How companies like Amazon and JPMorgan spy on their staff
businessinsider.com
businessinsider.com
Further, I don't put any personal accounts on employer provided hardware. For example, I always use a dedicated GitHub account for work stuff and the key and password never leave that machine. This ensures a clean break when I'm no longer at that employer.
Vlan is a good idea. Doing that now. Thanks.
I read a post on Reddit a few months back saying that everybody's body language in the office was being fed into a machine learning algorithm to analyse their emotions and stress levels to feed it back to their managers. Which is complete horseshit. They also said that everybody's laptop camera was being used to scan the surroundings for evidence of alcohol/drug use. Again, totally nuts.
I have to point out that a lot of people were hired when companies were still saying "as long as your team/organization is ok with working remotely, you don't need to come in office" until they completely changed their mind.
I’ve spent too much time doing analytics to believe stuff like this. The report is in CSV and there’s a comma in one of the fields on line 48,329 which caused the ready of the feed to be silently discarded.
Obviously, it is a device that's not yours and the company can do all kinds of things such as installing rootkits and other things to do whatever, but putting that aside, short of that level of commitment, is anyone familiar with these kinds of programs and whether or not they indicate in some way (e.g. macOS-level indicators that some app is using the microphone/webcam).
I'm just curious if I have my work laptop in clamshell mode and it goes to sleep, to what extent is it not a 24/7 active bug? Maybe I should be shutting it down every single moment that I don't want to risk being spied on?
Is "sleeping" the macbook and closing it shut, enough? Is it low-level enough of a block, or can apps circumvent even that?
I'm specifically putting aside Pegasus-level circumventions here, since then all bets are off. I'm just thinking about 'off-the-shelf' level apps that companies can license and use.
IT pros, stop and think for a moment about the risks. How long did that take you? Apparently the school administration and IT personnel completely overlooked them.
They were watching and photographing underage kids in their bedrooms, not that spying on anyone anywhere is ok. They thought they caught one with drugs (it was candy) in their bedroom and showed the images to the parents. The parents sued the school district and it was in national news (maybe on HN). Somehow I never saw child pornography charges, even though I don't know that they could have prevented it - just turn on the camera at the wrong time.
I blame the IT personnel too, especially the CIO / IT director who failed to point out the risk and stop it, and even the low-level people should have stopped when they first saw the inside of a teenager's bedroom.
Edit: as an example https://pickorchard.com/deploy-crowdstrike-with-jamf/
>Michael and Holly Robbins of Penn Valley, Pa., said they first found out about the alleged spying last November after their son Blake was accused by a Harriton High School official of "improper behavior in his home" and shown a photograph taken by his laptop.
For Apple silicon-based (and newer Intel-based), yes: https://support.apple.com/guide/security/hardware-microphone...
Not only is this a huge potential privacy issue, it's extremely annoying, because on many bluetooth headphones, it makes it impossible to, say, connect your phone to the headphones.
The issue with remaining on wifi is also extremely annoying if you're connected to a hotspot device. I discovered well into a vacation that my macbook was remaining connected to a hotspot and using up data - despite both "low data mode" (which has a penchant for magically turning itself off) and "wake for network access" set to never.
There was an option to disable allowing a bluetooth device to "wake" the system, which stops the mac from keeping bluetooth connections active during sleep, but that was removed in Catalina.
There's no excuse for removal of such an option, nor is there any excuse for not setting some logic such that only keyboards and mice retain active bluetooth connections.
The dumbification of MacOS marches on, as some anonymous mid-tier executive at Apple continues his or her mission to turn MacOS into iOS. We also lost wifi network priority a couple releases ago as well - a move that is so unfathomably stupid it defies belief. You used to be able to set a hotspot as high priority and then, say, a cafe's free (and far less secure) wifi network as a lower priority, and when you wanted to do something on the hotspot, you could just turn it on, and your mac would prefer that network. Now it's a roll of the dice at best.
When you're fired for saying something derogatory about your employer that is picked up by your company-issued computer sitting in your home office, do you have the resources to fight them in court, especially given your employer's law firm almost certainly has a cozy relationship with the judiciary in your area?
But there's a key difference. If employers want to track what time you're on the company laptop or if it's connecting from an IP address in the location you claim to be working from, that's legal. Monitoring nominally mic-off personal conversations isn't.
Actual productivity is not something they want to measure here, what they want is control.
This doesn't seem to be a logical conclusion. When you hire someone, do you care more about what they are delivering for you or do you just get some weird kicks?
Similarly if you actually cared about productivity you would never consider any kind of open or semi-open plan office, yet these are exactly the companies that do just that.
They think, “oh if you have 10 mins for doing the laundry during a work day, if you come into the office you won’t be doing that in office and perhaps use that 10 mins everyday to produce some additional non-zero value to the company”.
In their minds those 10-15 mins from everyone add up. I am not agreeing but that is what it seems to me.
2. To reiterate, I agree :-)
3. That being said, the only places where I've seen it actually used is where an employee is fired for a cause, fights it, and then company retrieves logs and hammers them with proof.
4. But still I agree - it's a nasty sleezy slippery path. I am a manager of people and managers and have zero desire for anything like that.
Oh geez. That tells me that less than 30 seconds of thought was put into that line in the policy. Surely, there are PTO days, sick days, business travel days, and other reasons to have that figure show as less than 60%.
Said differently, if it was 2019 and the team policy is 5 days a week, does HR imagine that figure would be 100%?
If work can only happen in the office at prescribed time, then work only happens then. If you waste your time and money forcing people to work in a shitty and distraction filled environment and then why should they be interested in donating their time to help you compensate for poor management.
MalwareBytes keeps a small structure in memory for every file it found during a scan. Sadly my computer had files on it and ran out of RAM.
SentinelOne's filtering scaled like linear search so as the ignore list got longer everything got slower.
If you recall, at the end of 2022 into 2023, Apple laptops and iPhones suffered from a series of webkit vulnerabilities which allowed root access.
Were these vulnerabilities repeatedly exploited by companies such as Amazon? Yes.
On personal, non-work devices? Yes.
Is this a gross (and federally illegal) misstep by Amazon, JPMorgan, and similar companies? Yes.
There are limits to everything, but for finservs, there's a reason why they do these things.
Source: I am/was infosec at JPMC and other large finservs.
How does this relate to your situation? And why have you been unemployed for a decade? Most of the time, interaction with HR is super minimal, so I don’t see how this would prevent you from being employed anywhere.
The HR people were comically evil and it was a useful learning experience. Those guys would burn the building down to “beat” the union over some bullshit issue.
Without a contract and a counter-party they usually deploy a more banal evil that feels more like incompetence. But when the chips are down, they’ll gleefully bone you.
I take your point though that you're saying some laws require explicitly enumerating them (from how I understood your comment).