Glassdoor not so anonymous
webworm.co
webworm.co
At some point in the gig, one of their clients went to them asking them if it was possible to de-anonymize someone glassdoor review since someone still-employed worked with them. They then went to me to see if I could do it for them. They didn't clarifywhy they went to me, but I legitimately think they wanted me to "hack" glassdoor. I told them in no uncertain terms that I wouldn't do it and they backed off.
A bit later they fired the employee.. I didn't hear how they found the person, but it really spoke to the lengths that some organizations will go to burn down the lives of those who speak up.
Use this google search to find more companies that do it:
"Glassdoor Alert: Employer Legal Action" site:glassdoor.com
https://www.glassdoor.ca/Reviews/Employee-Review-Media-Consulta-RVW23674692.htm
https://www.glassdoor.ca/Reviews/Canidae-Reviews-E845482.htm
https://www.glassdoor.com/Overview/Working-at-Echelon-Environmental-EI_IE1069898.11,32.htm
https://www.glassdoor.ca/Reviews/Canidae-Reviews-E845482.htm
https://fr.glassdoor.ca/Pr%C3%A9sentation/Travailler-chez-Echelon-Environmental-EI_IE1069898.16,37.htm
https://www.glassdoor.ca/Reviews/Employee-Review-BW-Legal-RVW58014087.htmEdit: yikes, people.
(SV reference)
Be smart kids. Do your employer bashing at the public library.
If you care at all if your company would see it, _don't_ do it anywhere near their hardware.
Any email provided to Glassdoor should be a burner on a service that is not one of the majors (no gmail) also set up with Tor browser, specifically for Glassdoor (and used for no other purpose).
Finally, the text that is posted should be somewhat disguised if possible, with altered vocabulary, atypical slang, and distinctly different grammar and sentence structure. Any facts that can reveal identity should be removed.
Under no circumstances should a native Android/iOS app be used to post or access any such review.
It sounds like we will have examples soon of what happens without these precautions.
I imagine that many reviews will be coming off Glassdoor's site rather soon.
I manage a company's google workspace, and we don't have managed browsers or devices, and no one has ever asked to have that capability.
Or the first case when some shared credentials get compromised probably from an infected computer and now you need to find which of the 80 laptops is the infected one.
Or the first time employee converts his laptop into a wifi access point for the office girl upstairs and unknowingly lets her inside your companies private network.
Of course, there are workarounds and better practices for every example. You can solve it without admin access to laptops and network request logging. But company property is not anonymous either with or without full admin access - so why jump trough the hoops to not have it?
If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game.
Laptops are cheap. There’s no reason to mix personal and corporate usage.
From an OPSEC perspective, sure. But the question was whether it's legal for an employer to do it.
You might also get a phone call (on your private phone) about a private medical matter while at work, but I would hope your employer couldn't use the CCTV audio they have in the office to decide to fire you based on that information (though I don't know if US laws actually protect workers in this case -- in Australia and basically all of Eastern Europe this would be insanely illegal on several levels).
> Laptops are cheap.
Not for everyone.
How often did that stop an employer?
Still cheaper then searching for a new job... without a current one.
(This probably doesn't work so well in the US.)
>Commenting on the ruling, Pam Cowburn, the communications director at in London, said: “The European court’s ruling is welcome. In some workplaces, it may be necessary for emails to be monitored, but if employers are going to do so, they should make staff explicitly aware of it.”
>Despite finding that Bărbulescu’s rights under article 8 of the convention had been violated, the court declined to award him any compensation, saying the ruling was “sufficient just satisfaction”.
The largest example probably is the 2020 GDPR fine of 35 million euro for clothing retailer H&M for violating the privacy of their employees, despite the employees being informed of that.
In most EU countries, tracking company-owned hardware is explicitly okay, and where it's not mentioned in law there are judicates that make it OK.
As I said, even the government and its wholly/partially owned enterprises are doing it, and working as a contractor for the government here requires you to track usage of your employees' workplace computers too, so I can't see how it could be in any way illegal. Same thing with working for banks and insurance, and I bet there are more cases.
Don't know about other EU countries, but at least NL deviates significantly from the sketched scenario.
[1] https://blog.iusmentis.com/2017/11/22/wanneer-mogen-mailbox-...
It’s a nightmare from a privacy point, but its also a problem for the InfoSec tools… How do they distinguish between an unmanaged private device on a private network or a unmanaged device on a corporate network?
Trivially, from the simplistic (check IPs and router MACs / SSID in use) to the marginally more advanced (deploy an agent that is only reachable from the corporate network) to determine if the tool should even be running in the first place.
E.g. tag the port on the switch, run a cable to the device so that it doesn't know there's a vlan involved, block routing between vlans. As far as I can tell that's probably good but might not be.
In the USA and other countries with subpar privacy laws.
For the employer to open/read such communication would be highly illegal, akin to opening others private snail mail.
I do believe that this also extends to corporate issued phones and computers. Especially since you’re automatically taxed for “private use” of such equipment when assigned.
I think you need to specify "here" to get an answer to that question.
That has nothing to do with putting private email in a private folder on the company mail server, near as I can tell, and nothing in that statement would address the statement about companies monitoring use of company equipment and network etc.
Since they’d need to know even in the private email case what they folder names were, for instance, to know there even WAS private email.
so you get charged a tax when an employer gives you equipment required for work? What happens if you can't afford that tax then?
This feels very wrong - taxing someone for a potential benefit when it is not proven that such benefit exists.
The vast majority of people prefer to also use the car privately, and pay the tax (which is reasonable, if taxation is reasonable).
