34 ms·
Ask HN: My client want an agent on my laptop. Is this the new normal?
I work from home in the EU as a freelancer for a US startup.
A few days ago, an email came out of the blue, demanding that I install an "agent" from a company named "Drata"* on my laptop. The motivation is that my client badly want a SOC 2 certification.
I have worked as a developer for more than 30 years. Tiny shops. Startups. Major league. I have never even heard about someone putting agents on developers laptops.
I'm pretty pissed off. So are the teams I work with.
Is this the new normal now?
Just for the record: I don't have credentials to production systems, and I don't work with production data. I just figure out how to transform dreams into code, I write parts of that code, and then I fix it as needed.
* Drata (https://drata.com/about) is on a "Mission to Help Build Trust Across the Internet". Their business model (in my case) seems to be to take money from companies to spy on their employees/contractors, and then they sell the employees/contractors private information to "targeted advertising". When I confronted them about this, they replied: "Feel free to reach out to your Drata administrator internally with concerns. Do note, that when your company contracted with Drata, any edits or redlines they provided will prevail for all employees of your company." - basically to just bend over and smile.
- corobo 5y agoIf your client can tell you how to work, you're not a freelancer. Go get some employment benefits
- dusted 5y agoYou have a third option: Install a VM for working with your client and let their agent run in that.
- MarkSweep 5y agoI second this. Create a VM for work or a VM per client. It makes it much easier to say “I don’t have any of your intellectual property” at the end of your contract when you can delete the whole VM.
- illud_tempus 5y agoThat's what I do today. One VM per customer, on a pretty decent workstation. My host file system is encrypted. If I install the agent, it will complain about the VM's file system not being encrypted. If I double encrypt, compilation times will go up quite a bit. Besides, running the agent in a VM will just be theater. If the host machine is compromised, no security in the VM will mean anything. I could just as well run the agent on dedicated VM with antivirus and disk encryption and just forget about it. Theater is theater. The audience would be the same, and they would see the same Play. However, it would not be ethical. It wold also lower my local security, as it's not impossible for malware to escape from a VM to the host machine. (I have worked for a VM vendor. I know a thing or two about VM's). I have reasonable good security on my devices. Complying faithfully with this requirement would lower my security. If I silo it in it's own LAN, on it's own hardware, it would lower my job satisfaction and my performance.
- yjftsjthsd-h 5y ago> If I double encrypt, compilation times will go up quite a bit. And that's the (poor) choice the company gets to make. Document/communicate that they're getting less work per money and let them deal with it.
- illud_tempus 5y agoI don't want to punish them for being stupid. I want them to not be stupid :) I like the challenges I work on. I work with very smart people. The managers I know well are mostly good people. But the company is growing fast, and there are new managers running loose every week, marking their territory and making signature changes. That's a bit exhausting. Ideally, someone would hit the breaks, and come up with a solution where the company get whatever certifucations they need, without pushing me into "I'm hurt, so I'll hurt them back by being less productive" mode. I enjoy being productive.
- dusted 5y agoAdd an unecrypted disk on which you can store VMs that require VM-level encryption.
- deleted 5y ago[deleted]
- Netcob 5y agoThere are no easy technical solutions to social/political issues. They'll simply make the software detect that it's running in a VM and ban that use. Then you'll work a few hours cheating the software, make your VM look extra realistic. Then the software will get upgraded and your contract gets a clause where you'll pay a fine if they catch you using a VM. Then managers will get the idea they might get complete control over an employee's life, scan their network, track what websites they visit, keep tabs on their social media. If they don't have social media where they should be posting how amazing their company is, they're fired. Many of these things are already happening. We have to fight it, unless you want to spend 90% of your time finding technical solutions to avoid it.
- secondcoming 5y agoWhy would anyone ban VMs? What difference does it make?
- benjaminwootton 5y agoI would buy another laptop specific for that customer. You can then either build the cost into your rates or suggest you bill them for it. You could even sell the laptop when the project ends. Of course you can also be principled over it if you don’t need the work. It is after all a B2B relationship.
- Copenjin 5y agoDon't let this become the new normal, find a better client.
- mixmastamyk 5y agoI would decline. There are other jobs out there. Another alternative might be to install it into a VM or old but freshly-paved computer.
- illud_tempus 5y agoSo far my strategy is to just ignore it and pray that the problem goes away by itself. If I have to deal with it eventually - quitting is the most appealing option. However, the reason I asked here is to get a feeling about how common this thing is. Is this normal? Am I the rat in the lab, or am I just late to the party?
- vanusa 5y agoI don't know first hand, but I would suspect it's more common in financial services and/or with government contractors.
- fdye 5y agoI do not know Drata, but an endpoint agent on a company machine is not that odd. Generally, they come from the big EDR companies, such as Carbon Black, CrowdStrike, etc. They would mostly run in the background and scan for malware, push out Group Policy changes, and yes, provide a backdoor to run scripts on your machine. Drata sounds a bit more like spyware though. Technically, EDR agents can do session captures (recording the screen, showing what was run on the computer over history, processes, network traffic). Generally, though its only utilized for incident response and not tracking a contractors time, making sure they are working, etc. Although I must admit, theoretically there is nothing preventing that, although its at a more technical level then most management would know how to decipher. I second the recommendations above. Only agree to install it on a company machine, same for any agent or company AV, etc. If they wont provide it then its a no go on any personal hardware of yours.
- chx 5y agoThis is spreading but still we must try to stop it. We will fail as we have failed so many times in the past but still we must try. Say, we fought against DRM and while the music industry have completely abandoned it, that victory turns out to be useless because the video streaming industry have embraced it total and there's not even resistance against it this time. I am so, so tired of fighting against these. I translated Doctorow's anti DRM speech in 2004 into my native tongue as one of my last acts as a Hungarian journalist. We have been fighting for so long. And the DRM war is lost. Nonetheless , we need to stand. We, who have the privilege to be able to say "meh, I quit" because we know the next job is just days away. We need to for the sake of all those who do not have such a privilege.
- vanusa 5y agoYou have two options: (1) quit or (2) "renegotiate the relationship", as the saying goes. Specifically, it's perfectly reasonable for you to say "OK -- if you're willing to provide me with a dedicated laptop". They can say no of course, but so can you. Or you can request a rate increase (which they would probably say no to, if they won't provide you with a laptop). Either way, those are you choices. Yes it sucks to a degree, but that's what work does generally and which is why it pays money. All we can do is moderate the suckiness-to-money ratio as best we can.
- illud_tempus 5y agoMy client is quite reasonable, and is willing to compensate a new laptop. It took me less then a few minutes after I read the mail to come up with algorithms to implement this thing without compromising my security or privacy. VM. Using an old laptop and remove the wi-fi card. Get a new PC or laptop. Wire whatever I choose on a vlan that goes directly to a VPN server in another country. However, I still don't like the idea of running an agent on my/a machine. It's a road I feel strongly against going down. But then, I came from a different time, when people still trusted each other and acted in good faith.
- zepolen 5y agoJust get the laptop, use it for work only. This is the best way forward. They are looking for their interests (minimize security breaches) and that's a perfectly understandable position and solution to the problem. In this day and age the risk from a breach is much larger than in the past. Since they are willing to provide the necessary equipment for that then there is no issue from your end.
- alserio 5y agoSince when a backdoor is useful to minimize security breaches?
- periheli0n 5y ago
- MrFoof 5y ago>Is this the new normal now? In my last four engagements, every single laptop provided by the employer had something. Usually Tanium or Carbon Black. Network interfaces being disabled entirely if you're not connected to their VPN. One client requiring the use of a Meraki hardware VPN appliance. This was an investment bank, a university, a software company and a health insurance company.
- EdSchouten 5y agoJust ask them to send you a company issued computer. Use that one to do the work for that one client.
- snapetom 5y agoThis is the standard operating procedure. No employer or client should expect you to install software on your personal machine. They should provide you with a machine if they want to keep an eye on you.
- eps 5y agoSoc compliance is not ensured by spying on employees activities. That excuse alone is a complete bullshit. If this were happening to me, I'd tell them exactly that and refuse to work under surveillance. This is completely unacceptable even if it is getting somewhat common.
- illud_tempus 5y ago> Soc compliance is not ensured by spying on employees activities That part is clearly Security Theater. Having worked with real security for decades (consulting, training, building server monitoring and alerting tools, building commercial firewalls) I get quite provoked by fake security. For example, this "agent" checks for disk encryption. It does not check for password strength, or even if there is a password (you can use full disk encryption under Linux without any password). It also require anti-virus, which under Linux is more likely to do harm than any good. What I don't understand is why they choose to do this to their engineering team. I don't know much about SOC 2, but from what I have read, the "concern" is mainly production related. Most of the engineers, including most of the really senior ones, never access production systems.
- GianFabien 5y agoHad a quick look at drata.com. Looks like vendorware. Some manager got hoodwinked into buying the product to justify their existence. Now they have to force everybody to use it to justify the exorbitant price.
- noisy_boy 5y ago> hoodwinked Or they just saw an opportunity :)
- DnDGrognard 5y agoNice day out (aka Jolly) at the golf club :-)
- celeduc 5y ago
- cjcampbell 5y agoI don’t think this is the new normal, though I would caveat my answer based on the structure of the business relationship and ownership of the device. I would most likely not agree to this arrangement for myself or any of my employees except on a client-provided device. I may be open to installing a limited management profile that I’m able to inspect, but my preference would lean hard toward writing requirements into the contract and providing evidence to the client that we had met the identified requirements. It’s an interesting question, and one that we’ve evaluated with respect to our own customers, who lean on freelancers and other small vendors. Getting back to my original statement about the nature of the business relationship, we’re asking questions about what level of technical sophistication a freelancer has and whether they’ve established enough of their own policies and procedures to meet regulatory requirements independently. Often times, that’s just not practical. Even then, my preference is for the client to provide a managed device to the freelancer or to offer them self-managed options with documentation requirements to prove compliance. Forcing a contractor to install an agent like you’re describing onto their own device feels like a privacy intrusion, and may also represent a risk to the contractor’s other customers.
