10 ms·
It's always been hard to know the extent of how draconian tracking actually is (IT pros tend to not talk about it much). In the US, there's the expectation tha
by crispyambulance 4mo ago
It's always been hard to know the extent of how draconian tracking actually is (IT pros tend to not talk about it much).
In the US, there's the expectation that when you use an employer-provided device that any and all activity on it can be fully monitored/recorded and used against the employee for any reason. In practice, however, few people worry about reasonable amounts web-surfing, being on hacker-news or doing life-activities on their work machines. Oh, here I am on hacker-news when I should be working.
With AI, this changes significantly since the man can now employ a robot to categorize and finely scrutinize every little thing with the pretext of "training" (to take your job). We will soon have to brace ourselves for an absolute draconian level of tracking.
- tamimio 4mo ago> employer-provided device that any and all activity on it can be fully monitored/recorded And the location, yes, your physical location as well
- kelseydh 4mo agoWork will even flag you for you using a VPN on your phone, e.g. if you check the company Slack.
- p0w3n3d 4mo agoDoesn't visiting hacker news count as personal growth? Or am I supposed to grow professionally outside the work?
- chaosharmonic 4mo agoMost of my knowledge of new tools comes from newsletters, forums, and content creators. I find things through passive media consumption (and, where I can get it, discourse with other enthusiasts) more often than I find them in the course of trying to solve specific problems. But not all managers think that your learning sources are valid, and care more that you spend time on their learning paths. Even if it's your off time. (Yes, there is a story attached to this haha... and more importantly, several different writeups[1][2][3] on how random internet wanderings have been more beneficial to my overall technological capability than people who insist on the importance of a CS background when building dashboards and client UIs. In practice, thanks to a dev box with insufficient RAM, and your typical tabbed-browsing problem, I used `pkill` over `ssh` -- something I picked up from toying with Over the Wire levels in my off time -- a lot more often than I used linked lists at that job.) [1] bhmt.dev/blog/scraping [2] bhmt.dev/blog/ctf [3] bhmt.dev/blog/feeds
- Hamuko 4mo agoMaybe? And yes.
- chrismustcode 4mo agoI once got told for an internal promotion I couldn't put anything regarding my current role, responsibilities and achievements in the role. I got told to put any volunteering or previous. Reason given was it's what is expected at work everything you do in your role, you need to show above and beyond.
- LiquidSky 4mo agoSeems like that'd just discourage people from going above and beyond at work. Why do more than the bare minimum to avoid being fired if nothing else you do counts?
- Forgeties79 4mo ago>Look, we want you to express yourself, okay? Now if you feel that the bare minimum is enough, then okay. But some people choose to wear more and we encourage that, okay? You do want to express yourself, don't you? (This is from Office Space for those who don’t know. Hilarious scene with Jennifer Aniston)
- eecc 4mo agoThe Flair scene? Oh seriously than got me so much vicarious embarrassment, I feel uneasy just at the thought of it.
- ProllyInfamous 4mo ago[Jennifer Anniston flips Mike Judge the bird, on-screen #inLove] >>"How's THIS for expression?!? I'm sick and TIRED of this ... job!" ---- I will never go above&beyond again – for any corporate entity – ever again. You can blame past corporate bullies, not yourselves.
- taude 4mo agoYou're 100% supposed to grow professionally outside of work.
- 1121redblackgo 4mo agopass
- mh- 4mo agoThis is such a curious POV for me - I'd genuinely like to hear your thoughts on this. Who owns your career growth if not.. you? (If you don't desire to grow your career, that's a viewpoint I can entirely understand.)
- serf 4mo agosome people see 'career growth' as going to seminars and networking with manager types. some people see 'career growth' as opening up a new technical manual and acquainting themselves with new stuff. I think it's import to differentiate; networking with managers and going to industry-specific (or even company specific) seminars offers next to zero enticement for me, but I usually always have the time to read about a new language or tech. In other words: If a growth opportunity arises, i'd rather it be personal growth.
- taude 4mo agoI don't think it matters how you define it. Engineering career growth is almost always going to be about understanding the new technologies, gaining communication skills in navigating an org. etc.... What you're calling personal growth is 100% related to career growth. And you sound like someone who does do things outside the hours of 9 to 5 that intellectually you find interesting, and likely makes you better at what you do 9 to 5... You're going to show up at that meeting someday, there's going to be a problem to solve, and you're going to have some ideas for things to try that are answers, because you read about that new tech. And someone's going to tap you on the shoulders to lead that or what not....
