▲ 1973 ▼ Not allowed to work from home (sh.itjust.works) submitted 2 years ago by sjmarf@sh.itjust.works to c/maliciouscompliance@lemmy.world 224 comments fedilink hide all child comments
[–] pearsaltchocolatebar@discuss.online 112 points 2 years ago* (6 children) In all of my IT jobs I would have been fired if I had signed into work accounts on my personal phone. It's a pretty big security risk. permalink fedilink source hideshow 12 child comments replies: [–] trxxruraxvr@lemmy.world 74 points 2 years ago (2 children) True, but in small companies it's not uncommon. permalink fedilink source parent hideshow 4 child comments replies: [–] Chocrates@lemmy.world 36 points 2 years ago (1 child) I was at a subsidiary of a very large company and had work slack, email, and all my code on my phone, without even the thing that lets them remote wipe your phone. It has to do with culture and willingness to put in the effort by the security organization permalink fedilink source parent hideshow 2 child comments replies: [–] ikidd@lemmy.world 15 points 2 years ago (1 child) Get hit with one ransom ware attack and that shit'll pivot 180. permalink fedilink source parent hideshow 2 child comments replies: [–] Chocrates@lemmy.world 7 points 2 years ago Yeah, or even just budget cuts. I am sure it's cheaper to just lock it down. permalink fedilink source parent [–] flicker@lemmy.world 3 points 2 years ago Not exclusive to IT; I had to weigh the benefits of continuing to work as a caregiver for a small company, versus working in retail for a massive chain (which translates to fantastic insurance benefits.) Sadly not a competition. permalink fedilink source parent [+] Tyfud@lemmy.world 16 points 2 years ago* (last edited 1 year ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] lemmylommy@lemmy.world 21 points 2 years ago (2 children) Fuck their data, what about my own? That pest of an app is not getting onto my device. And neither is anything else that gives an employer any control over my device. permalink fedilink source parent hideshow 4 child comments replies: [–] ricecake@sh.itjust.works 11 points 2 years ago A totally reasonable stance. For clarity, the android feature essentially makes a work dedicated partition on the phone. Their management app can manage that partition, and for the purposes of data movement it's essentially a distinct phone. If they've set it up correctly they can do a remote wipe without touching your personal data. https://support.google.com/work/android/answer/7502354?sjid=18390510946809838606-NC#zippy=%2Ci-own-my-device In a lot of cases the drive to have users use their personal devices rather than employer owned ones comes from the users, not the workplace. Only needing to keep track of one device is easier in many cases. permalink fedilink source parent [–] Benjaben@lemmy.world 7 points 2 years ago My policy as well. Non-negotiable hard no. But I'm fortunate enough to have at least some choice with regard to employment. permalink fedilink source parent [–] DrDystopia@lemy.lol 14 points 2 years ago (1 child) Unless it's 24h gold service with 24k gold pay, the work phone gets turned off at the end of office hours. permalink fedilink source parent hideshow 2 child comments replies: [–] Maggoty@lemmy.world 4 points 2 years ago (1 child) There are places that pay well for on call though. permalink fedilink source parent hideshow 2 child comments replies: [–] bekopharm@discuss.tchncs.de 3 points 2 years ago Sounds kinky. permalink fedilink source parent [–] leisesprecher@feddit.org 8 points 2 years ago Most companies seem to have don't ask, don't tell policies in place. Technically we're not allowed to use Teams on our phones, but most of us do, including management. I'm also technically not allowed to use Spotify on my laptop, but if they'd enforce that ban, IT would be gone tomorrow. permalink fedilink source parent [–] ricecake@sh.itjust.works 7 points 2 years ago Eh, it doesn't need to be, you just need to do the work of putting together granular access controls that can account for your risk profiles. The risk isn't much different between a company owned telephone and a personal telephone. They're both susceptible to most of the same attacks, or being left on the bus. permalink fedilink source parent [–] PrettyFlyForAFatGuy@feddit.uk 2 points 2 years ago (1 child) In my current job the old manager okayed working on our own devices. I would use my personal workstation to ssh into and do work on my work mac, did that for a few years. saved me disassembling my desk between uses every day or buying a costly KVM. They seem to be getting a lot more uptight about security these days (although the "you can work on personal devices" rule hasnt been explicitly rescinded) so i have stopped interaction between my personal devices and work devices. Having a M2 mac recently makes it easier, i can lie in bed and work pretty much all day on a single charge so my desk remains intact permalink fedilink source parent hideshow 2 child comments replies: [–] pearsaltchocolatebar@discuss.online 3 points 2 years ago I remote into my work laptop too, but I don't have any work data on my personal devices. And, my desktop is more secure than my work laptop. permalink fedilink source parent
