Slashdot Mirror


Telecommuting Backlash

coondoggie writes to tell us that advocates of the telecommute have stood up against recent finger pointing based on recent telecommuter screw ups. One of the more notable screw up was the recent loss of many veteran's personal information by a VA employee. From the article: "Despite years of growing acceptance, telework still has such detractors. 'The No. 1 challenge is cultural inertia. It's motivating the middle managers, teaching them a new way of doing work,' O'Keeffe says. 'It's the Luddite mentality that we need to change.'"

72 of 250 comments (clear)

  1. The problem isn't telecommuting by Loconut1389 · · Score: 5, Insightful

    The problem here isn't telecommuting, it is bad security practices and these problems probably would have happened one way or another, whether it's over a SSH tunnel, VPN, or local on the lan.

    1. Re:The problem isn't telecommuting by susano_otter · · Score: 4, Insightful

      It's kind of hard to walk off with tons of senstive information when it's being transmitted over an encrypted channel.

      I think it really is about telecommuting, and laptop computers. More and more, sensitive data is portable, and more people are taking advantage of that to move sensitive data from "secure" environments to "convenient" environments.

      Having some asshat steal a computer full of data doesn't really happen that often to people who keep their computers locked in an office at their employer's campus.

      --

      Any sufficiently well-organized community is indistinguishable from Government.

    2. Re:The problem isn't telecommuting by drinkypoo · · Score: 4, Insightful
      The problem here isn't telecommuting, it is bad security practices and these problems probably would have happened one way or another, whether it's over a SSH tunnel, VPN, or local on the lan.

      I both agree and disagree. On one hand, the problem IS bad security practice. It's possible to telecommute safely. On the other hand, the simple truth is that telecommuting opens up new attack vectors. Your data can now be attacked on your system at home, before the VPN is up. It can also be stolen more easily; security on your average office building is better than on your average house.

      On the other hand, THIS particular problem could have been avoided by simply using some encryption. Clearly, those who take home confidential data without encrypting it are morons. Some of you are now parting company with me over my allegedly elitist attitude but let's face it, people have been encrypting messages for hundreds (thousands?) of years. This is not a new concept. A user taking home confidential data should be asking themselves how they can protect that data. Anyone who doesn't ask that (in our litigious society, especially) deserves what they get, because they're stupid.

      I don't expect everyone to know how to keep data secure. I DO expect them to care enough about it to seek the advice of someone who DOES know.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    3. Re:The problem isn't telecommuting by Barleymashers · · Score: 2, Interesting

      Because of these type of events, I am now subjected to running everything encyrpted now by the company I currently have a contract for. Plus they force daily backups in case the laptop is stolen/lost. At first I thought it would be a hassle and there are some minor delays when the backup is taking place (seems to run at most inappropriate times), but so far I have gotten used to it and it really hasn't impacted my work. If this is the price I have to pay to telework, than so be it, it is better than having to trek the 80+ miles to the office every day.

      The real problem I have is the perception that when you "work from home" you are not really working, so I have to work extra hard so that people think I am working at all.

    4. Re:The problem isn't telecommuting by Loconut1389 · · Score: 3, Insightful

      Regarding the having the data on the work computer- this is exactly the problem.

      Of course the potential also exists for viruses or trojans to affect the data over the VPN.

      One could even argue that since these same problems could potentially exist on the local lan at the office (installing bad stuff on the machines (again, bad security)) that having it over a vpn is safer since it's not an always-on link.

      Bottom line- good security and not allowing people to take things home/offload data (part of good security) are crucial.

    5. Re:The problem isn't telecommuting by networkBoy · · Score: 5, Insightful

      Take your secure environment with you!
      My employer mandates that the encryption feature of our notebooks be used. But it's a PITA, especially if your drive gets corrupted. To counter that we have an on-line backup system that takes a daily image (file by file, not binary image of the disk, for obvious space savings possibilities) of your drive and stores it whenever you are in the plant. While you are off-plant you are still secure because of the encryption. If we lost a notebook we could lose billions of dollars (assuming it's the right notebook). Shit, the data on mine is worth ~$75-100M.

      The headlines should read: MegaCorp loses notebook with customer data on it. Company issues this statement: "This is a non-issue, the notebook was encrypted with a system that meets XYZ standard, it will take no less than 200 years for the system to be cracked."
      And the statement should be true.
      -nB

      --
      whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
    6. Re:The problem isn't telecommuting by Shadow+Wrought · · Score: 2, Insightful

      As much as I am an advocate of telecommuting, having your laptop stolen does no one any good. Middle managers may be luddites by definition, but opening themselves to this type of scandal so you can stay home simply doesn't balance on their risk/benefit sheet.

      --
      If brevity is the soul of wit, then how does one explain Twitter?
    7. Re:The problem isn't telecommuting by iminplaya · · Score: 5, Funny
      Shit, the data on mine is worth ~$75-100M.
      Stay online for just a little while longer. I'm trying to get a lock...
      --
      What?
    8. Re:The problem isn't telecommuting by AK+Marc · · Score: 4, Insightful

      Having some asshat steal a computer full of data doesn't really happen that often to people who keep their computers locked in an office at their employer's campus.

      No, the companies give away the working computers with all the data on them when they are obsolete.

      More and more, sensitive data is portable, and more people are taking advantage of that to move sensitive data from "secure" environments to "convenient" environments.

      A VPN into a corporate network then a terminal session would fix most of the complaints. Have them work directly from the server and there are no problems. Have the VPN client check that the firewall and virus software is installed, running, and up to date and there are fewer holes. If you are really worried about it, toss more money at it and make a non-split-tunneled hardware VPN from the homes of those that will be going in, then use locked down terminal services. They won't be able to get anything from the Internet without the protections that everyone else in the office has, and no data will be ever put on the local computer.

