> Additionally, Apple learned about Liu’s use of the schematic because he used it on a Mac mini which later synced via iCloud to the MacBook he took from Apple. Apple now also wants access to that Mac mini.
I'm very curious about the privacy implications of this. I know that anything I do and store on my company's laptop can be tracked, but I hadn't considered that if I forgot to sign out of my personal Gmail on it that they could legally search that information.
The files syncing to the company laptop's disk is a layer of nuance that makes this situation tricky to evaluate.
encourages, but doesn’t require. My work phone is an iPhone 14 that I only use for Slack notifications & to check the next day’s schedule when I don’t want to bother opening their laptop.
When Ashley Gjovik was fired, she complained the pressure to use work devices for personal stuff was considerable. I stopped carrying back then & haven’t felt any pressure.
A “carry” or “live on” device doesn’t have to be used for personal email and messages. It should just be used for more real-world non-test workloads. The lessons of only testing iPhone 4 in stealth cases hasn’t been forgottten.
I do agree that Apple likes to have it both ways, though.
Who I am is right there in the username (morganw), submissions & comments: Morgan Woodson. Not in SWE. Is it software if you write it in the hardware division?
Edited to add that I think EPMs are under more pressure to be Apple cheerleader than engineers.
I can't open pretty much anything, including shoghoth face and linked in, but thankfully this imageboard and YouTube are spared. I still wonder how the powers that be didn't bother to ban npm on dev machines
> I'm very curious about the privacy implications of this. I know that anything I do and store on my company's laptop can be tracked, but I hadn't considered that if I forgot to sign out of my personal Gmail on it that they could legally search that information.
If it's work-related, work computer only. If it's anything personal, personal computer only. This is especially true for situations where companies are using screen capturing tools that capture the screen every 'x' seconds[0].
The seeming convenience of using your work computer for everything isn't worth the risk but some people don't consider the legal implications, as you've noted in your anecdote.
Once your personal message to Bob or Jane enters an official record because it's included in the eDiscovery (even if accidental) result(s), it's over.
Better to not have a surface risk like that, than assume the process will keep your personal data safe.
I was under the impression that Apple requires its employees to login with personal Apple ID accounts for cloud storage.
> “You go through these steps of getting all your software set up, and all your devices provisioned to access internal Apple networks, and things like that. And it explicitly says you cannot use your corporate Apple account to set this up.”
How's that supposed to work? Apple requires employees to own Apple products or have a personal account in the first place? That doesn't sound believable.
That seems crazy to me. I've always had my employers either provide or offer to provide me with anything I'll use for work. Asking someone to use a non-corporate-managed account for work seems especially insane to me. I've never heard of that.
I've never heard of being asked by an employer to make an account associated to a non-work account (like a personal email). They should provision SSO, or at least use a company domain like apple.com or internal.apple.com for test accounts.
Day 1 at FooCorp: "Your email address is [email protected]. Conducting business activities with personal accounts is against policy and may result in disciplinary action including termination. It may also be a regulatory violation depending on industry."
This may have been an optional iCloud 2TB promotion for employees, but still relevant to the lawsuit.
I'm also under the impression that Apple requires its employees to dogfood their products and services. Hoping someone with personal experience and a lapsed NDA can chime in.
Techies tend to associate access control with legal control. Nothing could be farther from the truth, especially when it comes to legal discovery and subpoenas.
And it gets worse. The 4th amendment protects against unreasonable searches from the government without a warrant, not all searches. If you have evidence on your personal devices that a judge believes could be relevant to the outcome of a criminal or civil trial, be prepared to give it up or face a potential evidence tampering / obstruction charge. Doesn't matter if you never signed into your personal Gmail on your work computer or not. In a trial where work records are important, your non-work devices and accounts can be subpoenaed if there is a good reason to believe you have work materials on your Gmail or personal laptop. Like if in the first review of work e-mails, they find you've e-mailed one work file from your work to your personal Gmail one time or even just have been signed onto your personal Gmail while at work.
> I hadn't considered that if I forgot to sign out of my personal Gmail on it that they could legally search that information
I don't think this is true, this would still be unauthorized access on your employer's end and would be considered illegal. They're not allowed to pose as you to access your services iirc.
You should obviously still sign out (or never sign in in the first place) of course!
These things all vary across legal jurisdictions and with what you sign away in your contracts. If your contract doesn't say anything, then yes, your boss opening up your laptop while you're on lunch and reading through your logged-in but password-protected personal e-mail is not just a civil violation but gets into CFAA/wiretapping territory. California has some particularly strong default protections.
But you can 'freely' sign away these rights in your contract. Or if your contract binds you to follow internal policy and it's in the internal policy, that's usually enough notice and consent for the courts. When you're given a work device from a BigCo with a legal department that knows what they're doing, it usually comes with a EULA-style contract you don't read that authorizes everything.
California law does now say you can't be forced to give your employer your personal e-mail or social login, or other way of scanning your personal e-mail or socials. You can't sign this right away (just like you can't sign away your right to a minimum wage or workplace safety), but if you freely sign in while on a company device, network, and time, and your contract or policy is worded so broadly that anything you do on that device/network/time is the company's...
at a previous job something we impressed on to people was you should not use work laptops for personal business, not because we want to go trawling through your personal stuff, but because if your work laptop becomes discovery material for legal proceedings, do you really want that lawyers you don't know digging through your personal email?
(relatedly, we told people not to sign into work stuff on personal computers because then they might have to turn over those computers for discovery)
Yeah, from what I remember they have a funky iCloud file share thing set up for the whole company, and it requires them to either sign in with their personal iCloud account, or carry two iPhones (one for personal, one for work). Most employees understandably opt for the first option.
It surely is. Ascetism and stoicism are extinct virtues, maybe venerated only in Eastern Orthodox Christianity. Many of our holy fathers have suffered terrible torture and death, but they even welcomed it. That's why Orthodoxy is so hard to grasp in the West, where people damage their livers just to tame their headache a bit, let's say.
It’s funny, because Paul criticised such thought in Colossians 2:23:
> These have indeed an appearance of wisdom in promoting rigour of devotion and self-abasement and severity to the body, but they are of no value in checking the indulgence of the flesh.
Meaning: sure, looks good, but doesn’t actually help if the suffering itself is your goal.
(Notwithstanding this, Acts 5:41. A lot, in such topics, depends on exactly how you present things.)
I had a hell of a time getting WiFi roaming to work in my house between Omada APs in a low-interference suburban neighborhood.
Any combination of 802.11r and k/v seemed to just cause my phone's connection to drop for minutes at a time when moving around the house.
I wish I could remember my exact solution for you, I believe I just turned off 802.11r and k/v, set channel selection to automatic, and undid any manual or automatic power tuning.
Looks like a normal comment to me, what makes you think otherwise? It has pretty much no hallmarks of being generated, and plenty that point towards the opposite.
Starting the comment pointing out the name of the user you're replying to, and quoting the exact comment you're replying to, does sound really strange.
If you're deferring to the favors of a figurehead rather than the law, you would be much better off in Dubai. Everyone knows the game there, it is pure dictatorship, but the taxes are extraordinarily low, banking and KYC/AML is laissez faire, and if you're going to depend on personal connections to a leader rather than immigration law then you may as well go all in and get the better end of the deal.
I'm very curious about the privacy implications of this. I know that anything I do and store on my company's laptop can be tracked, but I hadn't considered that if I forgot to sign out of my personal Gmail on it that they could legally search that information.
The files syncing to the company laptop's disk is a layer of nuance that makes this situation tricky to evaluate.
reply