- 4mo ago
- veber-alex 4mo agoYep. One time my manager did a hour long lecture for our team on how personal growth is important and that we all should expand our horizons and learn new stuff. When I tried to reserve 2 hours A WEEK for studying tasks I got push back that I should do it on my own time. It was a complete joke.
- consp 4mo agoThis sounds like the "everything you create in your own time is company property since we cannot distinguish if what you do in your own time isn't company related" clause in some contracts. Under no circumstance is it actable where I live, but it can sure scare the hell out of people and presents a line of thought. Yes, some companies think they can own copyright on the things you write at home.
- doubled112 4mo agoIf my contract says that I must be available immediately at any time, do I have ANY personal time? Or is all of my time their time too?
- daveshistory 4mo agoAbsolutely. Your personal time is that time which, in retrospect, the company didn't need you for. It's strictly a backward-looking definition.
- ChrisMarshallNY 4mo agoI call that the "shower clause," because the company claims ownership of any ideas you come up with, in the shower. I think, like noncompetes, there's limits to how far the company can actually enforce it, but they bank on the fact that they have lawyers on permanent retainer, and you don't. Even standing up for your rights, against blatant corporate overreach, is expensive.
- cindyllm 4mo ago
- javcasas 4mo agoNo. You should grow professionally outside of work by also following the work-mandated professional development plan. And you will be punished if you don't do it, or you do it at a pace that doesn't match expectations. You know, don't forget the details.
- mikeyinternews 4mo agoOr grow professionally during work hours using a personal device.
- yoyohello13 4mo agoOne time my manager messaged me panicking about a big nextjs vulnerability. I told him, no worries, I saw it on HN and we patched weeks ago. He told me to use HN at work as much as I want.
- Onavo 4mo agoIf you can afford it, set up a proper trust fund for them.
- smohare 4mo ago[dead]
- deleted 4mo ago[deleted]
- apimade 4mo agoWhat you’re concerned about doesn’t stop at the employer. Anyone with access to data being processed about you may have incentives that align similarly with your employer’s use case. Advertisers, Internet service providers, phone manufacturers, social networks, tech platform providers, schools, families, spouses, nosy neighbours, nosy governments. The scale at which you can build a summary about someone is astonishing. How they breach policies, how they break laws, how they mishandle sensitive data, how they materially negatively impact customers. This whole thing is now a litigation nightmare, and frankly I can’t believe Meta is doing this so publicly. They’ve created an incredibly dangerous and lucrative lever in which vexatious and otherwise incentivised individuals and organisations can subpoena and demand evidence which, provided the ample data available, will surely produce enough evidence given the expanse of their employer base. They simply need to have a thread to pull on, so a judge doesn’t deem it a fishing expedition. Similarly, I worry for democracies with no checks or balances to prevent ruling parties from exploiting or abusing this power. For example, in India, there’s accusations of their equivalent of the NSA being used to spy on the opposition —- under the guise of “keep them honest”. https://www.idsa.in/system/files/book/book_IntellegenceReform.pdf https://www.idsa.in/system/files/book/book_IntellegenceRefor... In other Western countries whenever this type of work is conducted, it’s usually at Director or Minister-level approval. There’s lawyers involved, it’s heavily documented. What happens when systems, or products, are given the implicit approval of this same function by their very nature? We’re in weird times.
- fragmede 4mo agoThat smart TV you just got has ACR (Automatic Content Recognition), which takes a screenshot of what you're watching, twice a second, and sends it off to data brokers.
- eecc 4mo agoWell, at the risk implying intention and thus anthropomorphizing Larry... you know sharks don't eat, they simply consume food, like a fire consumes wood, this is what Larry Ellison advocates for: "Citizens will be on their best behavior, because we’re constantly recording and reporting everything that is going on"
- 4mo ago
- macNchz 4mo agoThis is something that genuinely runs the gamut across different companies—plenty don't even know the serial numbers of company-owned machines, never mind which devices individuals have, while others do effectively have live feeds of every employee's screen available to managers at all times. In between you have many businesses that manage their devices but only insofar as to enforce some basic protection and reserve the right to investigate it in the case that something does go wrong. In having conversations about this kind of stuff with company leaders, many will strongly reject any of the most invasive tracking stuff, believe it or not. I do agree, though, that for any type of surveillance, the rise of AI presents a really problematic opportunity to allow more targeted observation, since nobody has to spend their own time looking for what people are doing, they can ask an AI to keep tabs and look out for the things they care about. On that note, I think one of the more realistic risks for an everyday person doing personal things on a work machine is probably insider threat from a rogue IT admin, whose access allows them insight into company devices without enough oversight.
