Figure out who's leaving the company: dump, diff, repeat
rachelbythebay.com
rachelbythebay.com
As a dumb script it was not designed to be especially flexible. One thing I remember needing to fix was that by its nature it was archiving old data and preserving it, which meant that it was accidentally deadnaming trans people. My recollection is this was a small code fix, but an interesting lesson in social consequences of oblivious software.
Were you ever made change it by HR?
I left 5 years ago. Loved that thing!
We had the occasional HR interaction but to my recollection never anything nasty.
That's what I did. That said, I can't double-check to see if it worked. :)
Thanks for the tool, Evan!
Well, you can update Epitaphs and add a link to "go/laurentlb". Thanks!
You can have your cron do something like this:
curl https://internal.corp/employees.txt > employees.txt
git add employees.txt
git commit -m "Automated: $(date -u)" || exit 0
The || exit 0 should ensure no errors even if there is nothing to commitNow you have a commit history of every change made to that source of information - just run "git log" to view it.
I run this kind of thing on scheduled GitHub Actions all the time, see https://simonwillison.net/2020/Oct/9/git-scraping/
The other problem is that I sorta want transactional-database features on top of these things. Git does this well. I also want fast indexing on parts. Git does not do this well. I am considering writing a "standard" for the dumping of sqlite to git, so that I can just delegate this out; Any transaction can be expressed as a git commit, and I can run both at once for both the durability and the reasonable indexing; The sqlite database can be re-created and reindexed whenever, and it also sorta works for backups...
Definitely just spinning my wheels, though. We'll see where databases take us next.
https://docs.dolthub.com/sql-reference/version-control/dolt-...
Somewhat git-compatible, based on sqlite3.
I have a cron script stashing whatever is currently in an obsidian vault into a fossil repo. There's a fossil addremove command that makes that very easy. Thus distributed backups of said vault.
I would say git core concepts are pretty similar to fossil concepts, but actual plumbing implementation details are pretty distinct.
The major difference that I remember from a day-to-day "git porcelain" perspective is that rebases and other types of history rewriting are very discouraged.
For a Rosetta stone of somewhat comparable commands: https://fossil-scm.org/home/doc/trunk/www/gitusers.md
> Can it sometimes use existing git repos
You can, but it's kinda a lot of really slow busywork. And you lose some of the not-file-dvcs features of Fossil, but it is possible.
This page explains how: https://www.fossil-scm.org/home/doc/trunk/www/mirrortogithub...
I've been working on a tool that treats the git repo as the SSOT then lets you dump out all kinds of formats for data work including a sqlite DB. I haven't had as much time as I would like on it but it's at https://pypi.org/project/DataTig/
I think you're referring to SCDs, and there are plenty of well-defined ways to track these within relational databases:
https://en.wikipedia.org/wiki/Slowly_changing_dimension
Why git?
if git is-there-anything-to-commit; then git commit ...; fi
'is-there-anything-to-commit' is aliased to '! [ -n "$(git status -s --porcelain --untracked-files=no)" ]'I noted in the readme..
Know what's going on in your LDAP directory on-demand with Slack webhook integration.
See new hires, leavers, and promotions as they appear in LDAP.
Monitor when and what HR is doing.
Detect unauthorized changes in LDAP.
Monitor for accidentally leaked data.
Detect when users are logging in and out of LDAP.
There's also LDAPmonitor[1] which is designed for Microsoft and Active Directory which does effectively the same thing.You could get closure.
Now, one day a bunch of people just stop replying to email. You have a to wait a while to figure out if they are actually gone or just busy. And if you're waiting on them for some output to work on your project, they may just never deliver and you won't know why for a while.
The company directory, if there is one, often still shows them for 60+ days because of the WARN act. And it seems most companies won't make a "layoff list".
It's really hard to get closure if they won't even tell you who got let go, and if they don't give the people a chance to say goodbye by cutting off their access before telling them they are laid off.
So weird companies can’t just pay that out as severance
But since you technically have to be "on the books", if something like Slack is tied to your status in the company directory, it's easier to just leave it.
The WARN period exists to give you the money, but also keep you on for insurance and 401k vesting purposes (and similar). Getting cut off immediately, and suddenly losing insurance would be much much more disruptive, even with COBRA.
I happened to remember the total number of people who were in our org’s giant slack channel before the layoffs and thus was able to do some hardcore detective work subtracting the new number of people in the channel from the previous amount to get the answer…
Others colleagues would also usually organise a virtual envelope with money inside to wish you farewell.
I find it hard to imagine you have no such contact at all, or that you would say nothing in those meets. You are planning work every now and then, aren't you?
In the past, I've tried to give key people on longer-term projects I'm working on a heads-up. But I trusted them and it was longer-term. At the end of the day, I'm not going to let the word out before I'm ready if I'm worried it has the potential to bite me financially, e.g. because of vesting.
Simply shut down, just like a service or API that got deprecated. It is a weird experience, if you happen to know these leaving people only by email.
But we were seeing the list of deactivated slack accounts crop up slowly anyway.
May depend on your job market, but it’s a pretty normal tactic for a lot of people I know.
well.... yes? HR considering you "at risk" is a pretty good thing :)
For close colleagues leaving, WFH makes absolutely no difference though. Those you keep track of regardless.
The most toxic boss I ever worked for would request access to former employee’s Slack accounts under the guise of looking for data to transition their job. Their accounts would periodically go green when he logged in as them. Spooky to see ex-coworker accounts go green and know the boss is scouring their private messages.
