Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This isn't even as close to as bad as it made out to be. From the full text of ILCS after amendment:

(b)(1)It shall be unlawful for any employer to request or require any employee or prospective employee to provide any user name and password, password, or other means of authentication to gain access to the employee's or prospective employee's personal internet account.

(2)An employer may request or require an employee to disclose any user name and password, password, or other means of authentication for accessing any accounts or services provided by the employer or by virtue of the employee's employment relationship with the employer or that the employee uses for business purposes.

Note: Paragraph 1 retains the ban on asking for account information for personal accounts, and paragraph 2 authorizes asking for the info for business/employeer provided accounts.

So, unlike the headline, in fact this bill moves to legalize access to the businesses social media accounts.



Beyond that, the law creates a huge disincentive to ever asking for credentials for anything except the brightest of bright-line cases, because from the moment your employee refuses the credentials, you can't fire them for anything but cause without incurring a significant lawsuit risk.

The people talking about how a company could argue that their (say) Twitter account was a business account seem to miss the fact that such an argument takes place in court.


I get what you are saying, and I now agree that it's a net plus for employees.

However, I still worry about possible misinterpretation of the clause involving business use of personal accounts. I don't trust lawyers or judges. Sure, court decisions are probably correct well over 90% of the time, but that's just not good enough for me.


> I don't trust lawyers or judges. Sure, court decisions are probably correct well over 90% of the time, but that's just not good enough for me.

So now that you've rejected the lawmaking and justice systems wholesale, what do you propose to put instead?


Its not that I reject them wholesale, its that both systems desperately need to be fixed. I'll admit, I don't have the solution, but that doesn't mean one doesn't exist.


Thanks for that. I think this is a good law. If I'm working for you, this means you don't get access to my personal accounts. If you're working for me, this means you can't lock me out of accounts that I'm paying you to use.

The only place this law causes friction is when employees are either using personal accounts for business purposes or business accounts for personal purposes. It's a good law because it encourages a separation of the personal and professional spheres of one's life.


>The only place this law causes friction is when employees are either using personal accounts for business purposes or business accounts for personal purposes.

Right, which you shouldn't be doing so that you retain that clear separation.


>"or that the employee uses for business purposes."

This is the part that fucks the whole thing up. It's too vulnerable to misinterpretation or abuse.


Using an unauthorized Internet application to conduct business for your company was already something that could get you fired. The law doesn't authorize employers to break into your accounts; you presumably retain "quitting" as a recourse to turning over account information.


Of course, but when you see how many laughably horrible decisions our courts make on a regular basis, it wouldn't be all that surprising for a company to argue that your personal account was used for business purposes for a variety of reasons. For example, the mere mention of your employer's name on a site like Linkedin, or perhaps a developer that is known to work at a prominent company who maintains a programming blog.

It's also already a prosecutable offense to lock your company out of a business related account, so what is the point of establishing more legislation?


Laws that create prosecutable offenses in the ILCS say things like "Any person failing to comply with $(CLAUSE) shall be guilty of a $(CRIME_LEVEL)". This one obviously does not do that.

The reason for the legislation is that Illinois companies are specifically not permitted to demand credentials for personal social media accounts; it creates an exception to at-will employment in Illinois that would enable you to sue your employer if you were terminated incident to refusing credentials.


> Of course, but when you see how many laughably horrible decisions our courts make on a regular basis,

Only if you let HN and reddit rashly interpret your court decisions for you...

> It's also already a prosecutable offense to lock your company out of a business related account, so what is the point of establishing more legislation?

Because by itself, the previous language created an ambiguous situation. All the new bill does is clarify that the ban on asking for login credentials for a personal account doesn't override the offense of locking your company out of a business-related account.


The most vulnerable example would be retweets of your company's tweets using your own personal account. Retweeting mental barriers are so low (even compared to FB likes and shares) that a huge fraction of people would be caught under such an umbrella.


> retweets ... using your own personal account.

No, I think it's pretty clear. Once information is publish via the company's twitter account, it becomes public information. It would be a very long stretch for retweeting public information to change the nature of a personal account to fall under this law.

Not to mention, Illinois' has notoriously labor friendly courts (I live in IL). While landing in court is an obvious problem for the employee to defend/prosecute, the reputation/record of IL labor courts make it an even steeper hill for an employeer to climb than for the employee.


Hmm, how about things like tweeting links to your company's blog, your company's product, or your company's documentation? This probably happens a little bit less frequently but enough for us to at least take a cursory look.

While I would hope that most startups are above this kind of behavior, since startups tend to ask their people to use their personal accounts for marketing purposes, I have to at least have some concern...


Like I said downthread, reading the statute in the airless vacuum of a message board, it's easy to try to poke holes in it.

In reality, anything that amounts of an exception to the at-will doctrine creates an enormous minefield for employers. Terminated employees are very frequently disgruntled and can be counted on, over time, in the large, to bring meritless cases. Employers who want to survive without being stuck up for settlements are going to become very process-bound for how they handle credentials.

Think of it this way: worst-case downside to employee from this law: early termination. Downside to employer: horrifically expensive legal debacle.


According to the various quotes I've read there's no "non-public information" requirement.. just the vague "for business purposes" part.

While Twitter is the obvious example, what about a Github account? I've patched bugs or merged pull requests for my employer's projects from my own account. Would that qualify?


You should be careful about letting your employers' code hit your personal Github site for other reasons; an employer who wants to make it difficult for you to get a new business started can use IP issues to accomplish that.

Personal Github accounts are already a little bit fraught for that reason. The Illinois statute revision doesn't change the calculus; if you're an IL employee with a Github account you care about, you (a) don't want to be working for anyone who demands credentials to it, and (b) now have an avenue to extract a few tens of thousands of dollars from that employer should they ever be dumb enough to ask and then fire you.


I think the only litmus test necessary is that the account name use the companies name in someway. i.e. If your company is Acme Anvil Co and the terms Acme or Anvil are in the username (or vanity url, etc), in someway, then it qualifies as a business account. Barring that, any social media accounts should be viewed as personal, even if the following amassed under that account came by virtue of employment with the company in question.


Strongly disagree.

ANY type of legalized access to employee social media accounts is bad. Period.

Yet this is what we get when we freely throw any of our personal information online.


It legalizes asking for accounts, in very limited circumstances, in a manner that makes is extraordinarily risk simply to ask. It doesn't legalize seizing accounts.

You get that under at-will employment, there's a UNIVERSE of unreasonable requests employers can make that will permit them to fire you directly, right?


What's your point here?

It still legalizes asking for accounts and there's still room for misinterpretation.


My point is that the misinterpretation is catastrophically riskier for the employer than the employee. This is as it should be, but isn't something the author of this article (or many commenters here) seem to recognize. Some commenters even hint at a belief that employers can directly access employee accounts on third party services, which is not an action accommodated by Illinois law.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: