Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Keyboard strokes

  • 14-06-2024 3:41pm
    #1
    Registered Users, Registered Users 2 Posts: 165 ✭✭


    read an article that employees got fired as they were pretending to be at their desks and their employer had hidden software to monitor them. How common is this? Are employers in Ireland legally allowed secretly monitor websites employees visit and see what they type etc?



Comments

  • Registered Users, Registered Users 2 Posts: 7,486 ✭✭✭The Continental Op


    There is software that keeps the mouse moving on the screen when the user is absent. Perhaps that is what the employer spotted?

    Perfectly legal to monitor any activity on the companies website, email, servers, and PC's. Why shouldn't it be?

    Users own PC at home is a different matter but if the user is connecting to a work server then any activity through the company's internet connection may be monitored.

    I used to work for a company that made the monitoring software.

    Wake me up when it's all over.



  • Moderators, Business & Finance Moderators Posts: 10,613 Mod ✭✭✭✭Jim2007


    Well you don't actually need to monitor what people are doing to detect this, you just need to review the inventory of software installed on the machine. People installed a very specific piece of software to keep the mouse moving while they were away and as that is the sole purpose of the software it is kind of hard to deny what you were doing with this software.

    The other thing is that you don't know the actual reason the people were dismissed. Most companies have policies and security systems in place to prevent employees from installing random software on business computers. So if they not only broke company policies and deliberately hacked the company's security system that alone is enough to get them fired.

    As for monitor employee activity on company devices, yes it is legal and indirectly required by law! For example pretty much every business processes and stores GDPR data, that means they are responsible of security that data. Obviously, if they give you a device that can access such data and then failed to monitor your use of the data that could be a serious GDPR issues since you could have done anything with the data or even bigger issue in taking the device outside the EEA. Similar situations exist for medical data, money laundering activities and so on. So unless you are doing some very basic task for your employer, you can expect that you are being monitored in some way most likely data access and device location.



  • Registered Users, Registered Users 2 Posts: 13,131 ✭✭✭✭Flinty997


    You need to check your terms and conditions. Its probably in the computer usage policy if they monitor how the computer is used. If they've told you, then they can do it.



  • Registered Users, Registered Users 2 Posts: 13,131 ✭✭✭✭Flinty997


    You have to wonder how a company survives if it needs software to notice someone does nothing.

    Also its not like humans work 100% of the time. You might need to discuss something, or be away from a desk for a while.

    Post edited by Flinty997 on


  • Registered Users, Registered Users 2 Posts: 19,103 ✭✭✭✭Del2005


    The software is designed to make it look like you are using the keyboard, so it looks like they are working when they aren't. My company has software installed that prevents us from using their computers too much. Every competent company that supplies employees with computers or phones will have some type of tracking and/or monitoring software installed.

    The company didn't fire the people for stepping away from the computer for a few minutes.



  • Advertisement
  • Registered Users, Registered Users 2 Posts: 2,493 ✭✭✭tohaltuwi


    OP mentioned keystroke loggers there at the last bit. Yes these certainly exist. But I doubt most companies actively use these, only in very specific type scenarios and users would have to be informed of their use where GDPR applies. Hackers use them to gain usernames, passwords etc. I think companies outside the GDPR governance area might use them more.



  • Registered Users, Registered Users 2 Posts: 13,131 ✭✭✭✭Flinty997


    Looking as if you are working doesn't produce anything. You'd think they'd notice that before anything thing else.



  • Registered Users, Registered Users 2 Posts: 7,486 ✭✭✭The Continental Op


    This is the type of thing some people have been using, check Amazon they have loads of different ones. Before Covid I'm not sure they even existed.

    https://www.amazon.co.uk/VAYDEER-Jiggler-Prevent-Function-wiggler/dp/B08V4L6H7S/

    The early ones just moved your mouse on pixel up and down or left an right at intervals which fooled monitoring software into reporting that the user was using their computer. I've no idea if this was the reason for the sacking the OP refers to but is one possibility. Just as the "jigglers" have got more sophisticated I suspect so has the monitoring software.

    Wake me up when it's all over.



  • Registered Users, Registered Users 2 Posts: 7,113 ✭✭✭mada999


    All websites you visit while using the companies internet connection are more than likely being logged. Now whether they are actively being checked is another thing. However, I've once seen a managers ask for a log of a user's web history for performance reasons. Not sure where that particular ticket went though.

    Companies now have "insider threat" systems that record user sessions on their networks along with other Cybersecurity toys. With the prevalence of WFH I would expect companies to install these types of systems. TBF - most IT staff are not bothered what you are at normally imo but if you are using dodgy websites or installing software on company equipment then they could be flagged then.

    Personally I wouldn't be doing normal internet surfing in work and would use my work computer for only work stuff.

    Source : I work in IT



  • Registered Users, Registered Users 2 Posts: 19,103 ✭✭✭✭Del2005


    They most likely did. They fired them because they weren't doing anything but their computers where showing as being in use all the time. Doing nothing is a disciplinary issue which needs to be resolved with the manager monitoring the employee for a prolonged period, faking working is gross miss conduct and embezzlement which can be resolved by firing.



  • Advertisement
  • Moderators, Business & Finance Moderators Posts: 10,613 Mod ✭✭✭✭Jim2007


    Most managers have a good idea of what their subordinates should be able to accomplish in a day's work, especially if you have a few people doing the same job. You don't really need a computer program to tell you they are not doing the job. Finding a fake activity program on their office device is just confirmation.

