4 ms·
It's hard to believe that there's IT companies that would trust you to work on your own personal PC. It's a glaring security issue that sounds like a company pr
by natymad 4y ago
It's hard to believe that there's IT companies that would trust you to work on your own personal PC. It's a glaring security issue that sounds like a company problem, not a general difficulty for remote work.
- herbst 4y agoI am not sure why that would be an issue. I am 'just a coder' all I do is pushing and pulling things from git.
- natymad 4y ago- You can easily steal code - if you were working on a company laptop with USB device protection (can't connect drives to transfer without approval) and heavy website moderation (can't send code to yourself), leaking code would prove way more difficult. Compare that to just copy+paste on your personal computer. (ofc it's possible to steal from company laptops too, but you'll leave a very visible trail). - You're a security risk if your computer gets stolen: with company laptops remote disable is an easy option, not so much with personal ones. - Your dev environment can be radically different from others if the company doesn't install some software center (OS, dependancies). - You can't guarantee your personal PC isn't compromised by virus software, again playing into possibly leaking code. It's a liability to let devs download code to their personal computers. It's risky from both physical, and intellectual property perspectives.
- herbst 4y agoI've only really worked at 2 different companies. Both had none of the mentioned protections. One was a windows without real AD, and the other was a MacBook I setup myself. I never even heard of USB protection there like. I really understand where you are coming from, but that's definitely not the standard I have witnessed so far.
- natymad 4y agoThat's really interesting to hear, I assumed wrongfully that most places have similar policies in regards to devices (from my experience, and my peers'). Maybe where I'm working we're more harsh than usual:D because we've got the full package - company laptop, transfering anything work related to personal PC is a no go, at home we must use VPN with 2FA, can't connect unapproved USB devices (including mice, keyboards, phone charging, anything), heavy website moderation, and heavy user-based access moderation for anything, and the company laptops are 100% tracked - you have no privacy on it. Even personal phones have to follow some security measures to keep Slack and authentication app (screen sleep <5min, screen lock is a must, and Slack is password protected).
- mejutoco 4y agoI hope they have disk encryption, in case the laptop gets stolen or forgotten on the bus (mac os has this).
- bluedino 4y agoI'm using the same laptop I was at the office with the same USB mass storage policies and same web filtering and DLP.
- ejb999 4y agoDon't kid yourself, there is nothing you can do to prevent people from 'stealing' code they are working on if they are working from home or any other place where someone is not looking over their shoulder 100% of the time. There are reasons to force people to work on a corporate machine, preventing them from stealing code is not one of them.
- natymad 4y agoYou can't prevent any kind of theft 100%. The point of these measures is to make stealing as hard as possible without impeding work. Some guy commented on taking photos - are y'all really planning on taking a photo for every 200 lines, on scripts with lines in the thousands, in repos which contain tens to hundreds of files, which are just for one product? When your company is probably supporting more than a couple products?
- gardenhedge 4y agoHow would people steal code if they're on a corporate laptop and a VPN that blocks & tracks?
- swift532 4y agoIf sufficiently motivated, take pics with your phone. With a good camera, you could minify a lot of code into a tiny font size, take a photo or multiple photos, and OCR them later. Or encrypt the whole repo and just send it to a bucket somewhere. I mean there's got to be a lot of ways to do it if you really want to.
- deleted 4y ago[deleted]
- Sosh101 4y agoMost remote roles allow it in my experience.