Live data from Hacker News

Apple Gestapo: How Apple Hunts Down Leaks

gizmodo.com

21–30 of 65 posts

Re: Apple Gestapo: How Apple Hunts Down Leaks

#21
post #12

Earlier quoted context omitted.

How is it "sane" for companies not to be able to control and monitor their own Internet connections? People clearly do abuse those connections to violate IP, confidentiality, and insider trading agreements.

The people doing that just turn on encryption. The people that get in trouble for using encryption just encode the cyphertext as codewords in their email. Monitoring communication is mathematically impossible these days. The deep problem is that employees have a lot less to lose than employers. If you leak a picture of the next iPhone to your competitor, you lose, at most, everything you own. For most people, that's…

Technical countermeasures increase the cost of violating contracts. In the real world, DLP systems routinely catch violations, despite the fact that they are all (currently) trivially bypassable.

Your logic says, "wiretaps are meaningless, because monitoring voice is mathematically impossible". Leaving aside the fact that many things that are mathematically possible (such as undetectably encoding high-entropy data as a greater volume of low-entropy data) are practically infeasible, what's your point? Wiretaps, for instance, are clearly incredibly valuable.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#22
How long until someone needs medical attention during one of these lockdowns, and they are fired for leaving to go to the doctor, or feel that they must endure the problem (and risk complications) in order to keep their job?

Not long, I bet, and I imagine that this practice will remain legal for ... oh ... about 3 months after that first case.

I hope Apple increases the frequency of this practice so that it attracts the attention of legislators sooner, and so that their brightest employees seek employment elsewhere. The beginning of the end is near.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#23
post #15

Earlier quoted context omitted.

Scott, employees generally are only able to use their home Internet connections to violate confidentiality because their work computers and connections are poorly policed. And, it is as a direct result of rampant abuse of company resources that companies are now deploying draconian security controls on worker machines, locking down USB connections and intercepting and parsing Word documents in the OS kernel. I've bee…

It is also not a great epicenter of tech entrepreneurship. Perhaps a stable society where people are protected from overbearing authority is more valuable than making a couple of extra dollars today. It is definitely more valuable than a slightly smaller cell phone or a website where you can share 140 character messages with your friend. There are bigger risks to business than some employees posting a few internal wo…

I simply disagree that privacy on workplace computers is worth more than money or smaller phones. I see no greater good being traded for the drag on businesses. If you want workplace privacy, you can provide it for yourself, and you can avoid jobs where intense monitoring is a reasonable condition, such as R&D on the industry's most secret products.

I don't know what the worldwide financial crisis has to do with this, but intensive workplace privacy laws would have hurt the investigation and wind-down of fraudulently priced contracts, not helped it. Hey, you brought it up.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#24
post #21

Earlier quoted context omitted.

The people doing that just turn on encryption. The people that get in trouble for using encryption just encode the cyphertext as codewords in their email. Monitoring communication is mathematically impossible these days. The deep problem is that employees have a lot less to lose than employers. If you leak a picture of the next iPhone to your competitor, you lose, at most, everything you own. For most people, that's…

Technical countermeasures increase the cost of violating contracts. In the real world, DLP systems routinely catch violations, despite the fact that they are all (currently) trivially bypassable. Your logic says, "wiretaps are meaningless, because monitoring voice is mathematically impossible". Leaving aside the fact that many things that are mathematically possible (such as undetectably encoding high-entropy data as…

For now. This sort of thing just encourages active development and deployment of countermeasures. "The more you tighten your grip, Tarkin, the more star systems will slip through your fingers."

Re: Apple Gestapo: How Apple Hunts Down Leaks

#25

How long until someone needs medical attention during one of these lockdowns, and they are fired for leaving to go to the doctor, or feel that they must endure the problem (and risk complications) in order to keep their job? Not long, I bet, and I imagine that this practice will remain legal for ... oh ... about 3 months after that first case. I hope Apple increases the frequency of this practice so that it attracts…

I think it's pretty ridiculous to imply that Apple would accept spectacular corporate liability by dissuading someone from seeking emergency medical attention during an IT investigation. So my guess as to the answer to your question is: it will never happen.

Apple's brightest employees (on the high-security projects) have been aware of extreme security measures for many years now, and positions on those teams are sought after.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#26
post #23

Earlier quoted context omitted.

It is also not a great epicenter of tech entrepreneurship. Perhaps a stable society where people are protected from overbearing authority is more valuable than making a couple of extra dollars today. It is definitely more valuable than a slightly smaller cell phone or a website where you can share 140 character messages with your friend. There are bigger risks to business than some employees posting a few internal wo…

I simply disagree that privacy on workplace computers is worth more than money or smaller phones. I see no greater good being traded for the drag on businesses. If you want workplace privacy, you can provide it for yourself, and you can avoid jobs where intense monitoring is a reasonable condition, such as R&D on the industry's most secret products. I don't know what the worldwide financial crisis has to do with this…

If you want workplace privacy, you can provide it for yourself, and you can avoid jobs where intense monitoring is a reasonable condition, such as R&D on the industry's most secret products.

