairly strong pressures for them to do so. New hire training has natural variation, but often the person will tell you to "just sign in" to when the iCloud screen shows up on your new computer, without explaining (sometimes not even knowing) that this doesn't have to be an account you actually use, and many people do so thinking it is required to go forwards in the setup process. And Apple rewards you for linking your account: you'll get iCloud storage and access to all of Apple's apps for free.
But that's not all: there's a very strong culture at Apple of "dogfooding": using the beta software for yourself to try it out and file bugs against it. Doing this effectively all but requires having an account you actually use, and for many this is the main reason why they only have one work phone rather than two phones. Plus, on Apple devices if you're not signed into an account that you share elsewhere, a lot of things will not work: your Apple Watch will not sync or unlock the device, you can't listen to your Apple Music, the iMessages your coworker sends you to pick a spot of lunch are not going to be seen.
Obviously, it is always easy to tell an employee that they should trade privacy for convenience. But my point is that the culture explicitly pushes you in this direction, and Apple themselves are pretty bad about employee privacy. They've developed a full BYOD MDM solution that keeps your work data separate from your personal data, so companies can just access or delete that, but they don't actually use it internally. And you think you're being cool with your two iPhones that you bring to work? Nope, any device you bring onto the premises is subject to search, even if you have never MDMed it and only use it for personal work. So they, too, are way behind on where they should be with regards to maximizing privacy. It's regrettable that this employee found this out the hard way–but she certainly will not be the last, and I think it's entirely valid to call out Apple for not moving forwards as other companies have.
As posted in a sibling subthread:
Don’t add your “personal” iCloud account even if you want.
Your goal is most likely to not have to repurchase your music, apps, etc., but also not commingle your personal photos and messages.
You can do this with iCloud Family “child” accounts.
To use “your” stuff you paid for on a “work account” they ask you to set up using alternative email address, you can make the work account be a family child account.
Then the work account can use purchases etc., and you control its access even if work attempts to take it.
This sounds less like bad corporate policy and more like naive employees who didn’t think through the importance of separating work and personal devices.
Your recordings are all protected by hashing using advanced badthink crypto.
Each terrorism risk event is encrypted with a cryptographic safety voucher, which ensures a threshold of 30 badthink events need to be logged before the authorities are notified of your current location to be transported by iDrone to the Apple goodthink reeducation camp.
If the device is provided by the company, there should be little expectation of privacy on such devices.
I would not consider adding personal onedrive/Dropbox/etc. On a corp device, nor the email.
Almost sounds not believable. Any place I've ever worked at has if anything insisted to never bring private data into corporate environments precisely for security and legal reasons.