      I can think of lots of ways to make these just about as secure as those at the office. The problem isn't figuring out how to make them secure. The problem is getting executive buy-in and end-user compliance.

    9. Re:The problem isn't telecommuting by networkBoy · · Score: 4, Insightful

      :):)
      Have fun with:
      2 proxies
      3 NAT layers
      1 terminal server (which I suppose is another proxy).

      My real point was that there is not a reason for theft of a notebook to be an IP asset issue. If I can "safely" take my data with me, then why not customer data in the same method?
      the answer is simple: most companies think their IP is worth more than customer records. If they would simply make the statement:
      {IP += CustomerRecords};
      then there would be no issue, as you would see the data locked up tight.
      -nB

      --
      whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
    10. Re:The problem isn't telecommuting by modecx · · Score: 2, Interesting

      Totally, most of the problems could be mitigated by good security practices.

      What about encrypting the whole workspace that the user works on? For example, take a VMWare image with a Windows or Linux environment and all the apps that the user needs to use for this sensitive information, put it on an encrypted virtual drive volume and there it is.

      It dosen't seem that these computers are the target of people who want the data, or even know that it's there, they just want the hardware... But it would be a good idea to make it basically impossible for the casual or professional snoop to get at this data.

      --
      Constitutional rights may be respected, repealed, or modified; but they must never be ignored.
    11. Re:The problem isn't telecommuting by Henry+V+.009 · · Score: 5, Funny

      Wow. That's some awesome security.

      By the way, for making your 1361st comment on Slashdot, you win a free USB drive. Where do I send it?

    12. Re:The problem isn't telecommuting by aqui · · Score: 2, Informative

      Agreed, good policies are important.

      If the data needed to be on a laptop, why wasn't it encrypted?
      There's absolutely no reason why a laptop cant be set up to
      have the entire home partion set up to autoencrypt and decrypt.

      Users without proper login credentials wouldn't then be able to
      access the data (assuming proper encryption algorithms are used).

      Again policies that clearly define what information can leave the
      office and in what form need to exist in parallel with smart
      use of security technologies.

      Unfortunately most people (and that includes many managers and policy makers)
      don't really understand technology and as a result tend to seek solutions
      that they do understand, even if they are poor solutions, rather than admit
      that they don't know and ask qualified people for help.

      --
      ----- "Profanity is the one language that all programmers understand."
    13. Re:The problem isn't telecommuting by fm6 · · Score: 2, Insightful
      Correct. But this is just one aspect of a wider problem: many companies have plunged into telecomuting without proper planning. Scoping out good security procedures is important, but only part of what you need to do.

      One aspect I've really seen neglected is providing a decent communication infrastructure. Software people use shared whiteboards a lot, yet it doesn't occur to companies that their telecommuters need whiteboard software. And then there's teleconferencing: the last big meeting I went to was missed by a lot of employees because they didn't allocate enough slots with AT&T. Then again, with so many people involved, it would have made more sense to provide a audio stream and take questions over IM. But that didn't occur to anybody.

      And let's be realistic about folks who telecommute from the other side of the planet. Fine, Indians and Russians work a lot cheaper, and are (sometimes) just as good as their North American counterparts. But you can't arbitrarily fill slots from the other side of the planet: people who work together have to be awake at the same time!

    14. Re:The problem isn't telecommuting by mrbooze · · Score: 4, Informative

      What Cook County does for the sherrif's department now is, the laptops issued for police cars have nothing more than base installs on them, and the officers use ssl/vpn to access a remote console of their actual system which is a vmware virtual machine hosted in their data center.

      This means that when a sheriff recently left his laptop in an unlocked police car and it was stolen, there was nothing sensitive on it.

      This isn't that different from how I've been telecommuting for a long time. I use my laptop to connect up to the corporate VPN and then connect via remote desktop to a machine I have configured for myself at the home office, where I do all my actual work.

    15. Re:The problem isn't telecommuting by pilgrim23 · · Score: 2, Insightful

      Yep. that computer...the one with a USB port, the USB port that fits so snuggly on my jump drive. that computer is nice and secure right there in the campus...

      I still recall a dumpster loaded full of blue bar computer printouts covered in student grades outside the main campus registrar's office. and that was thirty some years ago...

          It has NOTHING to do with telecommute, NOTHING to do with security, it has EVERYTHING to do with butinsky bureaucracy and government gimme. When, as a culture, we finally start saying "None of Your Business" as the most common reply when someone asks you for personal information we will ALL benefit.

      --
      - Minutus cantorum, minutus balorum, minutus carborata descendum pantorum.
    16. Re:The problem isn't telecommuting by aslate · · Score: 5, Funny

      Via:
      2 PO Boxes
      3 Foreign countries
      A customer's secret, illegal account in the Cayman Islands

    17. Re:The problem isn't telecommuting by Sinus0idal · · Score: 4, Insightful

      What benefit do you gain from 3 layers of NAT and 2 proxies other than a ton of lag? A single well configured version of each should surely be sufficient.

    18. Re:The problem isn't telecommuting by Saint+Stephen · · Score: 4, Funny

      I used to have about a million drug test results on my PC (in 94, on my 486/50 w/ 40 meg HD baybee!)...

      Just for fun I did a GROUP BY query grouping who tested posted for what drug by SIC code, in descending frequency. The pattern was: Construction Workers, Marijuana and Cocaine, far and away #1. Second: employees of the school system, alcohol. Everything else was kinda scattered all over the map. I think that rather than demonstrating what kinds of people take what drugs, it demonstrates who gets hassled the most by the drug policies.

    19. Re:The problem isn't telecommuting by OnlineAlias · · Score: 3, Insightful

      Having some asshat steal a computer full of data doesn't really happen that often to people who keep their computers locked in an office at their employer's campus.


      Tell that to AIG. Reported 2 days ago...Fun News Link Outside of the VA lately the breaches have been from smash and grabs like this one. As an I.T. security guy, the first thing I look for when doing an assement is the physical security of home and especially branch offices. I'm not really disagreeing with you, just pointing out that one can't let their gaurd down, ever.
    20. Re:The problem isn't telecommuting by Emmettfish · · Score: 5, Funny
      This means that when a sheriff recently left his laptop in an unlocked police car and it was stolen, there was nothing sensitive on it.

      UN Inspectors are going to find that thief, because that thief has URANIUM TESTICLES. Stealing a laptop from an unlocked police car? Holy shit.

    21. Re:The problem isn't telecommuting by Fudge.Org · · Score: 4, Insightful
      Having some asshat steal a computer full of data doesn't really happen that often to people who keep their computers locked in an office at their employer's campus.

      Consider yourself lucky to have never experienced two floors (dozens of employees) of locked PC's and laptops removed overnight... more than once. In my experience it isn't someone but some group and they know what they are after and they have tools. Yes, most criminals are stupid, but many are organized and professional.

      What's the bigger payoff?

      a) single telecommuter setup in home where there is someone that is around most of the time

      b) office space with dozens of systems guarded by the lowest price bid security firm/system

      --
      http://fudge.org
    22. Re:The problem isn't telecommuting by Lummoxx · · Score: 3, Interesting

      What benefit do you gain from 3 layers of NAT and 2 proxies other than a ton of lag? A single well configured version of each should surely be sufficient.

      Just taking a swag at it...


      Home network
      Corporate network, likely main corporate domain and/or remote access point.
      Corporate subnet, likely his corporate sub-domain.

      That's easily 3 NAT's and a couple proxies, only the first under his control.

      Am I close?

      --

      I am a viral sig. Please copy me and help me spread. Thank you.

    23. Re:The problem isn't telecommuting by fisternipply · · Score: 2, Interesting

      Only works if you have a network connection. When you're working on, say, a construction site in the early stages, with a very mobile workforce, it's a little tough to use the VPN. And a cellphone modem doesn't work very well three stories underground.

    24. Re:The problem isn't telecommuting by saskboy · · Score: 3, Funny

      Haven't you heard of the Onion Layer in network security?
      It's security that makes people cry, especially when a part is cut out of it with a knife.

      --
      Saskboy's blog is good. 9 out of 10 dentists agree.
    25. Re:The problem isn't telecommuting by complete+loony · · Score: 4, Funny

      Oh crap, I shouldn't have said he's a customer.
      Oh crap, I shouldn't have said it's a secret.
      Oh crap, I definately shouldn't have said it's illegal.

      --
      09F91102 no, 455FE104 nope, F190A1E8 uh-uh, 7A5F8A09 that's not it, C87294CE no. Ah! 452F6E403CDF10714E41DFAA257D313F.
    26. Re:The problem isn't telecommuting by zippthorne · · Score: 3, Funny

      Based on what experience do you believe UN inspectors capable of finding uranium?

      --
      Can you be Even More Awesome?!
    27. Re:The problem isn't telecommuting by colmore · · Score: 5, Insightful

      The headlines should read: MegaCorp loses notebook with customer data on it. Company issues this statement: "This is a non-issue, the notebook was encrypted with a system that meets XYZ standard, it will take no less than 200 years for the system to be cracked."

      Oops, the laptop that was stolen had the PGP password written on a post-it-note. Or it was the guys' daughters' college fund account number. Or they were logged in while working at a coffee shop, got up to use the bathroom, and came back to an empty table. Or a corporate spy stole it once, put on a keylogger, and then steals it again. Ask the police how private your fingerprints are. Does your boss put retina scanners on all company laptops? Can you be sure that nobody with data access would be dumb enough to keep any of that info on their USB drive or a CDR? Are you using strong crypt on your swap space? What do your bosses do to make 100% sure that nobody is printing out information on their home deskjet and leaving the printouts in the recycle bin on thursday morning? Are you so sure that there aren't moles in your office that you'll let a billion dollars juts walk out the front door? If your data is really as valuable as you say it is, then you need to have the working assumption that someone out there is going to pull some James Bond style shit to get at it, they're not going to stop at "aw shucks, they *encrypted* it!" A password is relatively easy to bribe someone out of. If they never have to show up on site to access the data, then that's all they'll ever need.

      When your data is valuable enough that people would REALLY want to steal it, people, not protocols and passwords, are the big problem. When you let people just walk out of your office with company secrets, you're not just increasing the size of the problem, you're adding entire DIMENSIONS to it. People get lazy about things that they have to do every day. Lab Chemists and Biologists have horrible cancer incidence rates because they eventually get lax with safety procedures, even though they know better than anyone on the planet how dangerous what they're doing is. The human brain is set up in such a way that something it encounters every day without visible harm stops registering as "threat" pretty fast. No matter how rigorously you try to follow standard XYZ at the office, people will get lazy when they're looking over some work in front of the TV.

      --
      In Capitalist America, bank robs you!
    28. Re:The problem isn't telecommuting by supersnail · · Score: 2, Insightful

      The main point to be made here is that you do not store sensitive data in a location which is not physicaly secure. Not a home office , not a desktop machine anywhere and certainly not a laptop. But in a locked and secure server room. Also if you want a secure environment -- disable your companies desktop USB ports:- http://www.schneier.com/crypto-gram-0606.html#6

      --
      Old COBOL programmers never die. They just code in C.
    29. Re:The problem isn't telecommuting by RahoulB · · Score: 2, Funny

      Call Larry Ellison - it's a network computer!

    30. Re:The problem isn't telecommuting by CrazedWalrus · · Score: 2, Interesting

      Or alternately, I can't imagine that the personnell retention rate of those security firms is very good: doesn't seem like it would be very hard to get someone on the inside to help you out a little bit.

