Live data from Hacker News

Glassdoor not so anonymous

webworm.co

211–220 of 507 posts

Re: Glassdoor not so anonymous

#211
post #23
post #9

>Glassdoor’s FAQ goes into a little more detail about how they will defend user anonymity. They know this is vital their success: If glassdoor cares so much about anonymity, why didn't they engineer their site in such a way that prevents them from being able to deanonymize reviewers? For instance, not keeping identifying user details after they have been verified?

Probably because doing so is hard. You not only have to verify that a review is coming from an actual current or former employee, but then you have to ensure that the same employee cannot write multiple reviews. If you discard all links between a reviewer account and a review, how do you do that? I imagine there's some sort of zero-knowledge magic cryptographic thing you can do (or maybe something simpler, like a...…

Can’t you hash the email and then store only the hash? If your hashing alghorithm is heavy enough you could easily figure out that a review is already posted, but brute forcing the original value would be impractical.

Re: Glassdoor not so anonymous

#212

It appears that they have won the lawsuit against Glassdoor. https://www.nzherald.co.nz/business/kiwi-toy-giant-zuru-wins... Perhaps this event will send a chilling message to would-be whistle-blowers...

It's a warning to turbulent priests everywhere.

It's a reminder to use encryption and the darknet for any leaks.

Re: Glassdoor not so anonymous

#213
post #191
post #149

Earlier quoted context omitted.

> If so, is this legal? If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. Laptops are cheap. There’s no reason to mix personal and corporate usage.

> If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. In the USA and other countries with subpar privacy laws.

Which countries don’t allow a company to monitor activity on company equipment and company networks during company time?

Re: Glassdoor not so anonymous

#214

Earlier quoted context omitted.

If they have managed Google accounts they probably have admin on your device as well.

To belay paranoia, this is not always the case. I manage a company's google workspace, and we don't have managed browsers or devices, and no one has ever asked to have that capability.

Until the first case when an employee sends death threats from your company laptop and you need to provide the data to the police to help in investigation.

Or the first case when some shared credentials get compromised probably from an infected computer and now you need to find which of the 80 laptops is the infected one.

Or the first time employee converts his laptop into a wifi access point for the office girl upstairs and unknowingly lets her inside your companies private network.

Of course, there are workarounds and better practices for every example. You can solve it without admin access to laptops and network request logging. But company property is not anonymous either with or without full admin access - so why jump trough the hoops to not have it?

Re: Glassdoor not so anonymous

#215
post #149

Earlier quoted context omitted.

> If so, is this legal? If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. Laptops are cheap. There’s no reason to mix personal and corporate usage.

Surprisingly I was at a party in SF with a bunch of Apple employees. Somehow some topic came up and I was like "I don't do anything personal on my company laptop. I especially don't look at porn". All 6 of them said they used their company laptops and phones to look at porn all the time. Wow

I've heard some pretty simultaneously funny and Orwellian stories about this, mostly about people being fired for looking at porn using work laptops and the specific porn they were looking at.

Don't use work computers to look at porn, your employers already know about it.

Re: Glassdoor not so anonymous

#216
post #123

dang, can Nick Mowbray and Anna Mowbray, the founders of ZURU, compel News.YC to hand over my information if I wrote a poor review of their company in a scathing Tell HN?

I would hope so if your review was written in bad faith

Even if the company was Facebook?

Re: Glassdoor not so anonymous

#217
post #202

In 2016 I left a very scathing, and very truthful, of my current employer on Glassdoor a couple of weeks before deciding to quit. Two weeks later, Glassdoor sends me an email notifying me that the employer is pursuing legal action and I have two options: 1) delete the review, or 2) stand by the review if it's true and, when it comes down to it, my identity may need to be revealed in court when necessary. That was my…

[deleted]

Re: Glassdoor not so anonymous

#218
post #149

Earlier quoted context omitted.

If you sign into a personal Google account on a new Chrome profile on a managed laptop, can they get access to your entire Google account (drive, emails, etc.) remotely? Can they use an auth token or something to automate the process of downloading all your data? If so, is this legal?

> If so, is this legal? If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. Laptops are cheap. There’s no reason to mix personal and corporate usage.

None of my employers pay for Spotify.

Re: Glassdoor not so anonymous

#219
post #210

Earlier quoted context omitted.

DNS records of your VPN or corporate work station would be pretty easy. You can line then up with when the review was posted. Then investigate their workstation more "thoroughly".

I run a Tor middle relay on one of the 8 IP addresses I have purchased as a block from a certain ISP that allows you to, I have been for around a year. The amount of traffic passing through it is heavy. Obviously, this comes with certain caveats (the middle relay's, or any TOR relay IPs are publicly available and published weekly on GitHub and as you can imagine, some places like to instant ban anything to do with TO…

Its a nice setup, but you can’t see any DNS data in the TOR middle relay traffic. Middle relays just pass on encrypted data to the next tor node, not “the Internet”. So any DNS requests hitting outside from your 8 IPs are still all attributable to you.

Re: Glassdoor not so anonymous

#220
post #149

Earlier quoted context omitted.

If you sign into a personal Google account on a new Chrome profile on a managed laptop, can they get access to your entire Google account (drive, emails, etc.) remotely? Can they use an auth token or something to automate the process of downloading all your data? If so, is this legal?

> If so, is this legal? If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. Laptops are cheap. There’s no reason to mix personal and corporate usage.

I don't want to work somewhere where this would ever be an issue. More than happy to leave if they pull this kind of personal invasion (yeah, it's their property, but still- basic human decency dictates: don't do it).

Your advice is still sound.

Post reply on HN