Live data from Hacker News

Figure out who's leaving the company: dump, diff, repeat

rachelbythebay.com

331–340 of 392 posts

Re: Figure out who's leaving the company: dump, diff, repeat

#331

Earlier quoted context omitted.

What? First, Europe isn't a single country and there are large difference between legal systems. Second, what you said is just plain wrong in at least one. In France (which is known for strict worker protections) the employer can go through any employee's mailbox or files on their work computer/account provided 1. that the messages/files in question aren't clearly marked as personal 2. that the conditions for the acc…

> Europe isn't a single country Correct, but it does have a single ECHR. Even though some countries still ignore them.

What ECHR principle are you referring to here?

Re: Figure out who's leaving the company: dump, diff, repeat

#332
post #38

Earlier quoted context omitted.

Maybe this https://github.com/dolthub/dolt

Dolt is really close and yet just doesn't feel right; I don't want to "commit" between transactions, I want every transaction to be a commit.

You can do this with a setting:

https://docs.dolthub.com/sql-reference/version-control/dolt-...

Re: Figure out who's leaving the company: dump, diff, repeat

#333

Earlier quoted context omitted.

What? First, Europe isn't a single country and there are large difference between legal systems. Second, what you said is just plain wrong in at least one. In France (which is known for strict worker protections) the employer can go through any employee's mailbox or files on their work computer/account provided 1. that the messages/files in question aren't clearly marked as personal 2. that the conditions for the acc…

I agree with you, Europe has different countries and some of them are not in E.U. so different rules may apply. However, since France is in E.U. what you describe should be illegal. The article you refer to is 15yrs old btw....

The "article" is published by the French data protection authority. They update them when regulations change. They didn't update this one. Make a deduction, now.

> However, since France is in E.U. what you describe should be illegal.

What's the regulation or directive you're talking about?

Re: Figure out who's leaving the company: dump, diff, repeat

#334

Not a WFH thing. This is a USA thing!! Edit: OP said "Layoffs in the WFH era are weird" Yes they are, but people here don't suddenly go offline quite as weird is what I was trying to get at. Here in Sweden if you are FTE there is usually a 1-3 month layoff period (upppsägningstid) where you work and get paid still. At the end of the period you leave. People usually email the team and even the entire company with "hey…

This is not a particularly helpful comment. I work at a California-based company, though we have employees all over the world. In our layoffs, typically employees stick around for weeks, months, even 6 months sometimes.

How are we supposed to know? Sometimes people put cryptic slack status icons or messages. Sometimes they slack the team or close contacts or something. But in a company with thousands of people, unless an employee sends a email to the entire company, how are you supposed to know? The layoffs happened months ago, why would it occur to me that the person I am working with today will be gone tomorrow, unless they start every conversation with "hey, so I got laid off..."

Nobody really wants to relive that trauma over and over again. It's frankly MORE confusing the longer coworkers stick around after the 'event'.

Re: Figure out who's leaving the company: dump, diff, repeat

#335
I did this before. I ran a cron job once a day that counted the number of active entries in a particular file. It was neat to see the number bump up after an acquisition or drop after a layoff. It was neat to see the overall growth of the company I worked for.

I eventually decided that someone _might_ decide that, although freely available, in aggregate, this material could be _sensitive_. I stopped doing it. I deleted years of interesting data...

Re: Figure out who's leaving the company: dump, diff, repeat

#336
post #212
post #203

Earlier quoted context omitted.

Get a DLP system in place for god sakes. I’ve even seen off shore people work from VMs only where they can’t download or store any file locally, much less dump everything to a USB stick.

Top search result is from Gartner: alarm bells ringing. Data loss prevention seems to be enterprise speak for doing as much intrusive monitoring you can do, in as neutral speak as possible. 1984 is so appealing for so many people, it seems like it is just a book about the tendencies that power can take when it is not guided by sane principles. I have always been employed in a high trust capacity since I was a young a…

What does any of this have to do with theft? In most lawful places, if you dump source code and documents to take with you it’s not going to end well.

https://www.cnbc.com/amp/2020/08/04/anthony-levandowski-gets...

Re: Figure out who's leaving the company: dump, diff, repeat

#338
post #10

Love this bit: "Incidentally, if someone gets mad about you running this sort of thing, you probably don't want to work there anyway. On the other hand, if you're able to build such tools without IT or similar getting "threatened" by it, then you might be somewhere that actually enjoys creating interesting and useful stuff. Treasure such places. They don't tend to last."

I don't love it at all.

It's over-the-top posturing for posturing's sake.

A way to confirm this is to look for HN comments who posture the same. After the Overton window widening, they forget to hold back, and will openly say what we know: it's an abuse of the system that turns an outmoded address book into a gossip rag, to the surprise of the actual people involved.

Citations:

"First I just cared about which accounts got deactivated. Then I started tracking title changes, last name changes (people getting married), department sizes, company head count over time etc."

"LDAP's full of secrets. And to think that you can get nearly all of it with anonymous access. Team or department mergers before they were announced? Yep, I've caught those. Secret mailing lists for internal projects? Check who's a member and you can ferret out what's going on. Bonus if the list mail address gives some of it away."

"Lots of weird things depend on the LDAP tree being broadly accessible. It's just that it leaks more information than most people think."

"Monitor when and what HR is doing. Detect when users are logging in and out of LDAP."

Re: Figure out who's leaving the company: dump, diff, repeat

#339
post #203

Earlier quoted context omitted.

I worked at a large web dev company and for years they had this attitude. Then one designer put in his two weeks and spent the majority of the time downloading all the site files for all of the sites the company had built over the two years he was there. We're talking hundreds of static sites where he took the all the design docs and static HTML/CSS/JS files one would need to recreate them somewhere else. Instead of…

Get a DLP system in place for god sakes. I’ve even seen off shore people work from VMs only where they can’t download or store any file locally, much less dump everything to a USB stick.

If you're running a VM you're storing the whole state of the VM on the host machine, there's nothing technically stopping you from copying all the data, and worse, there's no way to even know that it happened.

What VMs are helpful for is cross-contamination and spyware attacks from other clients a contractor is working for.

Re: Figure out who's leaving the company: dump, diff, repeat

#340
post #10

Love this bit: "Incidentally, if someone gets mad about you running this sort of thing, you probably don't want to work there anyway. On the other hand, if you're able to build such tools without IT or similar getting "threatened" by it, then you might be somewhere that actually enjoys creating interesting and useful stuff. Treasure such places. They don't tend to last."

I wonder if this counts as personal data. It's a copy of everyone's name, job title and employment dates. I can certainly see many European businesses would be wary of an employee keeping this list.

uids are definitely not pii
Post reply on HN