Slashdot Mirror


Instant Message, Instant Transcript

shams42 writes: "Although the internet has been far from private for some time now, it seems that public awareness and concern over this issue is mounting. This article at CNN discusses the issue of companies monitoring instant messages for cyberslacking or leaking company secrets. There is also the possibility of them being included as evidence in court cases."

4 of 330 comments (clear)

  1. Re:Jabber + SSL by cuteduo · · Score: 4, Informative

    If the companies are monitoring for so called cyberslacking it
    may not matter much if you are using SSL/SSH with your instant
    messaging. There is software for monitoring the users' desktops
    and keystrokes which is one of many tools that employers can use,
    not only packet/traffic monitoring on company networks. Just to
    add another formula to things, monitoring can be completely seperate
    from the computer, they (employers) can also use well placed CCTV
    systems.

  2. simple solution by ross.w · · Score: 4, Informative

    Use SSH link to your PC at home to run text based IM client and/or web browser from your home address.

    I've not heard of an employer that monitors Port 22, and even if they did, it's encrypted so they can't pick up what you said.

    Best program for this is PuTTY (assuming you use NT at work)

    The whole thing assumes you are using *n?x at home and can run an SSH daemon on it.

    OF course best of all is to not shout from the rooftops what should be said in private.

    --
    If my call is important, why am I talking to a recording?
  3. I consider the instant transcript a "feature" by phoneboy · · Score: 4, Informative

    First of all, the only reason I use IM these days is for work-related purposes with co-workers on an internal Jabber server. Okay, we do our share of chatting that's not exactly work-related, but who doesn't have f2f conversations with people at work about things that have nothing to do with work?

    In any case, why I consider the instant transcript a "feature" is because my co-workers and I do tech support. We talk to each other frequently about customer issues. These transcripts often contain useful troubleshooting information. It seems awfully silly to type something more than once, so once a conversation is done, it's copied straight from Jabber into a case note. We usually do not make those kinds of notes viewable to customers, but they are good for internal documentation.

    For those of you who have issues with your employer "snooping" on what you're doing, I would not expect any sort of privacy with respect to your computer usage at work. However, your employer needs to tell you your computer usage is subject to monitoring. Employers who fail to notify employees of monitoring are subject to serious trouble if they decide to take advantage of any information they find out as a result.

    -- PhoneBoy

    --
    The views expressed herein are not necessarily those of anyone, including the poster.
  4. Traffic analysis by driehuis · · Score: 5, Informative

    Even when you encrypt your traffic, it will not protect you from traffic analysis.

    I happen to be the dude in between management and the users on my site. I refuse to eavesdrop on my users. Not all of my users realize it, but we've got a pretty liberal policy (don't break the law, don't be offensive to others, don't use excessive bandwidth during business hours; that basically sums it up).

    Some of my users know me for cracking down on porn or MP3 downloads, and think I'm reading their every keystroke. Because if I wasn't, then how would I know that they were doing stuff that they weren't supposed to do?

    The reality is, when I get complaints about Internet performance, I run some quick scripts on the logs to find out who is hogging the system. If, after eliminating the obvious business use connections, I'm left with a top ten and number two is downloading a gazillion of .xls spreadsheets from an server in Poland and all the URL's have /..%20%20/ in the path, I give that user a call.

    Usually, the user will accept the lecture that his contractual obligation to stick to the corporate guidelines is not optional. I sometimes learn through the grapevine that such a user thinks I'm a fascist. So be it. If other people can't work because of egregious abuse, I have to intervene.

    Do I even look at the stuff they're downloading? Not if I can avoid it. The only times I look at what they're downloading is when they start yanking my chain, giving me the go around that there is no law against downloading Warez or porn. Maybe there isn't, I've got no clue. I do know what's in their contracts though.

    Most of these issues are dealt with amically. People sometimes don't realize how big their impact on the corporate network is, and even if they do I usually let them get away with it if the abuse stops. They're usually pretty happy when I tell them I've got no clue what they were downloading, but could find out when forced to.

    Over the last year, IM became a bit of an issue because of the way their stupid tools communicated (if only they used persistent connections they'd fly right under the radar). At some stage, 30% of our proxies capacity was used to serve a few dozen IM sessions and it really started to hurt web performance.

    It's always funny when they let it escalate to management level, and I can at that stage let them rant about the invasion of their presumed privacy, and then drop the bombshell that I didn't even look at what they were downloading, and that it was trivial traffic analysis that gave them away, and that the reason they were in that meeting was because they incriminated themselves.

    --

    Bert Driehuis -- All I asked was a friggin' rotatin' chair. Throw me a bone here, people.