3 ms·
Using Blind with your company email on the company WiFi seems really dumb? Maybe I'm paranoid, but I act as though everything that goes through my company WiFi
by drngdds 8y ago
Using Blind with your company email on the company WiFi seems really dumb? Maybe I'm paranoid, but I act as though everything that goes through my company WiFi and on my company computer is being tracked and stored in some database forever under my name.
And I assume the company email is used to send you a verification email, which means your employer is now tipped off to the fact that you're using a site to anonymously criticize them.
- rootsudo 8y agoCorrect, it's very easy to find out who in the company is on Blind -- most corporations use Exchange. Easy as this: http://ivan.dretvic.com/2011/05/remove-specific-email-from-all-mailboxes-in-exchange-2010-sp1/ http://ivan.dretvic.com/2011/05/remove-specific-email-from-a... The article says "remove" but before you remove, you need to list all employees that have that email - if you just make a test account or look for the domain then you can pipe the results to a text file and that's your list of company insiders who are on the platform. What leadership does with that info, is well, never good.
- yanslookup 8y agoPosted above but someone at my org sent an invite to everyone. Having a list of everyone that received an invite does not mean they signed up...
- rootsudo 8y agoNo, but people who did have an email confirmation. You can search not only from domain sent, but from subject and body.
- yanslookup 8y agoWhat? The invite email from blind is the email confirmation from blind...
- yanslookup 8y agoWhat someone at my org did was send an invite to everyone, so pretty much everyone got an email. We use outlook webapps so it is easy enough to login on a non company device to click the link. My company knows everyone that got a link (everyone) but not who clicked the link.
- dpark 8y agoYou can't use Blind without giving them your company email. But yeah, you can reasonably assume that your company can track who received Blind invites. The WiFi bit doesn't matter much assuming Blind uses SSL (though I've never checked). Your company could see that you've connected but not what you've posted or read.
- throwawaymath 8y agoMany companies terminate their internal/corporate TLS traffic on a reverse proxy they control. This typically lets them see employee internet activity in the clear.
- dpark 8y agoThis works only if you're on a company-controlled device. If you're on a device they do not control, you won't have their root cert installed and this MITM attack is infeasible. If you're using a company-controlled device, you should of course assume they can see all of your network activity. They could easily be capturing all of your activity on the device itself without any MITM attack.