Can you? Can the majority of people make the right decision here?

It's illegal to sell your child to someone. Why is it legal to sell your privacy?

Re: Apple Gestapo: How Apple Hunts Down Leaks

#27
post #18
post #17

Earlier quoted context omitted.

I'm not arguing that these things aren't useful or driven by real problem; I'm arguing that they're wrong. As are the actions of employees in harming the companies they work for. But the American stubbornness in me goes back to the same logic of the Fourth Amendment, that despite the no doubt usefulness from a policing perspective of being able to search people without jumping through a lot of hoops, it is still wron…

What does the Fourth Amendment have to do with a company searching it's own property ? I just don't understand why you think that's wrong! I'm an ACLU-giving privacy nut (and I have real problems with how IT security is often managed), and I recoil from the idea that company employees should somehow have some claim on company property simply because they've been allowed to touch it.

I'm not saying that the right is guaranteed by the fourth amendment, just that the logic is similar.

Trying to boil down our disagreement: I don't believe that ownership of a device or communications medium entitles one to all of the information which passes through it. It seems we differ there.

So for me that leaves no conflict between something not being my property, but the things which are on it still being mine. "What should a company be able to monitor?" is separate, where both utility and privacy are part of the formula. I believe, morally, not from a utilitarian perspective, that personal privacy trumps corporate utility in this particular case and that a reasonable set of privacy laws encode that.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#28
post #21

Earlier quoted context omitted.

Technical countermeasures increase the cost of violating contracts. In the real world, DLP systems routinely catch violations, despite the fact that they are all (currently) trivially bypassable. Your logic says, "wiretaps are meaningless, because monitoring voice is mathematically impossible". Leaving aside the fact that many things that are mathematically possible (such as undetectably encoding high-entropy data as…

For now. This sort of thing just encourages active development and deployment of countermeasures. "The more you tighten your grip, Tarkin, the more star systems will slip through your fingers."

I think you think you understand my point, but you really don't.

In a frictionless intellectual vacuum, it is true that you can create undetectable covert channels. Covert channels are a fundamental problem in systems security, and that's been well-known since Salzer-Schroeder.

In the real world, the arms race of encoding and detecting extends to the horizon of our understanding of computer science and, most importantly, software engineering. Nobody knows all the mistakes that humans will make attempting to engineer systems to do perfect cover channels. For the forseeable future, both sides of this problem need to come to grips with the fact that they're armed imperfectly.

However, in the data leak scenario, the incentives are lined up to favor the monitors and not the leakers. The monitors have budget, continuous practice, access to all company communications to derive norms, and roughly the same access to equipment as the leakers. Meanwhile, if the leakers are caught just once, they're liable for extreme civil and (in some cases) criminal penalties.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#29
post #23

Earlier quoted context omitted.

I simply disagree that privacy on workplace computers is worth more than money or smaller phones. I see no greater good being traded for the drag on businesses. If you want workplace privacy, you can provide it for yourself, and you can avoid jobs where intense monitoring is a reasonable condition, such as R&D on the industry's most secret products. I don't know what the worldwide financial crisis has to do with this…

If you want workplace privacy, you can provide it for yourself, and you can avoid jobs where intense monitoring is a reasonable condition, such as R&D on the industry's most secret products. Can you? Can the majority of people make the right decision here? It's illegal to sell your child to someone. Why is it legal to sell your privacy?

Because that is a stupid analogy.

Re: Apple Gestapo: How Apple Hunts Down Leaks

#30
post #27
post #18

Earlier quoted context omitted.

What does the Fourth Amendment have to do with a company searching it's own property ? I just don't understand why you think that's wrong! I'm an ACLU-giving privacy nut (and I have real problems with how IT security is often managed), and I recoil from the idea that company employees should somehow have some claim on company property simply because they've been allowed to touch it.

I'm not saying that the right is guaranteed by the fourth amendment, just that the logic is similar. Trying to boil down our disagreement: I don't believe that ownership of a device or communications medium entitles one to all of the information which passes through it. It seems we differ there. So for me that leaves no conflict between something not being my property, but the things which are on it still being mine.…

Even in Germany, if a company states unequivocally that computer resources are for work purposes only, they can in many circumstances monitor usage.

I want to believe you and I don't really disagree on a fundamental level.

Because sure, to the extent that you're talking to your wife on AIM, it is simply none of IT's business what you're saying, and it is appalling that they would paw through logs of those conversations. To the extent that we can legislate against that kind of thing, and even harshly punish company staff for doing that, I'm on board.

But when you get to the place where a company can't provide a sensitive Internet-connected workstation for someone to deal with unreleased financials or the blueprints for a top-secret product, you lose me completely. Your argument simply doesn't seem tenable. Companies in the US have vast monitoring rights over their own property, and that simply hasn't fatally harmed personal privacy.

Post reply on HN