Live data from Hacker News

Glassdoor not so anonymous

webworm.co

481–490 of 507 posts

Re: Glassdoor not so anonymous

#481
post #473

Earlier quoted context omitted.

Neither did the internet. Or electricity before that.

And none of those are basic human needs. They're just comforts we've grown accustomed to.

Eh, you can't even apply for a job without internet access these days. I'd say internet access is essential for participation in society.

Re: Glassdoor not so anonymous

#482
post #229

Earlier quoted context omitted.

DNS records of your VPN or corporate work station would be pretty easy. You can line then up with when the review was posted. Then investigate their workstation more "thoroughly".

DNS over HTTPS would solve that, right? It's an options flag on Firefox.

Barely anyone supports it yet.

Re: Glassdoor not so anonymous

#483
post #306

Earlier quoted context omitted.

"The same employee cannot write multiple reviews" - they can create new accounts. But even if you want one account to not write multiple reviews, you can flag that an account wrote a review for a company without tying it to -what- review. You can even disassociate that; hash usernames with the company and store that to track who has written a review. Then, you can only confirm that a given user account has written a…

> without attempting to hash every username against it Given even a few million users, this is trivial. Other than that, I agree with you.

Certainly, but it moves it from a "we just have some legally-should-be inactionable data laying around" to "we don't even have that data laying around".

The fact that it's impossible to comply with "who wrote -this- review" is probably sufficient, but "and we don't even readily have access to who wrote -a- review" can help prevent fishing expeditions, since presumably a judge will be less amenable to such fishing expeditions if you can show it will have negative material effect to comply, while still not providing any legal path forward to sue for the prosecution.

But that also makes assumptions both of user counts, and rounds of hashing. 50 million users (seems reasonable with Glassdoor), with a sufficiently slow hash that takes a second to compute (easily done) means you'll have to wait a year and a half for results for a given company, or start to parallelize things, and, oh, look, now you have dev time and CPU resources and, well, this has a materially adverse effect on our business, and we'll be left with usernames we still can't release since this discovery order only is valid for this -one- review, and we have no way of knowing which it is.

Re: Glassdoor not so anonymous

#484
post #303

Earlier quoted context omitted.

How certain are you that in all jurisdictions where an (ex-)employer can get an injunction to force glassdoor to reveal the email address they wouldn't be able to get the legit email provider to reveal your true identity?

Create a gmail address from your local McDonald's wifi?

IP addresses aren't the only way to identify a user.

I also assume large free hotspot providers collect enough identifying information from their users for the purpose of aiding investigators and courts in identifying abuse of their networks. A subpoena could provide that info, and hotspot providers can choose to just hand over that info when requested.

Re: Glassdoor not so anonymous

#485
post #202

In 2016 I left a very scathing, and very truthful, of my current employer on Glassdoor a couple of weeks before deciding to quit. Two weeks later, Glassdoor sends me an email notifying me that the employer is pursuing legal action and I have two options: 1) delete the review, or 2) stand by the review if it's true and, when it comes down to it, my identity may need to be revealed in court when necessary. That was my…

I (somewhat unhealthily) keep an eye on Glassdoor reviews for old jobs. There was one that was both absolutely damning (about the CTO in particular), and almost completely factually accurate - the only inaccuracy I spotted was inconsequential to the overall message. I took a screenshot, it was gone a week later. To this day I don't know who wrote it, and whether they get scared into taking it down. But i've never tru…

There are services for reddit that log removed comments and allow you to see what the mods have deleted.

Just replace reddit.com with reveddit.com in the URL. It's not perfect but it allowed me to see that the mods of r/coffee are total weirdos, for example, who will remove any hint of a joke or even the faintest suggestion that someone owns a cafe (even when they don't mention the name).

Why hasn't someone built a similar service for Glassdoor?

Re: Glassdoor not so anonymous

#486
post #473

Earlier quoted context omitted.

Neither did the internet. Or electricity before that.

And none of those are basic human needs. They're just comforts we've grown accustomed to.

So you say it’s fine if your office had no electricity and running water?

Re: Glassdoor not so anonymous

#487
post #411

Earlier quoted context omitted.

