I see this assumption that people are being sneaky by using company devices for private matters on HN quite frequently, but it really doesn't gel with my experience.
> I […] installed Asahi on my work Macbook for the simple reason that I don't want to do anything personal on the Mac OS partition
A laptop takes physical space that I am paying for, not the company, unless the company is paying some slim percentage of my rent.
Why does the company feel entitled to have me store its stuff? Theres a policy that you can't leave the laptop at the office.
I've seen security breaches happen, and it's not the self-motivated users who cause them. It's the casual users who leave their computer unlocked, or go on social media with the same one browser they're using for work, or who click links in email without checking the source.
this sounds like personal use, though. I do appreciate your perspective, and am sorry that your IT dept has no sense of security. Disallowing password managers and ad blockers honestly sounds like a good sign to gtfo and find a more competent org, or dig in and drive some serious change from the inside.
A proper corporate security is to never have a chance for some client device to compromise the security.
Asking "why do you feel entitled" is starting off on the wrong foot.
I think that’s the part I personally balk at a bit (and what I suspect GP was getting at), not necessarily the act of installing whatever you want on the device.
Mixing work and personal like that seems a priori a bad idea. In many cases, work can even seize your device from you for legal reasons. Yes, you can keep the personal activities separate on an encrypted partion and otherwise walled off from the work bits. But this all just limits some of the possible downsides and doesn’t make it a good idea.
Would you be comfortable letting Bob in Accounting use her own computer, the one she uses to do payroll for the whole company? The same Bob who clicks every link in every email and installs every executable possible. The same Bob who doesn't remember passwords and has the payroll system password on a post-it note next to his display and uses auto-login on his computer because typing the password every morning is too much of a hassle.
Or would you rather have some "corporate spyware" on there doing basic sanity checks for malware, weird access patterns, enforcing a password policy and automatic locking when idle?
The problem with these corporate spywares is that they're designed for the Bobs of the world and I do not consider myself a Bob. When my employer was implementing one of these management nannies to enforce password policies, it would've rejected my password because it didn't have a number in it. However, mine was significantly longer than the minimum, so my password has like 25% more entropy than the minimum mandated.
If my employer trusts me enough to let me set up new AWS environments and secure our production databases, maybe they could trust me to secure my work laptop too. Different courses for different horses.
I've been in situations where programmers are forced under the same rules as random office workers. Like no admin permissions on their own laptop. If you need to install something, you had to call IT and they'd give you an admin account that was active for 30 minutes or something.
It was extremely fun when I had to test multiple applications and had to do this process many times a day :D