I know companies can get slack messages anyway, but seeing your boss do it in real time is extra creepy.
They're different parts of speech from the same root word, after all.
The word "private" means "having privacy" in the normal, everyday sense. Using that word to describe something that isn't private is lying. You and I both know there do exist many people who suffered consequences for not understanding the definition of that word.
In my opinion, the ethical thing to do is to use a different word when no expectation of privacy applies. And the upside is powerful: transparency gains trust.
Slack did this well: they call them "direct messages".
If you need privacy, use your personal phone (and don't connect it to the company wifi)
Granted, some of these ways might be legal or not depending on jurisdiction, but then lots of company will thread or cross the legal fine line if they are happy with the risk/benefit trade off.
Second, what you said is just plain wrong in at least one. In France (which is known for strict worker protections) the employer can go through any employee's mailbox or files on their work computer/account provided 1. that the messages/files in question aren't clearly marked as personal 2. that the conditions for the access are laid down in advance with proper notice. When an employee is let go, they need to be given time to empty their mailboxes etc of private correspondence or files. https://www.cnil.fr/fr/lacces-la-messagerie-dun-salarie-en-s...
You might be right that it’s not illegal, but it would be nice to have those kinds of protections. Trying to talk to anyone at work in the WFH era is a field of landmines, because you never know at any given time whether what you say will make it back to the person you’re discussing. Discussions like that are a normal and healthy part of socializing with coworkers, and it happens at every company. Except in the WFH era everything you’ve typed is a permanent record, whereas previously you’d be able to say something to a coworker without worrying that someone else will someday hear it.
But, it’s a new era. It’s easy to adjust. Just don’t get personal at work. It sucks, but work is designed to suck, or else it wouldn’t be work.
Anyone thought otherwise?
Private != personal. At least I never ever imagined one could even assume DMs on work IM are personal private conversations. They're organizationally grouped as chat between to accounts, as opposed to group chat, but they're at work, for work, using work-provided tools...
Or put another way: why would anyone consider work Slack to be different in this regard than company e-mail? Much like with e-mails, the difference between DMs and group chats is whether the number of participants is > 2.
You’re right of course. I just wish we had something to fill the void that was left by in-person interactions vanishing. I think I’ll be doing WFH pretty much the rest of my life, and I absolutely hate going into an office in general, but there are definitely some aspects I miss. Being able to chat off the record with a coworker is one of them.
Unless all calls are transcribed and recorded, it’s pretty “watercoolerish”.
First of all, they'll tell you that even the most junior helpdesk workers can remote onto your machine, reset your password, disable your 2FA, and monitor all your web browsing and chat history.
Second of all, that this unannounced product, this not-yet-filed patent, this big planned layoff, this prospective hire background check result, these upcoming financial results, this employee's reason for needing medical leave, this pentest result document, and this forthcoming change to pricing are Strictly Confidential. You shouldn't discuss them even with your own boss, unless you've first confirmed they're on the need-to-know list, and that certainly doesn't include level 1 helpdesk workers.
Most large companies, to address this contradiction, will say access is possible but rarely used, tightly controlled and carefully audited.
1) people think that anything sent on an employer system isn’t visible to the employer
2) people send private DMs from work accounts
Senior leaders tend to skirt this by using the telephone or video calls predominantly. However the infiltration of machine learning and AI means transcripts of calls, etc are now possible too.
In addition, the growing use of "disappearing" messages despite litigation holds has come up in more legal cases recently.
> However, since France is in E.U. what you describe should be illegal.
What's the regulation or directive you're talking about?
Correct, but it does have a single ECHR. Even though some countries still ignore them.
The patchwork of national laws and national interpretations of EU regulations is quite interesting, and rather confusing especially if you do offensive security work or DFIR.
As an example, when doing consultancy we would do the usual phishing as part of an assessment. Usually this is followed by dumping the users mailboxes to look for further credentials/access to corporate resources (eg: are they emailing passwords around?) - but in some countries such as Germany that’s often explicitly ruled out due to fear of breaching privacy regulations.
Not really, ECHR has already ruled on this.
It's pretty much only allowed if there's an important reason for it. For example, to recover something invaluable (contract, code, report) that isn't available somewhere else and cannot be replaced. In that case that's also the only thing that them employer can look for. They can't open obviously unrelated e-mails. So before talking to legal, make sure you have a valid reason.
That is valid for Germany.
However, if a company does find an unrelated e-mail they want to use against you (which is what most people fear), that makes them liable.
"We wish you well on your departure; as you embark on new adventures your about to open your eyes for the first time.
This may be a shock to some of you as you may discover that the world is more dystopian than you've may of seen from your altered reality mind-implants.
We would like to thank you for your service as a tool at the corporation."
As long as it doesn't read like stereo instructions ....
time to just acknowledge that its an overly long arduous convoluted setup that can be vastly simplified for the message it creates
More than one for me.
Learned that Office 365 now has a “login as” for email which is convenient for setting out of office, deleting calendar invites, or email snooping.
The new dystopia will be when an LLM steps in to reply like them.
WFH feels so sterile and impersonal in comparison.
I've been WFH since 2015 or so, so this isn't a RTO endorsement, just reminiscing.
I don't miss it enough to want to go back to an office though!
So given that outlook, WFH seems just kind of more “pure.” It’s distilled work, unencumbered by phony pseudo-friendships and awkward water cooler chit chat about sportsball. When we start a zoom meeting I can just launch right into the agenda without having to do that offtopic pre-meeting banter ritual. To me it’s work without waste. I feel like with WFH I get more done per hour and that means more time for me to do what I enjoy: things that aren’t work.