[–] trxxruraxvr@lemmy.world 74 points 2 years ago (2 children) True, but in small companies it's not uncommon. permalink fedilink source parent hideshow 4 child comments replies: [–] Chocrates@lemmy.world 36 points 2 years ago (1 child) I was at a subsidiary of a very large company and had work slack, email, and all my code on my phone, without even the thing that lets them remote wipe your phone. It has to do with culture and willingness to put in the effort by the security organization permalink fedilink source parent hideshow 2 child comments replies: [–] ikidd@lemmy.world 15 points 2 years ago (1 child) Get hit with one ransom ware attack and that shit'll pivot 180. permalink fedilink source parent hideshow 2 child comments replies: [–] Chocrates@lemmy.world 7 points 2 years ago Yeah, or even just budget cuts. I am sure it's cheaper to just lock it down. permalink fedilink source parent [–] flicker@lemmy.world 3 points 2 years ago Not exclusive to IT; I had to weigh the benefits of continuing to work as a caregiver for a small company, versus working in retail for a massive chain (which translates to fantastic insurance benefits.) Sadly not a competition. permalink fedilink source parent
[–] Chocrates@lemmy.world 36 points 2 years ago (1 child) I was at a subsidiary of a very large company and had work slack, email, and all my code on my phone, without even the thing that lets them remote wipe your phone. It has to do with culture and willingness to put in the effort by the security organization permalink fedilink source parent hideshow 2 child comments replies: [–] ikidd@lemmy.world 15 points 2 years ago (1 child) Get hit with one ransom ware attack and that shit'll pivot 180. permalink fedilink source parent hideshow 2 child comments replies: [–] Chocrates@lemmy.world 7 points 2 years ago Yeah, or even just budget cuts. I am sure it's cheaper to just lock it down. permalink fedilink source parent
[–] ikidd@lemmy.world 15 points 2 years ago (1 child) Get hit with one ransom ware attack and that shit'll pivot 180. permalink fedilink source parent hideshow 2 child comments replies: [–] Chocrates@lemmy.world 7 points 2 years ago Yeah, or even just budget cuts. I am sure it's cheaper to just lock it down. permalink fedilink source parent
[–] Chocrates@lemmy.world 7 points 2 years ago Yeah, or even just budget cuts. I am sure it's cheaper to just lock it down. permalink fedilink source parent
[–] flicker@lemmy.world 3 points 2 years ago Not exclusive to IT; I had to weigh the benefits of continuing to work as a caregiver for a small company, versus working in retail for a massive chain (which translates to fantastic insurance benefits.) Sadly not a competition. permalink fedilink source parent
[+] Tyfud@lemmy.world 16 points 2 years ago* (last edited 1 year ago) (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [–] lemmylommy@lemmy.world 21 points 2 years ago (2 children) Fuck their data, what about my own? That pest of an app is not getting onto my device. And neither is anything else that gives an employer any control over my device. permalink fedilink source parent hideshow 4 child comments replies: [–] ricecake@sh.itjust.works 11 points 2 years ago A totally reasonable stance. For clarity, the android feature essentially makes a work dedicated partition on the phone. Their management app can manage that partition, and for the purposes of data movement it's essentially a distinct phone. If they've set it up correctly they can do a remote wipe without touching your personal data. https://support.google.com/work/android/answer/7502354?sjid=18390510946809838606-NC#zippy=%2Ci-own-my-device In a lot of cases the drive to have users use their personal devices rather than employer owned ones comes from the users, not the workplace. Only needing to keep track of one device is easier in many cases. permalink fedilink source parent [–] Benjaben@lemmy.world 7 points 2 years ago My policy as well. Non-negotiable hard no. But I'm fortunate enough to have at least some choice with regard to employment. permalink fedilink source parent
