4 ms·
"Whenever I leave a company I make sure..." But its also that companies responsibility to ensure that the employer doesn't take anything. Apple know how to us
by khurs 3mo ago
"Whenever I leave a company I make sure..."
But its also that companies responsibility to ensure that the employer doesn't take anything.
Apple know how to use MDM on Apple laptops, why wasn't the device locked and located.
- kelnos 3mo agoAbsolutely, but just as it's not ok to enter someone's home just because they forgot to lock the door, it's not ok to exploit access at your old employer because their offboarding process missed something. I do the same as GP does; I don't want there to be any chance that my former employer has forgotten to revoke access to something, so I make sure to clear out anything that might remain on any device that I don't return to them. Who knows, maybe another former employee will decide to steal from them around the same time I leave, and me having access credentials on a personal device, even if I haven't used it, might arouse suspicion.
- khurs 3mo agoBut it's Apple, which is a huge target. Never mind these individuals, you will have China, Russia and other seeking to infiltrate it. In any top r&d area, one wonders if they perhaps should be searching staff on way out and making then sign out and return CAD drawings etc.
- junofan 3mo agoYou get trustworthy people by trusting people. Generally when I was there there was a presumption of trust. Given how blatantly the defendants are alleged to have acted, that’s still the case.
- ClumsyPilot 3mo ago> You get trustworthy people by trusting people Huh? Do FBI/CIA/etc run that way?
- LPisGood 3mo agoDo they get trustworthy people?
- matwood 3mo ago> Generally when I was there there was a presumption of trust. The reality is, there has to be. And, if you can't trust someone then don't work with them. I was talking to an amazing lawyer/business person I know one day and I asked about writing 'air tight' contracts which would never put you in a position to be screwed. He said something along the lines of, that's impossible. Someone could take you to court and you could still lose even if you think the contract is perfect. What he said next stuck with me over the rest of my career, 'if you truly can't trust someone, no contract will be fool-proof. The solution is simply to not work with or do business with them.'
- tiohijazi 3mo agowhat part of "Mr. Tan warns them not to tell Apple that they have taken jobs at OpenAI, so they can stay at Apple as long as they can." did you miss?
- paxys 3mo agoUm, no. Why would it be their responsibility? There are laws regarding IP theft. If you willingly break them you can't just say "well your security wasn't good enough".
- khurs 3mo ago[flagged]
- nearlyepic 3mo agoHuh? This analogy makes no sense. It’s beside the point anyways. The utility of laws isn’t in stopping something from occurring, it’s in establishing remedies for when they do. Someone illegally transferred IP to a competitor that had knowledge they were stealing, and now Apple is seeking their remedy. “They could have prevented it” is victim blaming.
- bathtub365 3mo agoApple is obviously the victim but prevention is easier than what is happening now, which is potentially going to court, discovery, etc.
- paxys 3mo agoThere's really no way to prevent an employee from taking a piece of paper or a digital file from one place to another. The most you can prevent is accidental transfer. If they are malicious they will find a way no matter what guardrails you put.
- habinero 3mo agoAnd they can get you for theft, etc, if you do. Sometimes the social and legal controls are far more effective.
- tanseydavid 3mo agoIf you leave your house unlocked and someone steals your stuff AND is never caught, you're SOL.
- achierius 3mo agoMany devices are indeed locked down. But given that it's an OS company and hardware vendor, many employees have access to hardware with e.g. SoC fusing that allows them to install custom-signed firmware. It's very difficult to make an OS lock out the people whose job it is to build the platform that OS depends on.