Additionally, my colleagues and I share big parts of our life: every damn workday. None of my friends are capable of talking as long and nuanced about things happening at my workplace. They don't really want to hear emotional rants about bullshit projects because they have no way to relate to those feelings.
But I want to rant about bullshit projects and thankfully, I have colleagues that like hearing such rants from time to time, as they totally can relate. When I am mad about some shit, start talking about it and they ask "oh, was that XY who said that?" and it totally was XY, that is comforting.
I have friends, yes, and I don't need to meet my colleagues after work. But I still have healthy social relationships to them.
I talk to my friends during the day. I'm lucky that we're all remote, but honestly even my in office family members can chat sometimes at work.
When I was in the office, I rarely connected with coworkers. I was often the youngest and/or just not in the same life stage. I could exchange pleasantries and that was about it. I have a grand total of 2 friends from work after over a decade of work across several companies. My social life is still vibrant outside of that.
I don't even understand where people think you can't connect to peolle WTH. I just had an hour long chat with a coworker about nothing at all. Sometimes people just need to chat about nonsense and VC people. Peoppe seem to be afraid of that, but I don't see why. We can work and talk. We did it in the office.
That's not what we see in practice. Most people with a sudden windfall (stocks, lottery winnings etc.) keeps showing up for work. Because how else would you stay socially meaningful in our society? Nobody really wants to sit at a beach sipping drinks the rest of their life, accomplishing nothing.
There is clearly a social aspect of work, at least for the majority that we can call socially functional. And it's at least as important as getting paid. Work is also a social role, and it hurts many people if they are left out of it. It's not easy.
Yes. Absolutely 100% I am looking forward to it and counting down the days.
It forces people into a thought experiment on what they would do if they didn't have to work.
Speak for yourself.
At a previous employment (a 100% WFH position) I had most of my colleagues in India, roughly 4 time zones away from my own so we almost never met in person, and we'd have personal chit chat sessions while working.
Then I've worked with people who weren't present even when you were sitting right next to them. They'd come into the office, say "morning", put on their noise cancelling head phones and be gone for the rest of the day (modern open space office life in a nut shell).
In-person I tend to be a little more no-nonsense, whereas over video calls I'm sitting comfortably at home with a cat in my lap, already relaxed and much less uptight as an emotional starting point.
Indeed nowadays I have seen many articles publishing that it is even more prominent idea with Zoomers entering workforce and have a clear boundary between co-workers and personal outside-work friends. The companies actually do not like this because this means that those people have literally 0 loyalty to the company and only care for the money. Which is shocking, I know. \s
In the beginning of the pandemic, we even switched to cooking at the office kitchen. Now there are only 2 people left on the floor, and eating lunch has stopped completely. Most of my colleagues I only see 1 or 2 times a year (Christmas party and work stuff that requires physical attention).
I noticed that it is much harder now for people to integrate when they are new. There is no real forum left for beginners to ask dumb questions they would rather not see in some chat log.
But I do miss lunches. Even the loud, obnoxious people are much more tolerable in that context.
this is a key point; employees who have been together a long time can easily switch over to maintaining that same level of connection while WFH (I've experienced that). But it's very hard for a "new guy" to integrate if s/he has never interacted, or only occasionally, with their coworkers in person.
That "back in the day" algorithm required an office that emphasized butt-in-seat, lacked flexible working hours, and lacked both personal offices and multiple exit points.
If I trusted them for the 3 years they worked for me, I can trust them for another week or two.
Tie up loose ends, take your time. We're all adults here.
I understand that under the worst circumstances bad things can happen but that's always the case.
Then one designer put in his two weeks and spent the majority of the time downloading all the site files for all of the sites the company had built over the two years he was there. We're talking hundreds of static sites where he took the all the design docs and static HTML/CSS/JS files one would need to recreate them somewhere else.
Instead of going after the guy legally, they passed and then instituted the same policy. You put in your two weeks? Nah, you're out the moment you hit send on that email. Manager alerts security, who then come over to your desk. You get your jacket and whatever you walked in with and get walked out. The one designer totally ruined the company from ever letting someone stay for their two weeks.
It could have been unannounced and they just stop showing up.
You either trust your people or you don't. If you don't, get rid of them and lock them out. If you do and you still have to let them go then don't worry about it.
People are far too inhuman in professional relationships and I strongly dislike that tendency. You likely spend as much time with your colleagues as your spouse, make it a real connection.
If you can't meet that use keycards instead of keys, voip instead of real phones, lock file cabinets, I mean go all the way.
Corporate America loves pretending. Pretending you're part of the family and then treating you like you're trying to rob the place at the drop of a hat.
That's the messed up thing. Be consistent and don't be fake. People can deal with you for being overly formal and paranoid but probably not for being a phony backstabber, that's how you grow haters.
The hardest thing for a brand to shake off is a bad reputation, whether they justly deserved it or not. You don't want haters in the Internet age.
Yes, most reasonable adults remain reasonable even after fired
But once you hire a thousand, ten thousand, a hundred thousand people… statistically there are gonna be some wackos you didn’t filter out!
It’s tough. I agree that treating each other like humans is the best policy.
Also if you want to work with the people you like again but need to actually downsize because of external pressure, good luck trying to get them to come work for you at your next venture after some fucked up bridge burning ceremony.
