Live data from Hacker News

Glassdoor not so anonymous

webworm.co

281–290 of 507 posts

Re: Glassdoor not so anonymous

#282

Earlier quoted context omitted.

If it’s a managed corporate laptop that uses Chrome, then they could remotely check the browser history, likely directly to the review itself.

If you sign into a personal Google account on a new Chrome profile on a managed laptop, can they get access to your entire Google account (drive, emails, etc.) remotely? Can they use an auth token or something to automate the process of downloading all your data? If so, is this legal?

It will depend on your employee handbook, but generally any data you produce on a company laptop belongs to the company. Anything in the browser cache is fair game.

Re: Glassdoor not so anonymous

#283
post #175
post #149

Earlier quoted context omitted.

> If so, is this legal? If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. Laptops are cheap. There’s no reason to mix personal and corporate usage.

> If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. From an OPSEC perspective, sure. But the question was whether it's legal for an employer to do it. You might also get a phone call (on your private phone) about a private medical matter while at work, but I would hope your employer couldn't use the CCTV audio they have in the office…

> Not for everyone.

Still cheaper then searching for a new job... without a current one.

Re: Glassdoor not so anonymous

#284
post #175

Earlier quoted context omitted.

> If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. From an OPSEC perspective, sure. But the question was whether it's legal for an employer to do it. You might also get a phone call (on your private phone) about a private medical matter while at work, but I would hope your employer couldn't use the CCTV audio they have in the office…

> From an OPSEC perspective, sure. But the question was whether it's legal for an employer to do it. How often did that stop an employer?

I don't know if this is the case in the US, but in Australia it's very easy (and relatively cheap) to take your employer to tribunal over violations of employment laws (if it was very clear-cut or severe violation you could even make a complaint to the relevant regulator which could launch an action on your behalf). Something being illegal means if they did do it, you'd be owed compensation.

Re: Glassdoor not so anonymous

#285

Earlier quoted context omitted.

If they have managed Google accounts they probably have admin on your device as well.

To belay paranoia, this is not always the case. I manage a company's google workspace, and we don't have managed browsers or devices, and no one has ever asked to have that capability.

I am going to guess you don't have any security or compliance folks.

Re: Glassdoor not so anonymous

#286
post #56

I just attempted to look at the reviews. There's an uncloseable pop-up telling you to log in. Normally I wouldn't bother, but curiousity got the best of me - I logged in with my Google OAuth. Not so fast - you haven't contributed to Glassdoor in the last 12 months, here's another annoying pop up and you cannot dismiss it until you do. Does anyone actually bother to use this dark pattern infused service?

Apparently this is the review they sued over - https://old.reddit.com/r/newzealand/comments/sv8yyv/kiwi_toy...

Can't believe they'd try to sue over that. For one, it's pretty much only critical of the Mowbrays themselves and I can't see anything in there that wouldn't be an honest opinion so safeguarded by NZ law.

So it comes across to me like the Mowbrays personally trying to stomp someone into the ground with legal fees knowing they have no case. Hopefully the legal system can protect them from that exploitative use.

Seems on song with that basis of the comment, doesn't it?

Re: Glassdoor not so anonymous

#287
post #264

This is the worst kind of publicity for ZURU. They thought it was difficult to hire employees because of a handful of critical reviews on Glassdoor? It's about to get a lot harder. The company should have spent those extra resources researching how to make their employees happier (and hence, more productive).

This. If the names of the employees become known, they should rise to be heroes of the workers movement, in parallel with a massive boycott of zuru!

Re: Glassdoor not so anonymous

#288

Earlier quoted context omitted.

Does Glassdoor require verified ID or something to sign up? Why don't people simply use a VPN and appropriate email to sign up and leave reviews?

Try to register an email address using a host that won't have you flagged as a malicious user should you use an account with that host to sign up for major company's services like Glassdoor. It's virtually impossible to use Tor to register an email address without activating JavaScript, and the email hosts that allow it are very sketchy, and my personal suspicions are that many of them are blatant honeypots.

Sorry what? It's trivial to get an email address from legit email provider, create alias addresses, then sign up to something like Glassdoor using VPN. The only thing Glassdoor will know about you is your email address, which is not easily traced back to your real ID if you don't want it to be. Particularly for low level "crime" like negative reviews.

Re: Glassdoor not so anonymous

#289

Earlier quoted context omitted.

No, they get the user information now - before any charge is made in New Zealand to justify providing access to the data.

I know it is cool to shit on the US, but: “We are deeply disappointed in the Court’s decision, which was effectively decided under New Zealand law.”

Yeah it was odd finding out this was an NZ decision. I was under the impression that they were a bit ahead of the US on privacy.

Re: Glassdoor not so anonymous

#290
post #35

Once had a contract where my client wanted me to do "security work", which was initially meant to be for pentesting their clients, but it turned into me building their wifi auth system. At some point in the gig, one of their clients went to them asking them if it was possible to de-anonymize someone glassdoor review since someone still-employed worked with them. They then went to me to see if I could do it for them.…

DNS records of your VPN or corporate work station would be pretty easy. You can line then up with when the review was posted. Then investigate their workstation more "thoroughly".

That's why you shouldn't use your work computer for anything but work!
Post reply on HN