- schnitzelstoat 4mo agoYeah, many companies don't want the liability issues. Like what happens if I open my bank account on my work computer? You could argue I can expect someone to be watching but I have no warning that someone is? Here in the EU that would probably be an easy lawsuit.
- wpsimon3 4mo agoCan’t speak for the EU, but the companies I’ve worked for in the US explicitly state what they do not track in their privacy/use policy when giving out laptops/phones/tablets. E.g. their anti-virus or firewall system may ignore URLs related to banking, medical, or political affiliation and chose not to log or decrypt that traffic
- galleywest200 4mo agoOnce I was trying to find a scene from a TV show at work for a joke with colleagues, and the quote I used ended up triggering a very NSFW search. Did not get fired, not even talked to. Thank goodness!
- caymanjim 4mo ago> In the US, there's the expectation that when you use an employer-provided device that any and all activity on it can be fully monitored/recorded I don't expect this. I know that some companies install spyware on their devices, but I don't expect it, I don't accept it, and if they did it without disclosing it I'd be furious. I understand they're allowed to do it. I'd never work anywhere that did.
- stingraycharles 4mo agoI think the keyword is “can”. It is allowed, contrary to eg the EU, where this is not allowed.
- caymanjim 4mo agoYeah, I know they can. I just can't believe it's normalized and that people simply accept it. Good on the EU for pushing back.
- 3form 4mo agoI guess from my perspective there are even more dire problems in the US that I'm surprised people accept. But it seems they don't know, or care, or know that they should care. Perhaps it's the lack of proper authoritarian regime in the US' past that drives this. I believe the temporal proximity of such makes people aware of, and angry against, the many traps that such systems leave in their "law", so you can be imprisoned anytime for anything. EU has a bunch of countries with varying degree of such past.
- mrhottakes 4mo agoMost people need to work to support themselves so it's quite inconvenient to single-handedly solve all of the problems in the US. Suggesting people simply don't know or care is very naive.
- bigfudge 4mo ago
- jimmydddd 4mo agoI wonder if the AI's that replace us will be periodically web surfing and checking HN as part of their daily work flow?
- daveshistory 4mo agoOnly on their 30-minute breaks, perhaps.
- Nasrudith 4mo agoGiven the complaints about data-usage from LLMs, they'll be not only checking it but doing so frequently enough to make you look like an utter slacker as the near zero marginal cost means they can index it just in case it happens to have a useful answer to an obscure question.
- prmoustache 4mo agoWhy would you do that on the employer-provided device? I just use another laptop and my smartphone. I am even using headphones if I want to listen to something for privacy, no idea if my company would go as far as recording from my microphone but I am not willing to take the risk.
- mrhottakes 4mo agoYou bring a personal laptop to work with you?
- prmoustache 4mo agoI have been working from home for the last 8 years but when meeting the team onsite I have seen people bringing small personal laptops and ipads so it seems quite common. Those days at the office were so sporadic that I could do with my smartphone only.
- mrhottakes 4mo agoI've never seen anyone do that across almost two decades in tech, it's a security risk that would absolutely get you the wrong kind of attention in an organization that takes itself seriously.
- jamespo 4mo agoPersonal laptops go on guest wifi with zero access to company resources, just like personal phones
- prmoustache 4mo ago+ everybody working in tech has a large mobile data plan, no reason to even connect to the wifi guest network.
- mystifyingpoi 4mo ago
- Qem 4mo agoWith companies enrolling AI to help look over the shoulder of their employees, I wonder how hard it would be to do some prompt injection just changing what is displayed in the surveiled screen for it to see. Potential for a new vulnerability vector?
- deleted 4mo ago[deleted]
- paradox242 4mo agoRegarding what is available, imagine a system with reports and dashboards showing a timeline of which application was in focus and for how long, metrics on "activity" like keypresses and mouse clicks, periods of inactivity, lists of websites visited, whether you are joining scheduled zoom meetings, whether your camera was on, when you badged into and out of the office, periodic photos being taken from your webcam, geolocation on where you sign in from, and I could go on. Most of these things are available bundled with most of the business Microsoft subscriptions while other telemetry comes from other tools or homegrown sources and is available to managers and IT staff on demand. Now, most of the time no one was really looking at most of this unless they had a reason to, and while I am no longer in this end of things since LLMs have reached this stage of maturity, I can imagine they are now being tasked with constantly watching for patterns in worker activity which deviate from the expected norm and are fully capable of notifying your manager automatically along with a detailed analysis of your activity. The thing to understand is that the modern office is a veritable panopticon.
- mywittyname 4mo agoThis is the fruition of Microsoft's dream, since it's the most obvious way to drive copilot usage in a way that A) burns mad tokens, B) is actually useful to paying customers. Though, I have to wonder if distracting leadership with shit like this will be bad for business in the long-term. Both because leadership will fail to do their jobs, being too busy playing peeping tom on employees, but also because it takes their eyes off the prize - measuring the things that make money.
- dheera 4mo ago> however, few people worry about reasonable amounts web-surfing, being on hacker-news or doing life-activities on their work machines I'd suggest doing it on your phone, not work PC. If you have urgent personal errands e.g. an email to respond to here and there and you'd rather have a keyboard, bring a personal laptop, connect it to 5G and do it from your car.
- isodev 4mo agoRegardless of your stance on AI, we shouldn’t normalise tracking of this magnitude at all. Some safety guardrails for security and IP protection - fine, most tools have that builtin. Anything beyond that is abuse, plain and simple.
- giancarlostoro 4mo ago> (IT pros tend to not talk about it much) > In the US, there's the expectation that when you use an employer-provided device that any and all activity on it can be fully monitored/recorded Uh, kind of, you have to explicitly be fully aware of it, if they don't tell you in a meaningful capacity, you still have a reasonable expectation to privacy and it could turn into a lawsuit in your favor. ESPECIALLY if you access anything personal, medial, or even financial it could land your employer in hot hot water. In fact, they probably added the 30 minute escape hatch because of those things I mentioned, because yes, those are valid scenarios to have total privacy.
- flippyhead 4mo agoOr, the tracking won't change much, it'll be the big-brothering that will dramatically accelerate
- phreeza 4mo agoIs it really that different with the current iteration of AI compared to what was possible 10 years ago? There may be some new awareness at the executive level of what is possible, but I feel like a "slacker detector" or whatever would have been possible with xgboost or lstms.
- ZiiS 4mo agoReading hacker-news is work; and never tell my Boss otherwise.
- Balgair 4mo ago> We will soon have to brace ourselves for an absolute draconian level of tracking. Somehow this reminds me of the old adage in finance :"The optimal amount of fraud is not 0" Meaning that you could of course come up with a system in your accounting or banking or stocks or whatever that is totally 100% fraud proof. But that system would be so onerous that none would use it. They'd go back to a more fraudulent system that is easier. Like, 15 retinal scans, a blood draw, and a bank approved minder just to buy a taco isn't workable, duh. I'd say the same here too. You can of course use AIs and LLMs to figure out exactly how much work a person is doing and try to optimize them down to the second. Amazon is currently doing this in their warehouses. Any given month comes up with yet another instance of a worker dying on the floor and people having to continue working around the literal corpse. And Amazon then has to run through communities, one after another, trying to hire people to work in that system. Their SEC filings note, incredibly, that population exhaustion is a real threat to the workforce. Thus, the optimal amount of surveillance for an evil megacorp is not 100%. Draconian, sure. But Amazon is already over the balance point and is trying to squeegee back towards the optimum. So far, it seems to be a lot further back than we thought.
- deleted 4mo ago[deleted]
- alterom 4mo ago>Thus, the optimal amount of surveillance for an evil megacorp is not 100%. Yes, and they will do it anyway, as long as they can afford it, and even if they can't. Business decisions aren't always optimal.
- nonethewiser 4mo agoSame principle as too much security. One of the things that contributes to this is that the safety side usually doesn't have any incentive to reign itself in. There is an old adage for that general idea. "The treatment should not be worse than the disease"
- fullshark 4mo agoWhat a relief, it won't be 100% but just to the extent that Amazon does it in their warehouses.
- Aurornis 4mo ago> With AI, this changes significantly since the man can now employ a robot to categorize and finely scrutinize every little thing Corporate endpoint monitoring software has been able to track time spent in apps and websites for a very long time. They could produce breakdowns of time spent in apps and even categorize popular websites based on a database. This is unrelated to the topic, but worth mentioning in case someone assumes that AI tools were needed for time tracking and breakdowns.
- deleted 4mo ago[deleted]
- alsetmusic 4mo ago> It's always been hard to know the extent of how draconian tracking actually is (IT pros tend to not talk about it much). Having worked at a FAANG and then downsizing back to IT (it's pretty great if you don't need the paycheck), I'll say a bit here. I was FAANG for 8.5 years, though in a more limited role for half of that. I've been doing the IT thing since 2018, first at a small private company and then at a gov state agency. We were ~25 people and we had one person who was a nightmare. They created a toxic work environment. I asked for a meeting with the owner and brought a laundry list of documentation about their behavior, including spending most time not performing the job (browsing online shopping instead). He asked if I knew their device name so he could pull it up and see what she was doing right then. I didn't know. I'm sure he checked later. Every computer had management software that allowed remote viewing and remote control because of course they did; we managed fleets of machines. I genuinely don't think the owner ever had the impulse to spy or check up on anyone until that moment, when he was receiving really troubling news. I worried more about the security camera installed after a break-in because it could expose my long breaks when I came in super early in the morning. Where I work now, users have to approve a screen sharing session. I can't just spy on someone like at my former employer. But there's undoubtedly metrics being recorded in case anyone ever needed to profile a user's work time (say a labor lawsuit, for example). We all know we can be tracked on work devices. My expectation is that while your company can, theoretically, track everything, they have no motivation to waste their time unless given a reason. Maybe AI will change that as the cost of tracking creeps closer to nil (probably). And at Meta, I think they're evil enough to consider the cost worthwhile anyway. But probably not a big deal most places so long as you aren't up to anything beyond slacking off. People have work to do.
- jasondigitized 4mo agoAnd employees will employ robots to do hyper realistic work like activities to game the system. Here's an idea...... find good leaders who understand team building and culture and let the score take care of itself.
- ryandrake 4mo agoI've always, throughout a 25+ year career, kept personal business on personal devices and work business on work devices, and never cross the streams. Oddly, this is really controversial on HN, though! I've gotten so many weirdly angry responses when suggesting people try it, like it's a huge inconvenience to just bring a personal phone to work in order to do your banking and fuck around posting on HN. It's so much easier now than pre-smartphone to keep worlds separate. There's no reason my employer needs to know what personal errands I need to attend to throughout the day, and they obviously are not going to approve of me doing confidential work business on my personal devices, so it's a win-win.
- thinkingtoilet 4mo agoI'm the exact same way. If it's a work device, I'll literally never use it for something personal. Why give them any ammunition? Plus, laptops are so thin these days it's not really a burden to pack two, or use a phone like you said. It's one of those things where it almost certainly doesn't matter... until it does.
- gausswho 4mo agoI did find this odd at first too, but then I realized something: it's a pain to maintain a device. Customizing it to the way you like it is not only a waste of time, it's tedious and never ends in an age where defaults are often adversarial to your interests. It's enough work taking care of one pet/kid, you might not want another. Now I'm a nerd and I went through a realization that I should treat my devices as 'livestock not pets' and went to the trouble of building a NixOS config so that I can have two or three machines that all behave the same. But that's its own labor and still doesn't solve the phone problem. Or the fact your employer won't provision you a Linux with root. Living by this personal/business separation is probably something most folks would aspire to, but technology as we practice it conspires against them.
- switchbak 4mo ago"your employer won't provision you a Linux with root" - there's your problem!
- jlarocco 4mo agoOther than adding buzzwords to a features list, I don't see AI really moving the needle here. As you've said, it's always been the expectation that employers are watching over their networks. There's already loads of monitoring software available that can scrutinize, categorize, and track everything going through corporate networks. A company I worked at ~20 years ago had an internal website showing a live display of URLs accessed through their whole network, a "top 100" list, a break down into categories (news, email, games, etc.) and other stuff along those lines. They were absolutely categorizing and scrutinizing everything way back then, no AI needed.
