Live data from Hacker News

Glassdoor not so anonymous

webworm.co

241–250 of 507 posts

Re: Glassdoor not so anonymous

#242
post #35

Once had a contract where my client wanted me to do "security work", which was initially meant to be for pentesting their clients, but it turned into me building their wifi auth system. At some point in the gig, one of their clients went to them asking them if it was possible to de-anonymize someone glassdoor review since someone still-employed worked with them. They then went to me to see if I could do it for them.…

DNS records of your VPN or corporate work station would be pretty easy. You can line then up with when the review was posted. Then investigate their workstation more "thoroughly".

No post body was provided.

Re: Glassdoor not so anonymous

#243
post #169

Earlier quoted context omitted.

NZ is very well regarded for freedoms, literally topping the list https://freedomhouse.org/country/new-zealand/freedom-world/2...

Australia and New Zealand are near the top on that list. Libel and defamation is a very commonly sought after legal means of silencing an organisation, entity or person. In Australia it's been weaponised by politicians already: https://www.nytimes.com/2021/11/24/world/australia/defamatio... Yes, both countries are places you can raise a family, start a business, walk down the street without getting shot (at least it'…

Yikes, sounds like a manipulators fantasy.

Re: Glassdoor not so anonymous

#244

Earlier quoted context omitted.

> It appears a few other companies are doing this too, including Kraken ( https://www.kraken.com/ ) Kraken is still silly for going after them, IMO, but the Kraken case isn't as cut and dry. The person who had left the review on Kraken had accepted a large severance package that was conditional on signing a NDA. I think the bad PR Kraken got for going after them wasn't worth it (especially as the review wasn't really…

Who cares if they violated an NDA? NDAs are supposed to protect company secrets, not prevent criticism.

It can protect whatever the contract says. Usually, severance packages include a nondisparagement clause. I highly recommend requesting that they amend it to say "mutual nondisparagement" and re-word the terms to apply to both the employer and employee. That way you get paid to shut up, but they are also forced to abstain from making potentially disparaging statements about you. It's a good ask.

Re: Glassdoor not so anonymous

#245
post #237
post #210

Earlier quoted context omitted.

I run a Tor middle relay on one of the 8 IP addresses I have purchased as a block from a certain ISP that allows you to, I have been for around a year. The amount of traffic passing through it is heavy. Obviously, this comes with certain caveats (the middle relay's, or any TOR relay IPs are publicly available and published weekly on GitHub and as you can imagine, some places like to instant ban anything to do with TO…

Why would an employer looking to fire you care about plausible deniability? Even if your setup worked technically, if the traffic traced back to you then you'd probably find yourself fired under these circumstances regardless.

I think this talk about tracing traffic could well be missing a bigger point. The last time I left a Glassdoor review I had to provide a company email address to do it. This means, although publicly my review was anonymous, Glassdoor knew (and very likely still know[0]) exactly who left it. If they have to hand over email addresses to the company taking legal action there's no need to get clever with traffic tracing.

[0] Even with GDPR and similar legislation all they need is a valid business reason and they can keep my PII.

Re: Glassdoor not so anonymous

#246
post #44

Earlier quoted context omitted.

Pretty uncool to give employers ideas on how to force their IT staff to rat out employees who speak out. Edit: yikes, people.

Pretty much everyone is carrying around a pocket computer connected to the internet 24/7 with which they can do all their non work related tasks on, including badmouthing their employer.

If employees cross streams and use the same device on both the employer's network and off, and they post to Glassdoor off-network with the same device, a subpoena could reveal identifying information to the employer. Glassdoor can also choose to just hand over that information when requested, as well.

Re: Glassdoor not so anonymous

#247
post #77
post #56

I just attempted to look at the reviews. There's an uncloseable pop-up telling you to log in. Normally I wouldn't bother, but curiousity got the best of me - I logged in with my Google OAuth. Not so fast - you haven't contributed to Glassdoor in the last 12 months, here's another annoying pop up and you cannot dismiss it until you do. Does anyone actually bother to use this dark pattern infused service?

First time viewers can see a page freely. So all you have to do is clear your cookies after every page load and you wont be bothered. lol. But yeah, posting a review also gets rid of the banner permanently.

They’re super useful for demonstrating that closing just the incognito tab doesn’t clear your cookies, but closing the whole incognito window does.

Re: Glassdoor not so anonymous

#248
post #175
post #149

Earlier quoted context omitted.

> If so, is this legal? If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. Laptops are cheap. There’s no reason to mix personal and corporate usage.

> If it’s a company provided laptop then it’s a good idea to assume that every keystroke, DNS request, and network packet is fair game. From an OPSEC perspective, sure. But the question was whether it's legal for an employer to do it. You might also get a phone call (on your private phone) about a private medical matter while at work, but I would hope your employer couldn't use the CCTV audio they have in the office…

No post body was provided.

Re: Glassdoor not so anonymous

#249
post #202

In 2016 I left a very scathing, and very truthful, of my current employer on Glassdoor a couple of weeks before deciding to quit. Two weeks later, Glassdoor sends me an email notifying me that the employer is pursuing legal action and I have two options: 1) delete the review, or 2) stand by the review if it's true and, when it comes down to it, my identity may need to be revealed in court when necessary. That was my…

Does Glassdoor require verified ID or something to sign up? Why don't people simply use a VPN and appropriate email to sign up and leave reviews?

Try to register an email address using a host that won't have you flagged as a malicious user should you use an account with that host to sign up for major company's services like Glassdoor. It's virtually impossible to use Tor to register an email address without activating JavaScript, and the email hosts that allow it are very sketchy, and my personal suspicions are that many of them are blatant honeypots.

Re: Glassdoor not so anonymous

#250

Earlier quoted context omitted.

I live in the US, where people and corporations are notoriously litigious and I’ve worked at some terrible places. For example, I once had a coworker that would openly crush up and snort various pills between calls while fundraising for one of the two main political parties. This was not an issue for management. I would never post [name of that employer] from any account that could possibly be attached to my name any…

That doesn't sound great but was this person actually doing anything to interfere with you other than existing in your presence? Just curious, and I agree it's unprofessional. I can be quite judgemental, though.

Yes. A guy railing a line of Concerta right next to me while I was on a call loudly enough for the possible donor to hear and ask about it was a problem for me.
Post reply on HN