      It also probably wouldn't be hard to get a mole onto one of these security teams. Like you said, they don't have any special training coming in (military, police, etc). They're just department store types, and I can't imagine that the qualifications are much more than department store qualifications -- including simple "lack of criminal record".

      For organized crime, I'm sure a little identity theft wouldn't be beyond them. John Smith steals Arthur Dent's papers, gets the job, and the police knock on Arthur's door when they realize it was an inside job.

      Seems pretty basic to me.

    31. Re:The problem isn't telecommuting by thePowerOfGrayskull · · Score: 2, Interesting

      Similar to what we have. Cisco VPN, connected to terminal server, terminal server. Cut, paste, and print disabled. External network (including home LAN) and local hard drive access disabled while connected to the VPN. Traffic between your PC and the VPN is encrypted. There's presently no way to get data from the corporate network to your home PC, and thus no risk of data loss. While there are holes in it, you need to look hard for them. They aren't the kind any user will stumble across accidentally or via stupidity.

      On the other hand, people with corporate laptops don't have the same restrictions, and many people are perfectly able to use a USB key fob into their work PCs. These kinds of oversights defeat the purpose...

  2. Backlash for security? by DarthParadox · · Score: 4, Insightful

    Telecommuting isn't the problem. Ineffective security policies are.

    It's possible to set up secure connections between a telecommuter's computer and a secure server. Encrypted tunnels for VPN or something like that. Encrypt data on the laptop hard drive - if you even permit sensitive data to be stored there at all.

    But until government and corporations are seriously committed to taking the measures necessary to keep private data secure, incidents like this will keep happening, whether it's due to a stolen telecommuting laptop or a server that gets broken into.

  3. What finger pointing? by NineNine · · Score: 3, Interesting

    I read the whole article, and I couldn't find any instance of "finger pointing" by companies, the press, or the government. Who, exactly, is pointing fingers? This sounds like an article about a non-issue, if you ask me. I understand that many telecommuters want to continue telecommuting, but the article provides no information as to who this nebulous group of "finger pointers" are, or even if they really exist.

  4. the article says it all! by dan+dan+the+dna+man · · Score: 5, Insightful

    "The analyst whose laptop was stolen from his house was not a teleworker, just someone who took work home with him."

    On what grounds are you going to detract from telecommuting in that statement? Every worker I know a)has a latop and b)moves it around. I don't think any of us would call ourselves telecommuters in any sense of the word. The fact we take work home, on 'theivable' media isn't an argument against telecommuting, it's an argument for us not taking work home!

    I know there are telecommuters on /., but everyone I know, even in the IT industry has to go and show some flesh at a physical location to get paid. I'd love to telecommute but to be honest, it's mostly impractical for most people who have to engage with humans to get their job done effectively.

    The next question for me is, who is this backlash against?

    --
    I don't read your sig, why do you read mine?
    1. Re:the article says it all! by rthille · · Score: 2, Insightful

      The 'best' job I ever had was when I worked for a military contractor. I got paid overtime, I _never_ had to (couldn't) take work home.

      Of course the pay wasn't great and the work wasn't interesting, but my evenings and weekends were my own...

      --
      Awesome furniture, accessories and cabinetry in Santa Rosa, CA: http://humanity-home.com/
  5. Telecommuting by Badgerman · · Score: 4, Insightful

    Interesting article. It pretty much notes what's being said here - good telework requires good policies, good enforcement, and good planning.

    In my last job I telecommuted for a good 3-5 months until I left. The company had excellent policies and security. There wasn't a single reported incident of data theft from our division in the two-and-a-half years I was there. I was definitely more productive, and I was also better able to plan around illness, holidays, and emegencies.

    It's all about good policy. A company without telecommuters is still insecure if it has a crap IT Risk policy.

    --
    "The Sage treasures Unity and measures all things by it" - Lao Tzu
  6. VPN in / Tunnel in.. use Treminal Servers!!! by Wingfat · · Score: 3, Insightful

    Why cant these compaines use Term Server? it would then be a bit more on the secure side, at least that way you dont have dumb people taking their lap top home with personal data on it. I actually work as IT for a sub division of Bank of the West, we do not allow our users to have ANY borrower/customer data saved on their local machine. if they do they can be let go quicker then you can say "i didnt mean to save it on my desk top" some of the managers here can "telecommute" in. if they would let the loan processors here do that too, then we could close half of the office and save the company on rental costs energy costs and much much more. Plus not to mention the gas saved for the peopele that could work from home. I think with the gas the way it is, more companies should encourage their employees to stay at home.

  7. It can happen in an office building to by joshv · · Score: 4, Insightful

    I had a laptop stolen in a secured office building. Each floor required a badge, as did the lobby. A laptop at home is no more or less safe than a laptop at work. In fact, my house is probably harder to break in to than most office buildings.

  8. The real problem by Chysn · · Score: 3, Funny

    You know what the REAL problem with telecommuting is? It's kids. There you are, sitting at home, trying to set apart work from nonwork, but the kids know you're in the house. They want to play, and they're just so cute and irrisistible.

    --
    --I'm so big, my sig has its own sig.
    -- See?
    1. Re:The real problem by dhasenan · · Score: 2, Funny

      A handful of strychnine will solve that, albeit in a somewhat unpleasant manner.

  9. hogwash! That is a security issue, not slave issue by v3xt0r · · Score: 3, Insightful

    This is not the fault of telecommuting, although tyranical bosses who hate telecommutors will blame telecommuting (so they can chain you to your cubicle and bark orders and breath down your neck), when the reality is... accountability in the IT/Network Security dept.

    I telecommute from around the world and work directly off machines via SSH, so even if my laptop is stolen, nothing confidential or work-related can be compromised.

    Of coarse, if you're IT/Network security policies allow telecommuters to actually work ON their own hd's, then that is your fault for having a flawed IT/Network security policy.

    Either way, this is FUD for anti-telecommutism.

    --
    the only permanence in existence, is the impermanence of existence.
  10. security issues aside... by papasui · · Score: 4, Insightful

    One thing I personally feel is you don't develop a bond with your co-workers if you don't see them face to face. I'm a network engineer for a large fortune 500, I have a company laptop with VPN software that I can use to work from home if I want. Occasionally I do, especially if I need to watch a sick child but still want to get some work done. Otherwise I try to go into my office and be present for face to face meetings whenever possible. My direct boss lives and works 300 miles from my office and I rarely see him, maybe 6 times a year. We talk over the phone and email frequently but we don't have the kind of boss/employee relationship that I've had in the past. Very hard to feel comfortable working/trusting other people when they seem almost like strangers to you.

    1. Re:security issues aside... by inKubus · · Score: 4, Insightful

      Well, bonds are good. But so is working without distractions. For a coder or programmer, being at home is probably the best environment. No one cares about the lack of shower that leads to grease level 6 where the real work gets done. Maybe the nut cheese vapors have some sort of nootropic effect.

      Anyway, I think the best thing is a good mix of tele and in the office work. For me, I like to tele in the morning from home where I have my dual monitors, my espresso maker, my clean air, etc. It allows me to work solid in the morning right after getting up until I start to lose focus. I'm usually at my highest focus right after waking up. If I waste that time showering and driving, I'll just sit around at work.

      So I work in the morning from home and when the focus starts to fade I save all and sync up, and then go shower and commute. I spend about the same amount of hours working but FEWER hours in the car, etc. becuase the traffic is lighter at 10:30 than at 7:30. Plus there's fuel savings, etc. And I don't have to go in every day--sometimes you get on a roll and don't need to go to the office to stay motivated to work.

      There are some jobs that need you to be there: anything physical obviously (factory worker, garbageman, etc.). In my opinion, most meetings are bullshit though. Sending an email is usually enough to get it across. But I think some people need meetings to make them feel like they are part of a family. I'm like a hitman, a contractor, BOFH style, so I just do what I do.

      What really bugs me is when I get PICNIC calls from the office (usually the same couple of people) who demand I come in and make their computer run faster or reconnect the cable they kicked out of the wall. Oh well, I bill extra for those.

      --
      Cool! Amazing Toys.
    2. Re:security issues aside... by RedWizzard · · Score: 2, Interesting
      One thing I personally feel is you don't develop a bond with your co-workers if you don't see them face to face. ... My direct boss lives and works 300 miles from my office and I rarely see him, maybe 6 times a year. We talk over the phone and email frequently but we don't have the kind of boss/employee relationship that I've had in the past. Very hard to feel comfortable working/trusting other people when they seem almost like strangers to you.
      I think it's got more to do with the people involved. I've had great working relationships with people who work in offices in other countries and who I've only met in person a couple of times.
    3. Re:security issues aside... by papasui · · Score: 3, Interesting

      One thing I notice is it allows people who don't volunteer to fade in the background... Guy I work with has the same title as me (network engineer) but has been doing it for 5 years longer and actually reports to another network engineer who then reports to my boss (if that makes sense). He doesn't volunteer to take projects so people forget about him and don't offer him projects. It really requires you to make an effot to be noticed. That said it's working ok for me but I make an effort to try and make contact with my boss every other day.

  11. Questioning a basic assumptions by putigger · · Score: 4, Insightful

    I don't see anyone asking the question: "what effect does telecommuting have on productivity?" I work in the R&D arm of a major multinational corporation and the projects I work on are highly collaborative. I can often accomplish more in 15-30 minutes of face-to-face conversation with a colleague than in an hour or more over the phone or video conference, even with fancy collaboration tools like Lotus Sametime and Microsoft NetMeeting.

    1. Re:Questioning a basic assumptions by gvc · · Score: 3, Insightful

      Depends on what you're doing, your corporate culture, and how independent the workers are.

      Face-to-face can be a big waste of time. Meetings, water cooler chat, and so on tend to be more exercises in shoulder rubbing than productivity. They may increase or decrease employees' effectiveness.

      I totally agree that high-tech tools are a waste of time. Email is great when the rubber hits the road, phone calls are fine for brainstorming, and conference calls with a shared spreadsheet or ppt presentation or whatever are just fine for meetings.

      The real issue with telecommuting is the tendency -- perceived or real -- to goof off. So I guess if you're running a sweatshop, it is bad; if you're running an operation with employees who are mature and motivated to see the operation succeed, telecommuting can be good.

    2. Re:Questioning a basic assumptions by mswhippingboy · · Score: 3, Interesting

      Of course how effective you can be as a telecommuter depends on your profession. I work in IT and have been working 100% telecommute for about 7 years and it has worked out just fine. I can get a lot more done with email and phone than I ever could with face-to-face meetings. I can put my thoughts together concisely in an email and avoid the smalltalk. I can also keep working while I'm listening in on a conference call (thanks to the mute button) and multitask more than one project at a time. It's not uncommon for me to work on a project with the project leader in Arkasas, the DBA in Missippi, the customer in Texas and the data center in Louisianna so the work environment is disparate anyway. Face-to-face is fine and beneficial for gaining the comfort level of the employer, but if you can gain their trust with solid results it really makes no difference. As a bonus, I'm able to charge cheaper rates because I don't have a lot on travel expenses.

      --
      Sometimes the light at the end of the tunnel is the headlight of an oncoming train.
  12. Telecommuting is a cornerstone of geek culture... by Ingolfke · · Score: 4, Funny

    Without it... many geeks, particularly on this site, will be forced to bathe, work, and not "work" while watching ESPN, anime, or porn. The attack against telecommuting is the cultural eradication of the information age.