- trollbridge 3mo agoI once worked at a cybersecurity firm and they had a particularly botched rollout of MDM to Macs (which would regularly put the machine into an undesirable mode of 100% CPU usage plus max out upload bandwidth repeatedly trying and failing to backup the machine to some online backup service). I had work to do, so I simply disabled the MDM profile for the machine, installed an OS to my liking, and restored the apps I wanted to use, and went about things. A year or so later the company hit hard times and we had a large layoff that affected me, and at the end of the video call, the directory of my department mentioned that they needed to wipe my laptops but it "wasn't showing up in MDM". I said I'd be glad to jump on a call with IT to fix that, but then he mentioned the IT staff were laid off too. I then suggested I did get hired for my cybersecurity expertise, that I do take my obligations seriously, and he could just ask me to do whatever they were planning to do from the MDM console, and it would get done. He insisted that wouldn't be necessary since in his worldview the MDM was unbreakable and he just needed to reconnect to Wi-Fi or something. Very amusing worldview. In the real world, where I live, I would assume a highly competent employee could exfiltrate trade secrets without me being able to catch them via standard / automated means. This particular Apple former employee got caught because he bragged about it, not because of technical means to catch him. As I've pointed out to a number of people, the very best DLP solution can be completely obviated by someone aiming a camera at their company-issue workstation's monitor.
- justusthane 3mo ago> then suggested I did get hired for my cybersecurity expertise, that I do take my obligations seriously, and he could just ask me to do whatever they were planning to do from the MDM console, and it would get done. He insisted that wouldn't be necessary since in his worldview the MDM was unbreakable and he just needed to reconnect to Wi-Fi or something. > Very amusing worldview. It’s ironic that you’re displaying the exact behavior pointed out by the GP: > This is how you behave when you think you're so much smarter than everyone around you that consequences don't apply to you. MDM is implemented to protect company assets regardless of the actions of the users. It would not be due diligence on the part of the director to trust you to wipe your own device. It’s not clear to me what the point of your comment is other than illustrating that you’re smarter than your director.
- notatoad 3mo ago>it’s also that company’s responsibility Is it? I mean legally. Obviously it’s dumb of Apple to have left this guys access open, but that doesn’t mean they actually had any legal responsibility to lock him out. As far as I understand, the law is pretty clear that you can’t access anything you’re not allowed to by policy, whether there’s a technical block or not.
- nradov 3mo agoWhile it doesn't apply in this particular case, for healthcare organizations the HIPAA privacy rule implies a legal responsibility to lock out terminated employees from any access to protected health information.
- vel0city 3mo agoThat doesn't absolve an employee (or ex-employee) of the covered entity going about and abusing the access they do have.
- ClumsyPilot 3mo ago> that doesn’t mean they actually had any legal responsibility to lock him out If the property owner doesn’t make bare minimum effort to protect the property Then how much effort and money should taxpayer spend to protect and prosecute regarding the same property? It seems strange to imply that people that own nothing must through their taxes pay for protection of property of the people who do own everything.
- Aurornis 3mo agoCrimes are crimes and must be prosecuted as such. The phrase for what you’re doing is “victim blaming”. I don’t know what triggers some people to think this way other than a deep desire to find a contrarian take on a situation. But no, when a person commits a crime the responsibility and accountability for committing that crime is entirely on the person who committed the crime. If you start blaming the victim or downplaying the crime based on the victim’s circumstances, you are backwards. > It seems strange to imply that people that own nothing must through their taxes pay for protection of property of the people who do own everything I don’t know what you think you’re implying here, but by the numbers the wealthy and corporations pay significantly more in taxes than the “people who own nothing”. Everyone should get equal protection under the law, ignoring how much they pay in taxes. All criminals should be afraid of committing crimes equally, because crimes are crimes and society benefits when committing a crime is discouraged.
- izacus 3mo agoIt is NEVER any other persons responsibility to prevent you from commiting crimes. Never. They MAY make it harder for themselves, but at no point are is anyone required to make sure you're not a criminal. That's a difference between living in a society that robs you on every step and one where you can leave a laptop on a table in a cafe and it stays there.
- deebosong 3mo agoIn relationships, offloading personal responsibility onto someone else (aka blaming another person for your choices and behaviors and thoughts and actions) is something like projection, blame-shifting, codependency. This makes any healthy relationship impossible, as no one can be responsible for someone else's decisions and actions. Many emotionally immature folks appeal to this and use guilt and shame to get another person to believe they are responsible for someone else's emotions & choices. It's textbook toxic.