11 ms·
DNS records of your VPN or corporate work station would be pretty easy. You can line then up with when the review was posted. Then investigate their workstation
by Mandatum 4y ago
DNS records of your VPN or corporate work station would be pretty easy. You can line then up with when the review was posted. Then investigate their workstation more "thoroughly".
- chaps 4y agoPretty uncool to give employers ideas on how to force their IT staff to rat out employees who speak out. Edit: yikes, people.
- bogwog 4y agoAlternatively, it's a warning to employees on how they might get caught.
- MonkeyMalarky 4y agoOnce again for those in the back, never use your employer's equipment or network for anything you don't want them to see!
- quickthrower2 4y agoInsidious problems are things like sync (Google Chrome favourites, Dropbox etc.).
- quickthrower2 4y agoRefer to your work laptop as your “girlfriend”. (SV reference)
- Mandatum 4y agoI'm not for it, I'm just saying - it's trivial. I was in your position, kinda - spent many weeks "searching" but "found nothing". They fired them anyway.
- Zircom 4y agoPretty dumb to talk crap about your employer on said employer's hardware and/or network, regardless of how true it is or not.
- vorpalhex 4y agoNah that's a pretty obvious way to catch people and any sysadmin knows it. Browser history is a good spot to check too. Be smart kids. Do your employer bashing at the public library.
- xmprt 4y agoOr cool to give employees an understanding that employers aren't their friends and can and will go to extreme lengths to screw them over if it benefits the corporation. Also just general advice to avoid doing things on your company laptop if you don't want your employer to know about them.
- chaps 4y agoThat's all fine and dandy and I agree that employees should be informed of these methods. My issue is more with the framing of the post, which clearly doesn't have a cautionary spirit that informs those who'd potentially affected by a vindictive employer. Instead, it's playful curiosity of how to rat out an employee.
- lotsofpulp 4y agoPretty much everyone is carrying around a pocket computer connected to the internet 24/7 with which they can do all their non work related tasks on, including badmouthing their employer.
- feet 4y agoHow many get connected to company WiFi?
- lotsofpulp 4y agoThey all have the ability to disconnect with a swipe and a tap. Life does not get much easier.
- feet 4y agoRight, but I'm trying to consider the average user. They likely aren't aware their activity on their phone is being logged on WiFi. My assumption is that once they got it connected to WiFi, it leaves attention and isn't considered
- heavyset_go 4y agoIf employees cross streams and use the same device on both the employer's network and off, and they post to Glassdoor off-network with the same device, a subpoena could reveal identifying information to the employer. Glassdoor can also choose to just hand over that information when requested, as well.
- kadoban 4y agoThis is a good example of why not to do personal stuff on your work machine or work network. If you care at all if your company would see it, _don't_ do it anywhere near their hardware.
- chasil 4y agoActually, since Glassdoor's protection can obviously be compromized, anyone posting on their site should do so with Tor Browser, which anonymizes access by routing traffic through a minimum of three relays in the "dark web" of the Tor network. It might also be wise to do this on a public WiFi network (not your own ISP or mobile data provider). Any email provided to Glassdoor should be a burner on a service that is not one of the majors (no gmail) also set up with Tor browser, specifically for Glassdoor (and used for no other purpose). Finally, the text that is posted should be somewhat disguised if possible, with altered vocabulary, atypical slang, and distinctly different grammar and sentence structure. Any facts that can reveal identity should be removed. Under no circumstances should a native Android/iOS app be used to post or access any such review. It sounds like we will have examples soon of what happens without these precautions. I imagine that many reviews will be coming off Glassdoor's site rather soon.
- amadeuspagel 4y agoIsn't the entire point of glassdoor that people use their work email to prove they actually work for the company?
- SamoyedFurFluff 4y agoI believe that’s Blind.
- amadeuspagel 4y agoI see.
- atwood22 4y agoIf it’s a managed corporate laptop that uses Chrome, then they could remotely check the browser history, likely directly to the review itself.
- nhooyr 4y agoAre you sure this is possible? I thought managed google accounts didn't allow admins to access browsing or any other history.
- emmelaich 4y agoIf they have managed Google accounts they probably have admin on your device as well.
- not-so-jerry 4y agoTo belay paranoia, this is not always the case. I manage a company's google workspace, and we don't have managed browsers or devices, and no one has ever asked to have that capability.
- mike_d 4y agoI am going to guess you don't have any security or compliance folks.
- enkrs 4y agoUntil the first case when an employee sends death threats from your company laptop and you need to provide the data to the police to help in investigation. Or the first case when some shared credentials get compromised probably from an infected computer and now you need to find which of the 80 laptops is the infected one. Or the first time employee converts his laptop into a wifi access point for the office girl upstairs and unknowingly lets her inside your companies private network. Of course, there are workarounds and better practices for every example. You can solve it without admin access to laptops and network request logging. But company property is not anonymous either with or without full admin access - so why jump trough the hoops to not have it?
- gzer0 4y agoI run a Tor middle relay on one of the 8 IP addresses I have purchased as a block from a certain ISP that allows you to, I have been for around a year. The amount of traffic passing through it is heavy. Obviously, this comes with certain caveats (the middle relay's, or any TOR relay IPs are publicly available and published weekly on GitHub and as you can imagine, some places like to instant ban anything to do with TOR). Since it is only 1 of the 8 IP addresses; the other 7 remain free from blockages of any kind and the one running the TOR middle relay is setup in a manner in which I can use it normally (for the most part) and my traffic would just "blend in" with the normal tor traffic passing through it. You might ask, what is the purpose of this? Well, if it is normal for a lot of TOR middle relay traffic to be passing through one of my IP's on a daily basis, plausible deniability becomes a real defense as checking DNS logs becomes a moot point as there are requests being routed 24/7/365. Edit: https://hacky.solutions/blog/2020/06/06/operating-a-tor-relay.html https://hacky.solutions/blog/2020/06/06/operating-a-tor-rela... This is an excellent, detailed, and in-depth guide of the process of going through running a TOR middle relay. The statistics provided and data presented are simply superb, Great read!
- ywain 4y agoI understand why websites would ban Tor exit nodes, but what's the point of banning middle relays? Wouldn't those only communicate with either other relays or exit nodes?
- gzer0 4y agoSites that don't want Tor users should only block exit relays, but some will lazily block all relays. It's unfortunate but that is the current state of affairs right now.
- OJFord 4y ago'should' from whose perspective though? 'Sites that don't want Tor users' have no incentive to care do they? If anything it stands to reason such a site would block anything and everything to do with Tor, using it as a search term, usernames containing it, anything? (I don't know much about Tor, so am I missing something about 'middle relays' that such a site would want to allow them?) Edit: oh is the point that you're not accessing the site using Tor, just from an IP addociated with Tor use?
- dmos62 4y agoDNS over HTTPS would solve that, right? It's an options flag on Firefox.
- Mandatum 4y agoBarely anyone supports it yet.
- WheatM 4y ago
- saargrin 4y agoin any proper corporate IT , the workstation would already have DLP software which you can use to track Glassdoor use or any other activity ,if you wish
- 4dregress 4y agoThat's why you shouldn't use your work computer for anything but work!
- ulimn 4y agoYes, it's important to separate work you do for your employer from your personal life and everything else basically. I never understood people who use their work/school machines to do stuff that could hurt their employer/school. Or even just to cause them potential problems. But of course, the other way around is true imo: I won't use my personal devices for work - but that's mostly to prevent me from giving free extra work time to my employer.
- whoomp12342 4y agowhy on earth would someone log onto glass door with their corporate work station? are they a fool?