Live data from Hacker News

Using Brave's “Private Window with Tor” could get you fired

old.reddit.com

51–60 of 72 posts

Re: Using Brave's “Private Window with Tor” could get you fired

#51

Earlier quoted context omitted.

It is if you have a zero-tolerance policy and they break it. Their IT department will certainly ban Brave to prevent future uses of Tor, now that they’re aware! But there are many industries where a zero tolerance policy for Tor session origination from a desktop is absolutely legitimately appropriate, as it could otherwise be (even just one-time) exploited for massive potential harm to wealth and people. There’s a p…

Who would be comfortable working under such a policy? You'd never know what accidental action on your computer could lead to you being fired. Using a computer to do work is not like getting dressed and carrying a knife with you. You knew you put the knife there, you chose it. If you weren't thinking about the rules, that's on you. A regime where any accidental fat-finger or triggering of an unknown keyboard shortcut…

It doesn’t sound like a fun workplace, but nor should every workplace be fun. I’d really appreciate it if bankers and health insurance companies had to keep audited records and were disallowed encrypted / disposable backchannels, like Tor.

I assume that IT didn’t install Brave, the user did. No IT department at this strict of a company would approve a browser that actively inserts its own advertising into websites, much less has a Tor option builtin. So, then, why on earth would the user risk their employment by installing unapproved software without IT signoff?

If IT approved Brave and pre-installed it, then they would have grounds to contest the firing. That they’re let go suggests otherwise. One could likely predict the demographic of the let-go employee just by filtering for “would know and care about Brave” and “would not seek IT permission first”.

Re: Using Brave's “Private Window with Tor” could get you fired

#52

Well, it appears to be over zealous management. One might as well say “eating at your desk can get you fired”. The problem isn’t the eating. It’s the management.

One of the few comments in this thread that isn't rooted in Stockholm syndrome. Sure, it's prudent to do one's personal computing on personal devices - get a personal laptop or a GPD pocket or something like it for use at work, and only use their uplink via a wireguard link to something else you control (and/or get a cell modem). But management that fires people for using a protocol, and furthermore for using it incidentally? It makes me want to publish everything I do as onion only.

Re: Using Brave's “Private Window with Tor” could get you fired

#53

Earlier quoted context omitted.

Who would be comfortable working under such a policy? You'd never know what accidental action on your computer could lead to you being fired. Using a computer to do work is not like getting dressed and carrying a knife with you. You knew you put the knife there, you chose it. If you weren't thinking about the rules, that's on you. A regime where any accidental fat-finger or triggering of an unknown keyboard shortcut…

It doesn’t sound like a fun workplace, but nor should every workplace be fun. I’d really appreciate it if bankers and health insurance companies had to keep audited records and were disallowed encrypted / disposable backchannels, like Tor. I assume that IT didn’t install Brave, the user did. No IT department at this strict of a company would approve a browser that actively inserts its own advertising into websites, m…

Typically, workplaces this strict don't allow users to install software on their machines themselves at all.

This whole story still just sounds to me like a huge overreaction. I think we can invent a hypothetical situation where the company's behavior makes sense, or the employee's motives are impure, but I think it's much more likely that they just got scared and were rash and hurt an employee.

Re: Using Brave's “Private Window with Tor” could get you fired

#54

There are industries where compliance requires all work-related communications be logged and monitored. This logging is typically done through proxy servers on the network, and avoiding them is a _bad_thing_. They will also track web traffic through a proxy and MITM any https traffic by forcing the use of specific keys. They're trying to look for insider trading. Avoiding the proxy is the problem. Staff using their o…

What do they do about personal devices?

I'm not in the industry, but I am aware of this from various news articles. Quick googling...

Typically, devices are banned from restricted areas (trading floors). Where BYOD is "allowed", apply a corporate profile which prevents the installation of problematic apps. What these people do outside of office hours can get them in trouble too.

NYSE Rule 36 seems to cover this:

https://nyseguide.srorules.com/rules/document?treeNodeId=csh...

(d) Floor brokers must maintain records of the use of telephones and all other approved alternative communication devices, including logs of calls placed, for a period of not less than three years, the first two years in an accessible place. The Exchange reserves the right to periodically inspect such records pursuant to Rule 8210.

