Skip to content

Comment on Does employer have to tell if they're spying on you through your work computer?parent

Comments

It's corporate device, not corporate os.

I’m generally with you here, but in this specific case the GP’s stated purpose in doing so is to enable doing personal activities on their work device.

I think that’s the part I personally balk at a bit (and what I suspect GP was getting at), not necessarily the act of installing whatever you want on the device.

Mixing work and personal like that seems a priori a bad idea. In many cases, work can even seize your device from you for legal reasons. Yes, you can keep the personal activities separate on an encrypted partion and otherwise walled off from the work bits. But this all just limits some of the possible downsides and doesn’t make it a good idea.

Part of the "corporate device" is the fact that they can ensure its security.

Would you be comfortable letting Bob in Accounting use her own computer, the one she uses to do payroll for the whole company? The same Bob who clicks every link in every email and installs every executable possible. The same Bob who doesn't remember passwords and has the payroll system password on a post-it note next to his display and uses auto-login on his computer because typing the password every morning is too much of a hassle.

Or would you rather have some "corporate spyware" on there doing basic sanity checks for malware, weird access patterns, enforcing a password policy and automatic locking when idle?

Or would you rather have some "corporate spyware" on there doing basic sanity checks for malware, weird access patterns, enforcing a password policy and automatic locking when idle?

The problem with these corporate spywares is that they're designed for the Bobs of the world and I do not consider myself a Bob. When my employer was implementing one of these management nannies to enforce password policies, it would've rejected my password because it didn't have a number in it. However, mine was significantly longer than the minimum, so my password has like 25% more entropy than the minimum mandated.

If my employer trusts me enough to let me set up new AWS environments and secure our production databases, maybe they could trust me to secure my work laptop too. Different courses for different horses.

Yeah, these are the standard big corp problems.

I've been in situations where programmers are forced under the same rules as random office workers. Like no admin permissions on their own laptop. If you need to install something, you had to call IT and they'd give you an admin account that was active for 30 minutes or something.

It was extremely fun when I had to test multiple applications and had to do this process many times a day :D

Nevermind the fact that corporate mandated password changes every three months usually is pointless because the vast majority just change their password from "Password1" to "Password2" etc. Not very hard for a bad actor to identify.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.