Skip to content

Comment on Ask HN: My company installed chef on all of our machines, should I be worried?

Comments

If a company does not install surveillance-type software on hardware they own, they are taking risk. Any company over a certain size will do it, or with some regulations. Even signing a contract with a big customer if youre b2b, that company will give a security questionaire and might ask about policy and expect it.

If your company provides a laptop, assume they can intercept all ssl traffic(hsts makes this a little tougher though), and read all your work email, and see everything you do. They probably don't, but could so better safe than sorry.

If I was concerned, it would be that they are doing it themselves with chef and not using an off-the-shelf solution. Seems like a poor use of resources not to buy it.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.