The only thing that that accomplishes is that people don't put any notice.
No, it's the over-reaction by whoever instituted that policy that ruined the company. They should've cut their losses and ignore the outlier, perhaps make it tad more difficult to copy off data en masse without being noticed, and/or do many other things addressing this risk without ruining the workplace for everyone else.
This is the organizational equivalent of autoimmune disease. Works at every scale. On national/international scale, this is what terrorist organizations are exploiting - do an X amount of damage that may even be counterproductive to their goal, and watch the victim do 1000X damage to itself by overreaction.
This will work for the first 5-10-20 people, then word of mouth goes out about this policy and your evil designer is downloading everything the day before sending their resignation mail.
Though with sales orgs I think this is almost an expected practice - sales people are often hired on the tactit, never officially acknowledged basis that they will bring their leads list.
maybe the phone number too
You make it sound like he poached your clients or extorted your company. As they didn't go after him legally, I assume that didn't happen.
I assume all the files are on a thumb drive in his drawer, unopened, just in case he wants to remember how "that cool animation" was implemented. And when that moment comes, he will not find the thumb drive, anyway.
And all that security charade will accomplish is that people who care enough about their work, will make a copy the day before they quit. Congratulations, your policy achieved nothing, except get rid of their two weeks notice and everyone feel a bit worse working for you.
It feels like if an employee did this with modern projects, they would at the very least be summarily fired, if not have legal action taken against them.
1984 is so appealing for so many people, it seems like it is just a book about the tendencies that power can take when it is not guided by sane principles. I have always been employed in a high trust capacity since I was a young adult, there is not a technically feasible system in the world that could prevent me from wrecking havoc in a company. Social ones though, they are extremely effective.
All the DLPs rely on, effectively, regular expression searches of traffic.
This is fine if what you need to protect are SSNs, phone numbers, credit card numbers... but if your data is not easily recognized that way, they don't work.
If you ask the DLP vendors about their threat model -- and the salespeople generally don't know what a threat model is -- it's always a set of stories about a salesperson who clicks the download-as-CSV button on a CRM system, a DB reporting specialist who generates a report full of raw passwords and credit card numbers, and an off-shore programmer who sends AWS credentials via email.
Hopefully you can spot the non-DLP prevention mechanisms for all of these...
What is it?
https://www.cnbc.com/amp/2020/08/04/anthony-levandowski-gets...
Sure, they can't do any of that, and development becomes miserable. You don't have to go full VM and remote desktop to prevent those things.
Basically the machine is not allowed to access the internet and USB drives do not work. Only specific locked down applications like the email app, web browser, and so forth have internet access. Downloads are allowed but uploads are not.
A permissions interface is available for say legitimate transfers of data to a flash drive or a web upload, in that case the user will have to add a valid reason and the specific files into the form. Once that's checked and approved by a higher-up the files are temporarily placed in a special folder that permits transfer out. The same thing goes for external emails that aren't on a whitelist, they'll need approval before they get sent.
What VMs are helpful for is cross-contamination and spyware attacks from other clients a contractor is working for.
If someone is fired for cause then they go immediately, but if they are given notice then they are usually trusted with access, and it rarely goes wrong.
Stealing IP is rare because it's hard to benefit from it. If stolen IP is offered to another company, usually they report it to the owner to cover their backs legally. Funders are not going to want to invest in a company that is based on stolen IP, where their investment can become worthless overnight.
So I think these stories about how 'we have to treat employees like they are potential criminals' (not accusing parent of that, but you hear them) are bugos. Treating people like human beings is both right and economically efficient.
At least five times I can say I had no idea someone had been laid off or sacked until weeks later. I just assumed they were on PTO or something, and then in the middle of a meeting, I'd say something like, "Yeah, where's James been, I haven't seen him online for a few weeks now." Then the manager would chime in and say they got laid off or let go several weeks ago and they were waiting to announce it to everybody.
Twice my director had a meeting with the team and forgot to include myself and two other devs to announce someone had been let go - which is scary AF when we're all on Teams wondering why they just randomly left us off the meeting, which then made us all paranoid AF for a few weeks.
The whole process with laying people off or people getting sacked has just been handled in such a ham handed way, it doesn't inspire confidence at all, and people are constantly looking over their shoulder when a team loses people and have to pick up the slack immediately.
This time around, the laid off people show up as on vacation. If you see a team of people all on PTO until the end of May, you can presume that team is donezo.
It's not good practice for all situations -- you need some trust, despite the stressful situation, when people tend to show character and weaknesses -- but in this case, it worked out.
The departing employee posted a message of encouragement to the remaining people.
Kind words and contact info were exchanged, etc.
The company letting a manager relay a message, with any censoring, is certainly better than the person having no way to get their contact info to people, and they might also say something nice for morale.
My suggestion was meant as something that's feasible even for a company that already got burned by vengeful leavers; and also something that an individual manager has an easier chance of pulling off, without having to change all of corporate policy.
I told them that I really wanted to finish the work for a customer (large state organization) because I liked the customer. They let me stay for a week.
Of course that was bullshit, I took the time to have back channel communications with the customer to see if they would hire me as an independent consultant after I left and to start interviewing.
I’m sure they would have. But I gor a full time offer less than two weeks later.
I knew after the first year that I didn’t plan on stay at Amazon for more than four years and I planned accordingly.
I was nine months and two vesting periods short. But the severance more than made up for one.
The longer version of the story.
What is the wonderful closure you get?
