Live data from Hacker News

Don’t Put Your Work Email on Your Personal Phone

onezero.medium.com

91–100 of 278 posts

Re: Don’t Put Your Work Email on Your Personal Phone

#93

Earlier quoted context omitted.

How does one know if an employer is abusing MDM? Honest question... I have no idea. I just point my iPhone's mail app at our Outlook 365 server and that's it - I assume that installs a profile that allows them some remote access (I believe they can remote wipe the phone, but maybe not), but no idea how to tell if they're doing anything else. Edit - looking at Settings->General->Profiles, there is one entry, which is…

Generally MDM software swallows up everything. It's been a while since I managed an MDM instance but we could track everywhere the employee went by default and when I suggested we turn it off there wasn't an option nor did management want to. We could see every app pretty much everything on the device. I will never install MDM on my phone after managing it. I've also seen phones accidentally wiped. Back up your phone…

Does turning off location on your phone mitigate their tracking of where employees go? I realize the other problems are still there, but I'm wondering if that would help. I turn on location on my phone once in a blue moon when an app gets too damn annoying that I actually need to use right then.

Re: Don’t Put Your Work Email on Your Personal Phone

#94

Earlier quoted context omitted.

That is totally understandable, and I hope you don't get in trouble when law enforcement comes looking for your personal device that somehow got caught up in their list of devices to look for.

You watch too many movies.

I've been a party to too many situations where this sort of thing happens.

I'm not making this up, y'all; I've sat there with the other side's data collection party when my boss was telling me to let him collect the data.

Re: Don’t Put Your Work Email on Your Personal Phone

#95
post #21

This is certainly a very good reason to not put your work account on your personal phone, but my primary reason not to is that it's my device and I pay for the service. If my company needs me to be available beyond my 9-5 workday, they can pay for it. If there's an emergency, they can always call, but I don't like being "always on".

I recently got a new job where the email is completely locked down (only accessible on a networked computer or via the awful outlook web interface). It's been awesome not getting work emails on my phone.

Same here. If I have to VPN in I’m less inclined to look at email outside of work.

Re: Don’t Put Your Work Email on Your Personal Phone

#96
post #21

This is certainly a very good reason to not put your work account on your personal phone, but my primary reason not to is that it's my device and I pay for the service. If my company needs me to be available beyond my 9-5 workday, they can pay for it. If there's an emergency, they can always call, but I don't like being "always on".

Exactly- if work doesn't pay, they don't get to play on my phone. I'd be willing to check work email sporadically, and it's unfortunate that doing so in any capacity means allowing an unknown admin "wipe my phone" privileges. Companies don't handle that stuff with any sort of finesse and mistakes happen. Ultimately email on a phone may be a moot point for software developers: We use more independent chat apps like Slack, no one worries about texting you, and it's hard to do anything really more involved than messaging without opening your laptop (which probably is provided by work).

Re: Don’t Put Your Work Email on Your Personal Phone

#98
post #34

Our company uses G Suite's Advanced MDM on a G Suite Enterprise account. I administer its configuration. Unless I'm missing something, there's not an obvious way to "spy" on employees, which this article is claiming. Perhaps it's possible, but if it is, it would require a lot of deliberate effort to accomplish. For example, there's not an out of the box way to track employee location. There's not a way to track emplo…

Same, we use gsuite MDM for BYOD just to ensure that personnel's devices have basic security configurations (e.g. encryption, lock screen, etc.) Beyond that, this MDM is quite limited to what's possible to accomplish.

Re: Don’t Put Your Work Email on Your Personal Phone

#99
post #38

This is not about work email, this is about MDM software. The title is confusing.

There are a lot of companies that require you to enable MDM before you can setup an email account, I've seen it on android back in the day when I had a smartphone.

FWIW when that happened I just started using the cruddy web interface.

Re: Don’t Put Your Work Email on Your Personal Phone

#100
post #49

Earlier quoted context omitted.

>There's not a way to track employee internet browsing history out of the box. Some large enterprises use MDM to deploy certificates and proxy policies that essentially force you into a MitM situation, with the intention of tracking browser usage. Location is a bit more tricky. I would say that's less common, but I've seen MDM solutions that offer location tracking as a feature

Yes, there are probably sketchy MDM providers that specialize in employee tracking / spying. I'm speaking to what's possible to accomplish out of the box with G Suite's Advanced MDM offering, without an extreme amount of additional effort. (This is relevant because, when prompted to install a MDM profile, the MDM provider such as G Suite is visible to the end user)

I mention this because one of the top use cases for MDMs is deploying said MitM setups. It's common in certain industries, like for banks and for schools. Saying this from experience because I worked for a company that produced both an MDM product and a MitM product.

For an MDM solution on iOS there's a big list of supported profiles you can deploy after the MDM profile is installed ( see https://developer.apple.com/business/documentation/MDM-Proto... under "request types").

If the device belongs to the organization, you might not even know these profiles are installed, if it's a BYOD environment you know you are installing the MDM profile and if you open the settings page you can manually inspect which other sub-profiles have been installed by the MDM.

But you're right the MitM itself isn't built into the MDM, because that's a totally different product category ("Secure Web Gateway"). The MitM setup only works if you have an MDM to enforce the certificates and proxy setup upon the user.

Post reply on HN