Live data from Hacker News

Apple explicitly asks employees to merge their personal and work accounts

twitter.com

271–280 of 361 posts

Re: Apple explicitly asks employees to merge their personal and work accounts

#271
post #41

Earlier quoted context omitted.

Why are apple employees getting subpoenaed? Is this common at Apple?

Major companies are getting sued continually. It probably isn’t an individual person, but a product that a team or department worked on that is involved in the lawsuit.

How often is 'continually'? Is there any way to estimate how many times per year is each major company sued?

Re: Apple explicitly asks employees to merge their personal and work accounts

#272

Earlier quoted context omitted.

Perhaps this might help convince you: https://twitter.com/ashleygjovik/status/1426014545202479108

Thats a redacted screenshot by the person making the claim. Its not very convincing.

Are you familiar with Radar? It's an internal bug database that is used by all the teams inside of Apple. She redacted identifying information in the screenshot, but anyone with the appropriate amount of disclosure at Apple (several hundred, if not thousands of people) can go and look up the unredacted version where all the names and context is visible. Many with the ability to do so have confirmed it.

Re: Apple explicitly asks employees to merge their personal and work accounts

#273

Earlier quoted context omitted.

Okay, that makes a lot more sense. To be frank, this twitter thread seems sensationalist if reality is closer to "I didn't bother to create a separate work account" rather than "Apple asked me to merge my personal account".

I find it harmful to jump to a conclusion too early and blame the victim. Forcing someone to merge these accounts can take many forms and Apple has thousands of different teams and managers. Even if there was zero explicit or implicit force in place, the circumstances can still be non-obvious. If you get handed a MacBook, you're basically forced to work with an iCloud account. And the fact that making the mistake of…

> hands over data that was created before and outside the employment definitely points towards Apple abusing their position of power here.

Trust me, Apple legal would rather not dig through your personal information to find nuggets to hand to opposing counsel during discovery.

But if there's work information in your personal account, and Apple is legally compelled to go through accounts with work information as part of discovery... what's going to happen?

Re: Apple explicitly asks employees to merge their personal and work accounts

#274

Earlier quoted context omitted.

Okay, that makes a lot more sense. To be frank, this twitter thread seems sensationalist if reality is closer to "I didn't bother to create a separate work account" rather than "Apple asked me to merge my personal account".

I find it harmful to jump to a conclusion too early and blame the victim. Forcing someone to merge these accounts can take many forms and Apple has thousands of different teams and managers. Even if there was zero explicit or implicit force in place, the circumstances can still be non-obvious. If you get handed a MacBook, you're basically forced to work with an iCloud account. And the fact that making the mistake of…

> I find it harmful to jump to a conclusion too early and blame the victim.

The only victims I can possibly see here are those employees that had to review nude images inappropriately stored on a work computer.

Apple absolutely does not require that you use your personal iCloud account on your work machines, and any professional should know that it is inappropriate to browse, share, or store nude photos (of anyone) on company-owned hardware, and should never have placed their colleagues in a position of having to deal with those images.

Re: Apple explicitly asks employees to merge their personal and work accounts

#275

Earlier quoted context omitted.

Thats a redacted screenshot by the person making the claim. Its not very convincing.

Are you familiar with Radar? It's an internal bug database that is used by all the teams inside of Apple. She redacted identifying information in the screenshot, but anyone with the appropriate amount of disclosure at Apple (several hundred, if not thousands of people) can go and look up the unredacted version where all the names and context is visible. Many with the ability to do so have confirmed it.

> Many with the ability to do so have confirmed it.

Would you happen to have a link handy? I don't mean to be adversarial. That screenshot is just so incredibly outlandish that it comes across as something from an overdone movie and I honestly find it difficult to take at face value.

Basic human decency and social norms aside, I just can't comprehend what manager would fail to recognize something like that committed in writing as a huge legal liability.

Re: Apple explicitly asks employees to merge their personal and work accounts

#277
post #242

Earlier quoted context omitted.

I'm using a PinePhone right now and I hope I won't need to switch back to Android. I grew used to this freedom. However, I would recommend it only to the most determined people because many things don't work well. Forget GPS navigation. GPS does not get the correct location most of the time, AGPS only works through a hacky bash / python script. There is no good gps app anyway. The sms app on phosh is crashy and does…

> There is no good gps app anyway. Forget global positioning specifically, shouldn't a good OpenStreetMap atlas application without automatic positioning be feasible, if not presently available? Today it might feel like caveman technology, but it's not that long ago that having a high quality up-to-date world atlas that fits in your pocket would have been considered a considerable marvel. That such an atlas might als…

Let's forget GPS.

Well, you have those options which work well enough to be usable (you don't have pinch zoom, Gnome Maps takes a while to load, openstreetmap.org does not fit very good on mobile, both require an internet connection):

- openstreetmap.org

- GNOME Maps

Then you have Pure Maps. It allows offline maps using OSM Scout Server [2]. It seems good, however it overheats my PinePhone and crashes probably out of lack of resources. So I don't use it. It could be because of Flatpak, but I'm not sure.