  13. Oh yeah, the VA loss was just an accident... by MikeRT · · Score: 3, Insightful

    What are the odds that the weekend he'd take a dump of the records of 26M veterans home would be the weekend he got robbed? Someone better get the FBI on this guy's ass because he's probably got a fat Swiss bank account waiting for him after he loses his job and does a little time in the pokey. What a great coincidence that the time he takes the motherload of personal information home is the time he is the victim of a little "smash and grab..."

    1. Re:Oh yeah, the VA loss was just an accident... by ipfwadm · · Score: 4, Informative
      What are the odds that the weekend he'd take a dump of the records of 26M veterans home would be the weekend he got robbed?

      Insightful, eh? How about "uninformed".

      From MSNBC:
      The agency has acknowledged that the longtime midlevel employee -- who has since been fired -- improperly took the information home on an unsecured personal laptop for three years, apparently without his supervisor's knowledge.
      So no, this wasn't just "dumb luck". It was an accident waiting to happen.
  14. Giving up on telecommuting by Anonymous Coward · · Score: 5, Interesting

    Ive been telecommuting for over 5 years now and Im about to give up.
    People are resistant on working in ways to accomodate telelcommuting. People will wait for me to visit the office..even if thats many weeks - rather than pick up the phone.
    I also find that when people want to play politics - you are at a severe disadvantage when telecomuting.
    Every time management changes you have to reconvince them its viable and I have decided over all that
    Thats despite the fact that I work in an IT department for a large vibrant and successful company that prides itself on its forward thinking.
      So after 5 years - Im giving up - not for technical reasons.. which I have been able to manage one way or another - but because the culture - even in IT is just not accepting of telecommuters and in fact disdvantages them.

  15. Not an excuse to take private customer info home by Eric+Smith · · Score: 3, Insightful

    There's no good reason why a laptop taken home needs to have private information about customers/patients/clients/etc. on it. The customer data can be kept on an enterprise database server that is less susceptible to theft or to being accessed from insecure networks. The telecommuting employees can access the data remotely via an encrypted VPN, or use Windows Terminal Services, VNC, SSH, or the like over the VPN.

  16. Telecommuting is not a slam dunk by pedleyj · · Score: 4, Insightful

    The backlash against telecommuting is not just security related - it's cultural. How can an organization stay fresh and bring on new people who can learn from mentors and rapidly come up the learning curve if all the senior engineers are tucked up at home coding in their PJs? How will that organization build a culture, build commitment, build team spirit? There have to be some limits or a company will stagnate. security issues can easily be handled with better technology over time but I don't think the cultural ones are so easily dealt with.

    1. Re:Telecommuting is not a slam dunk by jasonditz · · Score: 2, Interesting

      They develop culture the same way sites like slashdot develop their own unique cultures... they build commitment by hiring committed individuals.

      As a telecommuter working for an organization composed largely of telecommuters, I can safely say it's not for everyone. But at the same time... disgusting, Office Space-esque cubicle culture... that's not for everyone either.

      I live a thousand miles away from any of my co-workers. I've never met anyone in my company. We communicate by phone, by email, by IM... and it just works. Sure, we don't have a company softball team that way, but we also don't have all the bullshit office politics I've heard some people who work outside the home talk about.

      I know people who've done the telecommuting thing and hated it, and couldn't wait to get out of it. For me though, I'm never going to work outside the home again if I can help it.

  17. If you can telecommute... by Anonymous Coward · · Score: 2, Insightful

    Think twice before pushing telecommuting to your boss, people. If you can telecommute from the other side of town and do your job effectively, someone from India or China can do it frm the other side of the planet, and for a lot less money. If there's an easier way to mark your position with a flashing neon "OUTSOURCE ME!" sign, I haven't heard of it...

  18. my company is safe: telecommuting is banned by Anonymous Coward · · Score: 2, Interesting

    The first time my company allowed workers to telecommute, they apparently had some folks who took that to mean they could loaf and not actually, you know, work.

    Some people got fired and management adopted a very strong but unwritten policy that telecommuting was completely disallowed. The telecommuting fallout had happened a couple years before I started working there but management was stil upset by the time I was hired. I learned the hard way when I had to come to work three times in the middle of an ice storm that should have allowed for some flexible remote working. No way.

    The irony is that the regular workers who show up in person at the office spend a lot of the day loafing around, playing computer games, surfing, wandering from cube to cube chatting, and generally not doing, you know, work. Management sees it but doesn't do much about it. But do this on company time where they can't see it? ouch.

  19. "Telework" is entirely implicated in the VA case by csoto · · Score: 4, Insightful

    "Telecommuting" means working away from the normal office environment. This guy was a "teleworker." Sure, he isn't NORMALLY a teleworker (e.g. he usually works out of the office). But he took work home. He was telecommuting. There would have been little chance of this data being stolen had he not "telecommuted."

    Telecommuting has drawbacks. The number one issue is that the home is not usually a good environment for work. This includes issues of safety and data security. Operations are at risk if you do not take sufficient precautions.

    One interesting solution to this is thin client computing. I've experimented with Sun Ray thin clients that connect over a broadband connection back to a server. No data is stored on the thin client. All it really transmits is pixels and keyboard and mouse clicks (encrypted, too). That's the right way to approach this. Never store data away from the people paid to protect it (then make sure those people do a good job).

    --
    There exists no way of exchanging information without making judgments. --Bene Gesserit Axiom
  20. Think of the rainforest by robertjw · · Score: 4, Interesting

    Really, what is more important, saving the planet or a few million VA records. I think the number one reason to support telecommuting is so people can live in the area of their choosing and still earn a decent wage. Commuting is wasteful of both time and energy. I can't believe the sierra club and greenpeace don't push telecommuting more.

  21. Re:Deserve what they get? by rahrens · · Score: 4, Informative

    Actually, IIRC, the telecommuter's boss and his boss both got dinged, too.