Anyway, welcome to the corporate world. It pretends to be personal, but it's business.
> Anyway, welcome to the corporate world.
I've been in the corporate world for 27 years, and been through many layoffs (usually as a survivor, sometimes as a victim). The ones during WFH have all been worse.
Our General Counsel and I met for the last time during the early months of the pandemic. Like most people during the shutdown, he hadn't seen anyone outside his immediate family or had a chance to tell a good story in a few months, which would have eventually killed him, anyway, and I got an earful as he unloaded all the work he was wrapping up. After, as lawyers excel at, he wrote a great letter to our CIO about it that led to probably my favorite exchange between us.
Six months later, someone called me to say they were headed to Legal because someone had died, and I was struck by an immediate sense of dread. I searched our website for any word, then our directory, and then for local obits and found nothing. Even the grapevine was silent, so I called his admin who pretty casually told me our GC had died six weeks prior.
Almost a year to the day later, the mechanisms caught up, and the org put out a "Remembering $generalCounselor". By then, we'd missed his funeral, his family had relocated, and many felt awkward trying to send condolences so late. Watching other's surprise, shame, and sadness wasn't reassuring, even if it told me I wasn't the only one.
We're not small, but we're personal, and each death has left a little void that we collectively haven't acknowledged or addressed. We still don't have a way to handle the losses and haven't talked about it. Having old saved contacts pop up after their extensions are reassigned is inevitably like a call from the grave. I try to keep in touch to keep track, but little by little, the connections are fading, and the memory and history of us with them.
Truly sorry for your collective loss, but where/what industry did you work in where this was a significant number?
Think, a city, and it swept through us like it did the hospitals and nursing homes.
Another large company I worked for sent out random meeting with the CIO, if you got the meeting you were laid off. At least the CIO did it himself.
That's cool, I've never seen anyone that worked in a 90's movie before!
Seriously, though, is that a thing? Was it ever?
I can imagine myself bringing it all in a handy box if I were suddenly fired (which is impossible in my country of residence, but it’s about the idea)
"Incidentally, if someone gets mad about you running this sort of thing, you probably don't want to work there anyway. On the other hand, if you're able to build such tools without IT or similar getting "threatened" by it, then you might be somewhere that actually enjoys creating interesting and useful stuff. Treasure such places. They don't tend to last."
I can certainly see many European businesses would be wary of an employee keeping this list.
They don't need to be a citizen, they don't need to have any sort of contractual arrangement with the data processor. If they're alive and identifiable, the GDPR applies.
>This Regulation does not apply to the personal data of deceased persons. Member States may provide for rules regarding the processing of personal data of deceased persons.
It's not part of the operative text of the regulation, but it provides for a clarification on what a "natural person" is, and the principal prohibition in the regulation is the processing of data about an identified or identifiable natural person.
I would also assume, but I'm not 100% sure, that there's some case law from the CJEU around whether or not the definition of "natural person" includes dead people, which is why it's not in the main body of the text.
One of the most important rules in GDPR is the requirement for companies to have an up to date list of all places where personal data is being stored, the reason it's stored there and what it's used for and the retention policy.
So an employee creating their own lists of previous employees could potentially get the company in trouble if it was discovered during some external audit if it wasn't listed.
Here’s what is crazy to me about employee PII (personally identifiable information) being considered sensitive.
Say in a well designed system you can audit who made each change or the last change to each business record. As an example, each database table has a login ID of who modified the last record/row most recently.
Now every single such table is polluted with PII?
I get having a list of all the places where personal data is stored, but some people think we need a list of all the places a pointer to personal data is stored (ie an identifier that enables linking; that is what “PII” literally means) and that is just such a bigger dataset I don’t think it is appreciated how deep the rabbit trail goes applying policy to technology.
Every email in an organization contains PII and every system emails can get saved and attached to.
Back to your comment, does GDPR require just listing the personal information locations, or also the (PII) identifiers to it? Is a name alone considered personal information (if I sign my emails with my name does that go on the list and if so, can companies just declare huge subsystems as having personal information?)
A business probably handles sensitive private data on employees (e.g. medical conditions, family records). Employees know this, and could report an ex-employer out of spite, especially if they're aware of poor data security.
What Rachel is describing is absolutely illegal under the GDPR.
If you do want to work there, though, maybe check the legal situation first...
I am almost certain, this counts as unauthorized processing of personal information. Just because you have access doesn't mean it's fair game to do whatever you like with it. Especially archiving, keeping a history or linking (external) data is not the intended use for such an interface. If you take the information home with you, e.g. on your work laptop, that may be a whole nother can of worms. May even count as business secrets you're exfiltrating.
At least in Europe, abusing such an interface likely would be illegal, certainly if you keep a copy/diff. Your employer may have to act against you, or become liable. Or they may use this misconduct later to conveniently terminate your contract (lol, especially, if you use your insights as leverage).
I presume the larger the network, the more likely this will get you in trouble. Conversely, collecting the data has little use otherwise.
How about you organize with your colleagues to voluntarily share employment information to gain collective leverage?
[LIVE]->[DIFF_N]->[DIFF_N-1]->...->[DIFF_1]=[LIVE_1]
You know, that's kinda how Git works.
Yes, if it contains employment information. A bunch of diffs can cross the threshold into event sourcing and if you have enough of them you might end up with a copy of the directory.
In jurisdictions where people have the right to be forgotten, they could ask for all their information to be erased. How would that work if you keep a copy of the employee directory? That is one example.
