Live data from Hacker News

Glassdoor not so anonymous

webworm.co

311–320 of 507 posts

Re: Glassdoor not so anonymous

#311
I have never used Glassdoor but I have a decent sense of what they do there …

… and it never occurred to me for even a moment that any user of Glassdoor provided personally identifiable details … why would anyone do this ?

Related:

Where can I see the op ? Blog says they are scared to repost it but I’m not.

Where can I see the “offending” material ?

Re: Glassdoor not so anonymous

#312

Earlier quoted context omitted.

https://www.glassdoor.com/Reviews/Employee-Review-Kraken-Dig... https://www.kraken.com/ is doing it too.

This Google shows all the companies listed within Google’s index with the “Glassdoor Alert: Employer Legal Action” flag; just kept removing the companies for the SERPs using the negative search operator until none were left. No idea why Glassdoor doesn’t just have a list of all the companies doing this. https://www.google.com/search?q=Glassdoor+Alert:+Employer+Le...

Manually curated list from parent process:

-Steidle

-legatum

-Medspira

-Media Consulta

-Keller, Fishback & Jackson

-ABG Accessories

-Echelon Environmental

-Admiral Markets

-canidae

-Discovery Clinical Trials

-kraken

-zuru

-bw legal

-kurland

-SynapseFI

Re: Glassdoor not so anonymous

#313

Earlier quoted context omitted.

Glassdoors business model is selling the ability to take down bad reviews. Why would they out their customers?

Hmm, that doesn't correlate with what they say[0] on their support site: "No! Employers cannot pay Glassdoor to remove reviews." That said, it seems like negative reviews can easily end up violating one of the many other terms of use[1] around review content. Specifically that a user will not: "Post Content that is defamatory, libelous, or fraudulent"... and "Act in a manner that is [...] otherwise objectionable (as…

A factual review cannot be "defamatory, libelous or fraudulent" by definition.

Re: Glassdoor not so anonymous

#314
post #191

Earlier quoted context omitted.

> If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. In the USA and other countries with subpar privacy laws.

Correct me if I'm wrong but if the assumption here is that the EU prevents employers from reading private correspondence of employees then I find nothing to back that up. On the contrary, an employer in the EU explicitly seems to have such rights, given they jump through a few formal hoops first: https://www.grcworldforums.com/business/can-employers-legall...

It depends on the country in question. In Ireland, for example, any workplace surveillance must be necessary, legitimate, and proportional. The employee also must be informed in advance of who, what, how, and when they may be surveilled.

It is very hard to see the Workplace Relations Commission (WRC - the body which handles workplace disputes) accepting that identifying a user on Glassdoor would meet the test of being necessary, legitimate, or proportional. This is particularly true as the WRC has previously found that monitoring internet usage for example for pornography is not proportionate where the employer has the option instead to block such sites and make a policy against their access.

Of course, an unscrupulous employer could also use surreptitious surveillance and find another reason to let the employee go, although firing an employee in Ireland is notoriously difficult short of gross negligence.

Re: Glassdoor not so anonymous

#315

Earlier quoted context omitted.

This is an interesting question post-pandemic where the network the laptop is using may be an employees home network, especially if there is some kind of active scanning involved.

Every home router should make it easy for people to create separate VLANs for work to protect against this.

VLAN's aren't security. No way to force respecting the protocol.

Re: Glassdoor not so anonymous

#316
post #149

Earlier quoted context omitted.

> If so, is this legal? If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. Laptops are cheap. There’s no reason to mix personal and corporate usage.

Surprisingly I was at a party in SF with a bunch of Apple employees. Somehow some topic came up and I was like "I don't do anything personal on my company laptop. I especially don't look at porn". All 6 of them said they used their company laptops and phones to look at porn all the time. Wow

My prior employer was the same, I wouldn't use it to make tooling or do anything that might be for my own business, or open source for that matter, they had been known to strong arm staff into giving over IP that might have ever been on that laptop or was ever created during your employment.

But they were quite frank about allowing us to do what ever we want on the laptops providing we delivered positive outcomes for the business.

If this meant the laptops were used to browse porn at home or even during business hours (clearly not on the shop floor if you were in the office) or playing video games, it was fair game.

This employer also had _incredibly_ poor standards and culture for removing misogyny and bigotry, in fact it was one of the worst I've ever seen. Not saying causation = correlation or similar but an interesting data point nonetheless.

Re: Glassdoor not so anonymous

#318

Earlier quoted context omitted.

Surprisingly I was at a party in SF with a bunch of Apple employees. Somehow some topic came up and I was like "I don't do anything personal on my company laptop. I especially don't look at porn". All 6 of them said they used their company laptops and phones to look at porn all the time. Wow

Apple generally encourages employees to use their devices as they usually would to “dogfood”.

Some cynicism on the part of their engineers would be prudent despite that advice. Lots of places encourage you to use the company phone as your only phone, which is convenient, but still not a great idea.

Re: Glassdoor not so anonymous

#319
post #175
post #149

Earlier quoted context omitted.

> If so, is this legal? If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. Laptops are cheap. There’s no reason to mix personal and corporate usage.

> If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. From an OPSEC perspective, sure. But the question was whether it's legal for an employer to do it. You might also get a phone call (on your private phone) about a private medical matter while at work, but I would hope your employer couldn't use the CCTV audio they have in the office…

At least in the EU, it's illegal yes - https://www.theguardian.com/law/2017/sep/05/romanian-chat-me...

Re: Glassdoor not so anonymous

#320

Earlier quoted context omitted.

This is an interesting question post-pandemic where the network the laptop is using may be an employees home network, especially if there is some kind of active scanning involved.

Every home router should make it easy for people to create separate VLANs for work to protect against this.

It's really difficult to find solid guidance on how secure that is.

E.g. tag the port on the switch, run a cable to the device so that it doesn't know there's a vlan involved, block routing between vlans. As far as I can tell that's probably good but might not be.

Post reply on HN