I get the 1984 vibe this has. How should companies defend themselves from insider threats?
Microsoft Purview: Additional classifiers for Communication Compliance (preview)
211–220 of 317 posts
Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)
#212Earlier quoted context omitted.
1) Nonsense. If you don't trust other people's code, you're screwed. You put yourself into the position where you have to audit your OS code, your CPU code, code of every driver that runs in your system. None of which you did. 2) Isn't WebRTC open source too? 3) Their code, their decisions.
These are extremely unconvincing and rather shallow refutations. I expect more of people on this forum honestly. Taking the core of your argument: "Trust". The point of E2EE is that we don't trust the network. We put all the trust in the client, something we control. Or at the very least we seperate our concerns. (please refer to this lovely interactive "Tor" diagram by the EFF for what I mean by splitting out concer…
That's not a refutation of my counterarguments at all. It just shows you're frustrated and talked yourself into a corner. We both know you don't audit your OS code, your drivers code, your hardware. All of them can be leaking your secret messages.
> Extremely dismissive, almost to the point of insulting.
Another non-refutation, another frustration, because you have no counterargument.
> It is absolutely not true that they are above criticism
Straw man logical fallacy. I never claimed they were above criticism. Criticize all you want. But expect your arguments disassembled.
> You need this to be able to trust your client, because the point is to decouple some trust from a single entity.
Without auditing your OS, your drivers and your hardware it's pointless. Any of them can leak your messages. Yet you're fine with it.
Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)
#213Earlier quoted context omitted.
This is no way to defend against inside threats. Any real threats will use other means of communication. Meanwhile this is just treating everybody as if they can't be trusted.
I’m sorry, what? Have you never worked for a bank or financial company? Never had to take a drug test for your programming job? US Federal law and the Hundreds of billions of dollars spent on audit, insider trading, cyber security, ex filtration tools STRONGLY point to a corporate culture that is obsessed with defending against internal threats, because that’s the highest source of risk.
Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)
#214I'm already not wanting to have personal conversations on teams. My tech savvy colleagues and the ones who can be convinced are on signal, where we talk about job offers and relationships. A few others do Instagram, and get to see my art photography. And occasionally I'll bump into someone when we're both in the office and be able to say whatever not looked over by AI. There's a real chilling effect on getting to kno…
Why would anyone have personal conversations on a platform which is linked to your work?
Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)
#215Earlier quoted context omitted.
Emails aren’t thoughtcrimes. This is nonsense. Everything in corporate email has always been subject to read by others, there is no expectation of privacy. As we’ve seen from countless court cases, they range from boring nothingburgers, to evidence of actual crimes.
I think it's that you can be considered effectively guilty (there's grounds to fire you or take disciplinary action against you) for tripping an ML routine without further evidence or proof, and that it seems more important to have "clean" corporate communication rather than actually act in good faith (as long as bad stuff happens on off channels, no one cares). Hopefully it doesn't make it outside of the corporate w…
Be good cogs; don’t leave logs.
Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)
#216This is nothing new: corporations have scanned instant messages, emails and even recorded phone calls for decades, and will fire you based on that evidence for violations of corporate policy. And will sue you or call the cops if they detect potential crimes. I’m kind of surprised so many people are shocked by this. I know of one company where dozens of people were fired because their email was scanned for external jo…
Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)
#217This seems to be office 365 implementing monitoring of official communications of employees & contractors for the office account? I don’t think it extends to a personal office 365 account, at least it didn’t seem to. Why is this exactly newsworthy? Any communication through official channels is the property of the employer anyway. To collude, leave & other stuff use personal channels maybe.
> Any communication through official channels is the property of the employer anyway. Why is there always this attitude of "it's a private business, they can do what they want". Why does the fact that they can do something distract from criticism of them doing it? The fact that this tech exists is horrifyingly dystopian on its own merits. But it also has widespread consequences in a country with so many employment mo…
Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)
#218This is nothing new: corporations have scanned instant messages, emails and even recorded phone calls for decades, and will fire you based on that evidence for violations of corporate policy. And will sue you or call the cops if they detect potential crimes. I’m kind of surprised so many people are shocked by this. I know of one company where dozens of people were fired because their email was scanned for external jo…
Why do people persist in using work emails for personal things like job interviews?
Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)
#219Submitted title was "Office 365 implementing AI to detect employees colluding, leaving and more". That broke the site guidelines: " Please use the original title, unless it is misleading or linkbait; don't editorialize. " - https://news.ycombinator.com/newsguidelines.html The proper place to include that sort of interpretation is by adding it in a comment in the thread. Then your interpretation is on a level playing…
I know it's policy to use original titles, but the editorialization in this case hardly seems sensational. Just look at the linked roadmap tickets: * https://www.microsoft.com/en-my/microsoft-365/roadmap?filter... * https://www.microsoft.com/en-my/microsoft-365/roadmap?filter... * https://www.microsoft.com/en-my/microsoft-365/roadmap?filter... * https://www.microsoft.com/en-my/microsoft-365/roadmap?filter... * https:…
Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)
#220Earlier quoted context omitted.
I know it's policy to use original titles, but the editorialization in this case hardly seems sensational. Just look at the linked roadmap tickets: * https://www.microsoft.com/en-my/microsoft-365/roadmap?filter... * https://www.microsoft.com/en-my/microsoft-365/roadmap?filter... * https://www.microsoft.com/en-my/microsoft-365/roadmap?filter... * https://www.microsoft.com/en-my/microsoft-365/roadmap?filter... * https:…
> I know it's policy to use original titles, but the editorialization in this case hardly seems sensational. It's interesting that the HackerNews guideline makes no statement about whether a custom headline is sensational or reasonable. It is: "Please use the original title, unless it is misleading or linkbait; don't editorialize." They probably have a slightly different reason for this rule than many people first im…