Some time ago when I hired on at Apple (I've since moved on to greener pastures) I had a tough time provisioning my corporate MacBook. Every time I tried entering my work email address I got kicked into an unfamiliar auth flow that ended up not working. After I mentioned how much trouble I was having, someone sitting near me in the office told me I needed to use a personal Apple ID to provision the device.
I created a completely new consumer iCloud account and used that. I never did anything remotely "personal" on that machine, and after I left Apple I never used that iCloud account again. In fact I don't even remember my password for it.
I went so far as to carry two iPhones, one personal and the other "corporate," and I only ever used my "corporate" iPhone with Apple employee apps. I never even connected my personal phone to the campus WiFi; I used wireless data for that phone the entire time I was there.
That said, I don't recall ever being asked to merge my personal and work accounts. It's just that if you want to do any personal stuff with corp hardware, it's much more convenient to just use your personal Apple ID when you provision the hardware.
"I went so far as to carry two iPhones, one personal and the other "corporate," and I only ever used my "corporate" iPhone with Apple employee apps. I never even connected my personal phone to the campus WiFi; I used wireless data for that phone the entire time I was there."
This is the way. Carry two devices.
Separate personal/work devices. Never connect personal to corporate network. Never send messages between personal and work. Never give out personal device # to colleagues.
Assume that everything on your work device is logged and monitored. Don't do vacation research, medical research, social media, Spotify, anything personal at all on your work device. Ever.
Is it really that extreme? Threat model, staying employed / defend against idle gossip.
Company surveillance (of their employees) is very real and unlike 'google reads all my emails' they actually can and do and it is a person they actually know whos private information they are viewing. I dont even need to get into the chance of every piece of information being in a lawsuit or get into the lack of any controls around data retention etc to be worried.
First step IT would take when I dropped my phone in 'because they had to run the update' - they would open my photos and take a look through. Second step - they would go to the deleted photos and have a look through. It was done as part of any company-mandated review of the device but out of personal 'curiosity'.
Every private message on teams etc was logged and routinely reviewed by a compliance team and often escalated to line managers - the team doing so knew everything professional and personal going on in the place. Who was getting hired, fired, promoted, working hard, slacking. Who was sleeping with someone, depressed, happy, gay, straight, having kids, getting divorced, getting a nose job, getting a vasectomy etc.
So whats the threat? I have nothing to hide, I am popular, a hard worker, not having an affair with the intern, so they are not going to trawl through looking for any dirt to diminish or fire me. There is little value in this information beyond gossip, but a permanent record remains all the same. For me there is little extra effort required to phone home from my phone rather than the recorded office line and that way the call wont be listened to by the guy in compliance.
A bank in Europe, it was EU wide laws that resulted in all mobile phones being brought into the surveilence net. It has been common in banks to use recorded lines for decades, but the regulatons effectively mandated monitoring of every communication internally and externally post the libor scandal.
That said, when I have worked outside the region or in less regulated positions - the intrusion into particularly email and written communications is the exact same. When you leave an organisation in particular, you do reflect on how big a trail of information you have left behind in their hands.
Financial companies are surely different from eg Apple though. As far as I’m aware, there are no laws forcing Apple to log as much of their internal communications as a typical financial company would have to.
Yes most of that would be illegal, except you gave them consent in your contract or other legal document.
This is also exactly why I always check all the paperwork for "personal usage" of the devices and services provided by the company (email and stuff). If there is nothing about it, I send my mom a random cat picture from my work email (always outside of office hours, in other cases it could be a contract violation). Why? Because if it's not forbidden, you are implicitly allowed to and after at least one private message was sent by the account, it's legally like a private account.
If your employer snoops in the account, it's a massive privacy violation (Datenschutzgesetz and DSGVO/GDPR) and a strong case in employment law. Never needed it, but it's better to be safe than sorry.
There is the law and then there are employment contracts. Sometimes these things overlap, intersect or contradict in interesting ways.
I dont think I have ever worked under an IT policy that was anything but 'for work use only' - although that didnt stop me from taking great pleasure at seeing how many work emails were used to sign up for sugardaddie etc whenever they leaked. I was never too fussed - having two phones, two emails, two laptops etc doesn't bother me in the slightest. You lose access to the work phone number / email / storage when you leave anyway so it's really of no use.
I have even come to like the physical separation of work and personal, there are times each needs more than 50% of my attention.
Bright distinctions between work and personal devices make it easier to stay disciplined.
Threat model is straightforward: I have no expectation of privacy on my work devices. I do not want my employer entangled digitally with my personal life.
> It's just that if you want to do any personal stuff with corp hardware, it's much more convenient to just use your personal Apple ID when you provision the hardware.
Yes, but I feel like a major takeaway is that you should never ever do that
I created a completely new consumer iCloud account and used that. I never did anything remotely "personal" on that machine, and after I left Apple I never used that iCloud account again. In fact I don't even remember my password for it.
I went so far as to carry two iPhones, one personal and the other "corporate," and I only ever used my "corporate" iPhone with Apple employee apps. I never even connected my personal phone to the campus WiFi; I used wireless data for that phone the entire time I was there.
That said, I don't recall ever being asked to merge my personal and work accounts. It's just that if you want to do any personal stuff with corp hardware, it's much more convenient to just use your personal Apple ID when you provision the hardware.