Live data from Hacker News

Apple Gestapo: How Apple Hunts Down Leaks

gizmodo.com

11–20 of 65 posts

Re: Apple Gestapo: How Apple Hunts Down Leaks

#11
I read through the article and thought that pretty much all the activity taken by the Apple Security team sounded reasonable. If I'm not mistaken, everything described was taking place in the work place/work systems/etc...

The sketchy companies go a little further, and start doing this with people's _personal_ lives. I'm thinking about when Patricia Dunn (HP Chairman) hired a private investigator to start hacking into people's Cell Phone Bills to find out who they were talking to - Not just from the office, or on office equipment.

There is a reason why you see so many Silicon Valley people carrying two laptops, two cellphones, etc... - One of them is for work, and is to be used in the workplace, and is handed over / searched / subject to surveillance / carries confidential company material. The other one is for personal stuff.

If there was a material leak from my organization, and it was jeopardizing my livelihood, I would darn well _hope_ company security would have its act together and would track down the leak in a professional manner.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#12
post #8

I don't know how people who work in large companies expect to have privacy on the company premises anyway: most of those companies make you sign a set of rules that basically says you forfeit your rights. Same concept in the military, you don't have a right to privacy because (they say) it would be to difficult to manage privacy and check for spies at the same time.

In more sane countries, they expect to have privacy because there are reasonable worker protection laws. Something of this sort would be illegal in most western countries. As an American that's been in Germany for the last 8 years, it often blows my mind what's actually taken for granted as being acceptable in the US. Searching through employees' mail is illegal here (as would be searching an employee's personal belo…

How is it "sane" for companies not to be able to control and monitor their own Internet connections? People clearly do abuse those connections to violate IP, confidentiality, and insider trading agreements.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#13

I read through the article and thought that pretty much all the activity taken by the Apple Security team sounded reasonable. If I'm not mistaken, everything described was taking place in the work place/work systems/etc... The sketchy companies go a little further, and start doing this with people's _personal_ lives. I'm thinking about when Patricia Dunn (HP Chairman) hired a private investigator to start hacking int…

A reminder: Dunn was charged with felonies for that stunt.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#14
post #12
post #8

Earlier quoted context omitted.

In more sane countries, they expect to have privacy because there are reasonable worker protection laws. Something of this sort would be illegal in most western countries. As an American that's been in Germany for the last 8 years, it often blows my mind what's actually taken for granted as being acceptable in the US. Searching through employees' mail is illegal here (as would be searching an employee's personal belo…

How is it "sane" for companies not to be able to control and monitor their own Internet connections? People clearly do abuse those connections to violate IP, confidentiality, and insider trading agreements.

People also use their home internet connections to violate IP, confidentiality and insider trading agreements. Using the purported Apple-logic from this post, Apple is (indirectly) paying for that too, so shouldn't they be able to monitor those connections as well?

A utility argument here, I don't believe is the way to approach this. There are all sort of "useful" things that companies could do that most folks would agree cross the line into invasion of privacy, in the US or elsewhere.

I think there are two important assumptions I'm working with:

- People have a right to privacy in personal affairs

- The work place being only for work is an idealization that in practice does not exist

My argument won't make sense if you don't agree on those two.

Employment is one of the fundamental elements of the social fabric, and the rights of employers and employees are participant to a more general social contract. There exists a line at which a company must sacrifice some utility to uphold its end of that contract (e.g. they can't make people work 12 hour shifts, 7 days a week, even if they think it'd boost output), and as employers have an imbalance of power in negotiating employment terms, the government, in the interest of the people, lays down some guidelines for what the minimum boundaries are. Every developed country has this. The only variant is the extent of those stipulations, not their existence.

I believe the right to privacy is important enough that it's something that an employee should not be obliged to forfeit it in an employment contract. And since it's clear that personal and professional spheres overlap in the workplace, no, I don't think the company should have unrestricted access to an employee's data or actions in the workplace or through work-provided mediums. I don't think there should be microphones in every room; I don't believe that all thoughts discussed in the coffee corner are thusly entitled to the company. Even if they did buy the coffee and the chairs and are paying you at that time. And for me, and the legislators of many (most?) western countries, that clearly extends to internet access and company cell phones.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#15
post #14
post #12

Earlier quoted context omitted.

How is it "sane" for companies not to be able to control and monitor their own Internet connections? People clearly do abuse those connections to violate IP, confidentiality, and insider trading agreements.

People also use their home internet connections to violate IP, confidentiality and insider trading agreements. Using the purported Apple-logic from this post, Apple is (indirectly) paying for that too, so shouldn't they be able to monitor those connections as well? A utility argument here, I don't believe is the way to approach this. There are all sort of "useful" things that companies could do that most folks would…

Scott, employees generally are only able to use their home Internet connections to violate confidentiality because their work computers and connections are poorly policed.

And, it is as a direct result of rampant abuse of company resources that companies are now deploying draconian security controls on worker machines, locking down USB connections and intercepting and parsing Word documents in the OS kernel. I've been involved in several deployments of these products (not a fan), and I can tell you that it's not an abstract concern that is driving their adoption. Bad stuff is routinely happening on company networks, and companies need to be able to protect themselves.

People have a right to privacy in personal affairs, but people need to make arrangements for their privacy when they're at the workplace. The idea that a Dell desktop that a Fortune 500 company provides you with becomes a bastion of personal privacy just because you decide to use it to check your GMail is untenable. Companies need workers to be able to handle sensitive information, and they need workers to be able to use computers and networks to do their job, and they cannot be expected to grin and bear it as their confidential information walks out the door and onto Yahoo Finance message boards.

Germany has powerful computer privacy laws. It is also not a great epicenter of tech entrepreneurship.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#17
post #15
post #14

Earlier quoted context omitted.

People also use their home internet connections to violate IP, confidentiality and insider trading agreements. Using the purported Apple-logic from this post, Apple is (indirectly) paying for that too, so shouldn't they be able to monitor those connections as well? A utility argument here, I don't believe is the way to approach this. There are all sort of "useful" things that companies could do that most folks would…

Scott, employees generally are only able to use their home Internet connections to violate confidentiality because their work computers and connections are poorly policed. And, it is as a direct result of rampant abuse of company resources that companies are now deploying draconian security controls on worker machines, locking down USB connections and intercepting and parsing Word documents in the OS kernel. I've bee…

I'm not arguing that these things aren't useful or driven by real problem; I'm arguing that they're wrong. As are the actions of employees in harming the companies they work for.

But the American stubbornness in me goes back to the same logic of the Fourth Amendment, that despite the no doubt usefulness from a policing perspective of being able to search people without jumping through a lot of hoops, it is still wrong.

The issue of Germany and entrepreneurship is a whole different rant, and there are legal barriers here which I believe stifle entrepreneurship. (The essence of the real rant though is that it's a deeper cultural issue.) But Germany sans privacy laws wouldn't suddenly be an entrepreneurial hotbed. If we're talking easing incorporation, sure. Making it easier to hire and fire people? Once again, I'd be on board. But I don't think privacy is a significant component of the equation.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#18
post #17
post #15

Earlier quoted context omitted.

Scott, employees generally are only able to use their home Internet connections to violate confidentiality because their work computers and connections are poorly policed. And, it is as a direct result of rampant abuse of company resources that companies are now deploying draconian security controls on worker machines, locking down USB connections and intercepting and parsing Word documents in the OS kernel. I've bee…

I'm not arguing that these things aren't useful or driven by real problem; I'm arguing that they're wrong. As are the actions of employees in harming the companies they work for. But the American stubbornness in me goes back to the same logic of the Fourth Amendment, that despite the no doubt usefulness from a policing perspective of being able to search people without jumping through a lot of hoops, it is still wron…

What does the Fourth Amendment have to do with a company searching it's own property? I just don't understand why you think that's wrong! I'm an ACLU-giving privacy nut (and I have real problems with how IT security is often managed), and I recoil from the idea that company employees should somehow have some claim on company property simply because they've been allowed to touch it.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#19
post #12
post #8

Earlier quoted context omitted.

In more sane countries, they expect to have privacy because there are reasonable worker protection laws. Something of this sort would be illegal in most western countries. As an American that's been in Germany for the last 8 years, it often blows my mind what's actually taken for granted as being acceptable in the US. Searching through employees' mail is illegal here (as would be searching an employee's personal belo…

How is it "sane" for companies not to be able to control and monitor their own Internet connections? People clearly do abuse those connections to violate IP, confidentiality, and insider trading agreements.

The people doing that just turn on encryption. The people that get in trouble for using encryption just encode the cyphertext as codewords in their email.

Monitoring communication is mathematically impossible these days.

The deep problem is that employees have a lot less to lose than employers. If you leak a picture of the next iPhone to your competitor, you lose, at most, everything you own. For most people, that's a few thousand dollars. The employer, on the other hand, can lose the entire market for their products.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#20
post #15
post #14

Earlier quoted context omitted.

People also use their home internet connections to violate IP, confidentiality and insider trading agreements. Using the purported Apple-logic from this post, Apple is (indirectly) paying for that too, so shouldn't they be able to monitor those connections as well? A utility argument here, I don't believe is the way to approach this. There are all sort of "useful" things that companies could do that most folks would…

Scott, employees generally are only able to use their home Internet connections to violate confidentiality because their work computers and connections are poorly policed. And, it is as a direct result of rampant abuse of company resources that companies are now deploying draconian security controls on worker machines, locking down USB connections and intercepting and parsing Word documents in the OS kernel. I've bee…

It is also not a great epicenter of tech entrepreneurship.

Perhaps a stable society where people are protected from overbearing authority is more valuable than making a couple of extra dollars today. It is definitely more valuable than a slightly smaller cell phone or a website where you can share 140 character messages with your friend.

There are bigger risks to business than some employees posting a few internal word documents to Yahoo Finance. The worldwide financial crisis was not due to inadequate monitoring of employees' personal e-mail, after all.

Post reply on HN