I'm more surprised Amazon (or any company, really) employees using an employer-managed device would have TikTok on them to start with, to be honest.
As the follow-up tweet says: "Completely independent of the specifics in this instance: get a second device before installing an employer's config profile on your personal device"
Does Amazon provide company phones or just install an MDM profile on your personal phone? I have TikTok installed on my phone, and if my employer said I had to remove it to access my work email, I'd ask them to buy me a work phone. It seems a bit ridiculous that they'd want to control what apps you download on your personal device without providing an alternative.
No, they are controlling the environment under which their company emails can be accessed.
If you, as an employee, don't want to remove TikTok I believe you will have that right, it's just that you won't be able to access company emails from that device.
Now, whether or not that leads to a company phone or you having to look for another job, depends on the individual and how important that individual is to the company.
If any company expects me to access my work email while mobile, they have to provide a phone. I never mix work and personal. I've also never had a company say no to that.
Adding another anecdote, when I said I did not want to let work control my mobile phone, my boss told me I could figure out whether I wanted to keep the job or not
Perhaps when I was younger I would, and did, switch jobs immediately when something like that came up. I've gotten older and the cost of switching jobs is not zero for me anymore
I agree with my co-commenter. At least in Germany your employer isn't allowed to do this. They must provide the means to do your work, if they have specific requirements (having a mobile phone, being reachable, accessing company email and so on).
Well I am commenting from America and there is very little they cant do unless they go out of their way to officially state they are doing it for an illegal reason
Depends on the jurisdiction. In Germany they do. Labor rights explicitly says that your employer needs to provide the means for you to do your work. And that includes mobile phones if they want you to access your work email (or whatever) from a mobile device.
Yes they do... The problem is some users in Germany actually prefer to use their personal one so they don't have to carry two.. But due to this mindset they can't.
I don't think the German approach is always the best.
Sorry for the late reply. I use only one. I have a dual SIM phone with a clear separation.
So I call private contacts from private SIM, business contacts from business SIM. I have Apps separated into business and private and the respective profiles are in place. Business partition (so to speak) is managed by employer. Private partition is MDMed by myself.
So I have both worlds - in one device. If my employer decides to delete the business partition. I have exactly no problem with that (we tested it and it worked like a charm - private data wasn't affected. We also tested access to private data being nil).
That framing is the exact point. I'm in the same boat. If my employer mandated that I not be able to use a personal device the way i want, a device I bought with wages i earned from working with my employer, the employer really SHOULD provide a cost free alternative.
It falls under the category of providing your own resources to do your job, and that territory enters socioeconomic discrimination territory real quick.
I might be with you if Uber, say, is requiring its drivers to install MDM--which I'm guessing would be a really bad idea for their drivers-not-employees position.
But for engineers and other office workers at tech companies?
As a practical matter, people have to buy lots of things to do professional jobs that they wouldn't need to buy without those jobs. In this day and age, if you want a second phone, buying a few year old phone is cheap as is adding another phone to your existing cellular account in most cases.
Wasnt there a recent supreme court ruling regarding the Native Americans of Oklahoma that said something to the effect of 'just because you keep doing an evil, doesnt make it right, and letting it be right is an injustice to those in the right'?
You have to dress into the office—albeit many don’t wear suits any longer. Many have to drive. Those who travel a lot need many accessories for the purpose. The ideas that well-paid professionals should have all these things covered by a company seems... unreasonable.
And, seriously, complaining about having to spend a few bucks for something you need at work is equivalent to circumstances around Indian treaties in the US?
It's rude to ridicule another's opinion online when they are discussing in good faith. Present data, differ in opinion, but don't ridicule. It's below you.
There's also no requirement to have your business email on your phone, at least in my organization in Amazon. I'm happy to leave it off and not worry about any issues like this.
Of course I do have other apps directly related to work... I guess those aren't an issue if I had TikTok?
When I worked at Google over 5 years ago, mobile device options for accessing company accounts were a company-provided and company-owned device with a company-paid phone bill, a personal device with company-provided mobile device management (and sometimes cell phone bill expensing if you for example had on-call duties), a personal device with only limited browser-based work account access, and no account access via mobile.
The first of these could sometimes have implications for ownership of personal projects created using the device, which was one of many reasons I picked the second option, but it was absolutely permitted at least for any case where the company cared about you having mobile account access.
