4 ms·
It's incredible to me how many people log into personal account on work devices. People should really research the amount of data security tools harvest.
by seneca 2y ago
It's incredible to me how many people log into personal account on work devices. People should really research the amount of data security tools harvest.
- dghlsakjg 2y agoWhere is a good place to start this research? We have crowdstrike falcon at work, and I would love to know what they are monitoring.
- Etheryte 2y agoIt's been quite a few years since I did anything in this space, but back in the day you could get quite a lot of information simply by wrapping things in sandbox-exec [0] and progressively adding allow rules as the application inevitably blew up. It's a fair bit of manual effort, and I wouldn't be surprised if someone has written a wrapper around it that automatically figures it out, but last I checked this was the most reliable way to explicitly see what a rogue application does. [0] https://www.karltarvas.com/macos-app-sandboxing-via-sandbox-exec https://www.karltarvas.com/macos-app-sandboxing-via-sandbox-...
- SketchySeaBeast 2y agoI sometimes see my coworkers with banking tabs open when they screen share. The level of trust is astounding.
- gnu8 2y agoYou will probably find that your corporate TLS MitM proxy excludes financial institutions so that employees can do their banking without any doubt that their own company would respect the confidentiality of their finances. If not, your cybersecurity team needs some help.
- flumpcakes 2y agoYes, when I was in charge of security at previous places we did not MITM a whole category of websites including banking, health, etc.
- rjrdi38dbbdb 2y agoIt certainly sounds foolish at first, but what's the real risk? Is your employer really going transfer themselves your balance or snoop on your utility bills? Now if you loaded a crypto wallet on your work device, that would be another story..
- SketchySeaBeast 2y agoI know there are bad actors trying to get into my company's network. They are a high visibility target and have fallen victim to ransomware attacks before. Even if I trusted my employer, I don't trust what else may be lurking there.
- crazygringo 2y agoIf your employer isn't requiring you to log in with a personal account on a work device (and they're not), and your personal data doesn't have anything you'd mind your employer seeing, then why not? Because then there's no slippery slope and you're making a conscious choice. A lot of people lead really boring lives and just want the convenience of using their personal e-mail on the work device. Their employer knowing that the kids need to be picked up from soccer at 6 is a non-issue. Obviously, if you do have things it's important that your employer/police/government/etc. not know, then don't, a million times. But if you don't care, then let people make that choice.
- dml2135 2y agoOne reason is that if your employer is sued your personal data/devices can get tied up in the discovery process.
- barbazoo 2y agoHow often does that really happen though, I’ve heard this argument so many times but not really the real impact it has from a real incident.
- hypeatei 2y agoI worked with someone who uploaded private git repositories to his email before quitting. People are not very smart. It's best to completely remove that avenue / temptation anyway, IMO. You can handle personal stuff on your phone. Logging in your work PC is asking for trouble.
- quesera 2y ago> Their employer knowing that the kids need to be picked up from soccer at 6 is a non-issue. That's great and fine, until anything non-trivial in your life happens. Illness, relationship drama, recruiter conversation, off-hand low-context remarks to/from friends... The corporate suckware hoovers up the data, and a) exposes you professionally to the company's whims of self-protection, and b) exposes the company legally to your personal imperfections. Don't cross the streams. It would be bad.
- swah 2y agoIn my case I "lend" my personal device for work (Git, Slack, Figma, Miro... use one Chrome for work and Chrome Beta for personal). So I suppose there's no software running behind the scenes. Should I still worry in this case?
- EricE 2y agoIt's not just data security tools - let your company get involved in litigation and now all your personal stuff is exposed to discovery too. Just dumb to mix personal and work - computers are no longer exotic.