580
submitted 1 year ago by t0fr@lemmy.ca to c/privacy@lemmy.ml
top 50 comments
sorted by: hot top controversial new old
[-] Pons_Aelius@kbin.social 219 points 1 year ago

Never do anything on work machines/networks you don't want to have to explain to hr/legal.

[-] ech0@lemmy.world 116 points 1 year ago* (last edited 1 year ago)

Sr. Systems Admin here. IT does not give 2 shits about what you browse UNLESS something is reported or something trips our Alerts (has to be something major like Child Porn).

We don't sit there and actively monitor and watch what you are browsing. We investigate when something is reported by a worker or an Alert/Filter gets tripped

HR also doesn't know unless we tell them.

[-] ensignrick@startrek.website 32 points 1 year ago

Second. I once had a staff member come to me all embarrassed because someone sent a dick pick via some dating app while they was on our corporate wifi. I was like, "I promise we don't care".

[-] Pantherina@feddit.de 15 points 1 year ago
[-] Pixel@lemmy.sdf.org 21 points 1 year ago

Https is no match for work monitoring: pre-installed software, certs.

load more comments (6 replies)
[-] JokeDeity@lemm.ee 21 points 1 year ago

Depends on the company size and the people above IT. Sometimes the boss is a chode and demands everyone be supervised like children constantly.

load more comments (1 replies)
load more comments (3 replies)
[-] teft@startrek.website 36 points 1 year ago

Also do some really weird things that are innocuous so the HR lady looks at you weird from now on.

[-] JoeBigelow@lemmy.ca 16 points 1 year ago
load more comments (1 replies)
[-] Zeth0s@lemmy.world 62 points 1 year ago

They see and scan all traffic, even what doesn't go through the browser.

No one should use work laptops other than for work

load more comments (4 replies)
[-] Raiderkev@lemmy.world 52 points 1 year ago

I never browse personal stuff on a company device. That's what phones are for. I also don't connect to company Wi-Fi on any personal device, because my company makes me sign in with my company's credentials. This should be common sense.

load more comments (4 replies)
[-] Shiki@lemmy.world 51 points 1 year ago

Anyone that uses work equipment for personal stuff deserves to be found out

[-] PeachMan@lemmy.one 49 points 1 year ago

Of course they can, they literally own the machine. You don't own it, so don't treat it like it's your own private job hunting platform or porn viewer.

[-] jmp242@sopuli.xyz 16 points 1 year ago

Yea, this regular "surprise" that work computers are... IDK... owned by work and are configured as the owner requires... is so strange to me.

load more comments (1 replies)
[-] Koof_on_the_Roof@lemmy.world 16 points 1 year ago

Unless you work in recruitment or porn…

load more comments (2 replies)
[-] Anticorp@lemmy.ml 41 points 1 year ago

Your work can also read your private Slack messages. You have been warned.

load more comments (7 replies)
[-] NegativeLookBehind@kbin.social 37 points 1 year ago

I used TOR at work once, to download some RPMs. Corp IT had a fucking meltdown

[-] possiblylinux127@lemmy.zip 20 points 1 year ago

I can't imagine why

load more comments (4 replies)
[-] stevedidwhat_infosec@infosec.pub 32 points 1 year ago

I work in cybersec - I’m not going to speak for all businesses or individuals but I will give you my perspective.

Sometimes we need to see browser history to help with timeline correlation, it’s mainly to see “how did this file get here, was it downloaded etc.

Sometimes the investigators need to check out the things they need to check out, BUT

BUT

It needs to be done precisely and sparingly where needed only. This means instead of going through the entire history file, or doing unrelated correlation work (spying on you without cause) you are going to only grab specific timeframes from things you suspect explicitly to prevent any overreach. It’s a tricky balance to hold but also why it’s so important for people in tech to be privacy advocates as well.

There’s a difference between searching for answers to a problem that arose and looking for/predicting problems (thought crime detected!)

[-] thebardingreen@lemmy.starlightkel.xyz 12 points 1 year ago* (last edited 1 year ago)

I also work in cybersecurity. Second everything this person said.

This thread is a good reminder, because at many organizations HR / management can and will look at your browser history (and computer activity in general) as a method of monitoring performance and staying in control.

But at my organization, we have never once looked at anyone's browser history (and I know that HR hasn't because they would have to go through us). We certainly could if we were asked to and we would if there was an incident (what we would care about is sensitive / confidential information getting leaked or suspicious activity on the network using a specific person's credentials, suggesting those credentials may be compromised). But in almost 2 years (we're a startup in the aerospace electronics sector) we have never once had cause to do that and we have a philosophy that happy relaxed employees who feel trusted by their employer are the kinds of employees that we want, so we wouldn't intrude that way without cause ever.

load more comments (1 replies)
load more comments (3 replies)
[-] UsernameLost@lemmy.ml 23 points 1 year ago

Oh no, my employer might find out I'm looking for other jobs after being overloaded for a year and a half and constantly having my concerns/feedback/process improvement initiatives brushed aside.

load more comments (5 replies)
[-] angelsomething@lemmy.one 18 points 1 year ago

I’m an infrastructure analyst and at my workplace I implement such rules for specific reasons: 1) we need to be able to have evidence should an employee act maliciously with a company device. We do also monitor all queries but it’s passive. We can drill into your browsing history in great detail but won’t unless we have to (speaking personally here as I follow the code). 2) people will do dumb shit. And will lie to get support. Now, having been on the other end of a support ticket, I get it. Unless you lie a little, you may not get support promptly. Therefore, it’s part of my job to check what’s the lie and what’s the actual issue, which includes being able to see the download history. I would not be surprised if malware is accidentally downloaded and then it autonomously removes itself from the download history as It has happened before. Strictly speaking, this is done for both your safety as well as that of the company. And generally speaking, you should NEVER use your work laptop/phone/iPad for personal use because of all of the above.

load more comments (10 replies)
[-] seiryth@lemmy.world 16 points 1 year ago

Forget chrome management. Any IT shop worth their salt is protecting their egress with a proxy, explicitly or transparently set.

Don't browse the net on your employer's network or devices. Use your phone. Get on 4G/5G.

[-] echodot@feddit.uk 15 points 1 year ago* (last edited 1 year ago)

So only watch mainstream porn on work computers, got it.

I've always assumed work will be looking at the browser history. Anyone who assumes they won't is an idiot.

load more comments (2 replies)
load more comments
view more: next ›
this post was submitted on 22 Aug 2023
580 points (100.0% liked)

Privacy

32142 readers
748 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS