4 ms·
What I find most interesting about these situations - and they've happened in google before - is that the employees are almost always fired for 'security breach
by postingpals 6y ago
What I find most interesting about these situations - and they've happened in google before - is that the employees are almost always fired for 'security breaches'. Is it a huge coincidence that the employees who want to unionise happen to always be breaching security, or is google just stretching the definition of security breach?
One could even say that their need to breach protocol to unionise is a violation on google's part in the first place. It should be incredibly easy to unionise.
- TazeTSchnitzel 6y agoPerhaps Google has a strict security policy with lax enforcement (i.e. regularly violated by employees and normally tolerated) which makes it useful for selectively enforcing against people you need a good reason to fire?
- hliyan 6y agoLex malla, lex nulla (bad law is no law). This is one of the best arguments in favor of either enforcing laws (or rules) to the letter or striking them down. This is the ugly side of leniency.
- drudu 6y agoNeither. Google is selectively enforcing their security policy. The article explains: "It fired a number of staff for violating data security - but the NLRB said the rules were applied only to those engaging in union activity."
- Xylakant 6y agoAlmost every one at all institutions I have worked in the past was guilty of a security breach of some sort. One org mandated that you were not allowed to have the 2FA token and your laptop in the same bag. But almost everyone, including me, at some point had their token on the keyring - if you’d throw that in your backpack, put the laptop in you had a security breach. In another, you were not allowed to leave the laptop in a car unattended - leave it in at the gas station while going to pay: security breach. And so on. Security breaches are convenient as cause: If rules are sufficiently byzantine, everyone breaches them at some point or another. “Security breach” also sounds bad enough that few will question the decision to fire. “But everyone does it.” is no defense against an alleged security breach. Whether the rules actually increase security doesn’t matter.
- loopz 6y agoSomehow, such dishonesty is tolerated for corporations. That will eventually bite the people back. Security is personal. Very few people in companies don't violate exposing their user sessions to others unattended, which is a security breach. With GDPR, such lax security may carry million dollar fines, and prison time.
- Hamuko 6y agoWe have that same rule about leaving our work laptop in a car unattended. I've followed that rule pretty religiously, so if I go to the grocery store on my way home, I do my grocery shopping with my laptop bag strapped to my back. But even I've violated that rule at least once when I've left my laptop in the car while I sprint to get my lunch that I forgot in the fridge. And even though the security risk from the laptop being unattended in the car for less than 60 seconds is a violation, if someone was so determined to get my laptop within that kind of a timespan, they'd be determined enough to grab it off of me in person. So the practical security risk there is zero, but you could still grill my ass for it.
- sn41 6y agoNot commenting on this particular scenario. But one reason for the continued existence of absurd laws impossible to comply with, is to selectively apply it against inconvenient people.
- kthejoker2 6y ago"If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him." Richelieu
- lmilcin 6y agoSecurity breaches are very convenient. First, practically any information revealed can be considered security breach even if you just forward a meeting invite with a list of coworkers to your private email or you talked to your friend at a party about what you do at work. This is all explicitly, prominently prohibited by contract (not a google employee but any large corporation I worked did that). Second, company can avoid releasing too much information about it exactly because it is security matter. Third, there is usually good track of evidence and it is easy to find. Just look at the mail the person sent outside the company and look for anything they should not be revealing (ie. almost any information). Fourth, there needs to be no precedent for firing employees for security incidents. Companies do that regularly for valid reasons. And yet as or even more frequently, they decide not to react, also for valid reasons.