Live data from Hacker News

Apple is making corporate ‘BYOD’ programs less invasive to user privacy

techcrunch.com

61–70 of 148 posts

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#61
post #28

It feels like an over engineered solution for a simple problem. If Apple were instead to add multi-users support to iOS then it would be as simple as having a work identity with dedicated apps and segregated data, and a personal identity as such, invisible to IT.

Such a "solution" would be a PITA. I for one am using my phone many times during a work day for personal stuff (e.g. messaging with my wife), and I am also often using it for work stuff in my free time (e.g. replying to email from my boss). I would go insane if I had to switch profiles every other time I had to do accomplish simple task in my phone.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#62

Earlier quoted context omitted.

Sometimes it is not about trust. It is about regulations within the industry one works/contracts in. But if this is the case I believe strongly, that the employer must provide the necessary tooling.

Which regulation requires spyware on endpoints, and where in the text does it say that?

In Germany for example most companies in the automotive space require all contractors to conform to the [TiSAX](https://enx.com/tisax/tisax-en.html) regulations.

These state, that there needs to be proof of several data security aspects on all devices of all people working in a facility for one of these companies/clients as a contractor:

- Anti Virus software up to date - Firewall active - Harddisk encrypted - Ability to remotely lock device - Ability to remotely wipe device

To ensure that this is in place at all times on all devices one needs a programatic solution - Endpoint Management. And as this needs to be root (for remote wipe) - this could be seen as spyware (as I like to call it internally).

So yeah - there are a lot of companies/industries enforcing this. As someone above said - banking is another industry, insurance, medical and other high profile stuff with sensitive data might come to mind.

The text does not say this - but this I added just from experience. And I actually hope that someday companies like mine could go the Apple way and ensure Endpoint Management on a per user account basis. That way I could still take home my company laptop and use it privately with a different user.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#63
post #28

It feels like an over engineered solution for a simple problem. If Apple were instead to add multi-users support to iOS then it would be as simple as having a work identity with dedicated apps and segregated data, and a personal identity as such, invisible to IT.

The problem is that most MDM solutions want to take over your device. At my employer, the MDM solution literally takes over your entire device. I've installed the solution on an iPhone, and a Samsung Galaxy S8 (with and without Knox) with the same result. Unfortunately, the result is I carry two phones instead of one.

I think Apple's solution to the problem might work. As long as the companies data is separate from mine, what I do on my phone is private, and basic functionality like screenshots are available on my phone, the solution looks good to me.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#64

Earlier quoted context omitted.

> while still being officially allowed to take the devices home with us, use them privately and so on. Who owns the rights to IP developed on these company-owned laptops? One of the biggest problems with this kind of ‘unspoken flexibility’ is that any side projects you work on are in-part owned by the company, under most standard agreements.

Isn't that the case regardless of what laptop you're using? As far as I can tell you should assume any side projects are Copyright (c) your employer unless you talk to legal first and make an arrangement (for each project). See for example: https://www.joelonsoftware.com/2016/12/09/developers-side-pr...

Fortunately, not in California.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#65

Earlier quoted context omitted.

I agree in general. And I do not get the BYOD thing. As another commenter said, an employer should provide the tools necessary. Or live with the constraints. I am in another camp. Until recently my employer had a policy of treating our devices somewhat like private devices. We are provided with the device, are allowed to use them at home at will, are full admins. We are only requested to encrypt the harddrive. My emp…

> while still being officially allowed to take the devices home with us, use them privately and so on. Who owns the rights to IP developed on these company-owned laptops? One of the biggest problems with this kind of ‘unspoken flexibility’ is that any side projects you work on are in-part owned by the company, under most standard agreements.

Me being in Germany and clearly not a lawyer. That said: I own all my intellectual property, of everything I develop in my free time on this device. And in Germany, at least as far as I am aware, these broad regulations some US employers try to force on their employees have been thrown out by court decisions. But not sure on that.

I would not work for a company that would try to ensure it owns all of what I do outside of company time.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#66

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

People seem to forget companies want to use BYOD because it saves them money. They don't have to pay for a phone for you to use, you've paid for it yourself.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#67

> Using the per-app VPN feature, traffic from the Mail, Contacts and Calendars built-in apps will only go through the VPN if the domains match that of the business. Shame that Apple doesn't take this one step further and do it system-wide.

Given their commitment to privacy as a selling point, it would be nice if Apple provided an integrated VPN service (say included with the upper iCloud tiers). For now I’m on the waitlist for Cloudflare’s offering - their DNS works fantastic.

VPN's are not a privacy panacea. Hiding your internet traffic from e.g. your ISP comes at the cost of divulging it to the VPN provider. Apple has been very clear that they don't want to be in a position where they would have to turn over sensitive information about their users to authorities, a position they can avoid by not providing such a service.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#68

Earlier quoted context omitted.

No, what you do on your own time (not company time) with your own resources can't be owned by the company, because otherwise everything you do would be owned by the company, which is absurd; suppose I went to a friend or relative and helped him/her out by writing a simple script, does that belong to the company now? How about posts you make on HN outside of work (if you do it at work, that's... questionable)? The pos…

Please see the link I added. You should check your employment contract to see the exact terms of the copyright assignment clause you signed, but it's definitely very common to have to assign any inventions you make that are "related to your employers area of work", regardless of what hardware you use or if you do it in the office or at home.

Well who signs contracts like these? I mean really? And why? I really cannot understand anybody giving away that much of their live for an employer/the next paycheck.

Yeah - if I am really, really in a tight spot financially - for as long as it takes to crawl out of such a mess - ok. But regularly? Long term?

Help me to understand.

And I also do not understand how a company could find this morally acceptable to have this idea.

I mean is this really the norm in the US?

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#69

Earlier quoted context omitted.

I agree in general. And I do not get the BYOD thing. As another commenter said, an employer should provide the tools necessary. Or live with the constraints. I am in another camp. Until recently my employer had a policy of treating our devices somewhat like private devices. We are provided with the device, are allowed to use them at home at will, are full admins. We are only requested to encrypt the harddrive. My emp…

> I am not willing to introduce spyware that also scans all devices within the network to my home network. In the EU I would seriously doubt that your employer is allowed to do this.

> In the EU I would seriously doubt that your employer is allowed to do this.

Sadly they are. At least as far as any lawyer on this topic currently stated.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#70

Earlier quoted context omitted.

Isn't that the case regardless of what laptop you're using? As far as I can tell you should assume any side projects are Copyright (c) your employer unless you talk to legal first and make an arrangement (for each project). See for example: https://www.joelonsoftware.com/2016/12/09/developers-side-pr...

Fortunately, not in California.

Depends. California’s law only applies if you aren’t working in the same business as your employer, which means if you work for any large company you almost certainly can get in trouble with pretty much anything.
Post reply on HN