The third option - accessing only browser sites - is under appreciated. I never needed to install Google's MDM on my mobile devices, I just used mobile web gmail and so forth. It's great, honestly, and the mobile web Calendar has the advantage that it doesn't destroy your battery life like the Calendar app will.
I even saw a guy using the code review site on his mobile, on BART. That was dumb from the standpoint of infosec, usability, and mental health, but shows how much is possible in the browser.
Part of me thinks that MDM on employee phones has become a something of a checkbox item because customers ask for it but it's not clear to what extent it really protects sensitive customer data (which is what they're concerned about).
Like most normal people I have no idea what PCI DSS requires. All I know is what the PCI compliance inquisitor says it says, or really what my risk management guy says the compliance guy says it says. And what’s the difference? If he says he says it says we have to have MDM on BYOD, it’s not like I’m going to write a first-principles rebuttal.
Having the code review app available outside of the corp network / VPN is pretty unusual, at least for shops who aren't just using SaaS services that are available publicly anyway (github, gitlab.com, etc).
Nowadays, at least on Android (though I think iOS has something similar now?), one can have a work profile, and the employer can only control activity in / monitor / wipe that profile. Most employers have switched to that for personal devices.
With all the security implications there could be, I would just refuse to use or own a smartphone in any capacity if it's related to work, unless there was no camera, mic, or GPS sensor (or they could provide hardware switches).
Seriously, they could be logging your exact location, remotely activating the camera or doing any number of disgusting things.
Requiring the use of a spy should not be a factor in an employment setting, of course we're seeing this is the case and it is very offputting.
Thankfully not something I need to worry about though.
Apples iOS MDM framework is exemplary in that regard. Access to the camera is not possible. Access to GPS is only possible if the device is marked as lost, which will visibly change the lock screen. Even when lost mode is deactivated, GPS access that happened during lost mode is highly visibly marked on the lock screen.
Installing an app that relays GPS and camera may be possible, but permissions need to be granted by the user explicitly- the MDM server cannot grant those permissions.
I don't think Apple is the best at this. Yes they limit the things you mention, but they don't limit visibility to things like the app list... This can already be quite revealing in some cases.
Google has in my opinion the better approach with work profile. Only give the MDM control and visibility over the work area and nothing else.
Apple has started heading into this direction with User Enrolment but it's not sufficient for most companies as it only allows built-in apps to be used for both work and personal data. And it requires Apple account federation which is problematic.
Amazon has MDM (Airwatch). AFAIK there are not generally company phones or phone plans. Monthly limit on reimbursement for phone business expenditures in the US is $50, although I think you can also expense the device itself.
> Does Amazon provide company phones or just install an MDM profile on your personal phone?
> Microsoft does the latter, so it wouldn't surprise me if Amazon does likewise.
Not true (source: current MSFT employee). More detailed explanation below, as neither former nor latter describes MSFT accurately.
So, for most teams and positions (there are many exceptions), you don't get a dedicated work phone. So yeah, if you want to access work stuff on a mobile device, you need to install MSFT MDM on your personal phone, and they will, allegedly, be able to control stuff on it (depending on the device itself and how MDM is configured).
However, there are no requirements to do it. You can simply not install any work-related stuff on your phone, so you won't need an MDM. I simply don't access any work resources on my personal phone. If I need to do work, i open my work laptop. If they want me to use work apps on mobile and be accessible, they should provide a company phone for this.
There have been zero conflicts around it on my end, even after multiple years of working there on multiple different teams. Not once have I even got an implied request from anyone (managers, colleagues, etc.) to be accessible on mobile (except for when I am on-call, but for that, they just need my phone number, not any specific apps installed on my phone, and everyone knows it) or any questions about it. Everyone is totally cool with people not being glued to their work apps on their phones on their own free time.
But you are correct, those who choose to use work apps have to give MDM permissions to their personal devices or buy a dedicated device for that (exceptions apply, because there are some teams that provide dedicated work phones). However, unless it is required for the job to be able to use work apps on your mobile device, I think it is fair if they don't provide a work phone. Makes it easier for me to not check on any work stuff during the weekend.
Yes, you're correct, and I didn't mean to imply that MSFT forces employees to install their MDM on personal devices. It was optional for me as well, with a large full-disclosure prompt stating that they can remotely wipe your device if you proceed with mobile setup.
At my company, you have to provide your own device, but the phone number/plan is either (a) paid for by the company, or (b) you get a $40/mo stipend for cell service.
