Live data from Hacker News

Apple is making corporate ‘BYOD’ programs less invasive to user privacy

techcrunch.com

131–140 of 148 posts

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#131

Earlier quoted context omitted.

> Me being in Germany and clearly not a lawyer. That said: I own all my intellectual property, of everything I develop in my free time on this device. > I would not work for a company that would try to ensure it owns all of what I do outside of company time. You might want to read the laws governing this, notably the "Gesetz über Arbeitnehmererfindungen" ( https://www.gesetze-im-internet.de/arbnerfg/ ) It's fairly sh…

> a lot of what you can invent is already owned by your employer by law I recommend § 18 and § 19 of said "Gesetz über Arbeitnehmererfindungen". They state that inventions that are clearly not done on the employers payroll (to paraphrase this) are so called free (you have to enable your employer to make that call and you could dispute him, if he tries to claim said invention) (§§18). But you need to enable your emplo…

You should reread the part I quoted above. It defines the terms used in §18/19: It’s §4(2) https://www.gesetze-im-internet.de/arbnerfg/__4.html it doesn’t talk about payroll or not payroll, it’s all about how related to your work assignment the invention is. The rules and regulations around calculating a fair compensation even grade on that exact metric among other things. So it’s essentially what the work contracts stipulate: inventions related to your work belong to your employer, even if done in your off time.

The problem in IT is that depending on what you do, everything might be related to a varying degree.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#132

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

But then how can we install the right certificates for the enterprise ssl man in the middle proxy? Which we obviously need to check your traffic for viruses and we definitely don’t log anything that will ever leak! Besides, if you aren’t doing anything wrong, why do you have so much to hide anyway? /s

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#133

Earlier quoted context omitted.

I agree in general. And I do not get the BYOD thing. As another commenter said, an employer should provide the tools necessary. Or live with the constraints. I am in another camp. Until recently my employer had a policy of treating our devices somewhat like private devices. We are provided with the device, are allowed to use them at home at will, are full admins. We are only requested to encrypt the harddrive. My emp…

> I am not willing to introduce spyware that also scans all devices within the network to my home network. In the EU I would seriously doubt that your employer is allowed to do this.

Why not? It’s a company device, if you don’t want your employer to access your network through it, don’t connect it to your network. You can hardly blame them for administering their own device.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#134
post #94

Earlier quoted context omitted.

I agree in general. And I do not get the BYOD thing. As another commenter said, an employer should provide the tools necessary. Or live with the constraints. I am in another camp. Until recently my employer had a policy of treating our devices somewhat like private devices. We are provided with the device, are allowed to use them at home at will, are full admins. We are only requested to encrypt the harddrive. My emp…

I am the employer in this situation. The problem was that 1 - some employees do not read policies (despite some really explicit training during onboarding) and disable the password so they don't have to type it during login; 2 - apple software is hot shit and somehow filevault disabled itself on an employee laptop. I'm 100% sure that it was previously enabled. It required multiple support calls, an OS reinstall, and…

Yeah that never happened with Microsoft’s Bitlocker

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#135

Earlier quoted context omitted.

> while still being officially allowed to take the devices home with us, use them privately and so on. Who owns the rights to IP developed on these company-owned laptops? One of the biggest problems with this kind of ‘unspoken flexibility’ is that any side projects you work on are in-part owned by the company, under most standard agreements.

Me being in Germany and clearly not a lawyer. That said: I own all my intellectual property, of everything I develop in my free time on this device. And in Germany, at least as far as I am aware, these broad regulations some US employers try to force on their employees have been thrown out by court decisions. But not sure on that. I would not work for a company that would try to ensure it owns all of what I do outsid…

> And in Germany, at least as far as I am aware, these broad regulations some US employers try to force on their employees have been thrown out by court decisions. But not sure on that.

Would be interested to hear about specific court decisions!