Cars that keep rotating between drivers are not subject to that (but exact record keeping of driver and trip required to avoid tax)
Similarly, employer provided phone subscription is assumed to be partly private use (50% of monthly subscription cost considered a a taxable benefit iirc), not sure what hoops you need to jump through to prove it is not private use at all. (But phone plans are cheap - excellent domestic plans are $10 or so)
Obviously this only happens when the equipment you get can plausibly be used for personal purposes. Such as a company car.
> What happens if you can't afford that tax then?
That's extremely unlikely.
Imagine I were to die in the office in some embarrasing way, on company time, in full view of company CCTV, do they have the right to upload the video to YouTube to make money from it?
What if they record audio of me at home, can they publish it? Can they show it to anyone at the company?
What if audio is recorded outside of compaby time by a company laptop thats had its lid closed? What if it's recording 24/7?
Are they allowed to snoop on traffic of my home network? If I have a home camera thats not password protected, can they help themselves to that Video?
If my network drive has no password, is it okay if they help themselves to those files?
I can't think of which law stops a company sharing a video of your death - presymably they own the copyright
Even more restrictive countries like Germany are fine with this.
People have legitimate expectations of privacy in the office and/or during working time.
Employment means selling your skills and effort, not becoming a servant or a slave in a feudal society.
Additionally, having delicate information in the hands of the company in general or sysadm/security engineers create a ton of liabilities.
There has to be a balance between security needs, corporate surveillance, privacy and worker rights.
That requires them to use tools which can easily let them know, for instance, what websites someone is visiting, and what executables are executing on the machine, what devices are being accessed and when, etc.
It’s pretty fundamental. An individual looking to secure their machine would need to do the same thing.
If a company abuses that to spy on every waking moment of an employee, that is obviously abusive (barring cases of investigating legitimate suspected abuse by the employee I guess?). But you’d need to somehow codify in law the line, and I haven’t see anyone having any success here so far.
I have seen employees steal massive amounts of trade secrets, secretly steal customers from employers, run porn sites from company equipment, etc.
I’ve also seen employees so creepy stuff like stalking customers, stalking other employees, harassing other employees using this tech too.
Personally, I’ve always kept employer laptops and stuff closed and off when not used, and try to segregate personal and work equipment, but that’s been more to avoid something embarrassing coming up during a presentation or the like.
People could be making backhanded deals on their phones or they could be having an urgent confidential conversation with their doctor or spouse. Should the company record and review phone calls?
People could be stalking customers/coworkers or making deals in the bathroom. Or they could be using it for more personal purposes. Should the bathrooms have CCTV with audio?
People could be selling company data in the company parking lot, in the mall or at home near/using the company laptop/phone that is permitted to be used for personal reasons, or just mandated to be near them, or they could do the same thing without presence or use of any company equipment. Where do you draw the line, and at what point is it even sufficient to prevent losing information etc.?
Do you trust your employees? All trust can be abused, yet how can the company function if they don't trust their employees at all?
https://www.grcworldforums.com/business/can-employers-legall...
It is very hard to see the Workplace Relations Commission (WRC - the body which handles workplace disputes) accepting that identifying a user on Glassdoor would meet the test of being necessary, legitimate, or proportional. This is particularly true as the WRC has previously found that monitoring internet usage for example for pornography is not proportionate where the employer has the option instead to block such sites and make a policy against their access.
Of course, an unscrupulous employer could also use surreptitious surveillance and find another reason to let the employee go, although firing an employee in Ireland is notoriously difficult short of gross negligence.
The US is more "employer-friendly" if you like, and much less complicated to fire employees (boo!) compared to Europe - yes. But generally not categorically different when it comes to the right of employers to snoop on their employees, which people here might want to be aware of.
Understatement of the year.
Wow
Don't use work computers to look at porn, your employers already know about it.
But they were quite frank about allowing us to do what ever we want on the laptops providing we delivered positive outcomes for the business.
If this meant the laptops were used to browse porn at home or even during business hours (clearly not on the shop floor if you were in the office) or playing video games, it was fair game.
This employer also had _incredibly_ poor standards and culture for removing misogyny and bigotry, in fact it was one of the worst I've ever seen. Not saying causation = correlation or similar but an interesting data point nonetheless.
I think that the periodic checks were set up because a subordinate of the manager's had seen the porn on the machine, and had gone to HR.
Your advice is still sound.
Exactly! I'm always amazed at people who do ANYTHING personal on corporate resources, especially in this day and age. Even when personal computers were rare and cost thousands of dollars I still didn't do jack shit on work computers, no matter how tempting or "acceptable use" it was.
Since it is only 1 of the 8 IP addresses; the other 7 remain free from blockages of any kind and the one running the TOR middle relay is setup in a manner in which I can use it normally (for the most part) and my traffic would just "blend in" with the normal tor traffic passing through it.
You might ask, what is the purpose of this? Well, if it is normal for a lot of TOR middle relay traffic to be passing through one of my IP's on a daily basis, plausible deniability becomes a real defense as checking DNS logs becomes a moot point as there are requests being routed 24/7/365.
Edit: https://hacky.solutions/blog/2020/06/06/operating-a-tor-rela...
This is an excellent, detailed, and in-depth guide of the process of going through running a TOR middle relay. The statistics provided and data presented are simply superb, Great read!
In addition, there is also this for those that do not want to go through the hassle: https://blog.cloudflare.com/welcome-hidden-resolver/
Cloudflare runs their own DNS Tor resolver.
(I don't know much about Tor, so am I missing something about 'middle relays' that such a site would want to allow them?)
Edit: oh is the point that you're not accessing the site using Tor, just from an IP addociated with Tor use?
Presumably most folks neither know or care about this distinction and just block all Tor related infrastructure outright, since some of the traffic coming through is malicious.
It's not illegal, but it's also not surprising when such folks are escorted out.
[0] Even with GDPR and similar legislation all they need is a valid business reason and they can keep my PII.
You mean you had to currently be working there, rather than formerly? I thought this lawsuit was about people who had already left Zuru, but I may have misread the article.