- rightbyte 4mo agoDoes that work with https and dns over https?
- itake 4mo agoI don't think AI introduces anything new. In theory, manager could pull the reports of their 4-12 people to see which programs are active and what websites they are using for how long once a month, targeting individuals that they are looking for a reason to bump. No AI needed.
- mjanx123 4mo agoWhen AI takes all the jobs, it will also need to take care of supplying all the demand/customers, as humans will no longer have the resources for that.
- rzz3 4mo agoIn so far as bracing for draconian tracking, I already would have never worked for Meta and especially wouldn’t now. I think we can vote with our feet and not work for companies that do this.
- nonethewiser 4mo agoIt's like a law of technology. As technology increases the ability to surveil increases. Then we learn why we weren't surveiled in the first place. It was just a lack of ability - not laws, benevolence of government, etc. I cannot imagine a world 100 years from now without much more surveillance. Literal thought police is not a crazy idea. That might only require more usage of something like nueralink and progress in processing signals from your brain.
- th0raway 4mo agoRidiculous tracking happened before AI too. Go read the book about Bridgewater, describing, among other things, how internal security worked when it was led by James Comey (yes, the one you know from the news, and was later FBI director)
- thatmf 4mo ago> Oh, here I am on hacker-news when I should be working. What else am I supposed to be doing while Cursor does its thing?
- johannes1234321 4mo ago> In practice, however, few people worry about reasonable amounts web-surfing, being on hacker-news or doing life-activities on their work machines. Oh, here I am on hacker-news when I should be working. This is all nice and good, till the employer needs a reason to fire an employee, then suddenly all such things become relevant. Maybe a bit less in at-will employment situations where there are low barriers for kicking people anyways.
- reactordev 4mo agoIf you touch it, in any way, it’s probably tracking
- toasty228 4mo ago> With AI, this changes significantly If the only reason you're free is because machines aren't good enough to get you yet you're fucked. You should be protected by laws, not by technological limitations.
- simplyluke 4mo ago> We will soon have to brace ourselves for an absolute draconian level of tracking I think framing it as inevitable is one of the biggest lies in the current AI narrative. No, I think the companies that are likely to be successful in the next decade are the ones who respect the basic decency of their employees and treat them as competent and responsible professionals, just as I thought the same thing in decades past when friends told me of mega-corp jobs where they installed mouse-togglers to keep the spyware on their work laptops happy while they were AFK. It's very similar to drug tests. I've always viewed them (outside of gov/clearance work) as a great sign of a culture that doesn't respect employees and sort of a lower-status portion of the industry. Meta has made it very clear where they're headed, and it looks a lot like getting a job at Cisco in 2012. I wish them the best of luck in being able to hire the talent they'll need from Gen Z (now well into their 20s) to be successful in AI and other emerging technologies.
- cheriot 4mo agoThe professions with the least negotiating power will have the most draconian "oversight". Imagine a cashier graded in real time on how many customers they smile at. Or tracking how many glasses in a restaurant are empty.
- beloch 4mo agoThe Stasi of East Germany are a good example of old-school totalitarianism, where there was ambition to know every thought, word, and deed of the entire population, but there were severe limitations imposed by the available manpower. Roughly 1.5% of the population were informants, so you had okay odds of getting off easy in any given interaction, but patterns of behavior would inevitably be reported. In AI supervised workplaces, you will be written up for a first or only offense. There may be enforcement thresholds that mean you don't hear about it immediately, but your every action is kept on record for when you do pass those thresholds. This sounds nightmarish, but you can always quit. The trouble is that billionaires dream of free economic zones and entire countries run this way, where they can finally feel "safe". If Meta employees think these 30 minute surveillance breaks will actually be honored, think again. Just using one may trigger increased surveillance. Put yourself in your paranoid employer's shoes. If your employee says, "Hey, could you please not watch what I'm doing for the next little bit", that's when you make sure the hidden microphones and surveillance cameras are pointed right at them. Maybe you don't show anyone the evidence you collect during these surveillance "breaks", but you can always use other infractions to deal with employees for what they do when they think they're not being watched.