Another example would be a proposed bill in my jurisdiction which will force employers to disclose all information it stores about employees at the request of any employee. This will make you (someone who has a copy of the employee directory) some sort of data processor, which comes with new requirements about how you store that data and for how long.
As someone else said somewhere in this thread, if you can see information, this does not automatically mean that you can store it.
With your argument you are conflating intellectual property and business assets of your company, with privacy and informational self-determination of your colleagues. The latter isn't necessarily in the direct interest of your employer, but rather a right given by ethics, or governmental entities. Never mind metadata, a simple copy could mean transferring sensible information to a context where access control for unauthorized parties isn't implemented. Eg. you could have your take-home work laptop stolen, or compromised while watching porn. Legislative example: Under the GDPR, a doctor or therapist is not allowed to handle any patient data on private devices, which extends to contact information stored on their private phone. Context matters.
Not everything is about money, or monetary damage. Privacy rights are about freedom and self-determination of the individual.
Although, the organizational structure and history of a corporation certainly has implications for operational security as well. Try mapping and exfiltrating employment graphs and collected personal metadata at a defense contractor and see where that gets you. Mind you, OP's respective metadata analysis has little informational value in a ten peopled start-up, where you talk to everyone anyway. We're here considering corporations large enough for the individual employee to miss operational oversight by direct means. Corporations large enough, that meta-data would be valuable for third parties, too. Trust matters.
It's over-the-top posturing for posturing's sake.
A way to confirm this is to look for HN comments who posture the same. After the Overton window widening, they forget to hold back, and will openly say what we know: it's an abuse of the system that turns an outmoded address book into a gossip rag, to the surprise of the actual people involved.
Citations:
"First I just cared about which accounts got deactivated. Then I started tracking title changes, last name changes (people getting married), department sizes, company head count over time etc."
"LDAP's full of secrets. And to think that you can get nearly all of it with anonymous access. Team or department mergers before they were announced? Yep, I've caught those. Secret mailing lists for internal projects? Check who's a member and you can ferret out what's going on. Bonus if the list mail address gives some of it away."
"Lots of weird things depend on the LDAP tree being broadly accessible. It's just that it leaks more information than most people think."
"Monitor when and what HR is doing. Detect when users are logging in and out of LDAP."
Team or department mergers before they were announced? Yep, I've caught those. Secret mailing lists for internal projects? Check who's a member and you can ferret out what's going on. Bonus if the list mail address gives some of it away.
`ldapsearch' is good if you know your way around LDAP. Apache LDAP Studio is a great UI tool if you just want to explore.
Everyone should know enough about LDAP to build a login service that binds against it for internal apps. You can exploit the groups the sys admins maintain to control permissions in your app. It's very powerful and an easy way to get up an running in no time.
It's also often the only way to get information that doesn't exist in an Intranet page, like, literally what teams are there in IT, where are their offices, who's somebody's manager, and of course, what distribution lists am I not on that some other user is on that's causing one of us to have issues accessing some internal company portal.
The ability to walk the tree is something else. Just like we don't allow zone transfers for dns anymore, there should have been similar best practice changes to ldap if people just gave it some love.
Sure, if you want to be the next SolarWinds.
Since the data was dumped, you could always go back and do more analysis. First I just cared about which accounts got deactivated. Then I started tracking title changes, last name changes (people getting married), department sizes, company head count over time etc.
> Incidentally, if someone gets mad about you running this sort of thing, you probably don't want to work there anyway. On the other hand, if you're able to build such tools without IT or similar getting "threatened" by it, then you might be somewhere that actually enjoys creating interesting and useful stuff. Treasure such places. They don't tend to last.
Couldn't agree more.
Why did I laugh maniacally?
Due to 'budget constraints' my contract is being terminated (they have just been through several rounds of layoffs, I was expecting this), my account will be one of the ones deactivated on the next monthly cycle - prior to that, I will have to handover the processing and expected 'deactivated' users 'error' logging behaviour to my replacements...
new-hires is built on top of the “people” python module / cli in our monorepo. That tool is so much more useful than just a way of diffing the org chart. Who is in what team, where are they, are they working today, is it time to celebrate their anniversary, etc. It also follows what I coin the “ZFS litmus test” for good CLI tools by providing -pH for parseable, headerless output.
Treasure such places indeed.
Later that company would go on to lay off 15% of software engineers in a day. The support team created tickets in the public issue tracker to decommission employee accounts, so a lot of people found out that way before anyone reached out for a meeting.
True true true. Especially if people are building quirky cool stuff in smaller orgs, its simultaneously a great place to work and has a higher extinction probability.
Note: don't ever depart with public criticism, you have little to gain and potentially a lot to lose with the burned bridges.
Honestly, I much prefer it to the long notice (sometimes 3 months!) you get in say some European countries. Just rip the band aid and move on. Most likely you'll have a way to connect with former coworkers easily on LI and such.
If I'm terminated I'm not gonna care about wrapping things up, I'm out of there.
I was young, with nothing to lose (or rather just no self-preservation), and so I spoke up that the policy of saying nothing was silly and potentially very dangerous. If that VP, who I saw around regularly, had emailed me for a list of our clients I would have sent it to him, if he had been waiting at a door telling me he had forgot his keycard I would have let him in, etc. You could argue "You should have always asked up the chain before doing that or refused to let him in on your keycard", but then I'd just shake my head at you. When a VP tells you to do something it's not a great career move to throw up roadblocks, even if it's company policy, in my experience.