I never understood people who use their work/school machines to do stuff that could hurt their employer/school. Or even just to cause them potential problems.
But of course, the other way around is true imo: I won't use my personal devices for work - but that's mostly to prevent me from giving free extra work time to my employer.
https://www.google.com/search?q=Glassdoor+Alert:+Employer+Le...
-Steidle
-legatum
-Medspira
-Media Consulta
-Keller, Fishback & Jackson
-ABG Accessories
-Echelon Environmental
-Admiral Markets
-canidae
-Discovery Clinical Trials
-kraken
-zuru
-bw legal
-kurland
-SynapseFI
https://help.glassdoor.com/s/article/Glassdoor-Alerts-Badge-...
Based on the wording on this page you have to be pretty flagrant to get a warning sign attached to your company.
“We are deeply disappointed in the Court’s decision, which was effectively decided under New Zealand law.”Have everyone's siblings read all the reviews and see if anyone recognized it?
- Oct 12, 2022 "They fired Bobby!!! Bobby's been working with us for 10 years and they fired him overnight?? Told you that place is bonkers!"
- Oct 14, 2022 "Mona's down, I repeat Mona's down!! This is a sinking ship! Do not attempt to join this place!!!"
Meanwhile in the C-suite's office.
"Seriously, who is this guy?"
(the non-trivial possibility they'll get the wrong person isn't going to stop fingers being pointed)
The place was a toxic personality cult around the owner/manager, and I left a Glassdoor review saying as much. Someone at the company found it within a couple months, and then overnight several current employees had posted glowing reviews refuting mine. Certainly we wouldn't expect a personality cult to launch an Internet brigade to protect the boss' ego.
* psyops: running/scurrying in your periphery
mentioning personal things from your personal/sex life yesterday, but addressed to others
compliment you for bad work, berate for good work
silent treatment
throwing out your performant code and replacing it with trash
employees one after each other, one by one turn against you, trying to give you the impression you are going insane... imagine you talk with someone on a daily basis and then all of a sudden he refuses to interact with you or gives you looks and avoiding you
slamming doors
doing borderline insane things before you, like getting elbow deep in the toilet then smiling at you
pretend face to face that nothing happened
"oldworld" things
etc etc
This oppressive system must be burned down, nuked big time.
Is this supposed to be a moral obligation? I'd be careful about putting moral obligations on other people.
It appears a few other companies are doing this too, including Kraken (https://www.kraken.com/) as you can see here: https://www.glassdoor.com.au/Overview/Working-at-Kraken-Digi...
EDIT: If anyone from Glassdoor is reading this, please advise on a way to either unlink my profile from my identity - or remove my profile and contact information altogether. I believe GDPR may provide some assistance here.
> This employer has taken legal action against reviewers and/or Glassdoor for the reviews that have appeared on this profile. Please exercise your best judgment when evaluating this employer. Learn more about Glassdoor Alerts.
i.e. "FFS stop writing reviews, but assume the worst is true and stay the hell away from these clowns"
Nothing like getting lots of press for suing critical employees to improve your rep.
https://www.reddit.com/r/newzealand/comments/w2lvgp/zuru_gla...
In their filing against Glassdoor, they declared their intent to sue the employees.
The judge's order only permits them to use the information for the purpose of pursuing defamation actions in New Zealand:
> 5. Zuru may use the information disclosed by Glassdoor only for purposes of the anticipated defamation action in New Zealand.
The Legal Action Canary?
- Reminds reviewers to avoid libel, since it may undergo legal review.
- Tells potential employees or customers that this is how the company responds to bad press/negativity (i.e. disproportionately).
- Doesn't subject Glassdoor to potential libel since the statement is objectively true (see court records).
Although I won't get too positive about Glassdoor as I've read negative reviews disappear[0].
[0] https://www.reddit.com/r/sysadmin/comments/8tfhxv/glassdoor_...
I decided to quit the toxic environment. Contractually I was supposed to get 2 months of basic pay, but Ness and Paypal conspired together and concocted a story where I have falsely accused someone of sexual harassasment and since it is false, I can be fired without that 2 months of money. Then they asked my to nicely sign a letter where I forfeit that salary willingly or they will report "this gross misconduct" to future employers.
My review in Glassdoor lasted a year.
Unless the 2 contacts from each company had a personal vendetta against you. Then I can see it.
(I'm basing this general comment on my understanding of French law. I believe it works similarly in many, if not most, European countries. I hope some actual legal experts can weigh in!)
You are saying this isn’t the case in some places outside the US. Which places, and how so?
In Sweden for example there is publisher responsibility which can limit truthful but harmful statement. Anti-doxxing laws has a similar purpose. There are also countries where people have a right to be forgotten, especially once a person has served their time in prison.
And if it affects the state, truth wasn't/isn't always a defense: https://en.wikipedia.org/wiki/Seditious_libel?wprov=sfla1
And in other legal systems, the value of truth depends on whether the case is a private or public one: https://en.wikipedia.org/wiki/Defamation?wprov=sfla1
A lot of the initial headlines were things like "Abe collapses at rally, shots heard" even though the article itself had a video of him getting shot and then falling down. Others just had a headline that equated to "Abe collapses during rally, currently in critical condition" without even mentioning a shooter.
Here's an interesting article about it: https://www.tofugu.com/japan/sued-in-japan/
More interestingly it’s a nice way to forestall future lawsuits as well.
Kraken is still silly for going after them, IMO, but the Kraken case isn't as cut and dry. The person who had left the review on Kraken had accepted a large severance package that was conditional on signing a NDA.
I think the bad PR Kraken got for going after them wasn't worth it (especially as the review wasn't really even that bad) but the ex-employee was also not really in the right there either, having violated their NDA.
