Live data from Hacker News

Apple is making corporate ‘BYOD’ programs less invasive to user privacy

techcrunch.com

91–100 of 148 posts

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#91
finally.

it's a thrice-removed description, but at a surface level it sounds better than android profiles, at least for work/home device sharing.

for sharing with family members (parents/kids, eg) it doesn't sound so awesome. hey, if it means kids have to have their own tablet, well more power to apple then!

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#92
post #10

> Apple also noted that one of the big reasons users fear corporate BYOD programs is because they think the IT admin will erase their entire device when the enrollment ends — including their personal apps and data. Yes. This is a true thing that users fear. It tends to happen because they're using phones that don't allow any more constrained option. It's nice to see iOS catching up with Android in this.

I didn't read TFA fully but I suppose from your quote, what they didn't say was what corporate IT fears.

I don't know how many corps care about this, but when I did that kind of job, I refuse to have my corp have access to a user's personal data, and be able to brick their personal device, etc. It's not acceptable from a privacy POV and not acceptable from an employee backlash POV. Anyway it was an easy choice because we never had sensitive data that could make it to a phone/tablet. In an environment more like that, I would probably have instituted some kind of privacy waiver that an employee would have to sign in order to BYOD (apple brand). That probably wouldn't fly today, in europe. GDPR and all that.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#93
post #14
post #12

Earlier quoted context omitted.

> This is a welcome step. I moved (back) to iPhone recently and one thing I miss from Android is Work Profiles that can be turned on and off and act as pretty much a separated user. It sounds like this is slightly more limited than that, but it’s a good start. At least being able to easily turn work stuff off on the weekend is a huge deal for work life balance (and I feel a bit uncomfortable when my work stuff is eff…

I'm using Android (Pixel 3), and the work profile works for me. IMO it is much better than having to carry two phones.

Is it something different than just a separate local account?

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#94

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

I agree in general. And I do not get the BYOD thing. As another commenter said, an employer should provide the tools necessary. Or live with the constraints. I am in another camp. Until recently my employer had a policy of treating our devices somewhat like private devices. We are provided with the device, are allowed to use them at home at will, are full admins. We are only requested to encrypt the harddrive. My emp…

I am the employer in this situation. The problem was that

1 - some employees do not read policies (despite some really explicit training during onboarding) and disable the password so they don't have to type it during login;

2 - apple software is hot shit and somehow filevault disabled itself on an employee laptop. I'm 100% sure that it was previously enabled. It required multiple support calls, an OS reinstall, and a full machine wipe performed at an apple store to get it re-enabled, so I believe the employee who says he didn't disable it.

Either way, I had to install an mdm to make sure that there always is a password on the machine, a lockout time, and filevault enabled. That mdm, unfortunately, gives me far more control than I want, but there's nothing I can do about that; it's a package deal. I'd prefer not to install them, but one idiot disabling passwords, even after very specific training, because it's inconvenient to type them ruined it for everyone.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#95
post #10

> Apple also noted that one of the big reasons users fear corporate BYOD programs is because they think the IT admin will erase their entire device when the enrollment ends — including their personal apps and data. Yes. This is a true thing that users fear. It tends to happen because they're using phones that don't allow any more constrained option. It's nice to see iOS catching up with Android in this.

I didn't read TFA fully but I suppose from your quote, what they didn't say was what corporate IT fears. I don't know how many corps care about this, but when I did that kind of job, I refuse to have my corp have access to a user's personal data, and be able to brick their personal device, etc. It's not acceptable from a privacy POV and not acceptable from an employee backlash POV. Anyway it was an easy choice becaus…

In addition, customers are starting to require their vendors who have access to their data institute MDM. So it's increasingly MDM or two separate devices.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#96

Earlier quoted context omitted.

Please see the link I added. You should check your employment contract to see the exact terms of the copyright assignment clause you signed, but it's definitely very common to have to assign any inventions you make that are "related to your employers area of work", regardless of what hardware you use or if you do it in the office or at home.

Well who signs contracts like these? I mean really? And why? I really cannot understand anybody giving away that much of their live for an employer/the next paycheck. Yeah - if I am really, really in a tight spot financially - for as long as it takes to crawl out of such a mess - ok. But regularly? Long term? Help me to understand. And I also do not understand how a company could find this morally acceptable to have…

Unfortunately it is the norm. (With tech companies)

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#97
post #88

Earlier quoted context omitted.