- DarthNebo 5y agoAsk them to provide a temp laptop for you.
- mxxx 5y ago+1. If it’s their laptop and you’re only using it for their work, no problem. If they’re expecting you to provide the hardware, then politely decline.
- ww520 5y agoIt's not normal. Ask them if they and Drata are willing to be on the hook for all your potential bank breach in the future, as they are key-logging your online banking access. Ask them if they can put up a surety bond or insurance for any of your financial loss due to breach of privacy.
- jevoten 5y agoI believe reducing loss of privacy to only financial costs is the wrong approach. How will you quantify this cost when, for example, Drata runs some fancy ML algorithm on the gathered data, and starts offering employers a "unionization risk" score for new hires that they have intel on? What do you do when being without an evaluation by some spy company like Drata, since you're so privacy conscious, itself becomes a black mark for employers? Rights should not be thought of in terms of their financial cost.
- illud_tempus 5y ago> Rights should not be thought of in terms of their financial cost. Agree!
- neonnomad 5y agoThe Drata agent is a lightweight osquery agent that is read only that reads things like - screen saver timeout, auto-updates turned on, is AV software installed, etc. We collect that data to show the device is compliant with the companies policies and the compliance frameworks they have agreed to. The company this person contracts with requires the agent be installed to monitor compliance for all devices, employee and contractor. Most companies these days require devices meet xyz requirements around patching, av/edr, etc. if they hold company data. It never "key logs" anything or collects any of that type of information. Our agent has been third party security validated and we are happy to share the report with any prospect/customer as well as the configuration. Source: Work for Drata as the CISO
- ww520 5y agoDoes your software run as a Windows service? Is it installed as the System user or Local Admin user? Does it auto update over network? It’s just one update away from adding key logging. Put money on your claim. Put up a surety bond or insurance for users’ data breach. All the security audits won’t beat putting your own financial stake on the table.
- GianFabien 5y agoSomewhat tangentially: I note that most managers seem to equate hours at the keyboard with productivity. I have heard of some employees being monitored via the notebook's video camera. Is it so difficult to define deliverables and pay for completed and tested work? The business value of any given function point is the same whether it took 100 hours to develop or 10 hours. Of course, more productive programmers would benefit under such an arrangement. Oh wait ... the problem is that requirements specifications are never clear nor complete enough and there aren't any tests to confirm correctness of the implementation.
- 5e92cb50239222b 5y ago> Is it so difficult to define deliverables and pay for completed and tested work It is? It's a problem as old as the hills — how do you measure the amount of work done? I can churn out several new features in very short time, but then spend two days chasing a bug which results in a single-line fix. From the management POV this looks like I've been very productive for a few hours and then spent two days doing fuck all.
- mschuster91 5y agoIdeally you'd have a competent team lead that can evaluate whether people are bored out or overloaded with tasks and if their output quality matches expectations. JIRA, Trello or other tools are (usually) not used for the team's benefit, but as "actionable items" or whatever for clueless upper management.
- drran 5y agoThe manager then can look at data and think, "Hm, these bugs are costly. What we can use to reduce number of bugs to reduce costs?" Bugs are a waste. Number of bugs can be reduced with better practices: peer review, various tests; better software: linter, automatic verifier, compile time checkers (-Wall + -Werror, rust), code generators, libraries; or additional business process: quality assurance. To improve something, your manager need to measure it first. You can propose everyday reporting of spent time instead of spying tool, e.g. "2h working on #1234, 6h fixing bug #23456", which is much more valuable to your manager than raw data. In my previous company, we reduced the number of bugs and time to fix by an order of magnitude, because we were able to see the effect of changes in tooling and development process.
- rmchugh 5y agoTalk to your union. This is nonsense. We are SOC2 compliant at my employer without any surveillance tools. There are plenty of other controls that are perfectly reasonable though.
- jusonchan81 5y agoThe agent isn’t mandatory for SOC2, there is an option to just upload screenshots of settings periodically. I had the same situation and I opted to upload the screenshots.
- yjftsjthsd-h 5y agoWhat control is that for? I've worked at multiple SOC2 shops and not encountered any such requirement.
- vegai_ 5y agoSounds like you'll be purchasing a new laptop for that client and bill them for the price of the laptop, and several additional hours on maintaining said laptop.
- tyingq 5y agoI'd also throw in whatever equipment is needed to VLAN all of that away from everything else in your home. Even a second internet connection and router seems reasonable.
- secondcoming 5y agoOP could just use virtual machines. I use my own equipment for my work and it's all on a VM. Everything work related is done on the VM. If I leave all I have to do is delete the VM.
- luma 5y agoI'm surprised I had to scroll this far into the comments to find this obvious answer. Each of my customers has a dedicated VM and I compartmentalize all sensitive data into each environment. In this manner, I can run each customer's goofy VPN client, endpoint scanning, device policy compliance etc without any of it touching my primary system. If there is some security exposure in one of the VMs, it won't impact my primary system or adjacent systems (short of a VM escape exploit).
- wkrsz 5y agoDo you have Drata (the software mentioned by OP) installed in any of your VMs? Does it complain that it's installed in a VM? I've read that Valorant refuses to work on VMs and requires full hardware access for its anti-cheat software. I can imagine "corporate security" agent software doing the same.
- Vrondi 5y agoOMG, a comment with a clue!
- deleted 5y ago
- zorr 5y agoI haven't been in this case yet as most companies I've contracted for were/are small companies <25 employees where everyone brings their own laptop (or at least the contractors do). There was one company which required devices to be up to date on the latest security updates from the OS and every wednesday an employee was chasing everyone to get confirmation that our systems were updated. If a client would require an agent to be installed I would ask for a company laptop to do the work on.
- peterkelly 5y agoTell them no. End of story.
- hericium 5y agoThe concept of "working from home" forced by the pandemic is harming the "remote working" community by extensive invigilation and moving harmful office behaviors to private space. I talked to an Intel HR person (informal chat, I never applied there nor planned to) 2-3 months ago and after I stated that after a decade of remote work, I see pandemic-driven introduction of harmful concepts like spying on previously trustworthy contractors by control-freaking managers that have no idea how to prove themselves in new reality, I was given a look which would usually be reserved for a psychotic person believing that they're being watched 24/7. Quite an unique experience, contrasting with how HR folks are trained to do sect-like "love bombing". You want me to work for you and deliver results? My pleasure - that's what I do. You want me to hang a company logo in my place and sit in front of camera multiple times a day, log every minute of my time and creep on me in other ways? I never worked in "Office Space"-like environment and I'm not planning to. Go fuck yourself, I'm out.
- ciphol 5y agoThis reminds me of how adblocking software worked great when only a handful of nerds used it. Then when adblocking became more mainstream, sites bothered to develop workarounds to make ads show up anyway. Adblockers now try to develop workarounds to the workarounds, but it's a constant battle. Was it great when I was the only one with adblocking software? Yeah, for me. But it was worse for society as a whole, most of whose members had no adblocking whatsoever.
- sbarre 5y agoAnd now we have the majority-share browser vendor Google moving to cripple ad blockers with ManifestV3. So I guess we're winning?
- hutzlibu 5y agoWe as in tech nerds, or we as in whole society?
- realusername 5y ago
- deleted 5y ago[deleted]
- nixgeek 5y agoVery common at least in my experience. Almost all previous and my current job run a whole suite of stuff on all endpoints and feed everything from things your corporate laptop resolves, all the process invocations, all network flows being established back for analysis. These are all Fortune 100 businesses and things may be different in smaller shops? I don’t conduct personal business of any sort on a corporate device. Just not having direct access to production won’t exclude you from security protocols, else how can you guarantee nobody slipped adjustments into software you have checked out,a ‘git push’ originating from your endpoint, which then gets deployed?
- dgellow 5y agoI do some contracting work, and would almost for sure refuse such a demand, even if I end up losing the contract. That doesn’t sound reasonable to have a mandatory surveillance software to install, unless they want to provide their own laptop (or you buy one just for them and send them the bill). Really weird stuff, I hope that won’t become a trend.
- deleted 5y ago[deleted]
- zaphirplane 5y agoThey provide a laptop not on your personal machine because you other client data, right
- bell-cot 5y agoThis. If "work [...] as a freelancer" means that you are not their employee, and they need the legal fiction that you normally have other 'clients' who you freelance for... If they do not provide the laptop, do they mind if your other clients also have agents & such on your machine? If they are honest about this, then providing you with a nice laptop would be far cheaper than dealing with multiple-agent issues. Let alone getting into "how do we need to do this, to comply with laws & regulations?" conversations with lawyers. If they are not honest...
- illud_tempus 5y agoThey have an exclusive clause, so at the moment I work only for them (and on a few open source projects). Legally I work for a company in the EU which I own. They are willing to pay for a decent laptop. That is not the issue. The issue is that I feel quite upset about this requirement. My motivation to discuss it here is to get an idea if I am out of touch with current reality (like some old guys some times are) - or if this is a form of cancer it's worth fighting against.
