Earlier quoted context omitted.
> If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. In the USA and other countries with subpar privacy laws.
Which countries don’t allow a company to monitor activity on company equipment and company networks during company time?
Glassdoor not so anonymous
271–280 of 507 posts
Re: Glassdoor not so anonymous
#272Re: Glassdoor not so anonymous
#273I'd not heard of Zuru before. Turns out they make tons of cheap plastic crap that makes Happy Meal toys look well made. Their main brands are chinzy collectable toys that combine gambling with too many layers of plastic wrapping, Mini Brandz (because having kids collect mini plastic versions of Heinz and Miracle Whip isn't weird), and Bunch O Balloons (the ultimate in single-use plastic).
https://businessdesk.co.nz/article/the-life/my-net-worth-nic...
Re: Glassdoor not so anonymous
#274Once had a contract where my client wanted me to do "security work", which was initially meant to be for pentesting their clients, but it turned into me building their wifi auth system. At some point in the gig, one of their clients went to them asking them if it was possible to de-anonymize someone glassdoor review since someone still-employed worked with them. They then went to me to see if I could do it for them.…
DNS records of your VPN or corporate work station would be pretty easy. You can line then up with when the review was posted. Then investigate their workstation more "thoroughly".
Re: Glassdoor not so anonymous
#275Earlier quoted context omitted.
Isn't the final law here New Zealand's law?
No, they get the user information now - before any charge is made in New Zealand to justify providing access to the data.
“We are deeply disappointed in the Court’s decision, which was effectively decided under New Zealand law.”Re: Glassdoor not so anonymous
#276Earlier quoted context omitted.
> If so, is this legal? If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. Laptops are cheap. There’s no reason to mix personal and corporate usage.
> If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. From an OPSEC perspective, sure. But the question was whether it's legal for an employer to do it. You might also get a phone call (on your private phone) about a private medical matter while at work, but I would hope your employer couldn't use the CCTV audio they have in the office…
Re: Glassdoor not so anonymous
#277The best solution is to have zero knowledge (delete all info that can identify a user), but the second best thing is to have double logs. A real one (internal use only) and a false one (for legal usage only). I know it goes against the moral/legal sense, but hey we're living in strange times and the best thing is not to go against multi bilion companies that can force you to do anything they want.
Who from the court or Zuru (or any other "bad" company) can say if the reviews by bill brown with IP 123.124.125.126 or john james with IP 132.133.134.135 are real or not ;-)
Re: Glassdoor not so anonymous
#278Earlier quoted context omitted.
> If so, is this legal? If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. Laptops are cheap. There’s no reason to mix personal and corporate usage.
> If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. From an OPSEC perspective, sure. But the question was whether it's legal for an employer to do it. You might also get a phone call (on your private phone) about a private medical matter while at work, but I would hope your employer couldn't use the CCTV audio they have in the office…
How often did that stop an employer?
Re: Glassdoor not so anonymous
#279Earlier quoted context omitted.
Surprisingly I was at a party in SF with a bunch of Apple employees. Somehow some topic came up and I was like "I don't do anything personal on my company laptop. I especially don't look at porn". All 6 of them said they used their company laptops and phones to look at porn all the time. Wow
I've heard some pretty simultaneously funny and Orwellian stories about this, mostly about people being fired for looking at porn using work laptops and the specific porn they were looking at. Don't use work computers to look at porn, your employers already know about it.
Re: Glassdoor not so anonymous
#280Earlier quoted context omitted.
IIRC Danish law states that work email may be used for private purposes and that anything clearly labeled as private is to be considered such. For example, by moving email to a folder called “private”. For the employer to open/read such communication would be highly illegal, akin to opening others private snail mail. I do believe that this also extends to corporate issued phones and computers. Especially since you’re…
> Especially since you’re automatically taxed for “private use” of such equipment when assigned. so you get charged a tax when an employer gives you equipment required for work? What happens if you can't afford that tax then? This feels very wrong - taxing someone for a potential benefit when it is not proven that such benefit exists.
The vast majority of people prefer to also use the car privately, and pay the tax (which is reasonable, if taxation is reasonable).
Cars that keep rotating between drivers are not subject to that (but exact record keeping of driver and trip required to avoid tax)
Similarly, employer provided phone subscription is assumed to be partly private use (50% of monthly subscription cost considered a a taxable benefit iirc), not sure what hoops you need to jump through to prove it is not private use at all. (But phone plans are cheap - excellent domestic plans are $10 or so)