Live data from Hacker News

Apple is making corporate ‘BYOD’ programs less invasive to user privacy

techcrunch.com

141–148 of 148 posts

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#141
post #138

Earlier quoted context omitted.

If the other employer pays more or works you less you should move anyway, BYOD or not. If the other employer e.g pays less then you’re an idiot to take a 5 figure paycut or work 10 extra hours a week just to avoid buying a $300 phone. BYOD policies are irrelevant in the grand scheme of career planning.

In the grand scheme of things, one should not weight only BYOD policies, but they are certainly a red herring, a sign of employers that don't give a damn.

That’s not what a red herring is, but you are correct that it is a red herring.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#142
post #88

Earlier quoted context omitted.

>And I do not get the BYOD thing. I get it. My employer provided phone is a Blackberry Leap.

Can it receive calls and read e-mails? If so, that should be all my employer expects of me when I'm provided with a company phone. I can't imagine what they would want me to do that would require a smartphone. Anything more complicated would be better accomplished on a laptop.

>Can it receive calls and read e-mails?

Barely.

But there's more to it than that. I can't use the browser to look work-related things up because the blackberry browser hasn't been updated in years. I end up using my own device which defeats the purpose.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#143
post #139

Earlier quoted context omitted.

> You say spyware; I say software that guarantees there is a > password, that there is a reasonable lock-out time, that > encryption is enabled, etc. I am undecided if in the end the additional software is a net positive. I am totally on your side that some basic security measures need to be enforced. And I know that this might be possible in terms of culture and processes like onboarding with a small number of emplo…

fwiw, I've done SOC-x stuff, and I talked our auditors out of requiring routine password changes. That said, we seriously invested in 2fa, with high-pri stuff protected via yubicos. I also talked them out of requiring virus detection on our macs, but this took a lot of work to avoid trusting (most) laptops.

I can see this approach as something quite interesting. Suspect it would not work in our current environment. But we will have to see.

But also thanks a lot for the idea to do this and try that. Not sure if it works with being ISO 27001 certified - but at least one can try.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#144

Earlier quoted context omitted.

> I am not willing to introduce spyware that also scans all devices within the network to my home network. In the EU I would seriously doubt that your employer is allowed to do this.

Why not? It’s a company device, if you don’t want your employer to access your network through it, don’t connect it to your network. You can hardly blame them for administering their own device.

If an employer expected me to use such a device I would assume that they would also pay for me to have a separate internet connection (this could easily be tethering to my work provided mobile data).

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#145

Earlier quoted context omitted.

Why not? It’s a company device, if you don’t want your employer to access your network through it, don’t connect it to your network. You can hardly blame them for administering their own device.

If an employer expected me to use such a device I would assume that they would also pay for me to have a separate internet connection (this could easily be tethering to my work provided mobile data).

If you have a decent router you can just create an isolated network for devices you don’t trust.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#146

An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use. There's no way I'm letting my employer administer or install unknown programs on my personal laptop and cell even with this enrollment option. This has nothing to do with trusting or distrusting Apple. It's due to avoiding complexity: having to think about a zilli…

>An obvious solution is to carry two devices: one for work, on which the company can install whatever corporate spyware they want, and one for personal use.

I've lived under both regimes, and definitely preferred the multiple device one. It had its moments of inconvenience, but I loved putting the work phone in a drawer on Friday night and leaving it there until Monday morning.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#147
post #120

Earlier quoted context omitted.

The requirements I've read (obvi not comprehensive superset) all require this only for, as you say, access to their data . If you're not accessing the customer data via mobile device, you don't need MDM. I say my view of it isn't comprehensive, but a requirement that all devices be under MDM even if those devices don't have access to customer data, is quite an overreach.

That may be, but at many companies, many if not the majority of their employees are going to have access to some information that their customers consider confidential. As a result, it's easier to have a blanket policy. Given the general situation with data breaches and so forth, I wouldn't be shocked if, down the road, more and more companies decide that there's just too much risk with BYOD and require employees to…

Agree, it's easier for the company to have a blanket policy. And most companies will do that because, ain't nobody got time for [being overly competent]. But what I said was that the actual requirement given to vendors is, in my limited experience, written to apply only for access to customer data. That is, it is the implementation that is overly broad, not the requirement being passed down.

Re: Apple is making corporate ‘BYOD’ programs less invasive to user privacy

#148

Earlier quoted context omitted.

If an employer expected me to use such a device I would assume that they would also pay for me to have a separate internet connection (this could easily be tethering to my work provided mobile data).

If you have a decent router you can just create an isolated network for devices you don’t trust.

Sounds like something I would need my work to pay for...
Post reply on HN