"NDAs do not prohibit people from reporting suspected corrupt conduct to an appropriate authority. The Crime and Corruption Act 2001 and the Public Interest Disclosure Act 2010 provide safeguards that allow people who have signed an NDA to report suspected wrongdoing, including corrupt conduct, maladministration and the misuse of public resources.
Under no circumstances do they oblige people who have signed them to maintain secrecy about suspected wrongdoing. You can still report suspected wrongdoing despite signing an NDA."
[1] https://www.ccc.qld.gov.au/sites/default/files/Docs/Publicat...
/s
If you disagree with what the NDA covers, don't sign the NDA.
:)
Just put a "badge" next to companies known to sue employees who post reviews on Glassdoor.
No reviews are even needed from that point on to signify a shitty company; for all anyone knows all negative reviews may have been taken down through legal action, but the badge stays, signifying that there was at least one review so damaging that they had to get lawyers involved (or that the company climate is of that toxic kind that sues its own disgruntled employees more generally).
In the end suing will end up acting as the ultimate bad review for that company on the site.
I'd argue that "bad" companies with predominantly positive reviews, were the negative reviews were all effectively sued away, presumably hurt Glassdoor's model more than they help it, so it's in their best interests to flag "bad" companies using other means.
Also, "good" vs "bad" is an oversimplification. In reality the most likely outcome is that this badge will become another point for companies to game. But if the result of that it acts as a disincentive to suing employees that leave bad reviews, to me that's presumably a good outcome.
Eg by that logic, Yelp would have no incentive to allow bad reviews. Hell, they could just be a listing site that puts "5 stars (10,000 reviews)" next to every listing.
In my experience, that macro trust issue is rarely discussed, even though, at some undefined point in the future, it could pose a serious existential threat.
https://www.glassdoor.com/Reviews/ZURU-Reviews-E2286297.htm
> Glassdoor Alert: Employer Legal Action
> This employer has taken legal action against reviewers and/or Glassdoor for the reviews that have appeared on this profile. Please exercise your best judgment when evaluating this employer. Learn more about Glassdoor Alerts.
1) This alert doesn't show up at all on mobile.
2) IMO this should either affect the overall score or be displayed in search results as well, which is not currently the case: https://www.glassdoor.com/Search/results.htm?keyword=ZURU
Having said that, apart from what you also flagged, it's also a bit bland. Like "there's some legal stuff here, exercise caution".
Instead the badge could have symbolic character, an emotive icon ... something. Something that strongly implies "Danger Will Robinson" without explicitly saying so. Something any company would want to avoid risking that thing showing next to their logo, unless it was absolutely necessary.
As it is now, all I'm getting is a bland "huh, something legal must have happened here".
That said, at least here in the US, a carefully-bland legal statement strongly implies what you're looking for. Like, the more bland, the bigger the warning sign :)
And I just checked a company where I know it happened.
No warning.. so no idea why and how they show it..
https://www.glassdoor.com/Overview/Working-at-ZURU-EI_IE2286...
If so, it's on there, down in the reviews section
I stood by the review and Glassdoor notified me that the employer pulled back on the legal action. My review is still there. And Glassdoor did their best to not reveal my identity under the threat of legal action -- not until absolutely necessary.
Only TorBrowser by itself got escaped via JS.
How far should companies battle to reveal the sources of mean reviews? Why not simply reply to those reviews with a counterbalancing response? It's not a big deal. I don't condone making fake reviews out of spite, or whatever is claimed in this case, but chasing reviewers through court action is petty.
One of the values on Zuru website is something about "think different" but what is thinking different about suing a negative reviewer?
So much bragging over there on the zurutoys.co/about-us pages, they talk themselves up big time. No environmental statement that I can see btw, just how amazing they are. Should environmental policies start imposing limits on how many plastic fish fidget spinners the world needs? If less quantities are made, their rarity provides value on the used/recycled market. May mean less rooms in mansion for company heads. Better for planet though.
I also assume large free hotspot providers collect enough identifying information from their users for the purpose of aiding investigators and courts in identifying abuse of their networks. A subpoena could provide that info, and hotspot providers can choose to just hand over that info when requested.
Not sure I see the problem. They gonna subpoena Starbucks to get the (now probably long deleted) security footage for the time the negative review was posted?
It's annoyingly hard to create a truly anonymous email account these days. Even more privacy-respecting providers like ProtonMail make you verify your account using a phone number or email address when signing up through Tor (though at least with ProtonMail they claim to not associate that information with your account, and you can bypass verification by upgrading to a paid account via a Bitcoin payment).
What identifying information? There is no identifying information other than IP address, email and anything else you volunteered when signing up.
Remember the context here. It's "toy company" grumpy about a negative review, and wanting Glassdoor to hand over what they know.
Have a guess what Glassdoor will hand over? Email address, IP, and whatever else you willingly gave to Glassdoor. They won't have any other information from "javascript" or whatever you are claiming is leaked from normal web browsers.
Companies do not just log IP addresses and email addresses, there are billion dollar ad networks that have refined the game of tracking users across browsers and devices, and they certainly do not rely on just IP and email addresses.
Many companies keep extensive logs of analytics data that their customers generate that amount to much more than IP and email addresses. If a company is motivated enough, there really isn't anything stopping them from cross referencing their own logs and employees/users' identifying data with whatever Glassdoor, and any of its partner services they've integrated with, collected from their users.
And it isn't just JavaScript that leaks identifying information, most browsers do it by default. JavaScript just makes it stupidly convenient, more accurate and opens the door for novel methods for collecting identifying information.
I took a screenshot, it was gone a week later. To this day I don't know who wrote it, and whether they get scared into taking it down. But i've never trusted the anonymity of Glassdoor, which is why i've never personally left a review.
Just replace reddit.com with reveddit.com in the URL. It's not perfect but it allowed me to see that the mods of r/coffee are total weirdos, for example, who will remove any hint of a joke or even the faintest suggestion that someone owns a cafe (even when they don't mention the name).
Why hasn't someone built a similar service for Glassdoor?
> statements of “pure opinion” are protected by the First Amendment in America. But New Zealand doesn’t have this. Statements of opinion are not categorically protected.
That said, the warning that Glassdoor adds to the pages of companies that do this has to be the biggest warning not to go work for these companies; definitely a bigger deal than a couple of bad reviews.
Edit: there is even a Wiki page for it: https://en.wikipedia.org/wiki/Section_1782_Discovery
I definitely don't trust glassdoor. :(
I read 1 and 2 star reviews to check for anything I may need to be cautious about but I generally assume that 5 star reviews are intentional padding.
Do you find yourself leaving 5 star reviews regularly? Leaving reviews at all? Are you more motivated to leave a review if a bad experience or a good experience?
I have left both 5 star and 1 star reviews. Unfortunately some of my 1 stars have been removed. I leave 5 stars when it's good (ignoring any usual corporate politics that might exist, these exist anywhere regardless). My 5 stars are usually descriptive enough to make it authentic and not like "good place to work, friendly ppl, awesome culture". I leave 1 star when things get really bad, like really unethical backstabbing sort of bad.
But then again I don't understand how companies are able to get them removed off of glassdoor. Like, my current company has done everything from removing reviews to having good publicity on glassdoor/linkedin/any social media but they have not tackled one single negative review head on to change their culture. Lol.
On Glassdoor it's so obvious when something is HR or marketing. Lots of "people wear many hats and there's a high standard for quality, which isn't for everyone" type speak.
Negatives: "Sometimes we're too ambitious"
I'm considering giving a 1 star to a bar in my neighborhood. Pizza was shit, a side of fries was $8, service was fine, but it really burned spending $18 on just a beer (during happy hour) and fries.
The review was gone within 24 hours from Google Reviews. It's a racket and completely paid for. I filter by 1 stars at this point otherwise I'm unsure if I'm reading a purchased review.
Glassdoor refused to accept any of the new reviews. I assume they have some sort of mechanism in place to prevent a flood of new reviews, assuming it's something directed by the employer. Even years later I only see one or two new reviews despite dozens of them being submitted.
Does Zuru have proof it's because of negative reviews and not other causes?
Um... no? I don't. At all.
If another party so moves, they could ask the court to stop the plaintiff, and the judge will make a decision. But that's not automatic--somebody has to specifically ask for it.
But this weird, kinda archaic, jargony, overly-specific English is just how regular motions are written, by real lawyers in regular courts.
(And yes, it does sound funny, if you're not used to reading/writing it.)
There are also certain specific legal terms and phrases that work kind of like reserved words or functions in a programming langauge, because they invoke a specific legal effect in how the court needs to handle them. If you don't phrase your motion properly, your motion could be denied because it. Or maybe the judge let's it slide, but you piss them off and wear down their patience.
Anyway... For us, it sounds funny because we're ignorant of it. Just like how programming languages may sound funny to non-programmers: "If X then Y else Z" is similar enough to English, but it'll make the kids giggle if you ask them to read it aloud.
After verifying that you work for a company, why don't they physically destroy everything that could be used to de-anonymize you, leaving with only some kind of public key and a proof of that you work for company X?
For the legal part I think there were some countries (IIRC Sweden) that doesn't require to keep any logs so that they can move operations there with an owned company and legally anonymize users.
I know it's much easier written here on HN than actually done, but that should be the intention: anonymous by design ground-up.
// edit: fixed "do" to "don't" on first line
Even if someone actually worked for a company, it doesn't mean their statements about it are true. Someone might be disgruntled for a variety of reasons and slander the company, in which case it would be proper to sue in order for the review to be taken down.
The social issue here seems to be that there probably are more companies doing this for "revenge" purposes than for legitimately taking down slander.
Since it exists (whether such a service itself existing is a problem or not is out of the scope here) technical implementation is just a way of making the service work as intended (e.g. Providing anonymity to the users).
Glassdoor's entire value proposition is anonymity. The best way to respond to a subpoena, IMO, is to make it very clear that they have no way to know. Of course that might mean more legal action directed directly against them, but to me that's a cost of doing business as there is no business if people stop trusting Glassdoor to protect their identity.
Any mid or high level job you might as well just post under your name. There simply are too few people that have ever had your job and its only a matter of a bit of work to figure out who you are.
I wonder what the most common job by a single company in the world is? Amazon warehouse worker? Even if a few million people had that job I bet any HN data scientist could deanonomize almost every review.
https://businessdesk.co.nz/article/the-life/my-net-worth-nic...
Oh sure, they hide your name and email, but they have it. A good secret isn't a secret if someone knows it.
I always wondered if they should - and now I wonder if they could - have really anonymous reviews. Just don't tie a review to a user. Sure, ask users to create accounts, validate them, but once they submit a review, it's store without details.
This would make it impossible to respond to subpoenas such as this. And my question now is, could they?
> If Glassdoor can’t point to who said it, they’re the one who gets sued.
Why? HN doesn't have any information on me. If I say something that's alleged to be libelous, does that mean HN is responsible? That seems a bit out there.
they will present is as a review optimization strategy.
this is how yelp did it back in the day.
i dont know if glassdor does or did it, just pointing out other review sites did do it and never posted it on their "pricing" or "services" page for employers...
Yelp no longer does this?
Just passing along rumors I have no particularly informed insight here or verifiable reason to believe this is true, though I do believe it's in the plausible-to-likely range.
That said, it seems like negative reviews can easily end up violating one of the many other terms of use[1] around review content. Specifically that a user will not: "Post Content that is defamatory, libelous, or fraudulent"... and "Act in a manner that is [...] otherwise objectionable (as determined by Glassdoor)". That's really broad, and negative reviews can easily be framed as "defamatory" or "objectionable" even if they are factual...
[0] https://help.glassdoor.com/s/article/Can-employers-pay-Glass...
They could easily be telling the truth there, but still be effectively selling a good rating. They'd just have to sell a service to help monitor the reviews in some way for violations of ToS. Suddenly ~all of the bad reviews are "spam", "libel", etc. It's amazing how broadly things can be recognized as abusive if your pocketbook depends on it.
I have _no_ idea if they're actually doing this or not, but it's along the lines of the scam many review sites use.
I have worked at several companies that received a lot of poor reviews and often what happens if you keep track of those reviews over several months is that they "mysteriously" disappear. Of course by that point the person who left the review has probably moved on to a new job and can't be bothered writing another review that is sufficiently vague as to avoid potential removal. One company I worked at even had its overall rating significantly messed with (over 0.5 change within a month), as those old reviews disappeared and "mysteriously" a bunch of vapid positive reviews appeared.
All that said, I still check Glassdoor before every job I interview for. You just need to be mindful - especially for larger companies who can afford the time to curate their reviews - that the score is perhaps a little inflated, and that the reviews that remain are as tactfully-worded as possible to avoid deletion.
Foo Technology unambiguously did not exist as a separate company in any form.
Thing is, Foo was the unlikely company where the line workers were more satisfied than the Technology employees - the company overall was very decent but the technology org was toxic.
Accordingly, Foo Technology had lousy ratings and negative reviews, while Foo has largely positive reviews and a strong rating. The difference was on the order of Foo~=4.0 while Foo Technology~=2.0, both derived from a significant number of employees.
You can imagine the pitfall this could create as a prospective technology employee contemplating a stint at Foo.
As a disgruntled Foo “Technology” employee I contacted Glassdoor to notify them that a nonexistent company was distracting many genuine reviews away from a legitimate company.
Glassdoor notified me that they would not provide any corrective action unless the formal owner of the Glassdoor account for Foo agreed to it.
This told me that accuracy of reviews on Glassdoor comes in a few positions shy of their top priority.
Although in full disclosure, a year or two later the 2 separate “companies” did get merged on Glassdoor. I don’t know what the impetus finally was, but they certainly didn’t give a shit when I notified them of the snafu with their system.
The companies they'd be outing aren't valuable to glassdoor.
Another comment here suggests the following Google query:
"Glassdoor Alert: Employer Legal Action" site:glassdoor.com
Which does indeed highlight many other companies that have taken legal action against their reviewers.Since when does a NZ order apply to a non NZ company. For example, American media regularly publishes the names of persons charged with crimes in Canada where the name may be banned from publication by a Canadian court. It's a first amendment thing.
If US companies start obeying orders like this, how is it any different from getting a court order from a "totally neutral" court in Hong Kong, actually controlled by beijing, to de-anonymize the users of an american-based web service.
Looking at the details, it appears that they were sued in a us court in California, so the order does apply.
The court order itself is from a california court. They can't just tell that court to fuck off.
And now we just have US judges deciding they should apply NZ law without applying the 1st Amendment?
It is mostly up to the judge's discretion, but case law establishes 4 discretionary factors to consider: 1) whether the request is from a potential lawsuit participant, 2) nature of the tribunal 3) whether discovery can be obtained by other means, and 4)whether compliance is burdensome.
Also see: Kim DotCom. Broke no laws in New Zealand, will eventually be extradited for a civil matter. He's delayed it a long time though.
Maybe if they paid for them.
- Your real name
- Your real email address
- Your real salary and job title
- Your normal vocabulary and idioms
- Any of your devices (as in, go to an internet cafe or something)
They can deanonymize as much as they like all they're going to find is that "dbcooper42069[at]hotmail", using non-region specific language, took a very dim view of company X's management style and pay rates.
I think that this one is way harder to avoid than you might think, short of having someone else write the review for you (which might not be a bad idea!).
The other thing I can think to try to do would just be avoid any complete sentences, just give short bulletpoints or something. Resticting the amount of text should make it harder to get anything like a real match.
In a few reviews I've left (using different accounts etc for each one to avoid fingerprinting!) I've written the review myself, changed it to a formal register, thesaurus-ed a few words, and also threw in a few red herrings to make which team I was from appear ambiguous (for example, whine about sales tooling/CRM when you're an engineer that has nothing to do with sales).
In any case the idea of a company email is a little hard to define from the perspective of a 3rd party that deals with millions of companies; different TLD's, domains, sub domains etc make it very hard to nail down exactly which pattern is the definition of any given companies real email addresses.
The only way to get around this is some impossible to imagine global regulatory chnage where companies may never take action against negative non-anonymous postings.
I am not sure how to overcome this massive information asymmetry that corporations have against us
As a publicly elected official, I have had someone lie about me at a public meeting. An accusation which if true, would certainly inhibit my ability to get re-elected. Since it was in public, I could find the person who said it and got a public retraction at the next meeting.
Thankfully these occurrences are few and far between, but doesn't diminish the question about the rights of the target.
But what if this accusation was posted anonymously and I could not find the the accuser? Should I be allowed to get the name from the site?
I trust Glassdoor to keep their promise of not releasing my ID voluntarily, but when courts get involved all bets are off.
It’s like a “must be this talk to ride” sign at a carnival ride.
1. After turning in my notice to resign, the company I was leaving offered me a written agreement where they would pay me $2500 for leaving a positive review on Glassdoor.
2. Someone I used to work with posted a personal attack on Glassdoor, that was clearly against the policies (along the lines of "The CEO is human garbage"), and yet no amount of flagging or reporting the post resulted in them taking it down.
For example, I once had a coworker that would openly crush up and snort various pills between calls while fundraising for one of the two main political parties. This was not an issue for management.
I would never post [name of that employer] from any account that could possibly be attached to my name anywhere.
Just curious, and I agree it's unprofessional. I can be quite judgemental, though.
Edit: This is the funniest exchange I’ve had on this website, thank you. “Preferring people don’t do lines of apparently excruciating substances right next to me, at work, in an office, while I’m literally on the phone” being “moralizing” is hilarious.
https://www.nzherald.co.nz/business/kiwi-toy-giant-zuru-wins...
Perhaps this event will send a chilling message to would-be whistle-blowers...
I figure at this point I will need to literally buy a burner phone with cash if I wanted to create some identity not connected to myself online.
If glassdoor cares so much about anonymity, why didn't they engineer their site in such a way that prevents them from being able to deanonymize reviewers? For instance, not keeping identifying user details after they have been verified?
I imagine there's some sort of zero-knowledge magic cryptographic thing you can do (or maybe something simpler, like a... Bloom filter?), but perhaps Glassdoor didn't want to go for the effort and expense to implement it.
Just goes to show you, unless you can prove anonymity client-side, never assume you're anonymous on the internet, anywhere.
Just FYI, Glassdoor does NOT try to prove that reviewers are current or former employees. Anybody can post claiming to be an employee, and Glassdoor will accept their review.
But even if you want one account to not write multiple reviews, you can flag that an account wrote a review for a company without tying it to -what- review.
You can even disassociate that; hash usernames with the company and store that to track who has written a review. Then, you can only confirm that a given user account has written a review for a company, but not which review is theirs, and given a company you can't determine what users wrote those reviews without attempting to hash every username against it.
And that's if you -absolutely- have to try and prevent an account writing more than one review (again, noting that you can just create another account).
Given even a few million users, this is trivial. Other than that, I agree with you.
The fact that it's impossible to comply with "who wrote -this- review" is probably sufficient, but "and we don't even readily have access to who wrote -a- review" can help prevent fishing expeditions, since presumably a judge will be less amenable to such fishing expeditions if you can show it will have negative material effect to comply, while still not providing any legal path forward to sue for the prosecution.
But that also makes assumptions both of user counts, and rounds of hashing. 50 million users (seems reasonable with Glassdoor), with a sufficiently slow hash that takes a second to compute (easily done) means you'll have to wait a year and a half for results for a given company, or start to parallelize things, and, oh, look, now you have dev time and CPU resources and, well, this has a materially adverse effect on our business, and we'll be left with usernames we still can't release since this discovery order only is valid for this -one- review, and we have no way of knowing which it is.
It doesn't seem hard to me.
1. when making a review, send a verification link to the email on file
2. after the email is verified, post the review, but delink the email from the actual review.
3. to prevent the same email from being used to spam reviews, add a coarse grained timestamp (eg. rounded to the nearest month, depending on how much activity the company gets) of when it was last used.
4. if you want users to be able to update reviews afterwards, display a secret key to them and keep a hashed version on file. The user must present the secret key if he wants to update his review
Regardless, they need to just delete it now and say they lost the information, and risk the wrath of the NZ legal system rather than risking never getting a review again.
"Here, then, the question under New Zealand law ..."
The day the courts here decide to pay attention to say the Russian or Saudi laws a lot of people would get in a lot of trouble.
The point is to terrorise anyone out of criticising them, ever.
This is the most surprising part of this article to me. Not the NZ one, but the US one.
Does this mean you can say whatever you want in the US without risking be labeled libel? What if you're a victim of it (NOT saying in this case, but in general like personally)?
No. The question of whether a claim is of opinion or fact is itself an objective question of fact. “Donald Trump is an evil man” is a opinion claim, and cannot be libel.
“Donald Trump murdered his bastard son” is a fact claim and could (potentially) be libel.
For a defamation case to succeed in the US, the accuser has to prove that a statement was made that a reasonable person would interpret as a statement of fact. That means that something like "zuru is the worst place to work in the world!" would not put the person at risk of losing a defamation case, because "worst place in the world" is subjective, and no reasonable person would think it is an objective fact.
If they said something like "zuru management ate my babies!".... well, that still wouldn't get them in trouble because it is so obviously not true that no reasonable person would think it was a statement of fact.
If they said, "zuru didn't pay me my last paycheck," well then you might be at risk for defamation if it turns out they did actually pay you (the truth is always an absolute defense in the US, so you can't get in trouble for saying something that is true)
Now, even if it wasn't true, the accuser still has to prove that the person either KNEW it wasn't true, or completely disregarded whether it was true or not when they made the statement.
It is hard to get someone in trouble for what they write or say in the US.
So I guess this means HK-owned, New Zealand-headquartered, US-sales-team-based companies can now court order user information from other companies.
Interesting.
Edit: One of the “services” they provide is the ability to add your resume. Presumably that would provide some kind of job matching benefit, but I’m not familiar with it. But, that would be one source of users’ info.
There's an uncloseable pop-up telling you to log in.
Normally I wouldn't bother, but curiousity got the best of me - I logged in with my Google OAuth.
Not so fast - you haven't contributed to Glassdoor in the last 12 months, here's another annoying pop up and you cannot dismiss it until you do.
Does anyone actually bother to use this dark pattern infused service?
But yeah, posting a review also gets rid of the banner permanently.
So it comes across to me like the Mowbrays personally trying to stomp someone into the ground with legal fees knowing they have no case. Hopefully the legal system can protect them from that exploitative use.
Seems on song with that basis of the comment, doesn't it?
As long as your reviews are true and factual based, they don't have much of a case against you (libel or defamation), with exceptions of course like Depp v. Heard which wasn't trialed in the court of Virginia but really trialed in the court of public opinions and lots of lawyers thought Depp would loose.
Another exception to the high bar of winning libel/defamation case is Bollea v. Gawker - which Peter Thiel has enough deep pocket to literally bankrupted Gawker media.
Otherwise, stay truth state facts in reviews, you should be fine for the most scenarios.
Blind is more fun as they have a habit of forcing you to use your work email for "verification". They let other people on Blind too, but conveniently use that as a reason to kick them off if they say anything controversial.
I’ve used it to gauge the industry many times, research companies a few times. I think I’ve only ever left feedback myself once, and it was positive.
But I never had an actual expectation of total privacy. I figure you could piece identities together based on the posting date alone, especially if it is negative
If you’re an engineer worth hiring, you know that this layer of anonymity is just to prevent it from showing up on your grandma’s linkedin feed; or in a more paranoid way, your vengeful ex-boss easily googling your comments.
If someone really wants to find you, of course they will. I take a bit of a riskier tack. I’m usually just me… we’ll see how it goes in the end
Can they, in pursuing legal options against their employees prove the employees correct?
As soon as you onboard employees, pressure then to leave Glassdoor reviews. Since they just started, they obviously approve, albeit ignorantly.
Create account on Glassdoor, and leave a review.
On. My. First. Day.
It did not bode well for the rest of my employment there.
I don't understand the logic of the judge here. If even the most true-to-fact negative review may result in spending more for recruiting. Did not they have to demonstrate that they had monetary losses specifically attributed to dishonest negative review?
In Australia it's been weaponised by politicians already: https://www.nytimes.com/2021/11/24/world/australia/defamatio...
Yes, both countries are places you can raise a family, start a business, walk down the street without getting shot (at least it's very, very unlikely) - you can watch anything (provided it hasn't been censored which has laxed over the years), but you really, really can't say what you want about anyone.
There's a very well-known security specialist who's sued multiple boutique, small-time consultancies and individuals for defamation of his character. He was called a charlatan. This is what it's like on a small-scale, you can't even talk about an individual at local conferences in case they're recorded, because you'll be taken to court (and have to spend 10's of thousands of dollars defending yourself).
I don't see anything out of the ordinary, and there are definitely some common threads amongst negative reviews.
Wouldn't they have to prove the allegations are false?
That's mostly a US thing. England and many former english colony countries have quite liberal (illiberal?) libel laws that puts the onus of the person making the claim to prove it's true.
>defamatory statement is presumed to be false, unless the defendant can prove its truth
I am not saying this is an example to such case but I don't see any other option. Other than perhaps suing glassdoor instead, would that do any good?
This got me to thinking, though. If Glassdoor and similar websites are unreliable, what are some other tactics for learning about the internal culture of a potential workplace? Play the long game and make friends at every company you might be interested in in the future?
competitors are surely celebrating this ruling. especially those who physically cannot put anonymous commenters at risk while somehow still turning a profit without being able to traffic in tracking data.
It's quite easy to create a throwaway email and send your review from a public wi-fi.
Most people use Blockchain through established services such as Coinbase -- Coinbase, and most other legitimate services like this must comply with KYC rules. So instead of suing "a blockchain", they'd demand the identity of the wallet holder from Coinbase.
I can't see how going to a blockchain resolves any of these issues, but perhaps you could elaborate?
Source
A decentralized historical record, of any kind or quality, is something of dreams...
For a fee, of course :)
That CPO soon moved on.
The best solution is to have zero knowledge (delete all info that can identify a user), but the second best thing is to have double logs. A real one (internal use only) and a false one (for legal usage only). I know it goes against the moral/legal sense, but hey we're living in strange times and the best thing is not to go against multi bilion companies that can force you to do anything they want.
Who from the court or Zuru (or any other "bad" company) can say if the reviews by bill brown with IP 123.124.125.126 or john james with IP 132.133.134.135 are real or not ;-)
You're employer had a cakewalk seeing what you were posting if you did it from the office. :/
… and it never occurred to me for even a moment that any user of Glassdoor provided personally identifiable details … why would anyone do this ?
Related:
Where can I see the op ? Blog says they are scared to repost it but I’m not.
Where can I see the “offending” material ?
I wish it weren't so, but I'm afraid that will be the reality of it.
This would still generally allow anonymity.
Of course you could also have anonymity on a traditional platform by not requiring people to sign in with usernames but use a private key instead. So just use that part of web3 but no blockchain storage.
Answer: they don't.
If it's a big enough problem, it's noticed and addressed.
Could they theoretically not just play hardball, ignore the NZ courts entirely on the basis that they have no legal entity within NZ, and see what happens? Are there cross-border legal agreements that give the NZ courts any teeth? Or would it come down to NZ having to mandate that all ISPs block Glassdoor within NZ?
Zuru is suing in CA to compel glassdoor to produce information.
Zuru is not suing glassdoor for breaking NZ law in CA. That would make this case go away very quickly.
Instead, Zuru is saying they intend to sue NZ individuals in NZ, but in order to sue, they need info from US based glassdoor.
there may be some kind of cross border agreement to facilitate information between NZ and US. Politics aside, i dont know if a US company could be compelled by a US court to produce information to sue chinese or russian citizens, under those respective laws/jurisdictions?
I am sure there is some form of cross-border agreement between NZ and the US, but I don't know any details about it.
So yeah…Screw that person but also screw glassdoor for facilitating their narrative.
I agree moderation is key. They were so restrictive on amending the review in any way that it STILL exists. It’s been toned down somewhat, but the current moderation is a joke.
If they don't violate NDAs and the allegations aren't true, why shouldn't they be able to?
Finally, if Glassdoor is anonymous, why would they have any records of anyone who posts a review? If you want to claim some content has an anonymous author, you, the company hosting the content, cannot have any ability to identify the author. Otherwise all this "anonymous" info is a hack, malicious employee, or lawsuit away from no longer being anonymous.