New employer requiring right to intercept communication

grimstoner

Well-Known Member
Joined
Nov 27, 2009
Messages
311
Reaction score
0
A new company I started to work for recently, has asked me to accept the following terms :

"You hereby expressly give the Employer permission to intercept, monitor, read, filter, block or act upon any of your electronic communications (including, any communications that are personal in nature) which shall include, but not be limited to, his telephonic conversations, e-mails and any stored files."

Is this unconstitutional, or is this just the basic implementation of RICA?
 
Sheesh. Whoever wrote that is paranoid.

I think its standard practice for work emails to be intercepted, however, make sure that provision does not apply to personal emails. By personal, I mean emails sent using a non-work account.

Not that they could monitor my private emails anyway - unless gmail is a lot less secure than I think.

Flipping heavy handed though. Funny thing is if you treat people like children, they act like children.
 
Completely standard on work equipment..

If you send a private email from a work PC... they have the right to intercept and read it..

If you make a private call from a work phone.. they have the right to intercept and listen to it..

What they don't have any rights to is personal equipment...
 
Completely standard on work equipment..

If you send a private email from a work PC... they have the right to intercept and read it..

If you make a private call from a work phone.. they have the right to intercept and listen to it..

What they don't have any rights to is personal equipment...

I dont think this would give them the right to intercept private Gmail sent from a work PC though. At least they couldnt intercept it if they tried, and of course I would never hand over the password.
 
I dont think this would give them the right to intercept private Gmail sent from a work PC though. At least they couldnt intercept it if they tried, and of course I would never hand over the password.

Unfortunately it does..

And many companies have * certs on their filtering gateways so all SSL traffic is completely open to the security team...

Everything you do on a work pc is the companies business if they so chose it to be.
 
Unfortunately it does..

And many companies have * certs on their filtering gateways so all SSL traffic is completely open to the security team...

Everything you do on a work pc is the companies business if they so chose it to be.

How can this be legal? Or even secure? That would mean anyone with a cert could see my credit card details for instance when I make a purchase. Doesn't seem right.
 
Everything you do on a work pc is the companies business if they so chose it to be.

This. If it's done on a work machine/internet connection/cellphone/telephone they are within their rights to monitor it
 
Unfortunately it does..

And many companies have * certs on their filtering gateways so all SSL traffic is completely open to the security team...

Everything you do on a work pc is the companies business if they so chose it to be.

Yeah that cant be right. If it was so easy to snoop SSL traffic, nobody would bother with it. As long as you could get traffic to pass through your server, you could decrypt it. It would be a massive vulnerability.

As for whether they have the right to - morally I dont think they do. Legally, pretty sure I didnt sign that over to them.

Anyway, I use my personal phone for work matters - if a company got sticky with things like that, then I would say to them, either provide me with a company phone or I will refuse to handle anything work related with mine.
 
I dont think this would give them the right to intercept private Gmail sent from a work PC though. At least they couldnt intercept it if they tried, and of course I would never hand over the password.

Well you are using their resources to send that personal email & thus in breach of company policy. Something as simple as a keylogger or desktop actitvity recorder will reveal the contents of your email.
 
Well you are using their resources to send that personal email & thus in breach of company policy. Something as simple as a keylogger or desktop actitvity recorder will reveal the contents of your email.

Not in breach as long as I dont abuse it. We are allowed to send personal emails as long as we dont spend all day doing it.
 
Yeah that cant be right. If it was so easy to snoop SSL traffic, nobody would bother with it. As long as you could get traffic to pass through your server, you could decrypt it. It would be a massive vulnerability.

As for whether they have the right to - morally I dont think they do. Legally, pretty sure I didnt sign that over to them.

Anyway, I use my personal phone for work matters - if a company got sticky with things like that, then I would say to them, either provide me with a company phone or I will refuse to handle anything work related with mine.

Nobody said it was easy.... but its doable and is done, OFTEN...

Morally means squat when it comes to work equipment, and legally you are using their equipment, on their time... you signed a company Security document or agreed to it when you joined and that then gives them the right to monitor what you do.
 
Completely standard on work equipment..

If you send a private email from a work PC... they have the right to intercept and read it..

If you make a private call from a work phone.. they have the right to intercept and listen to it..

What they don't have any rights to is personal equipment...
What they should do is provide some equipment which is not intercepted. It is natural for a person to want to maintain unmonitored contact with family during work hours.
 
Not in breach as long as I dont abuse it. We are allowed to send personal emails as long as we dont spend all day doing it.

Ahhh now you're getting into the nitty gritty...

Companies do it, but that doesn't mean they have someone sitting there monitoring everything.... They just have the ability should they need to do so when an employee is abusing their priviledges.
 
What they should do is provide some equipment which is not intercepted. It is natural for a person to want to maintain unmonitored contact with family during work hours.

No, what they should do is nothing...

If you want to perform personal stuff during office hours and definitely not want to be intercepted, then provide your own equipment.
 
Yeah that cant be right. If it was so easy to snoop SSL traffic, nobody would bother with it. As long as you could get traffic to pass through your server, you could decrypt it. It would be a massive vulnerability.

As for whether they have the right to - morally I dont think they do. Legally, pretty sure I didnt sign that over to them.

Anyway, I use my personal phone for work matters - if a company got sticky with things like that, then I would say to them, either provide me with a company phone or I will refuse to handle anything work related with mine.
I like this idea. I have often used my own phones to further the company's interests.
 
Top
Sign up to the MyBroadband newsletter
X