Live data from Hacker News

Don’t Put Your Work Email on Your Personal Phone

onezero.medium.com

211–220 of 278 posts

Re: Don’t Put Your Work Email on Your Personal Phone

#211
post #21

This is certainly a very good reason to not put your work account on your personal phone, but my primary reason not to is that it's my device and I pay for the service. If my company needs me to be available beyond my 9-5 workday, they can pay for it. If there's an emergency, they can always call, but I don't like being "always on".

Yeah, my last job wanted me to install their rootkit/spyware on my personal phone for the privilege of being able to check my work email at night. I resolved this by letting my manager know how to contact me after hours in the event of an absolute emergency, and that otherwise I'll check my messages at the office when I get in to work.

Re: Don’t Put Your Work Email on Your Personal Phone

#212

Funny story (well OK, not so funny), I worked at a company where the FBI decided to pay a visit and investigate some potential naughtiness performed by members of the senior staff. They asked questions such as "Do you use your cell phone and personal email for company matters." Guess what a lot of them said, "Yep, have to." That immediately made their personal equipment, etc. in scope for the investigation and they c…

"...don't know who you are really working with..." this resonates with me, I recently left a company of finding out that the recently hired VP was the Presidents favorite bar tender, he was also trying to coax her into a relationship. The VP had also backdated her resume and was claiming to have been at the company about 4 years prior to her actual arrival.

The back dating no doubt matched a back dated stock option grant that would allow her to claim that she was fully vested.

That is just fraud and the board of directors should be all over it (they would have visibility into the hiring of executive staff). Now if the company has no board, or the board is composed entirely of founders, this sort of stuff slides by. Best to avoid working in the future with anyone associated with the senior staff in future companies.

Re: Don’t Put Your Work Email on Your Personal Phone

#214

Funny story (well OK, not so funny), I worked at a company where the FBI decided to pay a visit and investigate some potential naughtiness performed by members of the senior staff. They asked questions such as "Do you use your cell phone and personal email for company matters." Guess what a lot of them said, "Yep, have to." That immediately made their personal equipment, etc. in scope for the investigation and they c…

> After hearing about that, I never attach anything work related to my personal equipment. There is too much liability.

Wait, didn't you just softly admit to some (any?) wrongdoing?

Re: Don’t Put Your Work Email on Your Personal Phone

#215

Earlier quoted context omitted.

> Maybe I should keep a Doesn't help you. Either your personal devices are in scope or not. If they are, then they all disappear and you're unlikely to get them back. Investigators don't trust the subjects of the investigation to tell them what devices are in scope or not. If your devices are in scope, they'll take everything that has any chance of having data on it. (Source: many many reports from subjects of such i…

In the FBI's defense, they did return all the equipment after they were done with it (if I remember correctly within like a day too). Funny enough though, one guy thought it was strange that after they gave his phone back, all of his text messages from then on were suddenly emailed to his work email also. Wouldn't happen to be that all email in the company was saved indefinitely due to the archiving server?

> All email in the company was saved indefinitely due to the archiving server

Not at all. Many companies actually do the opposite. A previous company I worked for had a 30 day email deletion policy, though we could setup special folders for 13 month retention on emails.

At another company, we were in the backup space and some enterprises had very restrictive backup and archive policies. One was to the point that our backup software was pretty much useless.

To limit liability, files that are not involved any ongoing legal issue such as a lawsuit are deleted as soon as possible without interrupting the business. Once there is a lawsuit, any relevant documents or emails can be deleted. This is all from the point of view for civil lawsuits. I assume gov't investigations are similar.

Re: Don’t Put Your Work Email on Your Personal Phone

#216

Funny story (well OK, not so funny), I worked at a company where the FBI decided to pay a visit and investigate some potential naughtiness performed by members of the senior staff. They asked questions such as "Do you use your cell phone and personal email for company matters." Guess what a lot of them said, "Yep, have to." That immediately made their personal equipment, etc. in scope for the investigation and they c…

> After hearing about that, I never attach anything work related to my personal equipment. There is too much liability. Wait, didn't you just softly admit to some (any?) wrongdoing?

Not even remotely. It’s good legal sensibility to avoid opening yourself up to unnecessary liability and investigation.

Re: Don’t Put Your Work Email on Your Personal Phone

#217

Funny story (well OK, not so funny), I worked at a company where the FBI decided to pay a visit and investigate some potential naughtiness performed by members of the senior staff. They asked questions such as "Do you use your cell phone and personal email for company matters." Guess what a lot of them said, "Yep, have to." That immediately made their personal equipment, etc. in scope for the investigation and they c…

Recently my employer has pushed for Okta Identity management. And somewhere in that plan they somehow thought appropriating employee personal phones was a good idea. Now we can't login to certain internal apps without a mobile device because Okta needs one time password/accepting push notification. And the otp/push notification should necessarily happen on a mobile device. Given that company hasn't provided any mobil…

My company recently required the use of a specific 2FA app that I didn't use in order to validate credentials on our laptops when accessing our VPN. I don't personally like having to put an app on my phone however, using an app to validate identity and using an app too conduct business are two very different things. I'm still considering requesting a physical token though...

Re: Don’t Put Your Work Email on Your Personal Phone

#218
post #107

Earlier quoted context omitted.

Slack, on my phone? Are you nuts? If you want me after hours you call. Thats the only option you have.

Are you, with a straight face, saying that you'd rather receive a PHONE CALL than a notification from an app that you can set time-sensitive notification methods for (i.e. DND overnight, etc.)? I'm not fan of getting any kind of work message outside of working hours, but I'd FAR rather let my co-workers send me a slack message that I can ignore and/or deal with when I feel like it than call me on the phone. No one at…

Yes I do. Why? It raises the bar. Its all too easy to whisper someone via electronic communication. If you need to get to speak to the person, and they hear my kid yelling at the background, perhaps they'll wonder if I got other things to do in my leisure time.

Furthermore, I don't find it particularly bright to host sensitive data by such a vague company. Bonus negative points for the infosec community using such.

Re: Don’t Put Your Work Email on Your Personal Phone

#219

Earlier quoted context omitted.

That's a good question. But as long as you don't save any files on your personal computer, it is just a transport device like a car that gets you to work. I'm guessing the law isn't that forward thinking though. Maybe I should keep a <$200 mini-PC, just to RDP into work so I have no problem giving up that machine.

> Maybe I should keep a Doesn't help you. Either your personal devices are in scope or not. If they are, then they all disappear and you're unlikely to get them back. Investigators don't trust the subjects of the investigation to tell them what devices are in scope or not. If your devices are in scope, they'll take everything that has any chance of having data on it. (Source: many many reports from subjects of such i…

Could I just have "work" buy me the $200 mini-PC for RDP sessions from home so that it is not a personal device?
Post reply on HN