[–] lemmylommy@lemmy.world 21 points 2 years ago (2 children) Fuck their data, what about my own? That pest of an app is not getting onto my device. And neither is anything else that gives an employer any control over my device. permalink fedilink source parent hideshow 4 child comments replies: [–] ricecake@sh.itjust.works 11 points 2 years ago A totally reasonable stance. For clarity, the android feature essentially makes a work dedicated partition on the phone. Their management app can manage that partition, and for the purposes of data movement it's essentially a distinct phone. If they've set it up correctly they can do a remote wipe without touching your personal data. https://support.google.com/work/android/answer/7502354?sjid=18390510946809838606-NC#zippy=%2Ci-own-my-device In a lot of cases the drive to have users use their personal devices rather than employer owned ones comes from the users, not the workplace. Only needing to keep track of one device is easier in many cases. permalink fedilink source parent [–] Benjaben@lemmy.world 7 points 2 years ago My policy as well. Non-negotiable hard no. But I'm fortunate enough to have at least some choice with regard to employment. permalink fedilink source parent
[–] ricecake@sh.itjust.works 11 points 2 years ago A totally reasonable stance. For clarity, the android feature essentially makes a work dedicated partition on the phone. Their management app can manage that partition, and for the purposes of data movement it's essentially a distinct phone. If they've set it up correctly they can do a remote wipe without touching your personal data. https://support.google.com/work/android/answer/7502354?sjid=18390510946809838606-NC#zippy=%2Ci-own-my-device In a lot of cases the drive to have users use their personal devices rather than employer owned ones comes from the users, not the workplace. Only needing to keep track of one device is easier in many cases. permalink fedilink source parent
[–] Benjaben@lemmy.world 7 points 2 years ago My policy as well. Non-negotiable hard no. But I'm fortunate enough to have at least some choice with regard to employment. permalink fedilink source parent
[–] DrDystopia@lemy.lol 14 points 2 years ago (1 child) Unless it's 24h gold service with 24k gold pay, the work phone gets turned off at the end of office hours. permalink fedilink source parent hideshow 2 child comments replies: [–] Maggoty@lemmy.world 4 points 2 years ago (1 child) There are places that pay well for on call though. permalink fedilink source parent hideshow 2 child comments replies: [–] bekopharm@discuss.tchncs.de 3 points 2 years ago Sounds kinky. permalink fedilink source parent
[–] Maggoty@lemmy.world 4 points 2 years ago (1 child) There are places that pay well for on call though. permalink fedilink source parent hideshow 2 child comments replies: [–] bekopharm@discuss.tchncs.de 3 points 2 years ago Sounds kinky. permalink fedilink source parent
[–] leisesprecher@feddit.org 8 points 2 years ago Most companies seem to have don't ask, don't tell policies in place. Technically we're not allowed to use Teams on our phones, but most of us do, including management. I'm also technically not allowed to use Spotify on my laptop, but if they'd enforce that ban, IT would be gone tomorrow. permalink fedilink source parent
[–] ricecake@sh.itjust.works 7 points 2 years ago Eh, it doesn't need to be, you just need to do the work of putting together granular access controls that can account for your risk profiles. The risk isn't much different between a company owned telephone and a personal telephone. They're both susceptible to most of the same attacks, or being left on the bus. permalink fedilink source parent
[–] PrettyFlyForAFatGuy@feddit.uk 2 points 2 years ago (1 child) In my current job the old manager okayed working on our own devices. I would use my personal workstation to ssh into and do work on my work mac, did that for a few years. saved me disassembling my desk between uses every day or buying a costly KVM. They seem to be getting a lot more uptight about security these days (although the "you can work on personal devices" rule hasnt been explicitly rescinded) so i have stopped interaction between my personal devices and work devices. Having a M2 mac recently makes it easier, i can lie in bed and work pretty much all day on a single charge so my desk remains intact permalink fedilink source parent hideshow 2 child comments replies: [–] pearsaltchocolatebar@discuss.online 3 points 2 years ago I remote into my work laptop too, but I don't have any work data on my personal devices. And, my desktop is more secure than my work laptop. permalink fedilink source parent
[–] pearsaltchocolatebar@discuss.online 3 points 2 years ago I remote into my work laptop too, but I don't have any work data on my personal devices. And, my desktop is more secure than my work laptop. permalink fedilink source parent