Going forward the company agreed to send out bland, generic "X is no longer with the company" for "legal" reasons (as in they couldn't say "was fired", "left of their own accord", etc). Which was better for sure. I never thought to scrape our company directory, that's a clever way to do that for sure.
I'm sure totally unrelatedly, we got dinged a bunch on our SOC2 reports improper "off-boarding" and not removing access from terminated folks since no one knew to remove them.
Once we added quarterly SOC2 controls to make sure only employees had accounts it was always a shock to see who had to be removed.
I know the intent was to improve morale, but it had the opposite effect.
Not having closure is one of the most common grievances people have about relationships, friends, lovers, siblings, or colleagues that disappear.
It seems purposely malicious.
Stemming the tide maybe? Don't want people to leave when they see a respected or well tenured person leave / get laid off?
All happened after an acquisition, so I'm not sure if this was business as usual for the other company or in response to increased attrition.
We ended up with an alumni slack like others here have mentioned.
It was a useful way to keep tabs on any skulduggery that was going on.
Unrelated, but Confluence has very powerful support for email alerts on changes. These include notifications of deletions, and the email includes the diff of the deleted content. One thing I do at any org that uses confluence heavily is set up notification rules on some interesting spaces and check in from time to time.
Is be surprised if any competently run large org allows that anyway. Just takes one rogue dude trying to make a quick buck by selling the info to spammers and you’re dealing with that for the next decade
IT admins call this "User Lifecycle Management" and it's typically a required feature for enterprise-scale customers.
(I work at WorkOS and we help developers with this: https://workos.com/directory-sync)
But I've also seen companies with no MDM at all, so YMMV.
If it's in my team/department, I'll know about it one way or another. If not ... Why would I care? People come and go, and if we're friends outside of work, we'll have other channels.
Besides that, most companies I worked at don't even maintain the LDAP/whatever properly. I've seen contacts from people that left/were fired stay around for years.
On a more macro level: you might be interested in an apparent layoff/significant restructuring.
Someone used to (/maybe does) run this as an email service ('orgdiff') at Arm. I wouldn't have gone out of my way to do it myself, but it was something to skim with a Monday morning coffee.
What if they're someone you're working with on and off. Or if you're waiting on some tasks from them?
too true
The web UI allowed elaborate queries so the first time there was a big layoff the ph web page almost went down because everyone was querying to find out who was laid off. Management got mad at this but they really shouldn't have; its correct that you shouldn't work someplace that tries to hide attrition no matter what the source!
My friend never got put into dept 700 because i recruited him into Google a few years later ...
Why? Because a good termination process is sensitive to there needing to be a communication about a termination that can happen well after the actual process of eliminating their access and telling them it's their last day.
So a better termination process is something like:
1. Employee goes to a physical space (preferred) where they don't have their work equipment or talk to their manager and/or HR using something that isn't work controlled (phone call, etc.).
2. A manual or scripted process executes that forces sign outs of all work things (computer, slack, google, whatever). Credentials get reset and not disabled. Perhaps someone can try to look for password reset metadata or other things that might indicate a departure, but it's a lot harder than looking for disabled uids.
3. After the person leaves or has finished their conversation remotely, the team that works with this person gets a broader communication from someone to tell them about the departure. If the company is small enough, maybe there's a broader communication to more people.
4. The rest of the termination process gets fired off that does disable accounts, etc.
Why don't all IT departments do this? Well for a lot of reasons:
1. They don't care, don't have incentives, or haven't been told by HR, etc. to care about handling the termination process in a more sensitive way.
2. For any sufficiently complex company, the number of edges cases of systems where you can't force a logout or handle a password reset increase over time. It takes a lot of testing to make sure a process works because vendors have bugs all the time or unintended behavior.
3. The risk of poorly communicated terminations increase as the number of people that either perform or can troubleshoot the automated process to terminate increase. As others commented, you don't want some ticketing system that is readable by a wide amount of people to see termination requests, so now how do you communicate a termination without too many people knowing about it?
Strangely enough, I think trying to achieve the most sensitive but automated process is good because it forces the company to communicate and acknowledge a departure before the full termination process fires off, but maybe I'm in the minority.
I automated a small newsletter called "The Weekly Diff" for a few close trusted coworkers and sent it out each Friday with a list of who's new and who was missing from the company directory. And I kept a scraped database including phone numbers in case anyone wanted to reach out to anyone after they'd been removed.
Sometimes you make the best out of a failing company culture. Kept a lot of friends that way just by reaching out with some words of support :)
ldapsearch … > new; diff old new > updates; mail … < updates
(On phone, pseudo code, definitely wrong)
The other is perhaps more interesting. I built a tool for a tool for a population of specialists in a large company. The tool requires ldap data synced in, and I capture the diffs. That sampling approach provides surprising insights into what’s active/hot/declining, even when the total size of the company would making tracking every employee change quite difficult.
https://github.com/MoserMichael/gittools/blob/main/git-whois...
However I can't shake this feeling that the mindset that got us from treating servers like pets to treating them like cattle is creeping into workforce planning, and the WFH movement is making it that much easier.
Why plan capacity when you can scale resources up and down on-demand on a whim? With the emotional and morale implications of letting people go hugely reduced it becomes easier to think like that.
Well that depends I guess. A lot of companies/orgs have privacy policies that prohibit accessing services out of "curiosity." I.e. if you're working at a university it's OK to access student information if you're doing it for a specific work-authorized purpose but you can't go casually looking at people's information just to satisfy some personal interest.
