Earlier quoted context omitted.
what company has 470k employees?
My guess is that he is talking about Accenture
Apple is making corporate ‘BYOD’ programs less invasive to user privacy
111–120 of 148 posts
Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy
#112Earlier quoted context omitted.
In Germany for example most companies in the automotive space require all contractors to conform to the [TiSAX]( https://enx.com/tisax/tisax-en.html ) regulations. These state, that there needs to be proof of several data security aspects on all devices of all people working in a facility for one of these companies/clients as a contractor: - Anti Virus software up to date - Firewall active - Harddisk encrypted - Abil…
What kind of anti-virus is required on a Mac? (Not debating, just curious.) I work for a FAANG on fairly sensitive projects and I’ve never heard of anyone in my org having anti-virus. FileVault, remote wipe, etc., but not anti-virus. Are their credible anti-virus systems form Mac and Linux?
It all about fulfilling IT and law checklists.
Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy
#113Earlier quoted context omitted.
But Apple wants you to buy your kids their own devices.
True, but it's also a pretty obnoxious form of nickle and diming for a company selling $1,000+ iPhones, and well worth complaining about. It’s also yet another way that locked-down devices allow manufacturers to advance their interests at the expense of consumers. There’s a Jailbreak tweak that enables multiple profiles...
Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy
#114Earlier quoted context omitted.
Isn't that the case regardless of what laptop you're using? As far as I can tell you should assume any side projects are Copyright (c) your employer unless you talk to legal first and make an arrangement (for each project). See for example: https://www.joelonsoftware.com/2016/12/09/developers-side-pr...
I want to be clear that my question relates to artifacts you produce on company-owned resources - not just in your own time on your own machine. Legal precedence around IP ownership - when you've used company-owned machines - is far less clear.
Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy
#115Will Apple employees will be allowed to use this program? They're notoriously paranoid about maintaining secrets. Wonder if their IT department would give up the control.
There were a few (software) restrictions placed on the devices, namely that you had to have password lock turned on, and a password complexity policy. But after that they really did not interfere at all. When I left I reset that phone myself, and then bought a new iPhone and used the backup (not including OS) of that phone off of iCloud (of course minus the Apple email account they just turned off, and a couple of Apple-only apps I was using).
Other than some basic access controls on systems (especially around iOS sources), and a lot of prototype-asset-tracking (I ran a lab with a lot of that), Apple really does trust their developers to do the right thing. If they trust you to have the information, then they trust you not to share it without a lot of big-brother monitoring.
And there really is very little in the way of an IT department at Apple as you would normally think of it. They provided the network and the printers, but setting up your own computer was usually up to you and whatever help you got from your team (who really were the ones who knew what you needed for resources).
Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy
#116An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…
It's also worthwhile to set up a separate home LAN for work stuff. This not only protects you, but it also ensures that work data is kept away from roommates, guests, etc. Prosumer-level routers and access points like Ubiquiti can broadcast multiple SSIDs and tag traffic on each with a different VLAN. Not at all hard to set up and definitely worth the peace of mind.
Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy
#117Earlier quoted context omitted.
In Germany for example most companies in the automotive space require all contractors to conform to the [TiSAX]( https://enx.com/tisax/tisax-en.html ) regulations. These state, that there needs to be proof of several data security aspects on all devices of all people working in a facility for one of these companies/clients as a contractor: - Anti Virus software up to date - Firewall active - Harddisk encrypted - Abil…
What kind of anti-virus is required on a Mac? (Not debating, just curious.) I work for a FAANG on fairly sensitive projects and I’ve never heard of anyone in my org having anti-virus. FileVault, remote wipe, etc., but not anti-virus. Are their credible anti-virus systems form Mac and Linux?
I strongly believe all this software only enlarges the potential attack surface.
Not sure if this "zoo" of software is more of a security theater and a legal protection to be able to tell everybody "we did all we could possibly do" in case of an attack/hack/what not.
But even if I strongly suspect my device was more secure before, I know, that lot's of less tech-savvy people will have at least some standard (encrypted SDD, and such) enforced. So I am not yet decided if in the end the net benefit is positive.
Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy
#118Earlier quoted context omitted.
I didn't read TFA fully but I suppose from your quote, what they didn't say was what corporate IT fears. I don't know how many corps care about this, but when I did that kind of job, I refuse to have my corp have access to a user's personal data, and be able to brick their personal device, etc. It's not acceptable from a privacy POV and not acceptable from an employee backlash POV. Anyway it was an easy choice becaus…
In addition, customers are starting to require their vendors who have access to their data institute MDM. So it's increasingly MDM or two separate devices.
I say my view of it isn't comprehensive, but a requirement that all devices be under MDM even if those devices don't have access to customer data, is quite an overreach.
Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy
#119Earlier quoted context omitted.
The problem with employer-provided tools is that they sometimes barely meet the minimum requirements. Sure it gets the job done, but it’s no fun. I’d rather buy and manage my own device, which is then powerful enough for my needs.
You're doing it on their time, not yours. If they don't want you to be productive, you don't have to be.
Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy
#120Earlier quoted context omitted.
In addition, customers are starting to require their vendors who have access to their data institute MDM. So it's increasingly MDM or two separate devices.
The requirements I've read (obvi not comprehensive superset) all require this only for, as you say, access to their data . If you're not accessing the customer data via mobile device, you don't need MDM. I say my view of it isn't comprehensive, but a requirement that all devices be under MDM even if those devices don't have access to customer data, is quite an overreach.
Given the general situation with data breaches and so forth, I wouldn't be shocked if, down the road, more and more companies decide that there's just too much risk with BYOD and require employees to use locked-down company-provided devices.