As for how to build a good alternative, I see these possibilities:

- contribute to Pure Maps to make it more lightweight. Maybe it's just a matter of building native packages for distributions like Mobian and Manjaro.

- Look whether KDE has a good app for that. They have Marble on the desktop but I'm not sure there is a mobile version that works well yet so porting this to mobile could be a way. KDE apps are generally very high quality though Marble could use some refinement.

- using C++ and Qt/QML with its Map widget, and find a way to use OSM Scout Server to provide the tiles. Actually, Pure Maps is a QML app.

- build a minimal web page showing a Leaflet or a MapLibre widget, connected to a backend built using a compiled language like C++ or D, itself connecting to OSM Scout Server to provide the tiles. Or to OSM Scout Server directly if it is possible.

The last option is probably the most lightweight solution, provided you probably have a browser already running on your phone. I'm not saying this out of my ass by the way, I'm building an SMS app using Svelte for the user interface and D for the backend connecting to the modem and managing the SQLite database. It's way faster than chatty. Maybe don't use React though, this is heavy (Mattermost works but is almost unusable, Element (Matrix) works way better but you still feel latency everywhere).

[1] https://openrepos.net/content/rinigus/pure-maps

[2] https://rinigus.github.io/osmscout-server/

Re: Apple explicitly asks employees to merge their personal and work accounts

#278

Earlier quoted context omitted.

Are you familiar with Radar? It's an internal bug database that is used by all the teams inside of Apple. She redacted identifying information in the screenshot, but anyone with the appropriate amount of disclosure at Apple (several hundred, if not thousands of people) can go and look up the unredacted version where all the names and context is visible. Many with the ability to do so have confirmed it.

> Many with the ability to do so have confirmed it. Would you happen to have a link handy? I don't mean to be adversarial. That screenshot is just so incredibly outlandish that it comes across as something from an overdone movie and I honestly find it difficult to take at face value. Basic human decency and social norms aside, I just can't comprehend what manager would fail to recognize something like that committed…

Sure, here's one: https://twitter.com/vllry/status/1427360794925158425. I am not joking when I say many, many people had access to this–while I am not at Apple, I know people who are and they could see it too. (FWIW, I was on the Radar team previously, and this is exactly what it looks like–faking it this exactly would require a lot of effort.)

Re: Apple explicitly asks employees to merge their personal and work accounts

#279

Earlier quoted context omitted.

>Even the current CSAM implementation is actually all about privacy if you read the details on how it’s implemented. Lol, no.

Read this: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni... and tell me what's not about privacy with this? The alternative is upload everything unencrypted to providers who then scan there, which is how everything else works.

This is a ridiculous redefinition of the word, "privacy".

I don't need to read your marketing manual when there's no getting around the fact you are normalizing on-device scanning on personal devices and automated secret reporting to the authorities, which means iphones have now become adversarial.

Used to be that there was a clear delineation between a customer's device and a cloud server. Not anymore with Apple "privacy".

At least with Google I know that if I don't upload the photos to them, they're not scanning my device.

Just as a point of fact, there is zero point to encryption if Apple is able to access everything on icloud, which they can, because Apple doesn't allow you to do backups using a key that only you know.

That's just another one of Apple's penny-pinching scams so they can upsell customers on extra icloud space for backups which are also "encrypted", yet Apple can read everything.

Real privacy would mean real encryption, but then Apple couldn't do their upselling scam and also couldn't secretly scan all your personal stuff.

Re: Apple explicitly asks employees to merge their personal and work accounts

#280

Earlier quoted context omitted.

"I went so far as to carry two iPhones, one personal and the other "corporate," and I only ever used my "corporate" iPhone with Apple employee apps. I never even connected my personal phone to the campus WiFi; I used wireless data for that phone the entire time I was there." This is the way. Carry two devices. Separate personal/work devices. Never connect personal to corporate network. Never send messages between per…

> Don't do vacation research, medical research, social media, Spotify, anything personal at all on your work device. Ever. That's quite extreme. What is your threat model?

Is it really that extreme? Threat model, staying employed / defend against idle gossip.

Company surveillance (of their employees) is very real and unlike 'google reads all my emails' they actually can and do and it is a person they actually know whos private information they are viewing. I dont even need to get into the chance of every piece of information being in a lawsuit or get into the lack of any controls around data retention etc to be worried.

First step IT would take when I dropped my phone in 'because they had to run the update' - they would open my photos and take a look through. Second step - they would go to the deleted photos and have a look through. It was done as part of any company-mandated review of the device but out of personal 'curiosity'.

Every private message on teams etc was logged and routinely reviewed by a compliance team and often escalated to line managers - the team doing so knew everything professional and personal going on in the place. Who was getting hired, fired, promoted, working hard, slacking. Who was sleeping with someone, depressed, happy, gay, straight, having kids, getting divorced, getting a nose job, getting a vasectomy etc.

So whats the threat? I have nothing to hide, I am popular, a hard worker, not having an affair with the intern, so they are not going to trawl through looking for any dirt to diminish or fire me. There is little value in this information beyond gossip, but a permanent record remains all the same. For me there is little extra effort required to phone home from my phone rather than the recorded office line and that way the call wont be listened to by the guy in compliance.

Post reply on HN