Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Scott, employees generally are only able to use their home Internet connections to violate confidentiality because their work computers and connections are poorly policed.

And, it is as a direct result of rampant abuse of company resources that companies are now deploying draconian security controls on worker machines, locking down USB connections and intercepting and parsing Word documents in the OS kernel. I've been involved in several deployments of these products (not a fan), and I can tell you that it's not an abstract concern that is driving their adoption. Bad stuff is routinely happening on company networks, and companies need to be able to protect themselves.

People have a right to privacy in personal affairs, but people need to make arrangements for their privacy when they're at the workplace. The idea that a Dell desktop that a Fortune 500 company provides you with becomes a bastion of personal privacy just because you decide to use it to check your GMail is untenable. Companies need workers to be able to handle sensitive information, and they need workers to be able to use computers and networks to do their job, and they cannot be expected to grin and bear it as their confidential information walks out the door and onto Yahoo Finance message boards.

Germany has powerful computer privacy laws. It is also not a great epicenter of tech entrepreneurship.



It is also not a great epicenter of tech entrepreneurship.

Perhaps a stable society where people are protected from overbearing authority is more valuable than making a couple of extra dollars today. It is definitely more valuable than a slightly smaller cell phone or a website where you can share 140 character messages with your friend.

There are bigger risks to business than some employees posting a few internal word documents to Yahoo Finance. The worldwide financial crisis was not due to inadequate monitoring of employees' personal e-mail, after all.


I simply disagree that privacy on workplace computers is worth more than money or smaller phones. I see no greater good being traded for the drag on businesses. If you want workplace privacy, you can provide it for yourself, and you can avoid jobs where intense monitoring is a reasonable condition, such as R&D on the industry's most secret products.

I don't know what the worldwide financial crisis has to do with this, but intensive workplace privacy laws would have hurt the investigation and wind-down of fraudulently priced contracts, not helped it. Hey, you brought it up.


If you want workplace privacy, you can provide it for yourself, and you can avoid jobs where intense monitoring is a reasonable condition, such as R&D on the industry's most secret products.

Can you? Can the majority of people make the right decision here?

It's illegal to sell your child to someone. Why is it legal to sell your privacy?


Because that is a stupid analogy.


I don't think it is. People will often trade something for money that they really shouldn't. If a person has $a and wants $b, and someone will give them $b in exchange for $a, people will often give up $a regardless of the long-term consequences.

Apparently selling children was a problem for society, so it is generally not legal now. People made the wrong decision, and it hurt society, so now making the wrong decision is no longer an option, and our society is better for it.

I think selling your privacy for a salary is detrimental to society in the same way, so it makes sense to use the legal system to remove the option. Then employees can't be tempted into making bad decisions with respect to their privacy by their employer, or rather, by the threat of non-employment. Plus, people that care about their privacy will no longer have to be off-the-grid wackos, and their value to society is increased as a result.


So you think people are stupid enough that they cannot decide whether selling their privacy is a good decision, therefore the government should make this decision for them?

How about health..we know that people are so stupid that they will sell their health for food (eat cheap fast food that is horrible for their health). Should we ban fast food?

May be we should let people decide what people are comfortable with.


May be we should let people decide what people are comfortable with.

The problem is when people stop caring about privacy because so many others made that decision for them, and the choice completely disappears. I would want to ban fast food if all healthy food became unavailable as a result of its popularity.


I'm not arguing that these things aren't useful or driven by real problem; I'm arguing that they're wrong. As are the actions of employees in harming the companies they work for.

But the American stubbornness in me goes back to the same logic of the Fourth Amendment, that despite the no doubt usefulness from a policing perspective of being able to search people without jumping through a lot of hoops, it is still wrong.

The issue of Germany and entrepreneurship is a whole different rant, and there are legal barriers here which I believe stifle entrepreneurship. (The essence of the real rant though is that it's a deeper cultural issue.) But Germany sans privacy laws wouldn't suddenly be an entrepreneurial hotbed. If we're talking easing incorporation, sure. Making it easier to hire and fire people? Once again, I'd be on board. But I don't think privacy is a significant component of the equation.


What does the Fourth Amendment have to do with a company searching it's own property? I just don't understand why you think that's wrong! I'm an ACLU-giving privacy nut (and I have real problems with how IT security is often managed), and I recoil from the idea that company employees should somehow have some claim on company property simply because they've been allowed to touch it.


I'm not saying that the right is guaranteed by the fourth amendment, just that the logic is similar.

Trying to boil down our disagreement: I don't believe that ownership of a device or communications medium entitles one to all of the information which passes through it. It seems we differ there.

So for me that leaves no conflict between something not being my property, but the things which are on it still being mine. "What should a company be able to monitor?" is separate, where both utility and privacy are part of the formula. I believe, morally, not from a utilitarian perspective, that personal privacy trumps corporate utility in this particular case and that a reasonable set of privacy laws encode that.


Even in Germany, if a company states unequivocally that computer resources are for work purposes only, they can in many circumstances monitor usage.

I want to believe you and I don't really disagree on a fundamental level.

Because sure, to the extent that you're talking to your wife on AIM, it is simply none of IT's business what you're saying, and it is appalling that they would paw through logs of those conversations. To the extent that we can legislate against that kind of thing, and even harshly punish company staff for doing that, I'm on board.

But when you get to the place where a company can't provide a sensitive Internet-connected workstation for someone to deal with unreleased financials or the blueprints for a top-secret product, you lose me completely. Your argument simply doesn't seem tenable. Companies in the US have vast monitoring rights over their own property, and that simply hasn't fatally harmed personal privacy.


To be clear, and we seem to be approaching a middle-ground, I'm not against any and all technical measures of preventing corporate information leakage. But I do believe that there's a boundary, and it seems we agree here, as to how far that should be allowed to go. Unfettered access to all information on company owned devices as presented (sensationalized as it likely is) in the article that kicked off this discussion takes a flying leap over that boundary.


I wonder if I can pull you closer to my side of the middle by suggesting that it's reasonable for Apple to select for the 5th Generation iPhone engineers who are willing to undergo much more intrusive monitoring, especially if they are compensated for that.

Incidentally: drug testing is something you and I could bitch together about way into the night.


This is admittedly a tough one for me, because it brings it down to a choice between two things I'm not comfortable with:

- Corporate invasion of personal privacy

- Limiting a person's ability to choose to do things which I (or the government) think they shouldn't

My first swing at it was that I thought, "Ok, when the legal system much choose one side to protect, perhaps it should default to the weaker side; the side which is least likely to be under duress". But that's just sweet sounding bullshit that was a fancy way of saying, "As long as the weaker party actually wants what I would."

The best I can come up with, and this is oh-so-typically-German, is to say, "Ok, Apple still can't invade their privacy. But I'm fine with ratcheting up the legal repercussions of violating the trust of the employer."

In other words, I'd be fine if more things were promoted up from the level of contract violations and moved closer to the penalties for industrial espionage in an effort to provide a stronger legal deterrent for information leakage, and also to bring in a third-party arbiter (the courts) to decide when, as in any legal proceeding, additional search and seizure is warranted by just cause. (See, I knew I could work in the Fourth Amendment somehow.)

As noted, that is a typically German jurisprudential notion, and I did have to think it through some. (The question really for me is: did I end up here because I think this way? Or do I think this way because I ended up here? :-) )


    parsing Word documents in the OS kernel.
This is fascinating. What's the use case? And can you point me to the product?


Not the specific one, for NDA reasons, but Google for "Win32 data loss prevention" and you'll find a bunch.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: