Yet I just can’t stop to imagine the other side’s perspective and it’s making me laugh:
I’m sitting in front of the monitoring dashboard, chewing a sandwich, and then a spike of intranet activity shows on one of the charts. I look at the dashboard and immediately notice that it’s effect of some SMS broadcast. Nothing to see here: lazy Tuesday.
Then on the dashboard with user agents new column shows. 1 request. Curl’s user agent sticks out like a sore thumb.
“Oh, someone probably just copy & pasted contents of the text message to check it out through curl in order to be safe” wouldn’t take place in Top 10 thoughts that’d I have after seeing that.
What I end up thinking about is that even though I'm back at the office full time (and I'm one of the weirdos that actually prefer it) I have doctors appointments, school teacher meetings and such that have all moved online. So convenient!, except there's no way I can realistically attend them privately, so a 5 minute meds appointment is now once again a 3 hour travel ordeal.
End-to-End encryption doesn't matter if your employer is scraping your device. I know this is all obvious, but it didn't need to be this way.
You may have been caught in one of those exercises.
But anyway, always assume your workplace's VPN logs every access. The obvious retention period vary from one place to another, but the logs seem to always exist.
Outside of that, I keep my use very benign. I'm logged into the Financial Times and Stackoverflow. Most companies with knowledge workers won't look at any metrics they collect unless it's a security thing or they have a reason to look. But yes, assume that they can look if they want to.
Once they start snooping around, they're probably going to fire you regardless. They just need a story to tell.
I dick around all day at work, I watched YouTube video in the background, I still use paper notes so my cursor can be still for an hour sometimes, etc and I never received anything like that. That's over 4 employers since I went full time remote.
Not saying they're not "watching" me, but they don't seem to care.
Is there a typical profile for companies that go that far in the 1984 crazyness?
Context switches can really kill productivity. So much that sometimes I do much more work in a 2h window between 7am and 9am than the next 6-7 hours.
I'm not sure how much value there is in that kind of monitoring, but it isn't necessarily bad.
Is your phone personal? BYOD? Company-issued?
I can't fathom how "detecting curl" can put you in the doghouse, but I would shut you down too, for accessing malicious websites.
It seems misplaced to blame the company for surveillance when they're trying to keep everyone safe, including the devices in your home. It seems far more preferable to have a sting operation and catch mistakes, than to for-reals access malware and have it install on those same devices. That's exactly what they're trying to prevent and mitigate.
It would be the same whether you're at home on a personal device, or you're at your desk in the office with boss over shoulder. You would have a right to object to oppressive or intrusive company surveillance, but this doesn't even come close.
Of course, we have few details here, and I have leapt to a very particular conclusion about that situation; who knows what really happened. But in the interest of general knowledge, employees should be aware that phishing tests will be run, and you can expect to have a little chat if you fail the test (or actually get phished.)
Maybe your company isn't as bad as mine? If the test bypasses the spam filters and is correctly signed from an internal sender… what kind of idiot test is it?