    Don't make light of this, a number of people got really badly in trouble over this. As a measure of how seriously the gov't takes the situation, it is rare for any civil servant to actually get fired. In spite of the reforms of Jimmy Carter's days, it is still difficult to fire gov't employees. You'd better have your 'i's dotted and the t's crossed, too! Upper management hates to go that far, especially if the employee has over ten years in, and I think this guy had 11 or 12. Get fired like that, and you lose your pension and everything. So if they fired this guy, it's serious.

    I work for another Department, and we take security very serious. ALL agency laptops are installed with a standard image using Ghost, an image that uses Pointsec to encrypt the entire hard drive. Yes, we take a performance hit, but to safeguard data, it's worth it. Users have no choice. It is installed before they get it, and when they are issued the unit, they are given the opportunity to set the password (at least 8 digits). If they forget it, they are told, the HD is toast, and must be reformatted. (not really, there are admin PWs we can use, but that makes them MUCH more careful!) They are warned not to store data on the HD, cause if the OS develops a problem, all we'll do is reimage it. We use an elaborate VPN system, with tokens, to allow employees to remotely connect. They don't need to keep data locally, and it is discouraged. With our setup, a lost laptop is just a lost item; a thief would have to reformat the HD to use the laptop. Our data is not accessable.

    --
    "Money is truthful. If a man speaks of his honor, make him pay cash." Notebooks of Lazarus Long, Robert A. Heinlein
  22. We'll show those telecommuters...OFFSHORE!!! by kimanaw · · Score: 2, Insightful

    So those uppity geeks think they can sit at home on their tender pimpled asses and draw a paycheck ? Taking our sensitive data home ? Workin in pajamas ? We'll show 'em! We'll send our data and IP to the other side of the planet to folks we've never met, where our laws don't mean squat...and we'll save massive bucks to boot! Yep, that'll larn 'em...

    </irony>

    --
    007: "Who are you?"
    Pussy: "My name is Pussy Galore."
    007: "I must be dreaming..."
  23. This is not about telecommuting by HangingChad · · Score: 3, Insightful

    It's about walking around, in any circumstance, with megs of sensitive information on a portable device that isn't encrypted. Whether it's a desktop, laptop, USB device, external hard drive, PDA, cell phone or iPod. It's really about non-existent data security policies, data security audits of vendors handling sensitive customer and employee data and, above all, it's about no accountability in government or private industry for mishandling sensitive information.

    When companies are liable for millions in damages for lost privacy act data, you'll see change bordering on a religious revival. Until then, it's just the masses whining.

    --
    That's our life, the big wheel of shit. - The Fat Man, Blue Tango Salvage
  24. Use the BUILT IN stuff in your laptop by JFilz · · Score: 4, Informative

    I work at a place where I deal with or work with Telecommuter and is quite the norm. Of these MOST of these people are only part-time telecommuters.

    What I don't understand is why people are not the built in features of laptops - ANY NEWER Laptops have a Power on password. Many newer ones even have HARD DRIVE passwords (so you can't swap out the drive to use it on another PC). Some even are coming with THUMB readers. Prevent thiefs - ALL laptops have docking stations or cable slots where it can be LOCKED down. If not locked down and not in use then put it in to a LOCKED cabinet. Also to NOT have it in the open cab of car (put it in the trunk - for the smash grab and dash thiefs) - also not good if it hits you in the back of the head in an accident..... Use a BREIFCASE or BACKPACK or CARYBAG that does not scream "I GOT A LAPTOP FOR YOU TO STEAL!" (these are all actual policies where I work).

    Also you can secure your Email by always accessed it via VPN and by using IMAP based or HTTPS web based (and/or require RSA token access). Any Local "copy" in the email client is encrypted (We use PGP? or such). I don't telecommute - but I personally only use IMAP (when at work) or WEB BASED email clients (ie: Squirrelmail and such) for the last 12+ years. No chance if SOMEONE steals my PC and tries to look at my MAIL - I don't even have a PC based mail client (no spam bot using POP3 on MY email account - unless they use there own client-but then I have that port BLOCKED on my personal firewall). In 12 years I have not got infected by even ONE virus by email (I get a "hit" every couple of weeks with one - but getting fewer)...My ex-wife however insist on using a pop3 client and has gotten infected many times.

    Also setup most business applications such they can be used via VPN and a local client or has a web based interface and/or Citrix/Termial Services or VMWare or such. Also provide Backup space on their servers for your "EXCEL" and "WORD" type of documents. A hot sync Software tool make this easy.

    One big thing is adopting a software policy - ONLY install APPROVED software on any BUSINESS PC - no personal software or "free downloads" or demos. As well only approved "accessories" may be attached/used (ie: Thumb Drives and External drives etc). And by approved - I mean not by some "know nothing" boss or supervisor - but approved by IT and/or management who is in touch with what is acceptable and is safe to use. After all this is not your personal PC but own by your employer's. (like the "scattered" or "found" USB drives that was used at one BANK location - most was picked and pluged into the BANKS PCs by there own employees.)

    Where I work they also PUSH all virus/spam/firewall and security fixes so your always up to date. They also adopted a PASSWORD policy where you have to change password often and not duplicated etc....

    With a GOOD policy and ENFORCING it to protect everyone's butt and with a bit of free software and/or a bit of spending of money/time - a Stolen Laptop could means little to NOTHING in impacting a business - with the biggest being the replacement cost of the laptop and going though and wiping out and resetting any and all of the user's passwords (in case people "keep" a list of passwords on the PC or use "auto complete" or other password reminder tools....) and yes I now there is secure "password" tools out there that would be hard to defeat - at lease before they able to crack/hack it to it - you should have all you password reset.

    A stolen laptop that causes problems for a business - they had set them selves up for failure to begin with - however the one of the WEEKEST parts is the employee them selves. It costs very little to make a POLICY, and to make minor changes in how people use there PC. Just remember to enforce it (MANUALLY spot checking if you have to - even "leak" out a rumor that it will happen before you do - I can just hear the hard drives going crazy when that gets around....), if you don't - a policy on paper means zilch (nothing) if people are not following it.

