Live data from Hacker News

Glassdoor not so anonymous

webworm.co

321–330 of 507 posts

Re: Glassdoor not so anonymous

#321

Earlier quoted context omitted.

Every home router should make it easy for people to create separate VLANs for work to protect against this.

VLAN's aren't security. No way to force respecting the protocol.

Tag on the switch port?

Re: Glassdoor not so anonymous

#322

Earlier quoted context omitted.

That's actually a fantastic response. - Reminds reviewers to avoid libel, since it may undergo legal review. - Tells potential employees or customers that this is how the company responds to bad press/negativity (i.e. disproportionately). - Doesn't subject Glassdoor to potential libel since the statement is objectively true (see court records). Although I won't get too positive about Glassdoor as I've read negative r…

Reminder that libel vs truth is dependent on where you are. In the US you don’t risk libel when speaking the truth but there are places where this isn’t the case.

To add some specifics, I think the common case outside of the US is one where the published elements must both (a) be true, and; (b) have been published for some "legitimate purpose". The phrase "legitimate purpose" is generally understood to mean "whose primary purpose is not to cause harm or nuisance". An example of legitimate purpose would be governmental transparency. An example in which something true could still be considered libelous might be notifying your ex-spouse's employer of his/her public intoxication charge for the purposes of stunting his/her career.

(I'm basing this general comment on my understanding of French law. I believe it works similarly in many, if not most, European countries. I hope some actual legal experts can weigh in!)

Re: Glassdoor not so anonymous

#323
post #35

Once had a contract where my client wanted me to do "security work", which was initially meant to be for pentesting their clients, but it turned into me building their wifi auth system. At some point in the gig, one of their clients went to them asking them if it was possible to de-anonymize someone glassdoor review since someone still-employed worked with them. They then went to me to see if I could do it for them.…

It might be possible to do linguistic analysis (ie. What they did to catch the Unabomber) to compare the language they used in the review vs how someone usually write in things like performance reviews, manager evaluations, emails, etc

Most of the time they won't need to go that far. The review itself will usually indicate which department a person's from and what their main gripes are. Sure, this won't work for FAANG or a factory where everyone hates "long hours, low pay" though the text analysis probably won't help much either, but if it's someone from an SME's dev team (n=10), the dev team manager is going to have their suspicions as soon as they see the bullet point about rescinded work from home policies or lack of attention paid to testing deployments...

(the non-trivial possibility they'll get the wrong person isn't going to stop fingers being pointed)

Re: Glassdoor not so anonymous

#324
post #303

Earlier quoted context omitted.

Sorry what? It's trivial to get an email address from legit email provider, create alias addresses, then sign up to something like Glassdoor using VPN. The only thing Glassdoor will know about you is your email address, which is not easily traced back to your real ID if you don't want it to be. Particularly for low level "crime" like negative reviews.

How certain are you that in all jurisdictions where an (ex-)employer can get an injunction to force glassdoor to reveal the email address they wouldn't be able to get the legit email provider to reveal your true identity?

Do you extend that to the VPN provider used to sign up to the email provider?

How far should companies battle to reveal the sources of mean reviews? Why not simply reply to those reviews with a counterbalancing response? It's not a big deal. I don't condone making fake reviews out of spite, or whatever is claimed in this case, but chasing reviewers through court action is petty.

One of the values on Zuru website is something about "think different" but what is thinking different about suing a negative reviewer?

So much bragging over there on the zurutoys.co/about-us pages, they talk themselves up big time. No environmental statement that I can see btw, just how amazing they are. Should environmental policies start imposing limits on how many plastic fish fidget spinners the world needs? If less quantities are made, their rarity provides value on the used/recycled market. May mean less rooms in mansion for company heads. Better for planet though.

Re: Glassdoor not so anonymous

#325
post #252
post #221

Earlier quoted context omitted.

IIRC Danish law states that work email may be used for private purposes and that anything clearly labeled as private is to be considered such. For example, by moving email to a folder called “private”. For the employer to open/read such communication would be highly illegal, akin to opening others private snail mail. I do believe that this also extends to corporate issued phones and computers. Especially since you’re…

> Especially since you’re automatically taxed for “private use” of such equipment when assigned. so you get charged a tax when an employer gives you equipment required for work? What happens if you can't afford that tax then? This feels very wrong - taxing someone for a potential benefit when it is not proven that such benefit exists.

> so you get charged a tax when an employer gives you equipment required for work?

Obviously this only happens when the equipment you get can plausibly be used for personal purposes. Such as a company car.

> What happens if you can't afford that tax then?

That's extremely unlikely.

Re: Glassdoor not so anonymous

#328
post #230
post #225

Earlier quoted context omitted.

I understand why websites would ban Tor exit nodes, but what's the point of banning middle relays? Wouldn't those only communicate with either other relays or exit nodes?

Sites that don't want Tor users should only block exit relays, but some will lazily block all relays. It's unfortunate but that is the current state of affairs right now.

'should' from whose perspective though? 'Sites that don't want Tor users' have no incentive to care do they? If anything it stands to reason such a site would block anything and everything to do with Tor, using it as a search term, usernames containing it, anything?

(I don't know much about Tor, so am I missing something about 'middle relays' that such a site would want to allow them?)

Edit: oh is the point that you're not accessing the site using Tor, just from an IP addociated with Tor use?

Re: Glassdoor not so anonymous

#329

Earlier quoted context omitted.

It might be possible to do linguistic analysis (ie. What they did to catch the Unabomber) to compare the language they used in the review vs how someone usually write in things like performance reviews, manager evaluations, emails, etc

And they fire the wrong person. And the real poster adds another review. It can almost be a skit. - Oct 12, 2022 "They fired Bobby!!! Bobby's been working with us for 10 years and they fired him overnight?? Told you that place is bonkers!" - Oct 14, 2022 "Mona's down, I repeat Mona's down!! This is a sinking ship! Do not attempt to join this place!!!" Meanwhile in the C-suite's office. "Seriously, who is this guy?"

This could happen even if the culprit does get fired - as far as I know, there's nothing preventing you from posting reviews despite no longer being employed by the company.

Re: Glassdoor not so anonymous

#330

Earlier quoted context omitted.

DNS records of your VPN or corporate work station would be pretty easy. You can line then up with when the review was posted. Then investigate their workstation more "thoroughly".

If it’s a managed corporate laptop that uses Chrome, then they could remotely check the browser history, likely directly to the review itself.

Do you mean Chrome has some special support for this, or is this the same as for any other browser (where the adversary could copy the history db file)?
Post reply on HN