- blitzar 5y agoAre you able to, as Your Company LLC, (self) certify yourself as a SOC2 complaint entity? Maintain your own records and be able to provide them for audits from the parent company? I agree with much of what has been said, security theatre etc etc; but at the highest level, should companies take IT security seriously, absolutely. Is the implementation correct? Probably / certainly not. The real cancer is the total disregard for security and data privacy that has metastasized to the point where a leak containing everything from a company doesnt even register as an incident anymore. If your contract was with the CIA and they had requirements, you would probably be on board with them. We have all been around the block and seen the state of some peoples computers; even technically gifted people with malware and spyware riddled computers, with the CashFollowerDataScrape Browser Toolbar installed and Password123 securing everything. Do these tools stop this sort of stuff, not really. Work / Personal device seperation is always the answer, the red flags are the companies that demand compliance, but refuse to provide equipment. If the contract wants you to do something you are free to accept or decline. If the contract wants code written using their style guide it would be a similar cosideration, even if it meant spaces instead of tabs. if the contract wants you to code only using your index fingers only, are comfortable with it taking 10x longer and will pay 10x your normal hourly rate, you are free to accept or decline.
- _pmf_ 5y agoInstall it on a spare laptop.
- byron4242 5y agoI recently did something similar. The ironic thing is that I work for a privacy-focused startup where such a practice is in total opposition to personal values held dearly by most people who work there. They claimed (and I assume that it's the truth) that this requirement was forced on them by the insurance industry. Apparently insurers are at the moment super-focused on cybersecurity threats and it's simply impossible for them to obtain general commercial insurance without having this in place. Going without the insurance means greatly diminished valuations and prospects for an exit. So I installed the agent on a webserver that I have that has absolutely no data other than the static files that it serves to the web and that consequently are by definition public. So far they haven't noticed that it's not my actual work machine, and I expect that, with this being a mere box-ticking-exercise that they don't really care about and are on some level even opposed to, they have zero intention of taking it beyond "don't ask don't tell". The thing I'm slightly worried about is that the agent logs logins and failed login-attempts. The problem is that employers who under normal circumstances never look at that data might suddenly get the idea of looking into it when employment disputes come up. So I'm a bit worried about creating an audit trail that basically says I never log in to my machine. Maybe I need a cron job which, with a small amount of random variance, logs into the machine in the mornings and out again in the evening, but that would be crossing a line, legally speaking. With the current state of affairs I can plausibly plead negligence (I meant to install it on my personal device and just didn't notice that I was actually connected to the server when I hit "install"), but with an elaborate setup involving cron jobs and such, I'm clearly establishing that I'm acting in bad faith.
- illud_tempus 5y agoI can easily engineer myself out of this crap. But that feels like a much worse solution than just dropping out. I have two qualities that makes customers willing to pay a premium. I am very good at what I do. I am honest. I don't want to compromise my integrity.
- deleted 5y ago[deleted]
- peppermint_tea 5y agoAnything corporate software is a no go on my personal devices. I like to draw a clear line between work and personal life. The only exception I made is having google authenticator on my cellphone, I feel like I would have been unreasonable to ask a company provided phone for this application only... kvm switch are great to be able to re-use your input/output devices without mixing up personal and corporate stuff... this is what I use... A physical button to separate the 2 environments.
- gnfargbl 5y agoIf you are a freelancer then your contract should allow you to do work for others. In which case, your response to this client has to be "Sorry, but my business laptop potentially has data from other clients on it. I can't let you install this monitoring agent without violating my contractual confidentially agreement with those other clients. I always maintain client confidentiality and will do the same for you. If you want to ship me a dedicated laptop for your engagement, I would be happy to install whatever you want on it."
- anm89 5y agoThis sounds good on the surface but then you are still giving in to unnecessary surveillance during your workday. I would want a big compensation increase to deal with this. Like on the order of 2x my rate.
- qwerty456127 5y ago> If you want to ship me a dedicated laptop for your engagement, I would be happy to install whatever you want on it And they will install a trojan which would eavesdrop your talks, scan your home network and analyze its traffic.
- xyst 5y agoNetwork segmentation with vlan is what I would do.
- gnfargbl 5y agoYep, exactly. I used to put client devices on a segregated network and tunnel their traffic out to pfSense running on a cheap cloud box somewhere. Worked well. (I should say that intentional monitoring of my private comms was never a concern for me when I freelanced, but I was somewhat worried about infections in my clients' devices moving laterally to my home network.)
- unbanned 5y ago
- eksapsy 5y agoI know people who work for Fortune 500 companies who don't have such crap installed in their company laptops, and they mainly work remotely. I also work remotely and I dont have such thing installed either. Installing agents is a sign that the company doesn't value trust with their employees and treats them as liabilities. Companies that made me an offer who had asked me if I would have an issue installing an agent just got rejected from my employer list. If they don't trust me doing my job why should I trust them doing their job. Why not install an agent to the CEO's computer as well? After all I should trust him that he's doing his job well enough for us not to lose our jobs. I'm also dependant on him after all. These are all relationships where trust plays a major role. After all, if you think an employee isn't performing you can just have an annual PDR (Performance and Development Review) and figure out if you have to get rid of that employee or talk to him. Why spy on all of employees? Agents are just an excuse, not the means. It's a disgusting in my opinion excuse to spy on everyone. Whatever the case or how common this is, I won't ever accept agents to spy on me. You do you but I think everyone should do the same. I demand your respect to be mutual to my and your privacy and sense of trust. Agents are harming the remote development space and skew the perception of what it means to have a healthy team.
- illud_tempus 5y agoHave you been met with such expectations often? I have been a developer for more than 3 decades, and I have never even heard about it before.
- saati 5y agoIt almost happened to me once, some dude appeared at my desk and said he will install it now, I said ok, but this isn't MacOS like he assumed as I replaced it with linux (I got CTO approval first). He said he will be back in five and I never saw him again.
- illud_tempus 5y ago+
- 5y ago
- gorgoiler 5y agoDo you object outright to spyware, or to the client wanting to run their spyware on your equipment? It sounds like the spyware is non negotiable and I personally wouldn’t have issue with it if the client also provides a laptop on which to run it. The client is free to do whatever the hell they like with their own hardware. What’s objectionable about situations like this is the client wanting to have their spyware cake and eat it on someone else’s computer. That’s a great deal for them — why pay $5k for a laptop when you can just pay $100 for the spyware license instead?! I realize the economics aren’t exactly on point, but I tend to view situations like this as them stealing $5000 — my laptop — from me. So moving forward: 1/ you are “happy to help them reach their compliance goal and move to a Drata controlled environment” 2/ to do so you “will need to isolate them, as a client, to an airgapped environment solely for their work” 3/ which will need “$5k up front and a lead time of a week to order new hardware, or for the client to ship you a preconfigured laptop with configuration X Y and Z.” Saying yes with principled conditions is always a good route forward. Yes-but instead of no-but.
- illud_tempus 5y ago> Do you object outright to spyware, or to the client wanting to run their spyware on your equipment? I don't know for a fact that it is spyware. For now I just think of it as an "hostile agent". I object because a) I don't want frustrations at work. I want to focus on the problems I am there to solve (which are quite interesting), b) I don't want a hostile agent from a company selling data to "targeted marketing" in my network, c) I don't want such companies even to know my real name, d) I take security seriously - I hate security theater. That's what I object to.
- gorgoiler 5y agoThanks for responding and writing up more details. I empathise with the frustration of having to follow rules for rules' sake. Another approach you can try is to conform to their requirements on one machine, but do all your actual work on another. In the past I've been faced with similar situations where corporate IT required ne to run a "security agent" if I wanted to bring my own device to their network. I ended up bringing a Raspberry Pi which ran their "security agent", but then I did all my work on a laptop that connected through the Pi via NAT. This was at a high school where I was a teacher. The "agent" did an SSL MITM attack, allowing the school IT to see all my traffic. I'm fine with needing that stuff to keep the kids safe but I objected to the school needing to inspect staff traffic. If they mistrusted me to the level of needing to read my email, what the hell were they doing leaving me in a roomful of children all day? If you had two spare Pis you could do a three machine shit-sandwich: (1) trusted-pi is all yours and connects to your home network offering strictly controlled minimal internet access to... (2) the security-theatre-pi, running the client's weird spy/monitoring software; and then (3) your personal laptop connects via the security-theatre-pi. I'd prefer to be direct and up-front with them – it doesn't feel great to have to be duplicitous with people the way I did / suggest you do – but a $50 pi might be able to tick their box and let you get on with the interesting stuff.
- throwaway743 5y agoTell them to pound sand.
- gscott 5y agoBuy a mouse mover https://www.amazon.com/Liberty-Mouse-Mover-Blue-Black/dp/B07P6HBD1N/ref=sr_1_7?crid=17ZD6BT70TD7G&keywords=mouse%2Bmover&qid=1639734359&sprefix=mouse%2Bm%2Caps%2C339&sr=8-7&th=1 https://www.amazon.com/Liberty-Mouse-Mover-Blue-Black/dp/B07...
- DeathArrow 5y agoI would politely tell them to go f... themselves. Or explain them that I value privacy and if they don't, they can go search for another collaborator. Or tell them that installing spyware on my computer is going to cost them 2x the money.
- lordnacho 5y agoWe need an online list of firms that request this. People who use the list should be asked to turn down new firms that do this and inform the firm they are about to be listed.
- illud_tempus 5y ago> We need an online list of firms that request this May be we need a general rating list for software vendors.
- zby 5y agoLaptops are not that expensive any more - maybe you could dedicate one to that client?
- imhoguy 5y agoA middle ground solution may be to use virtual machine on your computer or e.g. ask for access to AWS Workspace under their control. The customer provided me an image with all necessary licensed software I need to use to provide the service, including software to connect to their production infra via VPN and encrypted filesystem. They don't have access to camera, mic, my private system or LAN (use NAT mode). Clipboard sharing is set with guest to host direction only. I can filter out any call home stuff I don't like on my router unless it goes thru their VPN. I Zoom them with my host system, then do screen-sharing of virtual machine window only. In my opinion separating customer gigs with VMs in general is a safe way to prevent accidental cross-customer data leak. Of course it depends on kind of work you do and software you use, however personal licenses often allow to use software on multiple devices by the same person.