  25. everybody? by alizard · · Score: 2, Interesting

    I've been writing IT articles since 1987. In those 19 years, I've visited my publisher's office exactly once and I've met exactly one of the editors I've worked for.

  26. Re:"Telework" is entirely implicated in the VA cas by solitas · · Score: 2, Interesting

    I can remember the only time a company let me telecommute: I broke one leg, the other knee, and shattered a hip in a car accident, and they gave me an LA-36 Decwriter II, an acoustic-coupler(!) modem, had an extra phone line put in during my convalescence, and whenever I needed paper or ribbon I had them the next morning.

    "Encryption", as such, consisted of mixing-up the data lines on the parallel-side(s) of the UARTs (8!=40320, back then they thought _that_ was hot sh*t; but I thought that was a pain in the *ss because I could only talk to the one modem at work and nothing else).

    Good times though (except for the medical).

    --
    "It's time to take life by the cans." ~ Bender ("Bendin' in the Wind", ep. 3-13)
  27. Re:hogwash! That is a security issue, not slave is by lotrtrotk · · Score: 2, Insightful

    ORRR.... The problem is having a flawed Corporate Management who will not supply the IT/Network group with the proper resources (budget/training/personnel) to IMPLEMENT proper IT/Network Security policies.

  28. The guy wasn't even supose to have the data by jpferry · · Score: 2, Informative

    This was not a telecommuting problem at all! This guy was not even supose to have the data on his laptop in the first place! He violated policies by taking the data home on his laptop Go back and reread the stories about what happened.

  29. There is none. by Kadin2048 · · Score: 2, Informative

    Shhhh, you're destroying the manufactured controversy.

    In reality, nobody is pointing fingers at telecommuters -- in fact, in the incidents that I've heard in the news lately, there wasn't any real "telecommuting" going on. Somebody just copied an assload of data off of the server to their local machine, and then took the machine home with them. I'd call that 'working from home,' not 'telecommuting.' And the copying of the data onto the local machine was just inappropriate to begin with. That's mostly a user-training issue and not a technological one.

    Sure, there are measures that could have been put in place to allow the behavior to happen without creating such a huge problem in the event the laptop was stolen: the drive could have been encrypted, etc. But ultimately, if you don't train your employees to follow the security procedures, there are always going to be problems. (Use encrypted HDs and don't tell people not to use USB sticks, you're going to get data loss. Say 'no USB sticks,' and they'll use CD-RWs. Or email. Or whatever. My point is, the problem at that point is not technology, but your users.)

    I doubt that the data loss events will cause anyone who's legitimately telecommuting or even working from home to do anything differently. The only thing it should do is serve as a wake-up call to managers who are allowing employees to do things that they're not really supposed to do (like take large amounts of sensitive data home with them). In the long run, it'll probably make the new encryption features in Win Vista more popular, but that's neither here nor there.

    All in all, I think the controversy was manufactured. It was obvious enough to anyone watching on CNN that the fault of the VA incident lay with the employee who took the data home on the laptop when they weren't supposed to; it wasn't a failure of some telework scheme, just user error / bad judgement.

    --
    "Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
  30. Oh well. by rmadmin · · Score: 2, Interesting

    This is very interesting to me. I work for a company that provides financial software. Our security is almost non-existant. I'm about the only person who could impliment any serious security, but it has been put to the bottom of my priority list by the boss. Makes me sick sometimes. Anyone that has worked for our company, or even one of our customer's companies, could EASILY rip someone off pretty bad. Not to mention completely fubar a load of businesses in one shot.

    Maybe I should force feed some of these articles to my boss. :)

  31. Outsourcing services by Aceticon · · Score: 2, Insightful

    Actually outsourcing of services is just the natural extension of telecommuting: stuff that can be done remotelly for $X hour by somebody a couple of miles away can just as easilly be done for $Y hour (were Y < X) by somebody thousands of miles away.

    In other words, anything that can be done remotelly is just as suitable for telecommuting as it is for outsourcing, since in it's simplest form outsourcing is just having your workers telecommute from a far place.

    The point here is that anything that does not require the worker to be physically onsite always or often will end up being outsourced and that the great telecommuting revolution that some still seem to expecting has already been overtaken by the even greater outsourcing revolution - forget about working from a paradisian island for western wages, at this point the best one can aim for is telecommuting a couple of days a week.

  32. The problem is often bad telecommuters. by AugstWest · · Score: 3, Insightful

    I've been told by many managers that they've tried it, and people just flat-out blow off work when they're home, and productivity drops.

    I've had several jobs now where telecommuting wasn't allowed at all, by company policy.

    Every once in a while I would have an "emergency," like a repair on the house, or a delivery of furniture, or whatever, and I would tell my boss that I would have to be at home, but that I would still be working. One time it was a Unix admin position, so it could be done from anywhere, especially since many of the servers were colocated or managed. Another time it was doing technical support for java deveopment teams for a major Swiss bank.

    So you tell your boss that you can't be in the office anyway, so you'll do some work from home. Then, while you're home, kick ass. Get tons of stuff done. Most people in an office kick back and do the minimum amount of required work, so it isn't hard to show how productive you can be when working from home. Do it off and on, maybe when you're sick, maybe when you have a child emergency, whatever, but if you can come up with a legitimate excuse to be home, take it, and work your ass off.

    A lot of times your manager will see that you're a very productive worker, and through some simple tactics you can work out a situation where you can increasingly avoid having to commute. I had an hour and a half train commute each way to the swiss bank gig, so it was worth doing some extra work to be able to sleep an extra hour and a half on occasion, and even if I worked an extra half hour at night, I was still done with work and home an hour earlier.