Live data from Hacker News

Apple is making corporate ‘BYOD’ programs less invasive to user privacy

techcrunch.com

11–20 of 148 posts

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#11
An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option.

This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zillion cases of what the employer can and can't do. I don't want to study a 30-page security whitepaper and 300 pages of documentation that probably come with this new enrollment thingie. But if I have two devices--with physical separation--I don't have to think about all sorts of security and privacy gotchas.

Buying a cheap extra work phone and carrying two phones is not that big a burden. Plus you can turn off the work phone during personal time, and turn off the personal phone during work.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#12
post #2

This is a welcome step. I moved (back) to iPhone recently and one thing I miss from Android is Work Profiles that can be turned on and off and act as pretty much a separated user. It sounds like this is slightly more limited than that, but it’s a good start. At least being able to easily turn work stuff off on the weekend is a huge deal for work life balance (and I feel a bit uncomfortable when my work stuff is effec…

> This is a welcome step. I moved (back) to iPhone recently and one thing I miss from Android is Work Profiles that can be turned on and off and act as pretty much a separated user. It sounds like this is slightly more limited than that, but it’s a good start. At least being able to easily turn work stuff off on the weekend is a huge deal for work life balance (and I feel a bit uncomfortable when my work stuff is effectively not isolated from my personal stuff.)

Did Android do away with work profiles recently? I used to have one and then following an update from the Enterprise, the apps were commingled and there was no way to explicitly "turn off work".

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#13

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

Naturally.

I never got the BYOD thing.

My employer should provide the required tools, if not, then the work is done within the constraints of what is available.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#14
post #12
post #2

This is a welcome step. I moved (back) to iPhone recently and one thing I miss from Android is Work Profiles that can be turned on and off and act as pretty much a separated user. It sounds like this is slightly more limited than that, but it’s a good start. At least being able to easily turn work stuff off on the weekend is a huge deal for work life balance (and I feel a bit uncomfortable when my work stuff is effec…

> This is a welcome step. I moved (back) to iPhone recently and one thing I miss from Android is Work Profiles that can be turned on and off and act as pretty much a separated user. It sounds like this is slightly more limited than that, but it’s a good start. At least being able to easily turn work stuff off on the weekend is a huge deal for work life balance (and I feel a bit uncomfortable when my work stuff is eff…

I'm using Android (Pixel 3), and the work profile works for me. IMO it is much better than having to carry two phones.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#15

> Using the per-app VPN feature, traffic from the Mail, Contacts and Calendars built-in apps will only go through the VPN if the domains match that of the business. Shame that Apple doesn't take this one step further and do it system-wide.

Wish they would enable per-app VPNs without MDM, e.g. with a profile generated by Apple Configurator or open-source tool.

Per-site VPNs are possible in Safari, which is a poor approximation that keeps the VPN active (consuming battery) as long as Safari is active.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#16

> Using the per-app VPN feature, traffic from the Mail, Contacts and Calendars built-in apps will only go through the VPN if the domains match that of the business. Shame that Apple doesn't take this one step further and do it system-wide.

Given their commitment to privacy as a selling point, it would be nice if Apple provided an integrated VPN service (say included with the upper iCloud tiers). For now I’m on the waitlist for Cloudflare’s offering - their DNS works fantastic.

I’d use it but it prevents me using a Pihole (via VPN). The Pihole points at Cloudflare though, so they get me either way.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#17
post #13

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

Naturally. I never got the BYOD thing. My employer should provide the required tools, if not, then the work is done within the constraints of what is available.

It's kind of weird that the employer wants the employee to bring their device, but don't want to trust the employee's device anyway.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#18

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

I agree in general. And I do not get the BYOD thing. As another commenter said, an employer should provide the tools necessary. Or live with the constraints.

I am in another camp. Until recently my employer had a policy of treating our devices somewhat like private devices. We are provided with the device, are allowed to use them at home at will, are full admins. We are only requested to encrypt the harddrive. My employee never had access to my data if I did not provide it to them.

So now two situations changed. Clients of ours force us to use endpoint management to ensure different "security" standards (some not as secure as I had before). Also we got bought by a bigger company and they have rules and regulations for their ~470k employees. These mean we will get some hefty spyware on our devices while still being officially allowed to take the devices home with us, use them privately and so on.

Well. I am not so sure, I will do this in the future. I am not willing to introduce spyware that also scans all devices within the network to my home network. I do not want some admin on the other side of the world to be able to download any file from my device. Or to upload any file onto my device.

So I will probably buy another computer (not having owned a private laptop for quite some time) to use at home. Same with my mobile phone.

On the other hand - I hate to carry two devices with me. For me separating out private/freelance stuff onto one machine and corporate stuff onto another makes things more complicated. And I know convenience kills security.

Sorry for my rant, without providing much to the discussion. I mean - it is my work device and my employer is within their full right to install whatever they wish - once the works council agrees.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#19
post #17
post #13

Earlier quoted context omitted.

Naturally. I never got the BYOD thing. My employer should provide the required tools, if not, then the work is done within the constraints of what is available.

It's kind of weird that the employer wants the employee to bring their device, but don't want to trust the employee's device anyway.

Sometimes it is not about trust. It is about regulations within the industry one works/contracts in.

But if this is the case I believe strongly, that the employer must provide the necessary tooling.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#20

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

It is a burden however, and one that isn't necessary if your company has a sane BYOD policy that protects them while not being too invasive.

The reality is, convenience wins again here. I, for one, don't give a shit what control my company has over my phone. Not only has nothing ever happened as a result of me using a BYOD policy, the overall rate in the industry seems acceptably low too.

I only have 24 hours in my day, I can't be worrying about things that aren't likely to effect me in any material way. I simply don't have time.

Post reply on HN