Hacker News new | ask | show | jobs
by eel 2095 days ago
> On January 15, 2018, Bohra used her work computer to search Google for “AMZN.”

How does the SEC know this? Is it most likely browser history? Google account history? Corporate monitoring software?

2 comments

Amazon probably had to comply with giving up the corporate monitoring data most likely.
Not only that but if she’s in finance, the monitoring requirements for what you do on work machines is even higher. And as a child comment said, Amazon complied willingly. Nothing forced at all. It doesn’t want insider-trading either.
Probably complied gladly. They don't want folks insider trading either.
the search query would be TLS encrypted. Amazon snoopware wouldn't be able to see it
Snoopware is often installed on the laptop itself, not merely listening in the middle.
She worked in finance...I’m sure every single keystroke was logged in addition to any TLS bypasses.
bypassed by a TLS cert installed by employer. also not that hard for amazon to develop a browser extension and force feed it through group policy
The query string is sent in plain-text in the URL parameters.

https://www.google.com/search?q=AMZN

Which goes down a encrypted transport connection. The t in https.
Corporate proxies MITM all https traffic
Lol, when I work for JPM IB tech in NYC, I opened a ssh tunnel just to be able to listen to my mp3 collection at home. infotech emailed asking me wtf I was doing with my tunnel. They know everything. Sorry to say that.