It's always kinda stressful to open this email and find out if one colleague you liked has decided to leave, but most times, this colleague informed you before the email arrives.
I eventually decided that someone _might_ decide that, although freely available, in aggregate, this material could be _sensitive_. I stopped doing it. I deleted years of interesting data...
Wouldn't work at "a certain company" if such company now made all their levels secret by default of course.
IIRC, it started from my resignation. Then we kept doing it for future leavers
Advice I wish I'd been given before graduating, second only to "get everything in writing".
To function in day to day tasks you need to be able to read stuff in AD. I have solved interesting problems this way like: How do I get access to X thing when the security groups are not documented? Find someone with access and recurse their MemberOf and diff your own.
I also have used it to find people leaving.
We had this internal web application. It had its own separate username/password table. I was asked to make it so you could login with your regular password instead.
It wasn't hard to solve the password part. I could make the web app consult the main system to verify your password at login. But... I couldn't eliminate the web app's user table entirely. It was too fundamental.
So I built a thing that ran periodically, got a list of users from both places, diffed the lists, and then did the required create/update/delete operations on the web app's user table. Thus the web app's user table mirrored the main login system.
I rolled this thing out and babysat it, keeping an eye on its log file. Naturally my code logged operations done on the user table. And I was like, "Hey, this is telling me who is joining and leaving the company!"
It even gave me a little additional info. The web app had certain roles and permissions, and these needed to correspond to organizational structure, which I got from the main login system. So if a user's web app roles changed, it was a clue they may have switched teams or got promoted.
I felt like I needed to be a bit careful with this info. Not that I wasn't allowed to have it, but I don't think IT expected anyone to have a tool that would make it that easy to notice changes as they happen. Potentially, I could have known someone was fired before their manager told them or something like that.
TLDR: Tried to streamline operations, accidentally developed a signals intelligence capability.
It would have been trivial to track everyone’s hours using this, which would likely have been unpopular.
The trick showed in the article can easily be done on AAD as well.
We haven't used this for the purpose of writing epitaphs, but we could. In fact, since such changes need to go through code review, someone could theoretically author their own removal and add an epitaph of their choice in the commit message; after they leave, the change can be approved and merged in their absence.
Of _course_ the right place to do this is hidden in the compiler.
;-)
It's like saying sorry for someone getting divorced.... in all likely hood you should be happy for them and congratulating them on ending a toxic relationship.
Yea, admins.
Is this a joke or for real?
Given the context of the post, the uid info is likely populated from a central source. I log into one box anywhere in their infrastructure and see who has what uids, it is evidence about who is permitted to that part of the infrastructure at that time.
It's totally my fault for misunderstanding.
Edit: OP said "Layoffs in the WFH era are weird" Yes they are, but people here don't suddenly go offline quite as weird is what I was trying to get at.
Here in Sweden if you are FTE there is usually a 1-3 month layoff period (upppsägningstid) where you work and get paid still. At the end of the period you leave.
People usually email the team and even the entire company with "hey im leaving here is my info"
Now people CAN get fired day of, but that has to be VERY grounded.
Again, Not a WFH thing. This is a USA thing!! I notice this time and time again where people complain about IT or WFH, but it's just that you're in the USA, land of the exploited.
Some links if you want to google translate https://www.unionen.se/rad-och-stod/uppsagningstider-om-din-...
There is "duty of loyalty" where you can get sued for leaks etc https://www.unionen.se/rad-och-stod/om-lojalitetsplikt-och-l...
99% of lay off are agreed and there is no need for account termination, my current company let's you have your account open 30 days after your last day, so you can move data out to your next company.
Can you expand on exactly what this means, as I imagine most companies would not want their data moved out to another company.
But there has to be a very good reason. Such as theft, or actual security worries.
I have genuinely spent a lot of time once sorting out the vegetable beds during a period of gardening leave. It was VERY therapeutic!
(Just as one example. The American economy is a big and diverse place. Though in the interest of full disclosure, I was working for Goldman in Singapore, but they were just following global corporate policy; and our labour laws in Singapore defer more to contracts than the US one. Eg no WARN act here.)
We also make 2-3x what you do for exactly the same work, sometimes up to 5-10x in tech.
There are tradeoffs, but in my experience European workers are more likely to wish that they could come to the US to work than vice versa. When contracting in Europe I've had clauses written into my contracts on multiple occasions that forbid me from disclosing my rate even to the people managing my work, because I was making more in one month than they (as senior project leads) did in a year...
Americans make more in highly skilled jobs, and less in low or unskilled jobs.
Beyond that I can't generalise, Europe is 44 countries. The Americans I meet were obviously keen to move here.
https://www.theguardian.com/technology/2017/aug/01/sweden-sc...
This is only part of the story. They can just pay you the 1-3 months and mark your firing as "effective immediately". Absolutely legal in Sweden, EU and US, and indeed even better for the person fired - 3 months of pay for no work.
That might be very local. There is a long layoff period in Austria too but I don't think any company will let you back into the office. You just get paid without access at home.
How are we supposed to know? Sometimes people put cryptic slack status icons or messages. Sometimes they slack the team or close contacts or something. But in a company with thousands of people, unless an employee sends a email to the entire company, how are you supposed to know? The layoffs happened months ago, why would it occur to me that the person I am working with today will be gone tomorrow, unless they start every conversation with "hey, so I got laid off..."
Nobody really wants to relive that trauma over and over again. It's frankly MORE confusing the longer coworkers stick around after the 'event'.