Live data from Hacker News

Ask HN: My client want an agent on my laptop. Is this the new normal?

news.ycombinator.com

321–330 of 506 posts

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#321

Earlier quoted context omitted.

> If you want to ship me a dedicated laptop for your engagement, I would be happy to install whatever you want on it. I wouldn't offer this. You're still going to need to login to Github/email/wherever with your personal password, manage private keys, and stuff like that. Just say no.

It's a widespread practice that companies provide laptops to contractors to compartmentalize the way they interact with the company's IT. But I'm really quite opposed to it. At one point I had 3 sets of machines: Two different 14" laptops from two different clients and my own machines. At some point you simply run out of space on your desk and end up constantly either working on screens that are too small (14" really…

I think there are absolutely a list of things that I don't want the company doing on my hardware, but I'm okay with on their hardware.

Off the top of my head, remote wipes/resets make sense. Frankly, I prefer the company has that option, just in case I lose my work laptop. Encryption should cover it, but I'll take the backup.

Compliance agents also have a legitimate reason to exist, but I don't want them on my personal PC. Some places maintain lists of allowed software (I think in part so they can track/inventory them for compliance stuff). I respect that they have the right to restrict what I install on my work laptop, but I reserve the right to install whatever I please on my own computer.

It would also not be insane for a company to do automated backups of company laptops to company servers. You want a way for Joe in marketing to get his data back when his cat pees on his laptop. I do not want all my personal documents on company servers.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#323

There's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over mon…

> Because otherwise they would fail SOC2 and managing your legal status as "Freelancer" vs "Employee" (for tax reasons??) is not worth not being certified.

It depends on the size of the company this person is working with. If it is large enough to be procuring Drata it means the people asking this dude to install the software is probably in a vastly different part of the company org structure as the teams our friend is working with. In addition, the "drata team" might not have yet considered their policy for contractors--in fact the "drata team" probably wouldn't even be the ones to draft a policy for that. It could be their legal teams who do that.

The solution really depends on how much of a fuss the poster wants to make of it. Personally I would be working with my clients inside that org to figure out a way to make their IT & legal department happy. If the poster has a good open relationship with their client, they'll find some solution. Perhaps the client loans the poster a dev workstation or something (which I'm sure can be structured in a way that doesn't fail the "contractor vs employee" tests).

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#324

If you are a freelancer then your contract should allow you to do work for others. In which case, your response to this client has to be "Sorry, but my business laptop potentially has data from other clients on it. I can't let you install this monitoring agent without violating my contractual confidentially agreement with those other clients. I always maintain client confidentiality and will do the same for you. If y…

> If you want to ship me a dedicated laptop for your engagement, I would be happy to install whatever you want on it. I wouldn't offer this. You're still going to need to login to Github/email/wherever with your personal password, manage private keys, and stuff like that. Just say no.

No sane person would use their personal logins or private keys for customer work. Create ones for that project! Yes, it is a pain but having a bunch of expensive lawyers breathing down your neck is an even bigger one!

You want to separate your customer's work from your personal or other clients' data, even if they don't install any spyware on your computer. How are you supposed to ensure that you don't accidentally breach any NDAs (that you, no doubt, had to sign) if you are commingling the stuff?

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#325
post #299

Earlier quoted context omitted.

Or they reimburse the consultant when they procure their own dedicated laptop for the client's work.

And hey, when the gig is over you got a new laptop that just needs to be formatted and it's all yours!

At my agency we have a client that always ships us locked down laptops (healthcare space so understandable). Thing is this client, while very good at getting the laptops out to you, is horrible at actually getting them back and pretty much lets you keep them....I have 4 Macbook Pro's sitting on a shelf behind me, all from this client.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#326
post #278

Earlier quoted context omitted.

I have worked in such an environment. It was likely running on an overprovisioned server, that had to be accessed via an Internet Explorer ActiveX plugin. I'd rather be using a green-phosphor VT100 at that stage.

That sound's like it is a looong time ago, todays VD's are extremely responsive just have a look at Shadow for example.

~6 years ago. I'd be surprised if such things weren't still deployed in places.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#327

Earlier quoted context omitted.

SOC2 isn’t prescriptive. SOC2 is just a certification that you are following your own internal policies. If the company made the mistake of creating a policy that they use this software as one of their controls, then the auditor will ding them if they don’t use it. It’s an absurd system.

Reminds me when I was doing PCI compliance. A PCI question asks if all outbound traffic is explicitly authorized. I took that to mean getting a list of all the IPs for the APIs of services we hit, and even constructed that entire list except for one, the payment processor itself. The payment processor did not have any stable IPs, and could not give me a list. Their official solution was to have our policy be that we…

As Vendan said, the point is to get explicit acknowledgement that you're aware of something and have either mitigated it or accepted it. Which sounds kind of dumb, like ISO9000 certification, where the joke is "it doesn't matter how bad our processes are as long as we write them down!"

I made that joke to a VP once, and he brightened up and said "Yes! Exactly! Because until you're actually following explicit processes, you don't even know what you're doing wrong, in order to fix it!"

So I'm a lot less cynical about auditing certifications like this now.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#328

There's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over mon…

> Do you have any evidence for this?? I've just been involved in selecting Drata as a vendor for SOC2 compliance planning for our company. If this is true it's a huge deal and totally against my understanding of their business model. It honestly sounds like bullshit to me! But if you have evidence that they do this, please let us know.

Unless their agent is Free Software, the reasonable end-user assumption is that they are doing malicious things. As we've seen time and time again, it's inevitable - either now, or in the future, they will come up with some bright idea for more features that involve being directly user-hostile. Your company may rely on their legal contract assurances, but I as an individual cannot.

My minimum policy for running sketchy binary blobs is in a VM on another machine. If you're adopting this type of software, it's incumbent upon you to make your corporate policy one of supplying computing equipment for everyone who is expected to run it. And also accept that employees will physically damage microphones and webcams to stop your supplied machines from acting as surveillance bugs of their personal dwellings.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#329

Earlier quoted context omitted.

If this is really the kind of things this company would do… why are you working for them?

> If this is really the kind of things this company would do… Because, until last week they didn't. Now I have to figure out if I'm just an unreasonable, stubborn old guy, or if this requirement is out of band.

Presumably the client will terminate your contract with them if you don't comply. So you don't actually have to install the agent until the day that they terminate the contract which is also the day that you no longer have to install the agent.

Re: Ask HN: My client want an agent on my laptop. Is this the new normal?

#330

Earlier quoted context omitted.

> Another approach you can try is to conform to their requirements on one machine, but do all your actual work on another. That would create a layer of cynicism between me and my work. I don't have that today, and I would rather avoid it.

But you’re the one describing a piece of software they are asking you to install as a condition of employment as a ‘hostile agent’. Feels like the layer of cynicism is already there.

Not on my part. Not with the people in the company I usually deal with.

When a new manager I don't know send me an email to install some "agent" from a company I have never heard about, and that company turns out to have terms and conditions from hell (like references to undisclosed terms and conditions they want me to accept) - then I label that thing, in my mind, as a "hostile agent". It's not something that will ever get access to my lan. It's something I don't even want in a VM, because it may know how to escape from a VM.

That's not cynicism. That's risk assessment.

Post reply on HN