Live data from Hacker News

Microsoft Purview: Additional classifiers for Communication Compliance (preview)

pupuweb.com

291–300 of 317 posts

Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)

#291
post #221

Earlier quoted context omitted.

Oh dear, you definitely chose the wrong person to accuse of not auditing their code. I'm typing this from my OpenBSD laptop, which, I assure you, I have audited extensively; but that's hardly relevant to this topic.. I just think it's funny that you would assume this of me. I'm also big on system-transparency[0] and micro systems like Oasis Linux[1] which attempt to limit things being able to hide. Granted, nothing i…

> which, I assure you, I have audited extensively; For which I call BS. Did you audit your OS code, drivers code and your laptop's hardware? We both know you didn't. Why do you make such an obvious lie? If it's magically not a lie, how exactly did you do it and how long did it take?

A belief you hold strongly because you have never enjoyed the beauty of an operating system code you can actually read I guess: https://github.com/openbsd/src

OpenBSD is a lot of code, sure, but far from insurmountable, the drivers are few and quite generalised.

I can’t really say how long it took me to read it because it was over a few years of getting curious and diving in, but it wasn’t much.

I’d say if you were to study the code for 8 hours a day it would probably take about 3-5 weeks.

That said: I’m not claiming that I did a full security audit and found all the bugs: I am stating outright that I have read every line of code in the source tree, and the majority of the code that I run from ports, it’s simple enough that you can do that.

And yes; I still get horrified at a lot of the ports; not everything is perfect.

Exceptions to my curious browsing include Chromium and firefox due to sheer complexity, (and I have had reason to dive into those: the tweaks file is fun); and I have read the majority of the GCC code too (which somehow is much less complex and is quite easy to wrap your head around once you’ve read the dragon book than the browsers).

But the OS. Like you claimed. Is not a binary blob, at least to me. I compile it myself, with a compiler I understand, and with code I have read and understand; this is not uncommon in OpenBSD users; the OS is literally designed in a way that is easy to read; because being easy to read means security bugs have less places to hide. (As per the OpenBSD philosophy).

All of the above notwithstanding, I’m writing this message from an iPhone so not everything in my life is so rigorously understood; I’m not a purist, just a curious tinkerer, like most Linux enthusiasts used to be before the ecosystem became a bit too complex to understand for any one person.

You could argue my phone can leak my chats, to which I say: your matter of “trust” comes back, and I don’t think I would trust my phone with my life to not leak my secrets (signal is asking people to trust them with their lives; journalists and dissidents). But I would trust my laptop.

Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)

#292
post #237

Earlier quoted context omitted.

There is a difference between an investigation under subpoena for example and An automated process that alerts whomever is chosen as overseers to all possible missteps and misdeeds. One is a very targeted and conscious effort the other is automated and pervasive everywhere all the time.

Building and selling AI software to do this is also a targeted and conscious effort. My view is this kind of thing is inevitable and pervasive because there’s a lot of internal risks that companies and governments are worried about. The only solution is to be so valuable that it doesn’t matter.

The targeted normally implies that you have a specific incident and a specific person suspected of a misdeed. Building an AI for blanked surveillance is the opposite of that, you aren't looking for a specific incident, have no specific person to suspect. You are basically accusing everyone of being a criminal without any evidence of wrongdoing. Most people don't want to spend their whole lives treated as criminals, anyone who does is free to live in north korea or russia.

Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)

#293

Earlier quoted context omitted.

> I’m kind of surprised so many people are shocked by this. I know of one company where dozens of people were fired because their email was scanned for external job interviews and the CIO had a report, which he used to prematurely cut staff when he needed to save budget. On a related note, if you were a Microsoft employee, how comfortable would you be talking with recruiters on LinkedIn?

I’d have no problems with it. If they were going to fire me over that, it’s their loss. And it’s not generally in Microsoft’s culture these days to be that petty.

My worry in that position wouldn't be getting fired, it would be getting the conversation (or, if it's got that far, the offer) spiked because someone in HR thinks they can either keep me in my current role by scaring off anyone I might talk to, or share my salary information so they can low-ball me, thereby stopping me from getting a pay bump.

Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)

#294

"The leavers classifier detects messages that explicitly express intent to leave the organization, which is an early signal that may put the organization at risk of malicious or inadvertent data exfiltration upon departure". In other words "how to promote and encourage paranoid behaviors from employers" :(

It's extremely revealing that this particular classifier is framed as "prevent data loss" not "intercept skills loss" or "figure out why your employees want to leave and then fix that".

Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)

#295

Reinforces that during interviews candidates should be determining what the company uses for internal communications and choose accordingly. Anyone using Teams is already a red flag.

What's a good alternative? I feel like it's a matter of time before similar feature is added to Slack and Co.

Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)

#296
post #45

I think if you have an E5 license there is already thoughtcrime functionality built-in. I remember someone demoing this to me in a Teams user group, and no one seemed to think it was creepy at all. In addition to flagging keywords it also used AI to detect undesirable thoughts and emotions, under the guise of anti-harassment and compliance. Unfortunately I can't remember the name of the feature but I think it might b…

Emails aren’t thoughtcrimes. This is nonsense. Everything in corporate email has always been subject to read by others, there is no expectation of privacy. As we’ve seen from countless court cases, they range from boring nothingburgers, to evidence of actual crimes.

> Everything in corporate email has always been subject to read by others, there is no expectation of privacy.

Depends where you work? I expect my work emails to be private.

Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)

#297

Reinforces that during interviews candidates should be determining what the company uses for internal communications and choose accordingly. Anyone using Teams is already a red flag.

What's a good alternative? I feel like it's a matter of time before similar feature is added to Slack and Co.

A few open source options (some with hosted plans)

- Zulip - https://zulip.com

- Mattermost - https://mattermost.com

- Rocket chat - https://rocket.chat

- Matrix - https://matrix.org

Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)

#298
post #24

I'm already not wanting to have personal conversations on teams. My tech savvy colleagues and the ones who can be convinced are on signal, where we talk about job offers and relationships. A few others do Instagram, and get to see my art photography. And occasionally I'll bump into someone when we're both in the office and be able to say whatever not looked over by AI. There's a real chilling effect on getting to kno…

> And occasionally I'll bump into someone when we're both in the office and be able to say whatever not looked over by AI. At my present workplace, we have cameras with microphones. They also have installed spyware on laptops and desktops, to be able to see the screens of employees. They also go through mails and have a list of all web traffic done by employees. Which is one of the reasons I've handed my resignation…

In most places where I worked, I signed an explicit consent form stating that all company-provided means of communication are for work purposes only, and may be audited. I suppose it's required by law.

So my rule of thumb for workplace is: expect no privacy.

If you want to use work-provided email, slack, etc to discuss things which you'd be very uncomfortable discussing in your office in the open, especially in the presence of your bosses, don't. Find a different venue.

Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)

#299

Earlier quoted context omitted.

Why do people persist in using work emails for personal things like job interviews?

I remember during the Ashley Madison leaks there were so many work emails. I wouldn’t even use work email for buying a movie ticket much less organizing dates and affairs. Some people are weird like that. There’s also old people who only have work emails. Lots of different people in the world.

Arguably if you're having an affair it's something to keep from your private email but your work email may not be as visible to a spouse ...

Re: Microsoft Purview: Additional classifiers for Communication Compliance (preview)

#300

Earlier quoted context omitted.

I think it's just another unfortunate manifestation of the phenomenon that Big Tech loves to exploit --- that people seem to care very little about privacy in general, or perhaps have been guided gently in the direction of doing so by those who stand to profit the most strongly from it. In your specific example, there could be a slightly more positive reason --- proof that you do actually have a job at where you clai…

> that people seem to care very little about privacy in general, or perhaps have been guided gently in the direction of doing so by those who stand to profit the most strongly from it. It's not just that they don't care: it's like they see some privacy-invasive thing and automatically use it because it's privacy invasive Like whenever people not only use chrome, but are logged into their google account 24/7 while usi…

The chrome thing is annoying as hell, as Google automatically logs you into Chrome if you log into basically any Google property.
Post reply on HN