- Falkon1313 5y agoIf they own the laptop, they can request you to install anything they want on it, including spyware. If it's your own laptop, you don't have to do that. That's yours, not their property. They can provide you with one configured as they request, or provide it and ask you to configure it that way. Or you could set up a VM for it. Corporate spyware is kinda common nowadays. It's mildly annoying but mostly unlikely to be a problem in many/most places. Mostly just there to deal with problem situations. And you mention that your client wants SOC 2 certification - chances are they'll never actually bother hiring someone to watch what you do on your computer, they just want to be able to check off a box on a form that says "yeah we do this, and all our employees have this thing installed, so we have central control of our data." to get the certification. Because that's what it's about. But also it's just bureaucracy, and probably just checking that box is all they care about so they can tell their clients/customers that their solution is officially certified safe. A lot o' stuff like that is driven by, and ultimately, just feature checklists.
- fhars 5y agoSince you are in the EU, have you asked them if they have confirmed with their DPO that the suggested data collection and processing is GDPR compliant?
- Ekaros 5y agoNot to forget any local legislations. Like secrecy of correspondence which would make it illegal for them to read stuff like emails that aren't shared with them.
- illud_tempus 5y ago> Since you are in the EU, have you asked them if they have confirmed with their DPO that the suggested data collection and processing is GDPR compliant? That was one of the six concerns I raised with Drata. Their reply was: "Feel free to reach out to your Drata administrator internally with concerns. Do note, that when your company contracted with Drata, any edits or redlines they provided will prevail for all employees of your company."
- throw_m239339 5y agoMake your client provide a laptop, simple as that. Make him send you a laptop or cover the cost upfront for a new laptop where he can install all the spyware he wants.
- jhoelzel 5y agoI have been tasked to write software like this for a couple of clients throught my carrer and once I even made a working prototype in C# for Windows. which turns out is not so hard. The reality is though, after i had completed the intial client-app for the Pc's I called the client and terminated the project. He was not to happy about it and a lengthy discussion about whats right or wrong about it ensured. We agreed that it is really not neccesairy and also unwanted surveillance. so i was happy and the code has been scrapped. ....Until his inhouse staff taught him how to read the logins from the actice directory.... Truth be told, if they supply the hardware and you consent to it( at lesat in europe), they are within their rights. If you think its right and give your consent to it, is up to you though PS: A permanently running agent is most likely to make screencaps too.
- psnosignaluk 5y agoAt a company like the one I work for, it's a hill noone can afford to die on. PCI-DSS demands at least some control over employee laptops to ensure that certain secure configuration standards are met. That entails dropping command and control agents on machines. Say what you will about PCI and credit card cartels, but no accreditation, no business. That said, as I work from home, my work laptop lid remains closed for all but a fortnightly company all-hands meeting, and I ensure that I keep zero personal data on it. I'd be an absolute no if the demand ever morphed to always on video or activity trackers. That's a bridge too far. As it stands, I understand the need for some policy enforcement/remote control of their assets, but will make whatever moves I must to ensure that policy doesn't infringe on the rest of my environment.
- mschuster91 5y ago> PCI-DSS demands at least some control over employee laptops to ensure that certain secure configuration standards are met. How does PCI-DSS compliance work in European countries, with GDPR and actual employee rights with teeth and serious fines at play?
- deleted 5y ago[deleted]
- sofixa 5y agoQuite easily actually. PCI-DSS certified companies ( mostly based on my experience at the one I'm currently employed at in France and things I've heard) have agents on employee laptops, but there's an upfront disclaimer what it does and what data it collects ( close to none - it checks for encryption, password policy, antivirus and stuff like this, but no actual activity data is collected). In some cases work has to be done on a terminal server, so no actual PCI-DSS covered data hits the employee laptops. And note, there was backlash against the agent being deployed, which was handled with full transparency - the scripts run by the agent are (internally) open source, there were assurances about privacy, etc. Considering the fines possible, and employee representation, employees are generally inclined to trust those assurances.
- 5y ago
- gibs0ns 5y agoHaving previously led a SoC2 implementation at a few large multi-nationals, the request coming from your company strikes me as either; A) they're being super lazy and using Drata as a blanket to cover a bunch of SoC2 requirements B) it has nothing to do with SoC2, it's just their excuse to push this employee spyware Try asking for a company provided computer. I'd also put that company device on it's own VLAN.
- Aeolun 5y agoNo thanks. If they don’t trust me we shouldn’t be working together.
- haspok 5y agoIf everyone refused to comply, they (and all other companies) would have to rethink their approach and back up. Sometimes I really wish for a trade union of IT workers, however bad that sounds.
- deleted 5y ago[deleted]
- lordwarnut 5y agoWhy does that sound bad?
- haspok 5y agoTrade unions can easily be run as maffia organizations, as it happened in the US in the 20th century.
- illud_tempus 5y agoThey worked pretty well in Scandinavia, and is one of the reasons people there are well payed, have good protections and world class health care.
- sirwitti 5y agoI had a similar issues this year - a client's admin wanted me to hand over my device for him to setup vpn access. My response was that I'm contractually forbidden to allow that since on my device there's data GDPR-relevant and otherwise of other customers. You can also make up a company-policy (even if you're a single person) and communicate it that way. "There's a strict company policy preventing me/us from installing this kind of software." Apart from that, this violates the no-asshole-rule.
- reincarnate0x14 5y agoI deal with critical infrastructure consulting all the time and if the client wants some specific agent run, they send me the laptop to do it on. Not only is your personal equipment yours, it likely contains information about other businesses that you probably have legal obligations to, like NDAs, and if the client doesn't understand that you can't ethically violate that for them, then they're not a client you need to be dealing with. It doesn't help that the 3-5 "IT agents" they run are rarely doing anything useful expect fulfilling 3-5 different directors idea of spying.
- Fradow 5y agoYou mention you are in the EU. That's important because the GDPR applies. Even if you are working for a US company. The details come down to what exactly the software is spying on (I won't look at their website): if it's too invasive, even on a company-provided computer (as many other commenter suggested), it can run afoul of the GDPR (i.e. illegal). There have been some cases already on that [1], and looking up some of them might prove to be a very effective negotiating strategy against that. [1] quick search on Google: https://www.complianceweek.com/data-privacy/employee-monitoring-proving-hot-target-for-gdpr-enforcement/30675.article https://www.complianceweek.com/data-privacy/employee-monitor...
- illud_tempus 5y ago> You mention you are in the EU. That's important because the GDPR applies. They have some lawyer speak in their "Data Processing Addendum" that is unclear to me. I suspect it is designed to enable a loop-hole in GDPR. I'm not an expert. It would cost me a fortune to get a law firm specializing in GDPR to dissect it. Drata declined to comment on my concerns about this.
- Fradow 5y agoThe "Data Processing Addendum" is a legal document that's meant to ensure a legal basis to get GDPR-covered data out of the EU (in my opinion it's a load of bullshit because it's fundamentally incompatible with the Patriot Act, but that's off-topic and beside the point, as far as you or me are concerned it's lawyer-approved). It's a common document that's meant to replace the Privacy Shield (that has been ruled not GDPR compliant a while ago). The Data Processing Addendum isn't a loophole to collect data that they don't have a legal basis to collect.
- illud_tempus 5y ago> The Data Processing Addendum isn't a loophole to collect data that they don't have a legal basis to collect. No. But it looks like a loophole to export whatever they have a legal basis to collect, to process it and share it in ways that GDPR was designed to prevent. In other words, to do what would be a crime in EU.
- woodpanel 5y agoThere is no justification for your client to even remotely think you should install this tool. - It's a massive breach of trust (I'd consider just asking for that tool a testament of no trust at all, irrepairable actually) - The job market gives them zero bargaining power If it comes "out of the blue" like you say, chances are it's being driven by a new guy. You'd do yourself and your client a huge favor by immediately, and visibly to all stakeholders, pointing out the idiocy of that guy's idea (remember, the trust is gone already, no need to sugar coat it then). Because there will be more of those ideas, if he's not interrupted, possibly harming the company in cataclysmic proportions down the road.
- illud_tempus 5y ago> being driven by a new guy. It is. Problem is, I like code. I don't like politics. I'm not good with people.
- hankchinaski 5y agoThis is legitimate when working with sensitive data even as a contractor. I have seen it a lot with fintech clients. In that case though they should provide a company laptop. I would never ever install something like this on my personal laptop.
- illud_tempus 5y ago> This is legitimate when working with sensitive data I work with code. Not data. I don't have access to production systems. I do too many mistakes, and I admit it. Just last month I killed the wrong k8s cluster ;)
- TruthWillHurt 5y agoIf you freelance via upwork this is a normal thing. Odd for contracting though.
- illud_tempus 5y ago> If you freelance via upwork this is a normal thing I don't. My clients usually find me via reputation or via open source projects I work on.
- shaicoleman 5y agoA monitoring agent is used on platforms such as UpWork, where you often deal with untrusted contractors for hourly contracts. That is a part of the contract that both sides need to agree on before starting any work. The screenshots can then be as part of the dispute resolution process, and can also protect the contractor in case of disputes from unscrupulous companies. The agent captures screenshots every few minutes, and the contractor can review and redact any screenshots before sending them. Adding a monitoring agent for an existing contractor is a major change in the contract terms, and not something that I would consider acceptable. It's not normal, and not something you should agree to.
- unbanned 5y agoThis is ridiculous. Whomever came up with this practice has their head in the clouds. Whether the work was done to a satisfactory standard or not should be the only measure, the journey there shouldn't matter a toss.
- stuaxo 5y agoPeople that pay the least trust the least - which makes sense, people know they are being screwed and treat things accordingly.
- yosito 5y agoAnother reason not to work with UpWork!
- neonnomad 5y agoJust to be clear the Drata agent never captures screenshots of the desktop or anything of the sort. It is a lightweight osquery agent that reads system information like patching, screen lock, firewall status, etc. We collect that information for security/compliance purposes so companies can ensure they are meeting their internal controls as well as formal compliance frameworks such as SOC2. We are happy to share our security validation report of the agent as well as the configuration with any prospects/customer. Source: I am the Drata CISO
- 5y ago
- daviddever23box 5y agoThere is no need for this tool with regard to any of the goals of SOC 2.
- pronlover723 5y ago1) Consider dumping the client 2) Consider getting a special laptop for them alone (and bill it to them) 3) Have them send you laptop for their work. 4) Go to 1
- MildlySerious 5y ago"I am not open to installing software that is non-essential to doing my job, and could put mine and other client's privacy at risk."
- gombosg 5y agoAre you sure you need to have that Drata agent on all the time? AFAIK it only checks a few items. We had to install it, too for SOC2 compliance. I installed it, let it send in a report (because I'm on Linux, I manually had to make a few screenshots as proof), then uninstalled it. I'm happy to do the above process next time they complain, if ever.
- mlaretallack 5y agoI work for a large company and even before remote working, all company laptops had to run CrowdStrike, this sounds very similar. However the rules where very clear, no using non-company laptops for work, this included contractors etc...
- usrbinbash 5y ago> demanding that I install an "agent" from a company named "Drata"* on my laptop. If a company sends me decidated hardware, including an LTE or 5G modem to connect to the internet, they can install on that whatever they want. Their hardware, their rules. My hardware, my rules.
- dathinab 5y agoSuch agents are often in breach of GDPR _and_ labor law in the EU. If your employee doesn't fulfill some other criteria, like providing all hardware containing such a agent, not requiring you to use our have the hardware powered on outside of you work time etc. it's unlikely to be legal. They might also need to provide you with a way to separate internet access, e.g. an LTE modem, a this agent the to scan the network which they are in, which is also in beach of law in case of home office.
- js4ever 5y agoInstall it in a linux virtual machine, if they don't have a Linux agent ... Too bad, because you don't have Windows or Mac. If they have a Linux agent it will be running only inside the vm.
- hestefisk 5y agoMaybe they could supply you with a secure VM with the agent installed? So you can separate their work from other activities.
- multimedial 5y agoInstall it in a sandbox.
- walterbell 5y agoOne-way mirrors are not sustainable for performance of non-prisoner workers. Do we need an open-source repo/db/blockchain to track companies which track workers? This could monitor certification/regulatory requirements, benchmark tracking across near-peer companies, real-world impact on human performance, and supply chain integrity of tracking vendors. If a tracking company is breached, it would be possible to flag all of the companies using that vendor.
- blunte 5y agoI predict that this will be the new normal for a while, until the myriad problems it causes really surface. As with other backdoors, these will leak important data and ultimately become priority attack vectors to steal or corrupt data. Of course there's also the worker privacy, but that will always get trampled on until the workers revolt. Part of selling yourself (whether your mind or your body) is deciding where to draw lines. What will you do, or accept, to get paid? I won't accept invasive monitoring. Companies like this can look elsewhere (and they'll find people who will happily trade everything for a little money).
- windex 5y agoAsk for a separate work laptop from them, put it on a different VLAN without access to local resources. Do not login to anything personal on it. That's what I currently do. I also keep it in an office room away from living areas of the house. The VLAN also shuts access to the internet 90 minutes after working hours.
- tony-allan 5y agoAKA - guest network at home...
- neverartful 5y agoCan you elaborate a bit more on your setup? What switch do you use?
- smorgusofborg 5y agoIt doesn't sound normal to me. I would recommend you contact your National Data Protection Authority and provide them the data you've received and cancel the contract.
- tgv 5y agoI work as an employee for a small company that wanted to get ISO-whatever certified, but as the only one in the company I had a BYOD agreement (reasonable fee for bringing my own laptop). The people that helped with the certification process came with some virus scanning plus remote access for maintenance plus login protection solution that everyone must install, or else our precious data would be at risk (in terms of precious metal, the data would be lead). Anyway, they got me a new MacBook Pro. Then they came with the same shit for our phones, but since everyone plainly refused, they found another solution for that. Because there always is one. But this was nipped in the bud at the start. Had people accepted it, there would be no going back, because there never is going back.
- illud_tempus 5y ago> ... they found another solution for that. Because there always is one. Thank you! That is the kind of experience I want a taste of :)
- sokoloff 5y agoIf you can afford to drop that client, drop them. If you don’t want to, make the pain to them apparent as a line item. Tell them complying with this is increasing your costs (by the need to protect other clients’ information) and that your rate will increase by <whatever amount makes this still appealing>. Make them see the costs of their decisions. We had timesheets instituted for a prior company. I had all my devs add an explicit time for entering timesheet data under a dedicated project code. 15 minutes a week for every dev plus 30 minutes for every lead all billed to one project adds up pretty quickly. "Why are we spending 1% of our time on filling out timesheets?!" "That is an excellent question."
- moltar 5y agoNo, that’s not a new normal. I work with many clients and nobody has ever asked me for something like that.
- Stranger43 5y agoUnder EU law that would potentially make you an employee rather then a contractor, as a major part of the destruction is control and time management and the more the Company wants to manage your equipment and time the more the balance swings towards employee status. This is also part of the reason why BYOD is going nowhere as the second the company wants to audit/control setting it's no longer "Your Own Device".
- illud_tempus 5y ago> Under EU law that would potentially make you an employee rather then a contractor, That is not going to happen. I'm a freelancer, and I am going to remain a freelancer. It that becomes too hard in EU, then bye bye EU :) I'm already an expat.
- cgio 5y agoI believe GP refers to the fact that by receiving employee status under law, you also receive a set of entitlements in addition to whatever you have agreed to as a freelancer. This is not about you having to change your preferred way of working, but about the fact that by forcing you to give up that much control, they also assume responsibilities that they probably have not assessed and you could take advantage of.
- physicsguy 5y agoThere’s not really blanket “EU law” on contractors, it’s up to the individual countries which all have wildly different tax and employment rules built on a small common base of employer regulation.
- Stranger43 5y agoNo but there is directives that greatly shape the individual member states laws on those subjects. It's complicated and would probably require an law school Phd. dissertation to fully answer how the whole mess regarding when a single unincorporated freelancer becomes an employee but it's a really really good argument to throw at overly aggressive corporate compliance types trying to push remote control agents onto a freelancers personally owned laptop.
- vegancap 5y agoI work for an ISO certified company, our company laptops have specific things for things like firewalls, allowed software, etc. Things for actual security. But no spyware, I don't feel like you need spyware to get ISO or SOC2, just sounds like a ruse to me for a company that lacks trust. Big red flag. If it's your own personal laptop, then it's your property, they have no right to make you install something on it. If it's their laptop they've given you, then they do. And it's up to you whether you want to work in that way. But as I said, that would sound alarm bells for me.
- Stranger43 5y agoA lot of those things happens because nobody especially not the junior accountants and paralegals doing the compliance audit understand security making a lot of non tech savy companies buy into expensive tools(triggering the sunk cost fallacy) based on what the salesdrones told the CEO/CIO/CSO over lunch and the shadier the product the better the sales team tend to be at hoodwinking customers using scare tactics into adopting their special spyware source just in case. I would also personally be pushing back using every venue open to me on this kind of behaviour but's it is often more a sign of incompetence then malice.
- _gsmq 5y agoWatch out for what all permissions that software agent has. Big firms when they issue their own hardware often install such agents that have ability to not just monitor activity, but also wipe out data or change user account credentials. I personally find it weird if the ask is to install such agent on BYOD (personal device), since not just the company data, but your personal data can also be wiped out remotely, or your account credentials can be changed remotely locking you out of your own device.
- neonnomad 5y agoThe agent is read-only and has no capability to wipe a device, it is a read-only agent that we have security validated with a third party. You can see my other responses in the thread around what it collects but it is just system information to ensure the device is meeting the appropriate security/compliance controls for the company to meet its compliance obligations. Source: I am the Drata CISO
- illud_tempus 5y ago> The agent is read-only and has no capability to wipe a device, it is a read-only agent that we have security validated with a third party. And you can change that over night, without notice to anyone not actively monitoring your platform for such messages. Why is that your policy. You expect a high level of trust. And still you engage in dark anti-patterns that nukes any kind of trust for anyone who know how to read.
- th3sly 5y ago"Zero Trust Networks" usually require an agent to be installed
- manishsharan 5y agoAsk them for funds to buy a new laptop and router ; buy a laptop with removable battery and put the laptop behind the new router taking care to ensure to isolate the laptop. Remove the laptop battery when not using the laptop.
- lmilcin 5y agoThe problem is the arrangement itself. They hire a contractor/consultant to get some value out of you. What they should be doing is monitoring if they are getting the value. Hours spent is not value. If I was in your situation I would ask them if they want to discuss the arrangement, the value and the guarantees they are getting. I would suggest we can agree on zero notice period and no questions asked termination policy (of course symmetrically). I would also want to discuss how they will know the work progresses so that they are satisfied they are not being robbed. If that wouldn't work I would part our ways and find other job. As to installing spying software that should be absolutely out of question. If you agree, you are just enabling them to do the same for other people. Listen, there is no value in having spying software on your computer. Will you work more diligently when you know you are observed? That only works for menial jobs, but if your job is to do anything complex you are just burning time for no reason.
