Live data from Hacker News

Apple is making corporate ‘BYOD’ programs less invasive to user privacy

techcrunch.com

101–110 of 148 posts

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#102

Earlier quoted context omitted.

Please see the link I added. You should check your employment contract to see the exact terms of the copyright assignment clause you signed, but it's definitely very common to have to assign any inventions you make that are "related to your employers area of work", regardless of what hardware you use or if you do it in the office or at home.

Well who signs contracts like these? I mean really? And why? I really cannot understand anybody giving away that much of their live for an employer/the next paycheck. Yeah - if I am really, really in a tight spot financially - for as long as it takes to crawl out of such a mess - ok. But regularly? Long term? Help me to understand. And I also do not understand how a company could find this morally acceptable to have…

> Well who signs contracts like these? I mean really? And why? I really cannot understand anybody giving away that much of their live for an employer/the next paycheck.

The outrage is a bit funny, because that's actually the law in Germany. It doesn't even need to be in the contract. (1) And if you think about it, it makes sense: Otherwise every employee who finds something patentable during working hours just clocks out, goes home and invents it "on his own time." And that would be a problem for an employer, too. So the deal is "employer pays you, and gets first dibs on whatever you invent in the general area that the employer pays you to work in."

(1) https://www.gesetze-im-internet.de/arbnerfg/index.html

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#103

Earlier quoted context omitted.

It is a burden however, and one that isn't necessary if your company has a sane BYOD policy that protects them while not being too invasive. The reality is, convenience wins again here. I, for one, don't give a shit what control my company has over my phone. Not only has nothing ever happened as a result of me using a BYOD policy, the overall rate in the industry seems acceptably low too. I only have 24 hours in my d…

What do you consider an acceptably low rate, and what is the actual rate? I hear stories all the time about companies that are tracking their employees' GPS locations. Many of the stories involve people getting fired.

Literally no you don't.

What happens more often: car accidents due to speeding or people being fired because their company tracks where they are and doesn't approve? Do you still speed?

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#104
post #73

Earlier quoted context omitted.

It is a burden however, and one that isn't necessary if your company has a sane BYOD policy that protects them while not being too invasive. The reality is, convenience wins again here. I, for one, don't give a shit what control my company has over my phone. Not only has nothing ever happened as a result of me using a BYOD policy, the overall rate in the industry seems acceptably low too. I only have 24 hours in my d…

The burden of having two devices seems lower than the burden of having to separate work from private life on a single device.

It's not, by far.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#105

Earlier quoted context omitted.

Which regulation requires spyware on endpoints, and where in the text does it say that?

In Germany for example most companies in the automotive space require all contractors to conform to the [TiSAX]( https://enx.com/tisax/tisax-en.html ) regulations. These state, that there needs to be proof of several data security aspects on all devices of all people working in a facility for one of these companies/clients as a contractor: - Anti Virus software up to date - Firewall active - Harddisk encrypted - Abil…

What kind of anti-virus is required on a Mac? (Not debating, just curious.) I work for a FAANG on fairly sensitive projects and I’ve never heard of anyone in my org having anti-virus. FileVault, remote wipe, etc., but not anti-virus. Are their credible anti-virus systems form Mac and Linux?

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#106
post #88

Earlier quoted context omitted.

I agree in general. And I do not get the BYOD thing. As another commenter said, an employer should provide the tools necessary. Or live with the constraints. I am in another camp. Until recently my employer had a policy of treating our devices somewhat like private devices. We are provided with the device, are allowed to use them at home at will, are full admins. We are only requested to encrypt the harddrive. My emp…

>And I do not get the BYOD thing. I get it. My employer provided phone is a Blackberry Leap.

Can it receive calls and read e-mails?

If so, that should be all my employer expects of me when I'm provided with a company phone. I can't imagine what they would want me to do that would require a smartphone. Anything more complicated would be better accomplished on a laptop.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#107
post #21

> Using the per-app VPN feature, traffic from the Mail, Contacts and Calendars built-in apps will only go through the VPN if the domains match that of the business. Shame that Apple doesn't take this one step further and do it system-wide.

If you mean you want a VPN to auto-connect when certain domains are used, I'm pretty sure this feature already exists since at least iOS 8. See https://developer.apple.com/business/documentation/Configura... and go to page 95, where it describes the OnDemandRules key for VPN configuration, which supports matching criteria based on domain names, SSID, interface type, and server reachability. EDIT: I misunderstood. The…

This should also be possible AFAIK, though I haven't put it into practice: https://developer.apple.com/documentation/networkextension/n...

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#108
post #28

It feels like an over engineered solution for a simple problem. If Apple were instead to add multi-users support to iOS then it would be as simple as having a work identity with dedicated apps and segregated data, and a personal identity as such, invisible to IT.

The problem is that most MDM solutions want to take over your device. At my employer, the MDM solution literally takes over your entire device. I've installed the solution on an iPhone, and a Samsung Galaxy S8 (with and without Knox) with the same result. Unfortunately, the result is I carry two phones instead of one. I think Apple's solution to the problem might work. As long as the companies data is separate from m…

> I think Apple's solution to the problem might work.

It might. As long as IT/Security can be convinced that it fulfills their goals. That doesn't seem like a sure thing.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#109
post #14

Earlier quoted context omitted.

I'm using Android (Pixel 3), and the work profile works for me. IMO it is much better than having to carry two phones.

Is it something different than just a separate local account?

They allow your workplace to remotely administer your work account without giving them full control over your whole device.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#110

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

I agree in general. And I do not get the BYOD thing. As another commenter said, an employer should provide the tools necessary. Or live with the constraints. I am in another camp. Until recently my employer had a policy of treating our devices somewhat like private devices. We are provided with the device, are allowed to use them at home at will, are full admins. We are only requested to encrypt the harddrive. My emp…

I’m going to guess the new employer is Deutsche Post DHL Group?

I’m basing this on you mentioning being in Germany and company size. Off topic, but I just went down a small rabbit hole of employers with >400k employees and there’s not many, most of them are either state owned/militaries (I’m assuming Russia’s Gasprom doesn’t have many German employees) or Walmart/McDonald’s (which has far more employees than 470k).

For anyone interested I guessed based on this article. https://www.lovemoney.com/galleries/amp/67573/the-worlds-30-...

Post reply on HN