Live data from Hacker News

Apple is making corporate ‘BYOD’ programs less invasive to user privacy

techcrunch.com

81–90 of 148 posts

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#81

Earlier quoted context omitted.

> while still being officially allowed to take the devices home with us, use them privately and so on. Who owns the rights to IP developed on these company-owned laptops? One of the biggest problems with this kind of ‘unspoken flexibility’ is that any side projects you work on are in-part owned by the company, under most standard agreements.

Isn't that the case regardless of what laptop you're using? As far as I can tell you should assume any side projects are Copyright (c) your employer unless you talk to legal first and make an arrangement (for each project). See for example: https://www.joelonsoftware.com/2016/12/09/developers-side-pr...

I want to be clear that my question relates to artifacts you produce on company-owned resources - not just in your own time on your own machine.

Legal precedence around IP ownership - when you've used company-owned machines - is far less clear.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#82
post #66

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

People seem to forget companies want to use BYOD because it saves them money. They don't have to pay for a phone for you to use, you've paid for it yourself.

It isn't just saving money: in the case of phones it is keeping you in easy contact. Having Teams/Slack/other on your phone so it will beep you when the company has a problem you could look at. A good company will be flexible in reverse so you can take that bit of time back when you need to, but many are not this decent so you are giving them your attention/time/effort for free.

The company could provide a device for that of course, but people often don't want that or it isn't reliable: they don't want an extra device to carry around, they don't remember to keep it charged, they forget to take it with them far more often than their own phone, ... So as well as the cost aspect BYOD can make thing more convenient in other ways.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#83

As someone who has managed 10k endpoints, BYOD is a very niche solution. The security threats that any company with data worth stealing has is non-trivial. Those folk in this thread moaning about corporate spyware, are living on another planet. Nobody has the resources, or the motivation to spy on anyone. When Oracle, Adobe and Microsoft come a knocking, knowing what is installed and being able to uninstall it save a…

There is some motivation. Imagine you're Tim Apple and you wake up one day to find The Verge has a front page story detailing all of your secret Apple Car technical details and plans through 2022 courtesy of a "source with firsthand knowledge of the project". I don't doubt for a minute that Apple has a corporate security team with the empowerment and resources to dig through employees' personal iMessages to find the leaker.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#84

This is nice and all, but I really wish that Apple would allow some real multi-account functionality. Especially for iPads, but also for iPhones. When I hand my phone to my kids to play a game, I don't want them to have access to my email / text messages / contacts etc. It's ridiculous that a 1000€ device is restricted to single user mode. It's even worse for iPads -- they are perfect devices for sharing in the famil…

The function is there, just not enabled for end users. Enterprise and Education can use multi user switching on iPads, plus a whole lot more.

Doesn't that work by deleting your profile and downloading the new one? It doesn't save the profiles on-device like desktop computers.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#85
post #13

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

Naturally. I never got the BYOD thing. My employer should provide the required tools, if not, then the work is done within the constraints of what is available.

[deleted]

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#86

Earlier quoted context omitted.

Which regulation requires spyware on endpoints, and where in the text does it say that?

Anything in financial services and probably health requires you to secure company data.

A regulation is a specific text, not a general idea about the importance of security or the sensitivity of an industry.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#87
post #34

Earlier quoted context omitted.

From experience it's usually that the employee thinks they need the most powerful 15" Macbook pro when their job entails something like writing blog posts or running code in AWS

And from experience, those squeaky wheels get the grease and the engineers flog along with what they have because they are too busy to put the necessary amount of complaining in.

Can confirm. The ergonomic setups of some non-tech staff I've worked with has definitely out-paced myself.

But some of the differences lie in understanding how to work around constraints.

I've been putting off requesting some specific administered software removal from my own machine for months because I keep getting caught up in much more pressing work. In most cases I'm able to just work around it. In other cases, it just eats up time. But I can see the path through to a solution more clearly than any corporate wrangling.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#88

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

I agree in general. And I do not get the BYOD thing. As another commenter said, an employer should provide the tools necessary. Or live with the constraints. I am in another camp. Until recently my employer had a policy of treating our devices somewhat like private devices. We are provided with the device, are allowed to use them at home at will, are full admins. We are only requested to encrypt the harddrive. My emp…

>And I do not get the BYOD thing.

I get it. My employer provided phone is a Blackberry Leap.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#89

Earlier quoted context omitted.

Sometimes it is not about trust. It is about regulations within the industry one works/contracts in. But if this is the case I believe strongly, that the employer must provide the necessary tooling.

Which regulation requires spyware on endpoints, and where in the text does it say that?

This is common anywhere you work with ITAR-controlled data.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#90
post #72
post #10

> Apple also noted that one of the big reasons users fear corporate BYOD programs is because they think the IT admin will erase their entire device when the enrollment ends — including their personal apps and data. Yes. This is a true thing that users fear. It tends to happen because they're using phones that don't allow any more constrained option. It's nice to see iOS catching up with Android in this.

I've had InTune and also some VMWare device management installed on my device in the past, and during installation you do get a warning that your admins will be able to delete everything on your device. It kind of makes sense for them to do that if your device is stolen, but I still just don't like handing over control of my device like that. They typically also enforce other annoying policies, such as not allowing r…

Oh, it definitely feels annoying and invasive. Without sandboxing, the options are invasive MDM (because that's the only kind possible) and no MDM at all.

I once watched an employer go from unwilling to adopt MDM to requiring it for accessing substantive systems on personal devices. The CEO lost his phone, and suddenly appreciated what MDM was good for.

Users were given a choice: MDM, sandboxed if they had a device with modern technology, or no significant access on personal devices. A lot of users had phones that didn't offer sandboxing, so myself and several others found ourselves explaining quite often that there literally was no option available where remote wipe wasn't possible. If they didn't like that, well, they didn't actually need access from their phones, so...

Anyway. I'm quite glad Apple is starting to actually catch up a bit.

Post reply on HN