Live data from Hacker News

Glassdoor not so anonymous

webworm.co

201–210 of 507 posts

Re: Glassdoor not so anonymous

#201
post #2

Glassdoor has posted a notice on ZURU's page regarding this: https://www.glassdoor.com.au/Reviews/ZURU-Reviews-E2286297.h... It appears a few other companies are doing this too, including Kraken ( https://www.kraken.com/ ) as you can see here: https://www.glassdoor.com.au/Overview/Working-at-Kraken-Digi... EDIT: If anyone from Glassdoor is reading this, please advise on a way to either unlink my profile from my ident…

> It appears a few other companies are doing this too, including Kraken ( https://www.kraken.com/ ) Kraken is still silly for going after them, IMO, but the Kraken case isn't as cut and dry. The person who had left the review on Kraken had accepted a large severance package that was conditional on signing a NDA. I think the bad PR Kraken got for going after them wasn't worth it (especially as the review wasn't really…

Being a shitty employer isn't the sort of thing an NDA is made for. It's not a trade secret that they treat their employees poorly.

Re: Glassdoor not so anonymous

#202
In 2016 I left a very scathing, and very truthful, of my current employer on Glassdoor a couple of weeks before deciding to quit. Two weeks later, Glassdoor sends me an email notifying me that the employer is pursuing legal action and I have two options: 1) delete the review, or 2) stand by the review if it's true and, when it comes down to it, my identity may need to be revealed in court when necessary. That was my catalyst to quit.

I stood by the review and Glassdoor notified me that the employer pulled back on the legal action. My review is still there. And Glassdoor did their best to not reveal my identity under the threat of legal action -- not until absolutely necessary.

Re: Glassdoor not so anonymous

#203

I’ve never used Glassdoor, so it’s a big surprise that they collect and retain identity information in the first place. I would never, ever provide my real name while talking about my previous employers, even if I was told that I would remain “anonymous”

I think they do try to verify that the person posting the review actually worked at the company they're reviewing. Otherwise it would be filled with spam and competitors trying to badmouth each other.

Re: Glassdoor not so anonymous

#204
post #15

> Zuru hasn't simply alleged that it suffered a loss; Zuru’s cofounders declared, under penalty of perjury, that because of the negative reviews, Zuru had to spend more money to recruit job candidates for a particular position. ” Does Zuru have proof it's because of negative reviews and not other causes?

They'll have a hard time arguing that suing their ex-employees doesn't make this moot. Any reputation they were trying to salvage is lost.

Re: Glassdoor not so anonymous

#205

Earlier quoted context omitted.

> It appears a few other companies are doing this too, including Kraken ( https://www.kraken.com/ ) Kraken is still silly for going after them, IMO, but the Kraken case isn't as cut and dry. The person who had left the review on Kraken had accepted a large severance package that was conditional on signing a NDA. I think the bad PR Kraken got for going after them wasn't worth it (especially as the review wasn't really…

Who cares if they violated an NDA? NDAs are supposed to protect company secrets, not prevent criticism.

[deleted]

Re: Glassdoor not so anonymous

#206

Earlier quoted context omitted.

If it’s a managed corporate laptop that uses Chrome, then they could remotely check the browser history, likely directly to the review itself.

I have actually done exactly that, copy over the sqlite broswer history sqlite database and run a query to generate a browsing history report.

I understand that this is all technically possible, but how do you feel about the morality of it?

Re: Glassdoor not so anonymous

#207

This is interesting but a more accurate title would be "New Zealand law allows corporations to sue Glassdoor for user data." As the article notes: > statements of “pure opinion” are protected by the First Amendment in America. But New Zealand doesn’t have this. Statements of opinion are not categorically protected. That said, the warning that Glassdoor adds to the pages of companies that do this has to be the biggest…

A US court deciding to go along with it is news, though.

An US court siding with a large corporation over a lone worker. Not news

Re: Glassdoor not so anonymous

#208

Earlier quoted context omitted.

Write your review, machine translate it into Mandarin, translate it back to English, and run it through a leet speak text filter

So you have to be a CIA spy to post a workplace review. Nice.

Welcome to The Land of the Free and the Home of the Brave©

Re: Glassdoor not so anonymous

#209
post #149

Earlier quoted context omitted.

If you sign into a personal Google account on a new Chrome profile on a managed laptop, can they get access to your entire Google account (drive, emails, etc.) remotely? Can they use an auth token or something to automate the process of downloading all your data? If so, is this legal?

> If so, is this legal? If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. Laptops are cheap. There’s no reason to mix personal and corporate usage.

Surprisingly I was at a party in SF with a bunch of Apple employees. Somehow some topic came up and I was like "I don't do anything personal on my company laptop. I especially don't look at porn". All 6 of them said they used their company laptops and phones to look at porn all the time.

Wow

Re: Glassdoor not so anonymous

#210
post #35

Once had a contract where my client wanted me to do "security work", which was initially meant to be for pentesting their clients, but it turned into me building their wifi auth system. At some point in the gig, one of their clients went to them asking them if it was possible to de-anonymize someone glassdoor review since someone still-employed worked with them. They then went to me to see if I could do it for them.…

DNS records of your VPN or corporate work station would be pretty easy. You can line then up with when the review was posted. Then investigate their workstation more "thoroughly".

I run a Tor middle relay on one of the 8 IP addresses I have purchased as a block from a certain ISP that allows you to, I have been for around a year. The amount of traffic passing through it is heavy. Obviously, this comes with certain caveats (the middle relay's, or any TOR relay IPs are publicly available and published weekly on GitHub and as you can imagine, some places like to instant ban anything to do with TOR).

Since it is only 1 of the 8 IP addresses; the other 7 remain free from blockages of any kind and the one running the TOR middle relay is setup in a manner in which I can use it normally (for the most part) and my traffic would just "blend in" with the normal tor traffic passing through it.

You might ask, what is the purpose of this? Well, if it is normal for a lot of TOR middle relay traffic to be passing through one of my IP's on a daily basis, plausible deniability becomes a real defense as checking DNS logs becomes a moot point as there are requests being routed 24/7/365.

Edit: https://hacky.solutions/blog/2020/06/06/operating-a-tor-rela...

This is an excellent, detailed, and in-depth guide of the process of going through running a TOR middle relay. The statistics provided and data presented are simply superb, Great read!

Post reply on HN