Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
illud_tempus
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
illud_tempus
5y ago
> The Drata agent does exactly what you are talking about Does it also name and shame? ;)
2.
▲
by
illud_tempus
5y ago
How does the agent know what user it is monitoring? What other kinds of personal information does it process or collect, locally or in it's server endpoint? An external IP address is personal information. A UUID identifying a block dev
3.
▲
by
illud_tempus
5y ago
> The agent is read-only and has no capability to wipe a device, it is a read-only agent that we have security validated with a third party. And you can change that over night, without notice to anyone not actively monitoring your platfo
4.
▲
by
illud_tempus
5y ago
> OP made a claim that Drata collects private employee info and resells it. That’s a large claim. What I know is: 1) They collect mandatory private information. They already know my name and my email, and they used that information to as
5.
▲
by
illud_tempus
5y ago
> Why do you think it covers the data collected by the agent? The agent is not the only concern. Before you even get to install the agent, you have to provide personal information to their website (I believe - I don't now, because I
6.
▲
by
illud_tempus
5y ago
> This is correct. The privacy policy listed here is for the website. Is that the 100% honest answer? From my understanding, your website is where you collect my mandatory personal information, if I agree with your TOS. It's not jus
7.
▲
by
illud_tempus
5y ago
> You are 100% correct. > Source: I am the Drata CISO May be you should go over your user agreement documents and: 1) Make sure that all relevant information is available, so a user can make an informed decision. 2) Distinguish betwee
8.
▲
by
illud_tempus
5y ago
Very informative. Thanks.
9.
▲
by
illud_tempus
5y ago
> We are happy to share our security validation report of the agent as well as the configuration with any prospects/customer. I am the OP. I am not your customer. My customer is your customer. My customer wants me to install your ag
10.
▲
by
illud_tempus
5y ago
> there is a lot of misinformation here around what the agent does May be. May be not. I have not decompiled their client, so I don't know what it does. However, Dratas Terms Of Service states: "Drata will notify you of updates
11.
▲
by
illud_tempus
5y ago
I can easily engineer myself out of this crap. But that feels like a much worse solution than just dropping out. I have two qualities that makes customers willing to pay a premium. I am very good at what I do. I am honest. I don't want
12.
▲
by
illud_tempus
5y ago
> Personally I would simply refuse and prepare for the possibility that this company will no longer be a client That is the easy solution. Problem is, I really like the projects I work on and the people I work with. Economically, I could
13.
▲
by
illud_tempus
5y ago
Not on my part. Not with the people in the company I usually deal with. When a new manager I don't know send me an email to install some "agent" from a company I have never heard about, and that company turns out to have term
14.
▲
by
illud_tempus
5y ago
> OK, well, I've skimmed it and I can't see anything that suggests they are going to spy on our employees and sell the data to advertisers "We, our service providers and our third-party advertising partners may collect and
15.
▲
by
illud_tempus
5y ago
> The poster says "Their business model (in my case) seems to be to take money from companies to spy on their employees/contractors, and then they sell the employees/contractors private information to "targeted advert
16.
▲
by
illud_tempus
5y ago
I don't use my private accounts for anything related to this client.
17.
▲
by
illud_tempus
5y ago
> have someone really familiar with SOC 2 certification working for them? Not that I'm aware of. I don't know the details. My interpretation is that some manager hired some company to help them with this certification that the
18.
▲
by
illud_tempus
5y ago
> The Data Processing Addendum isn't a loophole to collect data that they don't have a legal basis to collect. No. But it looks like a loophole to export whatever they have a legal basis to collect, to process it and share it i
19.
▲
by
illud_tempus
5y ago
> Under EU law that would potentially make you an employee rather then a contractor, That is not going to happen. I'm a freelancer, and I am going to remain a freelancer. It that becomes too hard in EU, then bye bye EU :) I'm a
20.
▲
by
illud_tempus
5y ago
> ... they found another solution for that. Because there always is one. Thank you! That is the kind of experience I want a taste of :)
21.
▲
by
illud_tempus
5y ago
> Another approach you can try is to conform to their requirements on one machine, but do all your actual work on another. That would create a layer of cynicism between me and my work. I don't have that today, and I would rather avo
22.
▲
by
illud_tempus
5y ago
> being driven by a new guy. It is. Problem is, I like code. I don't like politics. I'm not good with people.
23.
▲
by
illud_tempus
5y ago
> This is legitimate when working with sensitive data I work with code. Not data. I don't have access to production systems. I do too many mistakes, and I admit it. Just last month I killed the wrong k8s cluster ;)
24.
▲
by
illud_tempus
5y ago
> Do you object outright to spyware, or to the client wanting to run their spyware on your equipment? I don't know for a fact that it is spyware. For now I just think of it as an "hostile agent". I object because a) I don&
25.
▲
by
illud_tempus
5y ago
> If this is really the kind of things this company would do… Because, until last week they didn't. Now I have to figure out if I'm just an unreasonable, stubborn old guy, or if this requirement is out of band.
26.
▲
by
illud_tempus
5y ago
> If you freelance via upwork this is a normal thing I don't. My clients usually find me via reputation or via open source projects I work on.
27.
▲
by
illud_tempus
5y ago
> You mention you are in the EU. That's important because the GDPR applies. They have some lawyer speak in their "Data Processing Addendum" that is unclear to me. I suspect it is designed to enable a loop-hole in GDPR. I&#
28.
▲
by
illud_tempus
5y ago
+
29.
▲
by
illud_tempus
5y ago
> Since you are in the EU, have you asked them if they have confirmed with their DPO that the suggested data collection and processing is GDPR compliant? That was one of the six concerns I raised with Drata. Their reply was: "Feel f
30.
▲
by
illud_tempus
5y ago
They worked pretty well in Scandinavia, and is one of the reasons people there are well payed, have good protections and world class health care.
More ›