Live data from Hacker News

Glassdoor not so anonymous

webworm.co

351–360 of 507 posts

Re: Glassdoor not so anonymous

#351
Blind promises that "all email addresses are hashed, salted and then encrypted. Blind accounts are stored separately from the hashed email addresses. This means that a user’s activity cannot be traced to an email. As an added measure, we do not collect real names. We also discourage users from sharing too much personal information in their posts and messages, which others could potentially use to identify them."[1]

[1]: https://us.teamblind.com/logic

Re: Glassdoor not so anonymous

#352
post #90

Earlier quoted context omitted.

How many get connected to company WiFi?

They all have the ability to disconnect with a swipe and a tap. Life does not get much easier.

Right, but I'm trying to consider the average user. They likely aren't aware their activity on their phone is being logged on WiFi. My assumption is that once they got it connected to WiFi, it leaves attention and isn't considered

Re: Glassdoor not so anonymous

#354

Why don't they make the whole process anonymous? After verifying that you work for a company, why don't they physically destroy everything that could be used to de-anonymize you, leaving with only some kind of public key and a proof of that you work for company X? For the legal part I think there were some countries (IIRC Sweden) that doesn't require to keep any logs so that they can move operations there with an own…

That's a technologist's typical reaction. However, this is not a technical problem. In reality, if Glassdoor did something like that it's just going to increase the likelyhood of getting targeted directly for libel. Even if someone actually worked for a company, it doesn't mean their statements about it are true. Someone might be disgruntled for a variety of reasons and slander the company, in which case it would be…

Actually the technical aspect is the implementation details. If this is a social "problem", then the problem is Glassdoor's existence in the first place.

Since it exists (whether such a service itself existing is a problem or not is out of the scope here) technical implementation is just a way of making the service work as intended (e.g. Providing anonymity to the users).

Re: Glassdoor not so anonymous

#355
post #138
post #68

Earlier quoted context omitted.

This is a good example of why not to do personal stuff on your work machine or work network. If you care at all if your company would see it, _don't_ do it anywhere near their hardware.

Actually, since Glassdoor's protection can obviously be compromized, anyone posting on their site should do so with Tor Browser, which anonymizes access by routing traffic through a minimum of three relays in the "dark web" of the Tor network. It might also be wise to do this on a public WiFi network (not your own ISP or mobile data provider). Any email provided to Glassdoor should be a burner on a service that is no…

Isn't the entire point of glassdoor that people use their work email to prove they actually work for the company?

Re: Glassdoor not so anonymous

#356
post #328
post #230

Earlier quoted context omitted.

Sites that don't want Tor users should only block exit relays, but some will lazily block all relays. It's unfortunate but that is the current state of affairs right now.

'should' from whose perspective though? 'Sites that don't want Tor users' have no incentive to care do they? If anything it stands to reason such a site would block anything and everything to do with Tor, using it as a search term, usernames containing it, anything? (I don't know much about Tor, so am I missing something about 'middle relays' that such a site would want to allow them?) Edit: oh is the point that you'…

Exit nodes are the interface between Tor and the "clearnet" (regular internet), whereas relays just relay traffic between Tor nodes (to make it harder to trace the route). So there wouldn't be any Tor traffic from this person's IP going to websites.

Presumably most folks neither know or care about this distinction and just block all Tor related infrastructure outright, since some of the traffic coming through is malicious.

Re: Glassdoor not so anonymous

#357
post #319
post #175

Earlier quoted context omitted.

> If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. From an OPSEC perspective, sure. But the question was whether it's legal for an employer to do it. You might also get a phone call (on your private phone) about a private medical matter while at work, but I would hope your employer couldn't use the CCTV audio they have in the office…

At least in the EU, it's illegal yes - https://www.theguardian.com/law/2017/sep/05/romanian-chat-me...

From the article: The only thing they did wrong was not more explicitly mention the monitoring. So it wasn't illegal to monitor communications, rather it was illegal to fire someone for using their work account for private communication without sufficiently warning them. All they have to do is make you sign some document on day 1 and they're covered. Also they were not awarded any damages or anything, so it's not like you'd get a payday after being fired.

>Commenting on the ruling, Pam Cowburn, the communications director at in London, said: “The European court’s ruling is welcome. In some workplaces, it may be necessary for emails to be monitored, but if employers are going to do so, they should make staff explicitly aware of it.”

>Despite finding that Bărbulescu’s rights under article 8 of the convention had been violated, the court declined to award him any compensation, saying the ruling was “sufficient just satisfaction”.

Re: Glassdoor not so anonymous

#358

Earlier quoted context omitted.

I've heard some pretty simultaneously funny and Orwellian stories about this, mostly about people being fired for looking at porn using work laptops and the specific porn they were looking at. Don't use work computers to look at porn, your employers already know about it.

Quoted post unavailable.

[deleted]

Re: Glassdoor not so anonymous

#359

Never trusted the fact that reviews on glassdoor AREN'T anonymous... Oh sure, they hide your name and email, but they have it. A good secret isn't a secret if someone knows it. I always wondered if they should - and now I wonder if they could - have really anonymous reviews. Just don't tie a review to a user. Sure, ask users to create accounts, validate them, but once they submit a review, it's store without details.…

Need to track who said what for libel cases. There are plenty of unfairly scathing Glassdoor reviews. If Glassdoor can’t point to who said it, they’re the one who gets sued.

Re: Glassdoor not so anonymous

#360
post #57

Glassdoor has systematically taken down negative reviews for companies for years. I can’t say I love any of the “board” sites who engage in this type of product, and that includes Yelp, Google Places, etc

> Glassdoor has systematically taken down negative reviews for companies for years. For a fee, of course :)

I have never seen proof of this but that is my belief
Post reply on HN