richlind33: I clearly referenced network security, not the "actual state of things" re it's maintenance -- the lack thereof, to be specific.
Nearly 20yr always working for corporate overlords and no, many posts above are not even close to describe reality.
So, here is some real life experience not based on "common sense" or what was mentioned above.
Yes, most employers have no issue in you using their device for personal errands or use during on or off hours (this was the case in 2000s, not since at least 2010s)
Examples:
- in multiple companies have worked for the first screen - even before login - is a legal disclaimer reminding you that its not your device, the content is work product and you have legal responsibility (for the hw and sw) for the duty of care.
- in my latest role one could not even send attachments to outside e-mail accounts (besides dont even bother to connect storage devices)
- trying to install something just gets you a visit from IT; as from day one, if you want to install something it has to be approved by IT via requests one makes via the equivalent of a Google app store - there are no surprises on what is installed on a PC (even windows settings get reset if it goes against IT policy).
- If you think GOG not having the lastest version is annoying, in corporate world this is normal. Rare is the case where you have the lastest version (unless there was a security patch that was known that speeds up update).
- everything you do online is logged and tracked, you cant delete or hide your activity and in doubt, even if legit (e.g. banking), sites are blocked. But you can ask IT to whitelist a site, although its a hassle.
- use of VPN is mandatory, some even developed the own VPNs from scratch = their IP is more valuable and the cost is well justified.
- downloading content from websites is equally controlled and even sometimes opening a PDF can be issue (i.e. blocked by IT when in doubt).
- since a few years ago, there are weekly phishing trainings where users are tested to see if we fall for phishing or social engineering techniques. these are not PPTs or meetings, but actual very convicining emails with attempts wo warning or timings. it will be reflected in ones evaluation if you fail these random tests.
And many others measures that i wont bore with a wall of text but, the most important thing of all why one should never mix professional life with personal life - people who actually have life experence know this:
everything you develop or produce is work product since you are using work devices. And as such there is no expectation of privacy, meaning that the employer will know if you checked or not NSFW games, which bank you logged into, how long your sessions last, etc.... this is only used against you if you abuse the policy or someone really wants you gone.
Using a professional device as personal because its convenient is more a security risk for the user privacy than it is a security risk for the company.... TLDR: most companies dont care if you use the equipament some personal activity, because at EoD, you are legally liable (besides losing your job ofc).
Just in tiny Portugal alone there are about 1.2M companies, imagine how many are there globally....if things were as it was said, pretty sure that the dark web would have much more data... the issues mentioned here - as it also happes in other threads/online - are just assumptions to fill the lack of experience that is assumed as "true things/facts".
---
Also...on a funny note: raise your hand when working on a project for months and everytime the other giant corpo IT policy is incompatible to your evil corpo, and just sharing a file takes much more time than it should.... (reason #3243: why games may take longe to complete = doing things in larger businesses even if simple, take more time)