UK rules seem to ban BYOD?

https://www.lawyer-monthly.com/2018/03/fca-says-employees-ca...

Re: Using Brave's “Private Window with Tor” could get you fired

#55

There are industries where compliance requires all work-related communications be logged and monitored. This logging is typically done through proxy servers on the network, and avoiding them is a _bad_thing_. They will also track web traffic through a proxy and MITM any https traffic by forcing the use of specific keys. They're trying to look for insider trading. Avoiding the proxy is the problem. Staff using their o…

This is why I'm never not working from home again

Having a work machine and a personal machine side by side is invaluable to me..

Re: Using Brave's “Private Window with Tor” could get you fired

#56
post #20

My company blocks so much inane crap it’s ridiculous. Any site not explicitly reviewed by the firewall company? Blocked. Want to Google restaurants for lunch? Half the restaurants websites are blocked under the firewall rule against “alcohol and bars”. So much more. Trying to talk to IT about it is painful. I had to go through three levels of support over a week just to get a single site unblocked. Before Work-from-H…

> Trying to talk to IT about it is painful. I had to go through three levels of support over a week just to get a single site unblocked.

Don't talk to IT using their support channel. Escalate to your boss (and his boss potentially) about what you are trying to do, what's blocking you and how it's stalling the (revenue generating) project you are working on.

Re: Using Brave's “Private Window with Tor” could get you fired

#57

Earlier quoted context omitted.

It's absolutely reasonable to have security requirements. It's not reasonable to fire someone for a single, accidental violation. I hope the people in the above story realize that they've made a mistake.

It is if you have a zero-tolerance policy and they break it. Their IT department will certainly ban Brave to prevent future uses of Tor, now that they’re aware! But there are many industries where a zero tolerance policy for Tor session origination from a desktop is absolutely legitimately appropriate, as it could otherwise be (even just one-time) exploited for massive potential harm to wealth and people. There’s a p…

I thought in American prisons visitors mostly talk through glass? But maybe that's just something used in movies. Never been to an actual prison even here lol.

Re: Using Brave's “Private Window with Tor” could get you fired

#58

Earlier quoted context omitted.

It doesn’t sound like a fun workplace, but nor should every workplace be fun. I’d really appreciate it if bankers and health insurance companies had to keep audited records and were disallowed encrypted / disposable backchannels, like Tor. I assume that IT didn’t install Brave, the user did. No IT department at this strict of a company would approve a browser that actively inserts its own advertising into websites, m…

Typically, workplaces this strict don't allow users to install software on their machines themselves at all. This whole story still just sounds to me like a huge overreaction. I think we can invent a hypothetical situation where the company's behavior makes sense, or the employee's motives are impure, but I think it's much more likely that they just got scared and were rash and hurt an employee.

You can remove admin rights but portable software will still run just fine. It's actually really hard to stop unapproved software from running on Windows. You'll basically have to cut off all the methods of ingress like USB sticks and internet.

Re: Using Brave's “Private Window with Tor” could get you fired

#59

There are industries where compliance requires all work-related communications be logged and monitored. This logging is typically done through proxy servers on the network, and avoiding them is a _bad_thing_. They will also track web traffic through a proxy and MITM any https traffic by forcing the use of specific keys. They're trying to look for insider trading. Avoiding the proxy is the problem. Staff using their o…

Imagine not having a key logger and mouse tracer on your computer at work. Our machines also lock your account, computer and ID if you plug mass storage devices.

What good will a mouse tracer do without context of what's on screen? Never heard this being put in place for workplace surveillance. Complete screen recording yes but just mouse (or even keyboard which does make some sense) no

Re: Using Brave's “Private Window with Tor” could get you fired

#60

Earlier quoted context omitted.

What do they do about personal devices?

I'm not in the industry, but I am aware of this from various news articles. Quick googling... Typically, devices are banned from restricted areas (trading floors). Where BYOD is "allowed", apply a corporate profile which prevents the installation of problematic apps. What these people do outside of office hours can get them in trouble too. NYSE Rule 36 seems to cover this: https://nyseguide.srorules.com/rules/documen…

Jeez even at home? Glad I don't work in that industry. I hate anything economic or financial anyway :P
Post reply on HN