Live data from Hacker News

WFH – Watched from Home: Office 365 and workplace surveillance creep (2022)

privacyinternational.org

311–320 of 367 posts

Re: WFH – Watched from Home: Office 365 and workplace surveillance creep (2022)

#311

Earlier quoted context omitted.

You know, it's not just labor that contributes to economic output. Natural resources and accumulated knowledge and technology contribute too. Both belong to everyone with equal share. Giving people what their share of resources and technology has produced is only fair.

How does anyone have any claim to 'their share' of resources without any input? Just by being in existence, they deserve to consume natural resources / technology? I don't see how that makes sense.

Wow, so we reduce human beings and life to what, something without value of its own? You do know where that ideology ultimately leads, don't you? Hint: it leads to very bad, very dark places...

Honestly, I have no idea how people are so willing to sacrife human rights, right literally millions of people had to die in order for us to have them, for the sake of profit and capitalism, benefits only an extremely limited number of people actually have.

Re: WFH – Watched from Home: Office 365 and workplace surveillance creep (2022)

#312
post #143

Earlier quoted context omitted.

I sympathize - it must’ve been stressful to go through this. Yet I just can’t stop to imagine the other side’s perspective and it’s making me laugh: I’m sitting in front of the monitoring dashboard, chewing a sandwich, and then a spike of intranet activity shows on one of the charts. I look at the dashboard and immediately notice that it’s effect of some SMS broadcast. Nothing to see here: lazy Tuesday. Then on the d…

If I'm using curl, I'm probably also using git, ssh and wget. I think an active threat would be more likely to try to blend in (a giveaway would probably to use a user agent that declared I was using a different OS because it was hardcoded into the payload.) What I end up thinking about is that even though I'm back at the office full time (and I'm one of the weirdos that actually prefer it) I have doctors appointment…

[deleted]

Re: WFH – Watched from Home: Office 365 and workplace surveillance creep (2022)

#313
post #308
post #142

Earlier quoted context omitted.

> Even if the company has a rule that you're not allowed to use it for personal things, the law supersedes that and you still can't do it willy nilly. Companies are not homogeneous blocks of matter and there is always information some people at the company may need to know that others have no business dealing with. Tax, banking and health related information are some of the things that I can think of that would be sh…

> Tax, banking and health related information are some of the things that I can think of that would be shared on a need to know basis with people at work and have no business to be seen by people outside of the intended audience. I am against workplace surveillance, but why would people receive this information to their work email address?

Why would HR receive my information?

Re: WFH – Watched from Home: Office 365 and workplace surveillance creep (2022)

#314

During covid when WFH, I received a legitimate looking SMS message with a link, so rather than clicking it, I curl --verbose'd it (and one subsequent redirect) before seeing it was an obvious phishing / troll. The next day, my VPN & SSO was disabled with instructions to contact corporate security. My use of curl had been detected and while they didn't accuse me of anything, they claimed that they wanted to make sure…

Ah yes the famous phishing tests. They bypass every spam filter, and if your company is like mine, that uses a new external website every week for something, it's completely impossible to tell apart phishing from actual email.

Re: WFH – Watched from Home: Office 365 and workplace surveillance creep (2022)

#315

During covid when WFH, I received a legitimate looking SMS message with a link, so rather than clicking it, I curl --verbose'd it (and one subsequent redirect) before seeing it was an obvious phishing / troll. The next day, my VPN & SSO was disabled with instructions to contact corporate security. My use of curl had been detected and while they didn't accuse me of anything, they claimed that they wanted to make sure…

Were they taking issue with your use of a tool, or the fact that you apparently click on phishing links? Was that a test run by your company's cybersecurity department? Is your phone personal? BYOD? Company-issued? I can't fathom how "detecting curl" can put you in the doghouse, but I would shut you down too, for accessing malicious websites.

It's the url, i'm sure it had a get parameter to identify him.

Re: WFH – Watched from Home: Office 365 and workplace surveillance creep (2022)

#316

Earlier quoted context omitted.

I don't think this is correct - even under the GDPR. If the company has good reason to look inside someone's mailbox (I don't think the bar for that is particularly high for a company email account) then any personal data they encounter would be being processed under "legitimate interest" as long as they don't do anything unnecessary with it in order to achieve whatever it was they were doing.

Tue bar is actually quite high. Teo things can block it: if there is a workers council, it has to approve surveillance of an employees use of IT systems. That surveillance can only be target to specific, named users and for specific purposes, almost like a mini search warrant. If there is no workers council, at the latest stage a court will have a very, very close look at what isbpresented as evidence. The middle gro…

You need to be specific about what legal jurisdiction you're talking about here then - the world is a very big place and different laws apply.

I'm not aware of any EU wide laws that prevent what you're talking about here. In the UK an employment contract will state that the employer can monitor your activity if they need to and this is completely legal.

Source: https://www.gov.uk/monitoring-work-workers-rights

In some countries (Germany springs to mind) there are much stricter rules. A blanket statement like the one you've made here is not correct unless you're being very specific about where you're talking about.

Re: WFH – Watched from Home: Office 365 and workplace surveillance creep (2022)

#317

Always request a separate laptop and phone for work, and always create a separate set of accounts.

Why does it even need to be "request"? Are they that cheap these days that they won't pay unless asked (begged)? If the company needs you to use a computer, it needs to provide you one. I am sure not letting my personal and work machines mix, both for this and IP reasons, and on the other side, if I was in control of such things, using personal machines would be an exception.

My company would rather have me waste several days shuffling data around partitions rather than pay for the cloud disk that I actually need (3T, nothing insane).

Re: WFH – Watched from Home: Office 365 and workplace surveillance creep (2022)

#318

Earlier quoted context omitted.

> UBI in the ideal world replaces welfare, food stamps, and rental assistance. That's never going to happen. UBI will not replace existing welfare payouts, it will augment them. Until society is ready to let people and children die in the street because they (or their parents, in the case of children) gambled or boozed all of the UBI away, or it got stolen from them, or they simply burned it due to mental health prob…

> UBI is also a no-go in terms of "universal". It's just too unfair. What's unfair is to take away someone's welfare once they finally land a minimal pay job. That diminishes or removes the incentive to actually find a job.

> What's unfair is to take away someone's welfare once they finally land a minimal pay job.

Did I say otherwise?

Re: WFH – Watched from Home: Office 365 and workplace surveillance creep (2022)

#319

Earlier quoted context omitted.

> UBI is also a no-go in terms of "universal". It's just too unfair. What's unfair is to take away someone's welfare once they finally land a minimal pay job. That diminishes or removes the incentive to actually find a job.

> What's unfair is to take away someone's welfare once they finally land a minimal pay job. Did I say otherwise?

No. But then if UBI is unfair and welfare is unfair, then what's fair? Providing neither?

Re: WFH – Watched from Home: Office 365 and workplace surveillance creep (2022)

#320

Earlier quoted context omitted.

Tue bar is actually quite high. Teo things can block it: if there is a workers council, it has to approve surveillance of an employees use of IT systems. That surveillance can only be target to specific, named users and for specific purposes, almost like a mini search warrant. If there is no workers council, at the latest stage a court will have a very, very close look at what isbpresented as evidence. The middle gro…

You need to be specific about what legal jurisdiction you're talking about here then - the world is a very big place and different laws apply. I'm not aware of any EU wide laws that prevent what you're talking about here. In the UK an employment contract will state that the employer can monitor your activity if they need to and this is completely legal. Source: https://www.gov.uk/monitoring-work-workers-rights In som…

Germany it is, should have mentioned that.
Post reply on HN