    I used to manage remote teams in the Ukraine before the war and you could always tell who was swinging the lead. We just turned off their access to a key system for their job and when they continued to report progress on their work objectives it was curtain time.



  • Registered Users, Registered Users 2 Posts: 1,785 ✭✭✭dennyk


    Most managers have a good idea of what their subordinates should be able to accomplish in a day's work

    That's an optimistic take, I'd say; certainly most managers should know how to gauge their direct reports' productivity without resorting to ridiculous nonsense like activity monitors or keystroke loggers or whatnot, but that assumes that said managers are competent, and there are a lot of utterly useless 'Peter principle' managers out there.



  • Registered Users, Registered Users 2 Posts: 3,517 ✭✭✭Tork


    They're upfront about the IT and internet monitoring policy where I work. I don't mind because the information is right out there for everybody to see, and there shouldn't be any nasty surprises. I don't believe anybody has ever been pulled up for using the internet too much, for example. It's the sort of thing that could be used if they have reason to look more closely at somebody's work. Just about everything on a computer is logged locally or on the network anyway. You'd have to be pretty naive to think your employer doesn't have the capability to go digging if they want to.

    Those mouse jigglers have the potential to introduce viruses and other nasties into an I.T. system. You have no control over what software is pre-loaded on these dongles and you can never rule out malware. Any company that doesn't have decent security in place is asking for trouble. I have a feeling these dongles may not even work on our work computers. Even if they did work, evidence of them would be picked up by the auditing software that's routinely run on the system.

    Post edited by Tork on


  • Moderators, Sports Moderators, Regional Midwest Moderators Posts: 24,028 Mod ✭✭✭✭Clareman


    Most companies would take a dim view of people installing unauthoutised hardware or software on their network, I would say that this would be a bigger problem than people dossing. If you are worried about your Teams status changing just open notepad and put a weight on a key, keeps you alive, or so I've heard 😉



  • Registered Users, Registered Users 2 Posts: 2,495 ✭✭✭Markus Antonius


    I've worked in jobs where I had to use my own personal credit card/banking details and then expense costs back to the company. I think it would be pretty scandalous if an employer was using key-loggers on their computer and would be fairly sure this would not be legal.



  • Registered Users, Registered Users 2 Posts: 30,297 ✭✭✭✭AndrewJRenko


    It would be very unusual these days that end users would have admin rights to install software, or that USB slots would be open for hardware like this.

    It would not be legal, unless;

    • they had very good reasons for doing so, and
    • they told you in advance that they were doing it, why they were doing it, how they would use the information, how long they would retain it.



  • Moderators, Category Moderators, Arts Moderators, Sports Moderators Posts: 50,895 CMod ✭✭✭✭magicbastarder


    can you imagine the security headache of ringfencing the backend systems which stored all the keystrokes of your users? or protecting the traffic between the client and backend?



  • Registered Users, Registered Users 2 Posts: 6,811 ✭✭✭Clo-Clo


    With security concerns all companies will monitor endpoints, that is the best point of access for hackers etc. They won't bother monitoring every website a person visits as that is far too much data. They will have a bad list which would be the normals which will set off a trigger if you visit or depending on the technology will just block the user

    THey will also monitor what software you install on the system, again to make sure nothing dodgy and also from a license point of view they need to make sure the company is not using software which they are not entitled to use

    These people would of had to install the software on the system, fairly easy to run a command and see what every user has installed on every device. You could do it across an entire company in a few mins and then just limit the software to non approved, in a few hours or less you could identify every user in the company and the ones who have installed non standard products

    Also by the way the claims of people working abroad while supposed to be working in Ireland, all of that can be found very easily with modern security software, in fact most packages will inform the company that someone has logged into your PC from a different location to the one they normally log in and raise it as a security alert for the SOC to review

    Any MNC will have this as basic these days, most Irish companies as well, the only ones who didn't seem to be the HSE



  • Registered Users, Registered Users 2 Posts: 1,785 ✭✭✭dennyk


    Nah, it's grand; we have a policy that no one is allowed to access those systems or look at that traffic without authorisation, so job done!



  • Registered Users, Registered Users 2 Posts: 13,131 ✭✭✭✭Flinty997




  • Advertisement
  • Registered Users, Registered Users 2 Posts: 1,618 ✭✭✭Squatman


    hard to deny the intention of downloading the software (how an organisations IT allow this is another story), but proving that it was used may be more difficult



  • Registered Users, Registered Users 2 Posts: 308 ✭✭Titanium11


    We are monitored on absolutely everything in my workplace.

    If we make or receive any call, calls are recorded.

    The company also monitor and record all of our screen time on company computers.

    I wasn't informed of the second part until months after I started the job. I think they really should have told me at the start of the job.

    Companies are monitoring so much now.



  • Registered Users, Registered Users 2 Posts: 1,785 ✭✭✭dennyk


    Companies are monitoring so much now.

    Middle managers have to justify their existence via Excel spreadsheets and pretty pie charts, so if you actually have no clue what it is your direct reports are supposed to be doing, your only option is to proudly brag to upper management how you've increased your team's QoQ productivity by X% based on how many keystrokes per minute they are typing, and hope said upper management also has no fecking idea what your reports are supposed to be doing either and will just go along with it.



  • Registered Users, Registered Users 2 Posts: 30,297 ✭✭✭✭AndrewJRenko


    Any employer that is collecting this information would need to have a clear privacy policy published showing what information they are collecting, what is their legal basis for collecting the information, where it is being stored, and how long it is being retained.
    You also have a right to get a copy of any data they have about you.



Advertisement