Hacker News new | ask | show | jobs
by JoeBOFH 21 days ago
As much as I prefer the European way of some items. I think the American way of treating the work computer as a company asset and just locking it down to an insane degree makes way more sense. Especially for areas like finance.
1 comments

Exactly this.

I've been in a lawsuit with Oracle (as engineer, not direct). And their discovery hit EVERYTHING.

If I used work devices for personal messages, my personal messages would absolutely been in scope.

Or if I used personal devices for work, my personal devices are now in scope. Hell NO!

My work laptop is on my personal network. Its also on its own vlan and can only talk to the imternet, and not fellow devices. And I can attest to that as much if I'm ever called in for a discovery hearing.

I have my work items on a separate network as well but my motivation is more not trusting some random item being pushed down from corp and having it scan my network or something.
Yeah I'm about to do this too just to be safe.

Some of our antimalware like SentinelOne actually does this by default though we have switched it off for privacy reasons (EU)

The things you can see in S1 Deep Observability is insane.
Discovery doesn't work like that in Europe though. It's not nearly as all-encompassing. And personal messages definitely would not be in scope. I think this is one of the reasons there is so much difference in strategy.

When we get requests to "legal hold" an account for discovery, this is always coming from the US.

> Or if I used personal devices for work, my personal devices are now in scope. Hell NO!

In Europe, unless it's a criminal investigation, which this wouldn't be, there is no way a lawsuit would touch your personal devices if you didn't agree (and mostly also nobody would care I think).

That is more of a problem with the insane discovery system in the US than with anything else. If you had worked in Europe, GDPR would have protected your personal data from being sent over, as the Credit Suisse case has shown. They had to scrub all personal data before transferring files to a US counsel.