Microsoft will now snitch on you at work like never before
zdnet.com
zdnet.com
Not to mention they use the same standards to evaluate everybody. Whereas in some jobs (e.g. project manager) it's good to be on calls all day whereas with others (e.g. technical roles) it's important to have time to focus. They don't take this into account at all.
Of course I turn that crap off. I don't get the reports. But I'm sure it doesn't stop the actual collection of data. And more worrying, it shows there's people at Microsoft who think this stuff is a good idea and totally justifiable. Eeeew.
I know they say they don't show identifiable information to the employer. I have to trust them at that because I can't verify it. But collection of personal data is a bad thing whether it has consequences or not. Just knowing it's being collected changes one's behaviour and makes one feel unsafe. This is how a panopticon prison works.
Unfortunately some of the higher-ups at our company have been extensively groomed by Microsoft (remember the old saying: Microsoft is much better at talking to your boss than you are!) so I'm sure this will be switched on as soon as they can. Insights reports are already often re-enabled as a friendly 'suggestion', of course the holy Edge has been made the standard browser with its Bing search (tm). This'll be next.
I'm not against vigilance against 'insider trust/threat' issues by the way. I know the department that follows up on these and I know some of the things they have come up with were really bad. However I believe this is a typical thing that requires targeted investigation and human detective work, not dragnets and machine learning. The same way I believe this for society in general.
> The panopticon is a type of institutional building and a system of control designed by the English philosopher and social theorist Jeremy Bentham in the 18th century. The concept of the design is to allow all prisoners of an institution to be observed by a single security guard, without the inmates being able to tell whether they are being watched. > … > Although it is physically impossible for the single guard to observe all the inmates' cells at once, the fact that the inmates cannot know when they are being watched means that they are motivated to act as though they are being watched at all times. Thus, the inmates are effectively compelled to regulate their own behaviour.
https://www.wikiwand.com/en/Panopticon
One could easily draw a parallel here. An interesting paragraph here describes the design of the incentive structure within the prison’s management:
> [The prison’s designer] thought that the chief mechanism that would bring the manager of the panopticon prison in line with the duty to be humane would be publicity. Bentham tried to put his duty and interest junction principle into practice by encouraging a public debate on prisons. Bentham's inspection principle applied not only to the inmates of the panopticon prison, but also the manager. The unaccountable [prison officer] was to be observed by the general public and public officials. The apparently constant surveillance of the prison inmates by the panopticon manager and the occasional observation of the manager by the general public was to solve the age old philosophic question: "Who guards the guards?"[6]
The age old answers to this philosophical question propose that a guardian for the guard to be an absurd idea, or one that plays out only with a plurality of guardians, who guard others against the deception of other guardians’ “noble lies”.
> A noble lie is a myth or untruth, often, but not invariably, of a religious nature, knowingly propagated by an elite to maintain social harmony or to advance an agenda. https://en.wikipedia.org/wiki/Noble_lie
My company is pretty heavily into the Microsoft stack and I'm luckily a heavy voice in the decision making tree, this will never ever get enabled on our tenant. Here's hoping we don't unwittingly feed the ML machine behind this even if we never enable this. I hate this new world.
Do you, or anyone else, know if this happens or is commonplace? For software folks?
From reading into the docs a bit, it seems the data MSFT is gathering on users apparently is surfaced in a dashboard, initially anonymized, to help administrators create policies (to get started as part of a Day 0 experience). Once policies are defined, MSFT will start snitching on individual users to org admins, analysts and investigators, depending on the policy that is in place at the organization.
The article headline is technically true, in that MSFT is capturing this data today across O365 and Windows products, and they're expanding on what can be done with the data (fundamentally have the machine snitch on the employee). https://docs.microsoft.com/en-us/microsoft-365/compliance/in...
> Yes, your company will soon have extra-special robots to crawl along after you and observe your every "risky" action. It's not enough to have increased visibility on browsers. You must also have Machine Learning constantly alert for someone revealing your lunch schedule.
> Microsoft offers a link to its Insider Risk Management page. This enjoys some delicious phrasing: "Customers acknowledge insights related to the individual user's behavior, character, or performance materially related to employment can be calculated by the administrator and made available to others in the organization."
> Yes, even your character is being examined here.
Oh, you used a M$ personal computer at midnight to look at an adult site? Well, your work computer talked to your personal computer and told your boss on you, so we're firing you.
Wifi isolation/tls everywhere means it cant snoop traffic.
Other machines running Linux means no correlation of telemetry. (even if they ran windows it would be complicated legally and technically to do what you say)
Even the scenario above if remotely possible you would sue and at discovery it would be interesting / you would win more in settlement.