Live data from Hacker News

Apple is making corporate ‘BYOD’ programs less invasive to user privacy

techcrunch.com

121–130 of 148 posts

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#121

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

If you need it for work and are not an independent contractor then should pay for it.

BYODTEI

BYOD are a cost cutting measure by the office, but if you buy a second device then the cost isn't cut, it's transfered. To you. So congratulations on your pay decrease.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#122
post #98

Earlier quoted context omitted.

Which regulation requires spyware on endpoints, and where in the text does it say that?

Lots of them. It's under reasonable and appropriate security measures. You say spyware; I say software that guarantees there is a password, that there is a reasonable lock-out time, that encryption is enabled, etc. Leaking data because you let your most gullible employee install whatever he or she liked on their laptop and phone (eg facebooks spyware certs so they can read all your traffic) is going to get you in tro…

> You say spyware; I say software that guarantees there is a > password, that there is a reasonable lock-out time, that > encryption is enabled, etc.

I am undecided if in the end the additional software is a net positive. I am totally on your side that some basic security measures need to be enforced. And I know that this might be possible in terms of culture and processes like onboarding with a small number of employees.

And I know, that in a global corp this isn't feasible.

Non the less am I not sure that just throwing software at a basic problem of awareness really helps in the end. Esp. if the to be enforced standards like ISO 27001 are in some cases weakening the security.

I am enforced to use shorter passwords now. And I need to rotate them after a specific amount of time. I automatically have software installed (because next to security stuff we get some additional software) that does not exactly have a reputation of being secure.

So while there is light there is also quite some shadow.

If in the end this proves to be net positive. We will have to wait and see.

Any yes: I call it spyware. It has its own SSL certs, could potentially open my connections, monitors all and every connection my device makes, can (without me knowing) download any file on my device. And also can plant any file on my device without my knowledge.

As root it can add any additional functionality without my knowledge. And it does, as far as I have been told, scan any network I connect to for unmanaged devices and transmits (to quote) "a rich set of information for the located assets, including the hostname, MAC and IP addresses, device manufacturer, operating systems, open ports, applications, and historical information such as the first and last time the asset was seen on the network."

And it is not only being marketed as being compliant to GDPR, but actively helping and supporting companies to become compliant with this exact feature.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#123
post #94

Earlier quoted context omitted.

I agree in general. And I do not get the BYOD thing. As another commenter said, an employer should provide the tools necessary. Or live with the constraints. I am in another camp. Until recently my employer had a policy of treating our devices somewhat like private devices. We are provided with the device, are allowed to use them at home at will, are full admins. We are only requested to encrypt the harddrive. My emp…

I am the employer in this situation. The problem was that 1 - some employees do not read policies (despite some really explicit training during onboarding) and disable the password so they don't have to type it during login; 2 - apple software is hot shit and somehow filevault disabled itself on an employee laptop. I'm 100% sure that it was previously enabled. It required multiple support calls, an OS reinstall, and…

Why not let go of said idiot and keep the culture as it was? Why ruin it for everybody because of one bad apple? Why punish everybody and send a sign of mistrust to everybody for one idiot?

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#124

Earlier quoted context omitted.

Me being in Germany and clearly not a lawyer. That said: I own all my intellectual property, of everything I develop in my free time on this device. And in Germany, at least as far as I am aware, these broad regulations some US employers try to force on their employees have been thrown out by court decisions. But not sure on that. I would not work for a company that would try to ensure it owns all of what I do outsid…

> Me being in Germany and clearly not a lawyer. That said: I own all my intellectual property, of everything I develop in my free time on this device. > I would not work for a company that would try to ensure it owns all of what I do outside of company time. You might want to read the laws governing this, notably the "Gesetz über Arbeitnehmererfindungen" ( https://www.gesetze-im-internet.de/arbnerfg/ ) It's fairly sh…

> a lot of what you can invent is already owned by your employer by law

I recommend § 18 and § 19 of said "Gesetz über Arbeitnehmererfindungen". They state that inventions that are clearly not done on the employers payroll (to paraphrase this) are so called free (you have to enable your employer to make that call and you could dispute him, if he tries to claim said invention) (§§18).

But you need to enable your employer to use said (free) invention with reasonable terms - but you dictate the terms (§§19). Your employer can dispute the conditions and a court of law then has to decide.

So clearly this law does not enable your employer to claim nearly every invention you could make in your free time.

At least as far as my understanding goes. But I might be totally wrong here. I am somewhat out of my experience here.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#125

Earlier quoted context omitted.

Well who signs contracts like these? I mean really? And why? I really cannot understand anybody giving away that much of their live for an employer/the next paycheck. Yeah - if I am really, really in a tight spot financially - for as long as it takes to crawl out of such a mess - ok. But regularly? Long term? Help me to understand. And I also do not understand how a company could find this morally acceptable to have…

> Well who signs contracts like these? I mean really? And why? I really cannot understand anybody giving away that much of their live for an employer/the next paycheck. The outrage is a bit funny, because that's actually the law in Germany. It doesn't even need to be in the contract. (1) And if you think about it, it makes sense: Otherwise every employee who finds something patentable during working hours just clocks…

As already answered on another comment. This law does not enable an employer to claim every employees (patentable) invention. Please read the text - especially on the so called free inventions.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#126

Earlier quoted context omitted.

> Well who signs contracts like these? I mean really? And why? I really cannot understand anybody giving away that much of their live for an employer/the next paycheck. The outrage is a bit funny, because that's actually the law in Germany. It doesn't even need to be in the contract. (1) And if you think about it, it makes sense: Otherwise every employee who finds something patentable during working hours just clocks…

As already answered on another comment. This law does not enable an employer to claim every employees (patentable) invention. Please read the text - especially on the so called free inventions.

This is essentially in line what the article linked and the post to which you responded claims: inventions related to your assigned field of work are claimable.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#127

Earlier quoted context omitted.

Isn't that the case regardless of what laptop you're using? As far as I can tell you should assume any side projects are Copyright (c) your employer unless you talk to legal first and make an arrangement (for each project). See for example: https://www.joelonsoftware.com/2016/12/09/developers-side-pr...

No, what you do on your own time (not company time) with your own resources can't be owned by the company, because otherwise everything you do would be owned by the company, which is absurd; suppose I went to a friend or relative and helped him/her out by writing a simple script, does that belong to the company now? How about posts you make on HN outside of work (if you do it at work, that's... questionable)? The pos…

AFAIK, despite your work contract, CA protects personal projects even done on a company laptop. It just can’t be done on work hours or with a novel tool provided by work.

I’m paraphrasing an attorney’s explanations so I can’t cite the code.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#128
post #33
post #29

Earlier quoted context omitted.

The problem with employer-provided tools is that they sometimes barely meet the minimum requirements. Sure it gets the job done, but it’s no fun. I’d rather buy and manage my own device, which is then powerful enough for my needs.

Then it is time to change employer.

That’s a stupid hill to die on. Pick your employer based on important things like comp, work life balance, advancement opportunities, etc. If you have to fork over $300 to buy your own work phone then so be it, buy one and move on with your life.
Post reply on HN