- lucraft 5y agoThere's a load of nonsense in the comments here today. * Drata is a vendor that helps a company navigate your SOC2 compliance process, by organizing all the controls and helping you gather evidence that you have done so. For instance, they'll connect with Github and make sure everyone with access to your repos is a company employee. If you don't use Drata you have to gather this evidence yourself, repeatedly over months, and it's a pain. * The Drata agent is a pretty innocuous thing. It checks you have done things like turn on disk encryption, have updates enabled, and that the screen locks if you walk away. It does NOT monitor employee's activities. These kind of security checks are incredibly common and are required for certifications like ISO27001 and SOC2. SOC2 is not really optional for large enough b2b SaaS. * The poster says "Their business model (in my case) seems to be to take money from companies to spy on their employees/contractors, and then they sell the employees/contractors private information to "targeted advertising". Do you have any evidence for this?? I've just been involved in selecting Drata as a vendor for SOC2 compliance planning for our company. If this is true it's a huge deal and totally against my understanding of their business model. It honestly sounds like bullshit to me! But if you have evidence that they do this, please let us know. * As a freelancer, whether you are required to install security monitoring software is definitely an open question. If you're delivering work separately and not connected to company systems, then ok. If you're basically just acting like any other employee, and connected to the company systems, then you will probably have to do this. Because otherwise they would fail SOC2 and managing your legal status as "Freelancer" vs "Employee" (for tax reasons??) is not worth not being certified.
- ospzfmbbzr 5y ago> Reply to parent Next client! This is potentially an indicator of a bad customer or management. My hardware = my software (not yours) end of discussion. Don't like it? Have fun finding someone better that will put up with your nonsense. Now if they provide a laptop with corp network access etc that is different. I'm a professional similar to yourself. 15 years as a consultant and freelancer.
- lucraft 5y agoI agree: a company asking developers to install security monitoring agents like this should also offer company laptops. Same with mobile phones, actually, for remote wipe profiles and location tracking and things. If they don't offer company hardware I don't think they can rightfully demand agents be installed. But if they do, and if you decline to use it then you have to accept agents on your own machine. Not sure what OPs situation is - but I'd think it very reasonable to go back and say "if you want to install this you have to provide me a laptop"
- eknkc 5y agoDrata has a web application where you can upload evidences of the requirements. The agent just makes it easier. If you are not comfortable, it should not be a big issue. You can choose not to install it and upload a couple screenshots of requested settings (having disk encryption enabled, having a password manager installed etc) periodically. If the client forces it that is a little unreasonable because drata tracks if you uploaded stuff in a timely manner anyway. They don’t need to force it.
- neonnomad 5y agoJust wanted to say thank you for this response around what the agent actually does, there is a lot of misinformation here around what the agent does and we are trying to clear that up.
- illud_tempus 5y ago> there is a lot of misinformation here around what the agent does May be. May be not. I have not decompiled their client, so I don't know what it does. However, Dratas Terms Of Service states: "Drata will notify you of updates via an email or a notification on the platform. Unless the notice states otherwise, the updated terms of this Agreement will become effective and binding on the next business day after it is posted." I assume this is US business days. So I could be on Easter vacation in Romania, while they changed their contract. Drata gives themselves the right to change what they call "the Agreement" virtually without notice. Unless I have a hook in my email client, and a bot looking for notifications on their "platform", and are ready to get up in the middle of the night to print out and read their new "Agreement" - they could fuck me any way they like. Including updating their client with one that does something entirely different than the one thy have today. For a company with a mandatory service, they are surely engaging in a lot of dark anti-patterns. I don't believe for a second that they act in good faith. I don't trust them.
- deleted 5y ago[deleted]
- deleted 5y ago
- mynegation 5y agoYour laptop? No, it is not normal and say “no” to this. Their laptop that they are going to ship to you - yes, it is a normal, acceptable, and reasonable practice for many clients with strict security and/or compliance requirements
- nopcode 5y agoI don't know Drata but to me this is very common. And I don't see the problem. I usually carry ~3 laptops provided by my client or use remote citrix machines. In the rare event I have a customer that let's me work on my own hardware, I use VMs. VMs make it easy to segregate and backup work.
- dt3ft 5y agoNo, this is not the new normal and it will never be. I would never accept this. Period.
- brudgers 5y agoPick your preferred laptop. Add 25% to your final cost for overhead and profit on the hardware. Estimate the time acquiring and setting it up and send the client a proposed cost for their change to the scope. It is business.
- 0127 5y agoMy company is implementing this exact thing - and in general for company laptops I'd say it's not really too crazy (freelancers, contactors will most likely be given machines too if they need any level of access to our stuff/code). From what drata told our team - the agent is based on OSQuery, and just reports disk encryption, antivirus, screen lock, installed applications. Not sure what the other commenters in this thread are going on about but AICPA's soc2 common criteria _do_ require that a bunch of that stuff is configured. The reality we're facing is that unless we actually monitor for those basic security config things, sales/marketing/etc will disable those setting for no reason and promptly leave their laptop in a Starbucks with client user lists or confidential data on it. For other context - based on our research, compliance automation platforms like drata or secureframe greatly decrease the cost of the actual audit since it makes evidence collection that the proper security controls are in place and are functioning much easier. From your perspective though I 100% get the concern though from a freelancer - I'd say that they shouldn't want you to be handling their source code on your personal machine anyways and should prob. send you a laptop.
- bencollier49 5y agoJust out of interest - what happens if you have multiple clients who both want a Drata agent installed? Do you know how well it handles multiple servers?
- neonnomad 5y agoThis is actually an interesting use case for us, I don't think we have addressed it yet but thanks for giving us something to think on. Source: Drata CISO
- htrp 5y agoYet another use case for working through virtual desktops.....
- SkipperCat 5y agoAny decent company that has you work from home (contractor or employee) will provide you with a laptop. That laptop should be used only for work for that company and when you're done with the contract, you return the laptop. This is especially true when you're connecting to their network and using their data. I'm sure there are exceptions for certain types of contracts, but for hourly work this is the norm for companies that take their data security seriously.
- whalesalad 5y agoIf a client asked me to do something like this the answer would be simple: they’d no longer be my client.
- hutzlibu 5y ago"Just for the record: I don't have credentials to production systems, and I don't work with production data. I just figure out how to transform dreams into code, I write parts of that code, and then I fix it as needed." Since the certificate is about protecting user data - and you say you do not have user data - then I would not just accept it, without trying to reason with them, that the general approach they are doing is maybe too broad and unneccesary.
- daneel_w 5y agoThey have no legal bearing whatsoever for demanding that you install this on your own private laptop. Challenge the idiocy by instead asking them to send you another laptop, one that you will use just for this project, on which it will be OK to install the spyware.
- boudin 5y agoI would definitely refuse that. If it's a deal breaker, you can turn the demand around though, by asking what are the actual requirement for the SOC 2 certification to be met and, if possible, metting those in a way that works for you.
- anddt 5y agoI worked as a contractor for a large media company in Europe (fully remote, from Italy). We had company issued laptops prepackaged with corporate tooling (VPNs, accounts, etc.) and that came with a fair bit of corporate-spyware included from _at least_ couple different vendors. At one point, I was writing a small demo in golang for one of our projects and I've been contacted by a security engineer telling me that I've been hitting C:\Users\<yada>\AppData\Local\Temp\go-build2923888066\b001\exe\main.exe too frequently and that called a `cryptsp.dll` that according to him was highly correlated with ransomware attacks. I was adviced to stop working on that until my manager confirmed this was legitimate activity. I must admit, I've been quite freaked by the fact that they were listening for the single executables launched on my machine. Needless to say, this dragged on for a week due to complex internal politics. I thoroughly enjoyed a week of paid time off.
- jdavis703 5y agoI don’t know what your agent does, but from day 1, pre-pandemic we had spy software installed on our work laptops. It ostensibly inspects all network connections looking for malware. When I’m not using my laptop it’s closed, so the camera is off and the mic is muffled. It doesn’t seem like that big of a deal to me. The laptop is for work stuff, most of which is in the cloud under their control anyways. Worst they’re going to find is my raw and unvarnished work logs, which might hurt some feelings if anyone is over-sensitive.
- iandanforth 5y agoSounds like you need to say no. You can describe your expertise and ask if they care more about the appearance of security (SOC2 compliance) or real security. They will choose the appearance of security and you can move on.
- tw20212021 5y agoI don't find this uncommon. I also work as a freelancer, but for local companies (eu). Sometimes the company (banks for example) will ask me to work on one of their laptops, which has vpn and other software that they want. I can of course deny, but then I won't get the contract. As long as I don't feel that they are invading my privacy, like you hear some companies do by taking screenshots, checking for idleness, etc, then I don't mind. In your case I would just rent/buy a new laptop specifically for this job, install their tool and don't worry about it. At the end you can sell your laptop. Or maybe you can work out of a VM running on your laptop, and install it there.
- orra 5y agoThat's different tho. Firms that hire contractors can legitimately require the use of their own equipment, to an extent, on security grounds. However, a hiring firm installing software on equipment they don't even own? That's an entirely new level of control. Remember that contractors are free agents compared to employees. The immorality of this spying aside, contractors shouldn't cede this control unless they want to be treated as employees. They might gain paid holidays and better work security by doing so, but permanent employees are underpaid.
- rvdmei 5y agoYou are sort asking for legal advice. Not sure if I need to elaborate more.
- rvdmei 5y agoBut from a technical perspective, adding end-point protection everywhere is not only a trend, but often a requirement imposed by law and regulation.
- chiefalchemist 5y agoIf they want "ownership" then they could / should supply you with a laptop dedicated to your work for them. Three of the last four (marketing) agencies I worked for supplied me with a MBP.
- jorgeleo 5y agoRequest a laptop with whatever they want pre-installed. Use that laptop only for work for that client. Another solution: Virtualize a pc, put everything that you need to work for that client in that VPC, install they drata only in the vpc. Or better yet, ask them to provide you with a VPC image with what they want. I can understand being piss about it, but unless you are ready to drop them over this, getting angry will be of no consequence
- Arubis 5y agoThey can send you a laptop running whatever they want. Unfortunately, you can’t install an agent not under your direct control on your freelance business laptop, because it would potentially compromise your confidentiality and security agreements with your other clients. This is out of showing your other clients the same level of respect that your subject client can expect.