It turns out that I can use our 2FA app without MDM, on my personal. And nowadays, I rarely use slack or email from mobile, and I don't get calls.
I am pretty strong in the "don't put company stuff on personal devices" camp. Even if they don't control your phone by policy, they do technically. They put root certs on the device, and though they can't see individual app data (depending on config) they can see a list of installed apps, and enforce certain baselines.
Most companies I've worked for wouldn't provide a work phone and there's no explicit expectation that you read or answer work e-mails on your phone. But like everything else, if you don't read/reply to work e-mails on your phone, and your colleagues do, good luck getting that promotion/raise/bonus.
> I'm more surprised Amazon (or any company, really) employees using an employer-managed device would have TikTok on them to start with, to be honest.
I am too. Many years ago at my employer, someone fat-fingered a command and wiped every single iPhone/iPad that an employee had configured to connect the company email system. Even after restoring a backup, the devices would just wipe themselves again unless the owner managed to remove the MDM profile before it reconnected to the internet. A good fraction of my coworkers were affected.
I'm not giving anyone access to do that to my personal data.
Not exactly the same, but where I used to work someone had turned on "wipe the phone after x incorrect pins" without notifying anyone. Lots of people with kids got their phone remotely deleted.
After that I've never allowed an employer to control my personal devices. Not that I actually did before, didn't know activating that stuff had so bug implications. I just wanted the calendar on my phone.
With Android work profiles the employer can require you to allow remotely wiping the work profile, but that would not allow them to touch your personal profile.
I'd rather be able to blame myself for my stupid mistakes - not be beholden to Amazon's (or whoever's) MDM profile. Especially when companies don't make it clear that "if you log into your email on your phone using this app, we install MDM, root certificates, have the ability to remote wipe, etc. etc. etc."
I saw that warning when I started to set up my phone and I immediately stopped. If anyone needs to contact me about something urgent they can do it using the work approved IM client that doesn’t require a profile to be installed.
If it does get to the point where I need to have access to my company email, I will have a separate device.
That being said, if my phone was erased, it would only be a slight inconvenience, I can restore from backup.
My dad worked in construction, and from the late 80's and throughout all of the 90's his company kept offering him a company phone (I think car-phone first).
He never got one, because as he said, if they have your number they'll call you, if they don't then they'll solve their own problem. Looking back on it now, it was prescient advice.
I don't really agree... I like the flexibility. Sometimes someone from the US calls me with an urgent problem in the evening (I'm in Europe so not much overlap in work hours).
So what... Sometimes I go to the shop or bank during the day. Or even a walk to the beach if it's not so busy. They're paying me to do a (global) job, not to sit at my desk between 9:00 and 17:00.
Personally I love this flexibility. And I don't feel like I work more than 40 hours, I don't even count them but I doubt I do, especially if I omit the time I spend during "working hours" reading hacker news or other stuff. My work is my hobby anyway.
I do think people who like having fixed work times should have the opportunity to have them. But I also think people like me should be able to work like this without it being considered a bad thing.
Not everyone can afford 2 phones, but their employers expect them to be online all the time anyway. This is particularly true of people who work in US hospitals.
Why would you need to be able to afford 2 phones if your employer is requiring you to have a mobile phone for work? That's a situation in which the employer should provide the phone. I've been on-call or mobile-connected for over a decade, I have never had an employer even suggest that I should foot the bill for a work device. Either they've provided me a phone fully paid for work to be returned if I exit, or have covered the cost of my phone bill for my personal device in return for accessibility outside business hours.
There's no good explanation except that US healthcare orgs tend to misuse staff and clinical providers. Super-specialized doctor with untold postdoc training in faculty at my academic medical center? You've got to encrypt your personal phone to standard and install several required apps. No it is not expensed.
Apropos of the rightness or otherwise of this stance, I don't think "specialist physicians" typically fall into the category of people who "cannot afford 2 phones".
I agree. Neither do top industry execs, top sales personnel, etc. It seems from most of the comments that even in lieu of a work phone, compensation for a mobile plan is normal and expected most places. I may be mistaken, but the culture of large healthcare orgs does seem to promote an expectation that the employees be more altruistic then would be expected elsewhere, even within the employer-employee relationship.
I worked in a hospital and was oncall. My employer provided the phone. And the pager. To do anything else would be like asking an employee to provide a laptop, or a desk.
As the follow-up tweet says: "Completely independent of the specifics in this instance: get a second device before installing an employer's config profile on your personal device"