In general, this topic is not quite so clear, even in Germany. For a contrary argumentation, have a look at: https://www.lieb-online.com/files/luxe/publikationen/Urheber... (covers both Urheberrecht and Patentrecht, 15 pages, argues seemingly mostly in favour of the employer, but that does not mean they are wrong)

Keywords to search for, if you don't have the time now to read it as a whole:

- Freizeitwerk / freiwilliges Werk (it's a difference! but just because you do something in your freetime it is not necessarily a Freizeitwerk, in case your job is to produce such works and it could be of use to your employer, this is arguably not the case)

- Beweislast (just because you say or mean it to be unrelated to work, does not automatically mean it is -- side note: the bigger your employer, the less you can know about what is in their interest or not)

- Anbietungspflicht (describes the case using work ressources / work time)

- Pflicht zur Anbietung (for the free time stuff which is not "totally unrelated to the interests of your employer" -- so "automatic transition of usage rights via contract" is indeed suspicious and likely to be undermined in court, but they have a say if they want it)

Sounds somewhat like slavery indeed. ;)

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#136
post #33

Earlier quoted context omitted.

Then it is time to change employer.

That’s a stupid hill to die on. Pick your employer based on important things like comp, work life balance, advancement opportunities, etc. If you have to fork over $300 to buy your own work phone then so be it, buy one and move on with your life.

Yep, move on with my life to another employer.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#137
post #136

Earlier quoted context omitted.

That’s a stupid hill to die on. Pick your employer based on important things like comp, work life balance, advancement opportunities, etc. If you have to fork over $300 to buy your own work phone then so be it, buy one and move on with your life.

Yep, move on with my life to another employer.

If the other employer pays more or works you less you should move anyway, BYOD or not. If the other employer e.g pays less then you’re an idiot to take a 5 figure paycut or work 10 extra hours a week just to avoid buying a $300 phone. BYOD policies are irrelevant in the grand scheme of career planning.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#138
post #136

Earlier quoted context omitted.

Yep, move on with my life to another employer.

If the other employer pays more or works you less you should move anyway, BYOD or not. If the other employer e.g pays less then you’re an idiot to take a 5 figure paycut or work 10 extra hours a week just to avoid buying a $300 phone. BYOD policies are irrelevant in the grand scheme of career planning.

In the grand scheme of things, one should not weight only BYOD policies, but they are certainly a red herring, a sign of employers that don't give a damn.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#139
post #98

Earlier quoted context omitted.

Lots of them. It's under reasonable and appropriate security measures. You say spyware; I say software that guarantees there is a password, that there is a reasonable lock-out time, that encryption is enabled, etc. Leaking data because you let your most gullible employee install whatever he or she liked on their laptop and phone (eg facebooks spyware certs so they can read all your traffic) is going to get you in tro…

> You say spyware; I say software that guarantees there is a > password, that there is a reasonable lock-out time, that > encryption is enabled, etc. I am undecided if in the end the additional software is a net positive. I am totally on your side that some basic security measures need to be enforced. And I know that this might be possible in terms of culture and processes like onboarding with a small number of emplo…

fwiw, I've done SOC-x stuff, and I talked our auditors out of requiring routine password changes. That said, we seriously invested in 2fa, with high-pri stuff protected via yubicos.

I also talked them out of requiring virus detection on our macs, but this took a lot of work to avoid trusting (most) laptops.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#140
post #94

Earlier quoted context omitted.

I am the employer in this situation. The problem was that 1 - some employees do not read policies (despite some really explicit training during onboarding) and disable the password so they don't have to type it during login; 2 - apple software is hot shit and somehow filevault disabled itself on an employee laptop. I'm 100% sure that it was previously enabled. It required multiple support calls, an OS reinstall, and…

Why not let go of said idiot and keep the culture as it was? Why ruin it for everybody because of one bad apple? Why punish everybody and send a sign of mistrust to everybody for one idiot?

one idiot, and one serious macos bug (re: disabling filevault)

And the answer roughly comes down to (1) it trained me out of trusting, even in a small shop; and (2) now that I know these things happen, I have to protect against them. If I abuse what the mdm gives me, I expect my employees to fire me. ie quit.

Post reply on HN