Well... don't do that? Why would you ever have personal anything on a work computer?
Well... don't do that? Why would you ever have personal anything on a work computer?
(& then just rotate the credentials on it when you part ways with the employer.)
Some of my co-workers even do a Github account per employment.
I just don’t understand any rational otherwise.
So, would you care to more explicitly tell me what you think about my intelligence or ability to behave rationally compared to you? Or is there potentially some room for nuance here?
- people tend to use company devices for private stuff, even when its explicitly prohibited, - draconian policing leads to employee dissatisfaction; you won't be able to fire that great engineer you spent 3 months hiring because he logged in to Spotify running within Chrome, and if you can - and do - soon you will be unable to hire top talent,
Thus, even with those policies in place, end user devices still need to be considered un-trusted. Specifically, that they can be key-logged and remote accessed by the attackers.
Hence, (a) anything sensitive should involve transaction level validation, not just end user authentication, (b) for logging in an out, as well as for confirming sensitive operations, proper MFA needs to be in place (physical key + token on a mobile device, for instance), (c) apply lightweight, reasonable restrictions to reduce the chances of device compromise dramatically (e.g., no downloading of 3rd party apps or binaries - but do whitelist things like Skype or Spotify, force strong password for devices, etc).
This means reasonable personal use is perfectly fine, employees happy, and you are safer vs. assuming local devices are clean.
A more senior academic?
- Is the open-source software something that the company is sponsoring?
- If not, do you have permission to use company equipment for personal use?
> A more senior academic?
?
Do you do the above? If so, do you have a personal laptop? if yes, why utilize company property instead of personal, unless given permission to do so?
An example university policy [1]
> 11.5 reasonable personal use of College IT resources is permitted provided such use does not disrupt the conduct of College business or other users. Recreational use of the Halls of Residence network is also permitted, subject to these conditions;
We have a similar policy where I work. I have a personal laptop, but I don't take it to work. I am signed in to my personal GMail account on my work computer, along with many other accounts — like this HN account. If work needed to look at an employee's computer, we'd have someone from IT + someone from HR overseeing the process, and wouldn't look at anything clearly private, e.g. a personal email account. Doing otherwise would be a breach of the GDPR.
[1] https://www.imperial.ac.uk/admin-services/ict/self-service/c...
I'm sure there are plenty of people who have access to their company's private repos through their personal GitHub accounts.
No thanks. New account per job.
Involvement with private repositories is removed as soon as the organization removes the employee, or the employee removes themselves.
I think the horror stories could only happen if the individual's account has been used for generating many API keys or similar, but there are other reasons not to rely on that sort of thing.
Even if a tiny risk, it seems silly just to bolster the GH activity graph.
I think this is fairly common for people who work on open source projects.