We do two things.
One: we give them the choice. Yes it costs money, but not that much.
Two: we went with Kolide. To understand how they are different, go read https://honest.security.
451–460 of 506 posts
We do two things.
One: we give them the choice. Yes it costs money, but not that much.
Two: we went with Kolide. To understand how they are different, go read https://honest.security.
Earlier quoted context omitted.
No, "quitting" is rarely the right option - you do not need to proactively respond to the situation they created! If you're willing to no longer work there over this (as you should be), then that is a pretty strong BATNA. You soft refuse and give them alternative options that are acceptable to you (perhaps supplying their own equipment to run the spyware, a higher rate so you can procure your own dedicated equipment,…
Let them be the ones to terminate the relationship. Disagree - in general you never want to be expressly terminated. Layoffs are a different matter, of course. But an explicit "for cause" termination is always a red flag to any future employer. There's a decent chance that if you just passively stonewall, they will eventually give up. You really can't stonewall these things and I wouldn't suggest to anyone that they…
Every situation is a negotiation. I'm not advocating outright aggressive rejection, but rather passive stonewalling or responding with a counteroffer. Ultimately it depends on your position and what value you're providing. If management loves you (or needs you), that will go a long way in a sane place. You're a known quality employee getting the job done, and someone from HR or IT is coming along and rocking the boat. Obviously if you're already on shaky ground, then you've got a lot less leeway to play around.
Earlier quoted context omitted.
I had an employer that, once or twice a year would send out mandatory agreements we were "required" to sign-- under threat of dismissal. (I don't think this was legal at all). One day they sent out a particularly onerous "agreement" that said that we agreed not to use a phone while driving a car and doing so would be cause for termination etc. I went down to HR and asked them if they were really trying to regulate wh…
You're in the US --- California, to boot. I'm not sure what you accomplished by making the agreement "unenforceable", as your employer does not need to secure your agreement to terminate you for virtually any reason. Discovering that you text and drive in your spare time, off hours, is something they'll likely have no trouble firing you for, unless you have an employee contract that somehow gives you tenure except fo…
I am not a lawyer, obviously, but what I meant was, threatening someone to sign a legal document can't be legal, even if its your employer.
Earlier quoted context omitted.
You're in the US --- California, to boot. I'm not sure what you accomplished by making the agreement "unenforceable", as your employer does not need to secure your agreement to terminate you for virtually any reason. Discovering that you text and drive in your spare time, off hours, is something they'll likely have no trouble firing you for, unless you have an employee contract that somehow gives you tenure except fo…
Perhaps I didn't explain myself well. I am not a lawyer, obviously, but what I meant was, threatening someone to sign a legal document can't be legal, even if its your employer.
Earlier quoted context omitted.
Perhaps I didn't explain myself well. I am not a lawyer, obviously, but what I meant was, threatening someone to sign a legal document can't be legal, even if its your employer.
Sure it can? All sorts of jobs are contingent on signing contracts (NDAs, acceptable use policies, background check authorizations). Why would you think it wouldn't be legal? The "threat" is simply to stop employing you, which your employed (in the US) has an almost absolute right to do anyways.
Earlier quoted context omitted.
Keeping their software segregated is sound advice, but as they are your client there are a couple of other ways I'd offer to handle it: 1) Keep all software related to work for their company segregated inside a VM. Then you can install whatever they require without interfering with your main system or potentially exposing data for other clients. 2) If they want a separate physical system, tell them you would be happy…
We provide hardware to contractors all the time. They don't own the hardware so the loaner does not trigger a taxable event for them. When the contract is over, they return the hardware. The hard part about this in the current day and age is getting the units through customs.
This tends to be more of an issue for solo contractors rather than contract houses as the IRS tends to look the other way on most of the larger contracting outfits.
Earlier quoted context omitted.
> Another approach you can try is to conform to their requirements on one machine, but do all your actual work on another. That would create a layer of cynicism between me and my work. I don't have that today, and I would rather avoid it.
Well said, and good luck with your problem. These workarounds are a flag one is in the wrong place. I recently left the job where I did the two-pis hack.
Say no. Name and shame. The soc2 controls in question can be met with a handful of config changes and an antivirus install. (I’ve implemented soc2 controls five times) Full disk encryption with FileVault or Bitlocker Screen lock Enable automatic security updates Use of password manager Virus scan with ClamAv or windows defender. If they want an agent to make sure you’re working when you say you’re working I’d pass.
Source: I am the Drata CISO
Earlier quoted context omitted.
>We do not share your personal information with third parties without your consent, except in the following circumstances or as described in this Privacy Policy: Affiliates. We may share your personal information with our corporate parent, subsidiaries, and affiliates, for purposes consistent with this Privacy Policy. Service providers. We may share your personal information with third party companies and individuals…
The first paragraph says that it is the privacy policy with respect to the website. Why do you think it covers the data collected by the agent?
Source: I am the Drata CISO
This is neither normal nor reasonable. Do not accept it.