4 ms·
Typically this is disallowed from non company devices. If you're allowed to sync your corporate email to your personal devices, that's probably an oversight.
by willxinc 6y ago
Typically this is disallowed from non company devices. If you're allowed to sync your corporate email to your personal devices, that's probably an oversight.
- deleted 6y ago[deleted]
- KirillPanov 6y agoSo if IMAP-sync to corporate-owned laptops is a common and allowed use case how did an automated system notice this activity? It's not like the IMAP protocol sends the host MAC address or /etc/machine-id as part of the command stream. I'm really having a hard time imagining a plausible automated security system that would have led to this outcome.
- TaylorAlexander 6y agoI worked at Google and we used gmail, not IMAP, to view email. Corporate laptops allowed logging in to your corporate gmail, but I never saw anyone use IMAP and I have a feeling it wouldn’t be allowed. Once I left Google I had no access to my old corporate emails and I’m sure that’s the way they want it. I did thought experiments about data exfiltration and it would certainly be difficult. They control the OS on your system, they control the network, and they authenticate everything so no anonymous access is allowed. That’s why people get caught - they can see basically everything you’re doing on corporate machines or corporate networks and they know who you are.
- renewiltord 6y agoWell, then, there are at least a few paths of reasoning you can follow: * Google automatically flags this by the volume of data transferred and alerts human eyes * Google's alert erroneously fired and they made a press release about it * Google is lying * Your premise that it is a common and allowed use case is false Why stop when your conclusion is absurd. These paths don't appear to take great creativity to identify.