- NikolaNovak 5y agoyes and no. It's normal to have software that safeguards company's intellectual property (how suitable this particular software is, I cannot speak). However, with that goal in mind, it's also normal for company to provide a dedicated, company-owned-and-managed hardware as well, such as laptop or phone. Demanding that employee or contractor use personal hardware but install monitoring software seems a lose-lose proposition for everybody - it will not necessarily achieve the level of control and safeguards that company desires, and it compromises the contractor's ability to safeguard their own and other clients' data. Depending on circumstances, my own approach would be to start with a friendly email indicating that you understand and support their goals, and propose that the best way to achieve them is to use customer provided and managed hardware.
- pmelendez 5y agoUsually when clients need that level of vigilance, they provide their own laptops. I wouldn't say is a "new" normal, I think it has been common practice for a while at least in the consulting industry
- johlindenbaum 5y agoWe solved this by issuing company owned and controlled laptops to our contractors. Disk encryption, screen time outs, remote wipe etc. contractor machines with code and production access are treated as critical assets and are fully under IT control.
- jwmoz 5y agoJust say no? As a contractor it is my own hardware, no one is making me install anything.
- zivkovicp 5y agoPersonally I would simply refuse and prepare for the possibility that this company will no longer be a client... or charge more for the inconvenience and change in relationship status. I presume you freelance because of freedom to choose clients, projects, and terms. If this is really just your employer (only client), but you have a "freelance" relationship for tax purposes or whatever, then you might want to consider whether you will be better off just getting a job. As a software engineer, I assume you have employment options (there is demand everywhere it seems), so you can probably afford to do what makes you happy.
- illud_tempus 5y ago> Personally I would simply refuse and prepare for the possibility that this company will no longer be a client That is the easy solution. Problem is, I really like the projects I work on and the people I work with. Economically, I could drop out at any time.
- fallingknife_ 5y agoMove on. There are so many job openings right now... Find someone better to work with.
- _jwfergus 5y ago#1 - every client gets their own VM. Unless it acts badly on my network, I'll install pretty much any requirement they ask me to on that VM. #2 - if they require something specific in terms of hardware ("install this spyware directly on bare metal"), have the discussion about hardware setup cost/time and then expense them for the hardware you have to purchase.
- sciurus 5y agoMy employer-provided computer runs multiple agents. They're only used for security auditing as far as I can tell. One of them is reporting all the processes I'm running. Certain keywords will trigger IT to reach out to investigate. Another of them is intercepting all my web traffic, even going as far as installing its own CA and decrypting SSL. It's fun when that hiccups and I start getting SEC_ERROR_REUSED_ISSUER_AND_SERIAL errors everywhere. This provides great incentive for me to keep personal usage off my work computer.
- kgwxd 5y agoNot new, I've been working remotely on and off for 20 years, there's always something they want to install/control. I learned early on to require they give me a dedicated machine. It's just way too messy trying to use a personal (or other business) machine in an environment that requires that level of control. I've been offered the option to Remote Desktop into a VM the company controls but that always requires using their VPN (and sometimes requires a specific security suite be installed), same problem.
- Smeevy 5y agoI've being running a contract development shop for about 20 years and I think that this is very out of line. That said, our usual approach to dealing with customer-required installs like VPN clients is to just spin up a VM using VMWare Workstation on our development machines and do all of the things that touch their network with that. Given the nature of our work, we connect to their environments as little as possible and we leave those VMs off at all other times. We haven't had any problems with that approach thus far. Additionally, we don't offer our clients the option of giving us development laptops for our work with them. That just makes us churn hours without producing anything while we deal with whatever local IT silliness they have. Technical considerations aside, the idea that they want to spy on their contractors is troubling and I'd get away from that situation as soon as possible. Unless they decide to pull back on these requests, it sounds like they'll be just be emboldened to micromanage even more.
- cure 5y agoSince this 'Drata' thing is intended to keep employees/contractor computers in check with policy requirements, runs as (equivalent of) root, and auto-updates, I assume it must be: * completely open source * have gone through security audits with public reports, and a favorable outcome * have reproducable and verifiable builds, and those are the only ones distributed, and the end user can easily verify that their binary copy is an official build? Right? Because if not, aren't you just adding another attack vector onto all your employee/contractor laptops when you use 'Drata' to check a policy box on your SOC2 application? [edit: formatting bullet list]
- handrous 5y ago> Because if not, aren't you just adding another attack vector onto all your employee/contractor laptops when you use 'Drata' to check a policy box on your SOC2 application? I have bad news: gaining security certifications mostly through pointless or even harmful measures is the norm.
- danielzev 5y agoThe agent is intended to ensure devices meet the security/compliance requirements of the company. It is a lightweight read-only osquery based agent that we are happy to share the configuration of with prospects/customers. To address some of your other points: * We have been talking about making it open source, though it is not today. * We do have a third party security validated report that we are happy to share with prospects/customers. * Builds are pulled directly within the Drata portal and the agent does auto-update to ensure we can push any security updates to it that we need to. We do sign the code and you should be able to validate it. Source: I am the Drata CTO
- handrous 5y agoThey need to send you a machine if they want you on some kind of special network or to have their monitoring tools or whatever on it. That's it. Period.
- xuhu 5y agoDual boot between your personal OS and the work OS.
- Danborg 5y agoLoad the client in a virtual machine.
- deleted 5y ago[deleted]
- tw04 5y agoIf they have SOC 2 requirements your options are to install the client or find a different job. That will be completely non-negotiable. We have a division that has to be compliant and they are regularly audited and there are no exceptions allowed. The guys in that group complain daily about what a pain it is so I understand the concern/frustration.
- justinphelps 5y agoI have been through this as well. My client accounts for 90% of my current work, but my laptop contains information about many other clients. Due to the excessive access and control that their spyware requires (Cortex XDR with complete remote access capabilities in this case), I was unable to use the same computer that I use for all other work. I have no choice but to use a separate computer unless I'd be willing to hand over all the information and assets I have for other clients, which I am not. In my case, the client was able to provide me a machine specifically to use with them. I would say that this is the new norm if you're doing long-term engagements with any company that pursues SOC2.
- pjmlp 5y agoI would use GDPR on them.
- more_corn 5y agoSay no. Name and shame. The soc2 controls in question can be met with a handful of config changes and an antivirus install. (I’ve implemented soc2 controls five times) Full disk encryption with FileVault or Bitlocker Screen lock Enable automatic security updates Use of password manager Virus scan with ClamAv or windows defender. If they want an agent to make sure you’re working when you say you’re working I’d pass.
- neonnomad 5y agoThe Drata agent does exactly what you are talking about with a lightweight osquery based read-only agent. Literally just monitors some system settings like screen lock timeout, av-install, updates, etc. We collect that data to then be able to show your auditor you are meeting your controls. Source: I am the Drata CISO
- illud_tempus 5y ago> The Drata agent does exactly what you are talking about Does it also name and shame? ;)
- tonoto 5y agoI would see two rather easy options in this case: - Client supplies a laptop - You create a virtual machine/environment on your laptop and grids the client within the environment.
- Markoff 5y agoI mean if they provide you with separate laptop and all required software I don't see much harm in this.
- ryanmarsh 5y agoAlways do client work in a VM.
- jacquesm 5y agoI don't know anything about Drata but these packages are usually a small step away from malware if they haven't already crossed that line. If you have to do this then insist your employer ships you a laptop that you will use exclusively for the work you do for them. Your device: your rules. Their device: their rules.
- g42gregory 5y agoSend them a bill for a new dedicated laptop and extra time for setup and drop in development efficiency?
- e40 5y agoWhy not just run a VM for their stuff and install it there. You can block the camera and microphone from the host. Do you work in the VM.
- matheusmoreira 5y ago"Agent"? Yet another name for malware.
- Vrondi 5y agoIf all else fails, consider spinning up a virtual machine just for that client, and do all work, install all required apps for that client inside that VM only. I am truly shocked at all the outrage posts with no mention of this.
- tptacek 5y agoIt's not the "new" normal. It's a very old normal. I spent about 15 years consulting, on short- to medium-term often-recurring projects. Most clients didn't ask vendors to instrument their machines. Some did; for those clients, the solution tended to be that the client provided us with a machine to work on. Most of these agents are truly awful. I don't know anything about Drata. You should not be psyched to have that running on your machine; I would isolate it somehow so that it's only in contact with that one client's workload. But they're not making up the SOC2 thing. It's pretty likely they won't budge from this, not because they really care about the agent thing, but because they really do have a documented SOC2 process with "agents on desktops" as a stated control (almost everybody with SOC2 has some kind of agent somewhere, though you usually hope it's just MDM). They do not have a choice about whether to tool you up; your choice is likely just to stop working for them or not.
- citizenpaul 5y agoNever heard of SOC 2 Cert. Its as disturbing as CSAM. Its basically as you put it bend over and take it compliance, total subjection based on a power imbalance. I love the PR. Why is SOC2 important. Because relentless unrestricted spying allows you to foster a control system like never before over your pathetic serfs that dare wish to maintain a work life balance. When that project you forgot to assign goes over deadline use SOC2 to flay them with human resources over too many seconds of bathroom time causing the project to fall behind.
- betwixthewires 5y agoIt's not the new normal unless you let it be. If the other teams are mad, collude with them to refuse. They're not a client if they can make you do this, they're your boss. So don't let them make you do it, because you're not their employee.
- deleted 5y ago[deleted]
- heredoc 5y agoJust put it in a docker container.