The idea that 'company time' and 'company equipment' gives the company absolute right to record and ownership of recording is almost feudal. Imagine I were to die in the office in some embarrasing way, on company time, in full view of company CCTV, do they have the right to upload the video to YouTube to make money from it? What if they record audio of me at home, can they publish it? Can they show it to anyone at th…

You seem to be building a straw man here?

I assume he is trying to establish a dividing line between acceptable and not. For example, I'd consider all mentioned uses to be unacceptable and hopefully illegal, but I think others may be fine with it.

Re: Glassdoor not so anonymous

#488
post #413

Earlier quoted context omitted.

Most of developed countries except the US. People have legitimate expectations of privacy in the office and/or during working time. Employment means selling your skills and effort, not becoming a servant or a slave in a feudal society. Additionally, having delicate information in the hands of the company in general or sysadm/security engineers create a ton of liabilities. There has to be a balance between security ne…

Practically, the company needs to administer and secure their equipment for a number of reasons, including a legal need to keep their customers data safe. That requires them to use tools which can easily let them know, for instance, what websites someone is visiting, and what executables are executing on the machine, what devices are being accessed and when, etc. It’s pretty fundamental. An individual looking to secu…

Just because it is easy and achieves a purpose doesn't make it necessary or right.

People could be making backhanded deals on their phones or they could be having an urgent confidential conversation with their doctor or spouse. Should the company record and review phone calls?

People could be stalking customers/coworkers or making deals in the bathroom. Or they could be using it for more personal purposes. Should the bathrooms have CCTV with audio?

People could be selling company data in the company parking lot, in the mall or at home near/using the company laptop/phone that is permitted to be used for personal reasons, or just mandated to be near them, or they could do the same thing without presence or use of any company equipment. Where do you draw the line, and at what point is it even sufficient to prevent losing information etc.?

Do you trust your employees? All trust can be abused, yet how can the company function if they don't trust their employees at all?

Re: Glassdoor not so anonymous

#489

Earlier quoted context omitted.

Sorry what? It's trivial to get an email address from legit email provider, create alias addresses, then sign up to something like Glassdoor using VPN. The only thing Glassdoor will know about you is your email address, which is not easily traced back to your real ID if you don't want it to be. Particularly for low level "crime" like negative reviews.

I said try doing it using Tor with JavaScript disabled, which is the safe way to use the Tor Browser. I said nothing about a VPN. A VPN will not save you from leaking identifying information from your device and browser, while the Tor Browser at least attempts to minimize such identifying information.

> "A VPN will not save you from leaking identifying information"

What identifying information? There is no identifying information other than IP address, email and anything else you volunteered when signing up.

Remember the context here. It's "toy company" grumpy about a negative review, and wanting Glassdoor to hand over what they know.

Have a guess what Glassdoor will hand over? Email address, IP, and whatever else you willingly gave to Glassdoor. They won't have any other information from "javascript" or whatever you are claiming is leaked from normal web browsers.

Re: Glassdoor not so anonymous

#490
post #418

Earlier quoted context omitted.

Except where’s the money in that for Glassdoor? Glassdoor makes money from job listings and it’s in their interests to have positive reviews of companies as that’s going to get companies to pay for job listings because they’ll get more/better applicants if they have positive reviews.

The foundation of the site's usefulness is that the ratings have some signal. The value of job listings to a Glassdoor user is that they're from companies that Glassdoor rates as positive: an undifferentiated mass of ratings would be a completely useless site. The idea that they have no incentive to improve discriminativity (at the expense of company rating) proves way too much. Eg by that logic, Yelp would have no i…

This is true but there is enormous pressure for these businesses to directionally encourage review scores to trend north. Higher reviewed locations and businesses always garner far higher engagement, and this directly impacts top line. As you point out, there is some ephemeral point at which users might begin distrusting the site en masse, but this inflection point is always easy to ignore as "a problem for another day far in the future." In the mean time, tiny but substantial changes occur all the time which nudge that score higher and higher.

In my experience, that macro trust issue is rarely discussed, even though, at some undefined point in the future, it could pose a serious existential threat.

Post reply on HN