I agree in general. And I do not get the BYOD thing. As another commenter said, an employer should provide the tools necessary. Or live with the constraints. I am in another camp. Until recently my employer had a policy of treating our devices somewhat like private devices. We are provided with the device, are allowed to use them at home at will, are full admins. We are only requested to encrypt the harddrive. My emp…

>And I do not get the BYOD thing. I get it. My employer provided phone is a Blackberry Leap.

I don't get it. My employer provided phone was a Blackberry Bold. I need a work phone to make and receive work related calls, and to keep work related matters off my personal phone, enabling me to not have to think about work once I leave the office unless someone phones me.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#98

Earlier quoted context omitted.

Sometimes it is not about trust. It is about regulations within the industry one works/contracts in. But if this is the case I believe strongly, that the employer must provide the necessary tooling.

Which regulation requires spyware on endpoints, and where in the text does it say that?

Lots of them. It's under reasonable and appropriate security measures.

You say spyware; I say software that guarantees there is a password, that there is a reasonable lock-out time, that encryption is enabled, etc. Leaking data because you let your most gullible employee install whatever he or she liked on their laptop and phone (eg facebooks spyware certs so they can read all your traffic) is going to get you in trouble in a hurry.

For example, CCPA. Which applies to a lot of us in 6 months.

> duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information

https://leginfo.legislature.ca.gov/faces/codes_displaySectio....

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#99

Earlier quoted context omitted.

> while still being officially allowed to take the devices home with us, use them privately and so on. Who owns the rights to IP developed on these company-owned laptops? One of the biggest problems with this kind of ‘unspoken flexibility’ is that any side projects you work on are in-part owned by the company, under most standard agreements.

Me being in Germany and clearly not a lawyer. That said: I own all my intellectual property, of everything I develop in my free time on this device. And in Germany, at least as far as I am aware, these broad regulations some US employers try to force on their employees have been thrown out by court decisions. But not sure on that. I would not work for a company that would try to ensure it owns all of what I do outsid…

> Me being in Germany and clearly not a lawyer. That said: I own all my intellectual property, of everything I develop in my free time on this device.

> I would not work for a company that would try to ensure it owns all of what I do outside of company time.

You might want to read the laws governing this, notably the "Gesetz über Arbeitnehmererfindungen" (https://www.gesetze-im-internet.de/arbnerfg/) It's fairly short and clear. Work contracts often don't mention that because a lot of what you can invent is already owned by your employer by law.

Notably everything that can be patented and primarily results from your work or your or your experience at work:

    (1) Erfindungen von Arbeitnehmern im Sinne dieses Gesetzes können gebundene oder freie Erfindungen sein.
    (2) Gebundene Erfindungen (Diensterfindungen) sind während der Dauer des Arbeitsverhältnisses gemachte Erfindungen, die entweder
    
    1. aus der dem Arbeitnehmer im Betrieb oder in der öffentlichen Verwaltung obliegenden Tätigkeit entstanden sind oder
    2. maßgeblich auf Erfahrungen oder Arbeiten des Betriebes oder der öffentlichen Verwaltung beruhen.
You need to be fairly compensated etc., but the employer gets first rights. (and fairly does not necessarily mean market value)

The rules apply independent of which device you're using though. Compensation might differ slightly, but the rules around that are longer than the law itself :)

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#100

Earlier quoted context omitted.

Please see the link I added. You should check your employment contract to see the exact terms of the copyright assignment clause you signed, but it's definitely very common to have to assign any inventions you make that are "related to your employers area of work", regardless of what hardware you use or if you do it in the office or at home.

Well who signs contracts like these? I mean really? And why? I really cannot understand anybody giving away that much of their live for an employer/the next paycheck. Yeah - if I am really, really in a tight spot financially - for as long as it takes to crawl out of such a mess - ok. But regularly? Long term? Help me to understand. And I also do not understand how a company could find this morally acceptable to have…

A bird in the hand is worth two in the bush.

I'd rather get paid more today than take a lower salary with the potential to possibly, if I'm really lucky, strike gold with my own invention.

Post reply on HN