- MeinBlutIstBlau 5y agoIn the US, a company cannot mandate that stuff if you are in fact an independent contractor. If they get to monitor your actions, you've got a strong rationale for claiming you are in fact an employee. Lot of companies like to pull this BS thinking independent contractors are just cheap employees. They are in reality, wholly autonomous individuals that operate within the grounds of a contract. If I have to give them a product in X months, go dark for all X, then give them exactly what they needed in X months, I have fulfilled my obligations. They absolutely cannot monitor or manage you at all. I would tell them to get renegotiate the contract or get bent. They can demand all the oversight they want, but I'd explicitly state that they are monitoring me like a W-2 employee and not a 1099 independent contractor (like that explicit). This would ruffle some feathers but I'd make that clear so they know I'm not afraid to walk away. Some schmuck isn't going to pretend he cant just walk all over me just cause he has money. Having to screw around and find another vendor that can deliver something for them in the time they need it is just as important as getting it for the price you pay.
- AnimalMuppet 5y agoOne client asking for it does not make it "the new normal". It makes it "one client asked for it".
- nathias 5y agoNo, tell them this is not acceptable and don't do it. If you do or try to find some excuse it will only further this type of behavior.
- dboreham 5y ago> for all employees of your company As a contractor, you are not an employee so not covered. Basically you get to choose what to do, and in my experience this is not normal, although companies often do have IT requirements for systems that will have access to sensitive information, so the concept in general is not unusual. For me, the fact that this isn't purely about security (e.g. it's not some agent that comes from Cisco or some legit vendor only interested in security), I'd say no. But it depends how hungry you are for work. Since software developers are hard to find, I'd expect you can find work from other clients that don't have this requirement.
- iainctduncan 5y agoThis is second hand, because I've never worked for them, but my friend who worked for cisco was given a laptop that he only did cisco work on and couldn't use for anything else. I'd ask for that. Then they can have whatever the hell they want on it. I've been a contractor on and off for almost 20 years, and no way would I let someone insist on an agent. The most they can ask for is a VPN client.
- seanhunter 5y agoOne option is to ask them to set up a remote desktop instance for you (something like AWS workspaces for instance) that has their monitoring stuff on it and commit to only use this for working for them. Another option would be you set up something like that for working with that client and install their agent on it.
- TimButterfield 5y agoUse a VM (local or in the cloud). I do this for each client. If they have certain software, such as VPN, RDP launcher, etc., it gets installed in the VM. If they wanted an agent in the VM, I would add that also. This protects my main system from their software and, once the project is over, I can easily archive or delete the VM and not worry about a corrupted or compromised local system.
- madman2890 5y agoMake them provide you a laptop. Then only do work for them on that laptop.
- madman2890 5y agoMake them provide you a machine. Don’t do any other work on the machine they provide.
- adamdrata 5y agoHi, Adam here, CEO at Drata. While I don’t know all the details about this specific case, I want to clearly lay out and address some of the concerns and misinformation in your post. We believe trust is the most important aspect of any business, and it’s why we’ve ALWAYS made a point to be very transparent. As a company, we would never develop any software that does what you are claiming. In fact, Drata does just the opposite, by helping companies protect data. First, we should address the WHY. In order to be SOC 2 compliant, one thing businesses need to do is ensure their employees’ and contractors’ computers are configured securely. The “agent” is one way Drata efficiently does this, especially for teams with remote employees. Now, let’s look at the HOW: - The Drata agent is a lightweight, read-only osquery based agent that reads system information such as hard-drive encryption, screen lock timeout, firewall status, etc. Drata collects that information to ensure companies are meeting their security/compliance requirements and so that these companies can prove their SOC2 obligations are being met during audits. - Regarding the TOS, there is no monitoring or selling of your personal information. That is unequivocally false. The question you asked Drata about over email was directly related to the TOS, and not the agent (though we’ve explained what the agent does above). As we stated, we don’t sell customer data. We never have and we never will. I would be happy to chat more to address any concerns you have. You can reach out to me at adam [at] drata.com to chat anytime.
- deleted 5y ago[deleted]
- illud_tempus 5y agoHi Adam. I appreciate that this issue caught your attention. Question: If Drata is nice, why do you portrait yourself as evil in your TOS?
- sergiotapia 5y agoIt's normal but ask them for a work device. You shouldn't be expected to install this monitoring system on your own equipment.
- MrWiffles 5y agoI would tell them if they want an agent on my laptop, they need to send their own laptop because your privacy is non-negotiable. Full stop.
- bks 5y agoIf you are a contractor, ask your company admin if you are in scope. If you are in scope as them for a laptop. If you are out of scope, ask them to mark you out of scope for the audit.
- AlwaysRock 5y agoSay no, get a new client, or say yes. Those are your options. I would tell them no though. If its a company laptop they could have an argument but its you are a freelancer... I would not do that.
- worker767424 5y agoWhat if you tell them that in order to protect others' data, you need a separate laptop. As long as the client is happy to shell out 1500 euros, they you'll install all the spyware they want on it.
- shravvmehtaa 5y agoHi, founder of Secureframe (https://secureframe.com https://secureframe.com) here. Secureframe helps streamline compliance across SOC 2, ISO 27001, HIPAA, PCI DSS, and more. There are so many accurate responses in this thread. Like many have mentioned, SOC 2 is indeed not a prescriptive framework. Much of the confusion behind SOC 2 stems from that fact. It allows you to customize your InfoSec program to your company's needs. As we know, this can vary from company to company, hence why I read so many correct ways of approaching this specific situation in the thread. Why SOC 2? SOC 2 is primarily customer-driven (this is why it becomes so urgent on your org). Buyer's require their vendors to undergo these third-party audits for their own vendor security management. While they would love to take you at your word, they feel a bit better knowing that a third-party took a look under the hood of your InfoSec program. Employee vs. Contractor The legal status of an employee vs. contractor doesn't really matter for SOC 2 or most other InfoSec frameworks. At a minimum, what they really care about is the individuals ability to access, modify, view or otherwise have an effect on production/customer data. If an individual has that ability, they are likely in-scope (this can mean a lot of things). If an individual is indeed in-scope for your audit, they should follow your InfoSec program. You can always have carveouts for certain scenarios (for example, background checks are illegal in many countries so you may exclude them for individuals in those countries). Company Policy What this all comes down to is the policy that the company has put in place. Does the company require all employees and contractors regardless of access to have hard drives encrypted without any carveouts? If so, then the company must follow that practice, or they will risk get an exception on their SOC 2 audit report. SOC 2 has some minimum standards that auditors look for but ultimately the company sets its controls and policies (if they are barebones they might not get accepted). Auditors are human and since SOC 2 is not prescriptive, reasonable minds will differ as to what those minimums exactly are. Common Recommendation This has been mentioned a number of times in this thread but what we typically see and recommend is that you treat all employees as in-scope (this makes it easier on the company so they don't have to make determinations about who should and shouldn't be in-scope) and then for all contractors, you create a carveout where if they don't have access etc to production/customer data then they are not in-scope. In this case, such contractors would not need to track things like hard drive encryption, rendering the need for the agent moot. This seems in-line with the original posters role, and we would typically not have our customers require this of such a contractor. There is nuance needed to make some of these determinations. For example, a company could hire a contractor who only has access to source code. In this case, an auditor may say that this contractor is indeed in-scope since they have control to modify source code that is pushed to production, even though they don't have direct access to the production itself. We can't speak to the Drata agent, but based on what we would expect, the organization in OP's question is most likely trying to simplify evidence gathering when it comes time for the audit. There are other ways to grab such evidence (manual screenshots), but they are time consuming. Based on OP's job description it doesn't seem like its necessary for OP to be in-scope in this scenario and therefore the organization shouldn't need to collect such data. However, as we mentioned, this organization could have more stringent policies and without more information there isn't a wrong or right answer here. What we can confidently say is that it isn't a hard SOC 2 requirement.
- frank_be 5y agoI work as a CI(S)O for a startup. We have lots of freelancers and have Soc2. Unless you fake your soc2, there are two options: give freelancers a company laptop, or force them to install the agent. We do two things. One: we give them the choice. Yes it costs money, but not that much. Two: we went with Kolide. To understand how they are different, go read https://honest.security https://honest.security.
- irvingprime 5y agoIs this in your contract? No? Then forget it. This is neither normal nor reasonable. Do not accept it.
- smackeyacky 5y agoRun it in a VM. Doing work for clients often involves installing other software of theirs i.e. their preferred VPN client. I just run up a VM because having 10 different VPN setups is a disaster waiting to happen.
- ioman 5y agoAt a previous employer they wanted me to install some work software on my iPhone. Nothing particularly invasive as far as I could tell, just Okta, gmail, etc. I told them up front that it violated my personal security policy to install any work software on my personal devices. I told them this was for their protection as much as my own. This brought my boss up short and he wondered aloud why this wasn’t already company policy. Fast forward two months and it became company policy. So it’s my fault that everyone that needs to use company software on their phone has to carry a separate company phone.
- Meph504 5y agoAt this point, I've gotten to the point where each client I deal with, has their own vm. This insures no commingling of data between clients, and my personal use and the clients. In that regard, its easy for me to put an agent on their vm, I do run pi-hole so it doesn't matter what VM I'm in, most of this sort traffic gets filtered. I would also recommend reviewing the contract you have with them, to see if it allows them to put these sort of measures on you. And personally determine if this contract is worth keeping, a company wishing to push something like this, with that rigid a response, doesn't sound like someone you would want to maintain a relationship with. But either way, it seems like this is something that could be resolved without much effort.
- heybecker 5y agoIf you're not willing to walk away, you have no negotiating power.
- atmosx 5y agoIn your place I wouldn't accept that. If the client has such requirements they should be shipping their hardware to you.