Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

83% Positive

Analyzed from 534 words in the discussion.

Trending Topics

#apple#company#laws#manager#violate#policies#law#data#don#policy

Discussion (22 Comments)Read Original on HackerNews

wmf•about 2 hours ago
This guy is going to lose. If a company is violating no laws and your manager tells you to drop it, you can either drop it or quit. You don't get to choose how to interpret company policy.
Tyrubias•about 1 hour ago
I agree this engineer will probably lose the case because Apple has better lawyers, but I believe your underlying argument to be incorrect. If your manager asks you to violate company policy, then the correct response is to not violate company policy and instead contact HR/legal. Otherwise, saying “my manager made me do it” will not save you if heads start to roll. This applies to both policies that are strictly internal as well as policies that are due to an underlying law. When it comes down to it, neither you nor your manager actually interpret laws or internal policies.
wmf•about 1 hour ago
The article says he did contact legal and I guess they declined to intervene.
mixdup•about 1 hour ago
Yeah, this guy picked a weird thing to take a stand on. Apple corporate policy is not enforceable by state courts. IMEI to serial mapping is not a protected data class in any way in the US. I'm actually confused that this had to be handled by a person, one would assume that AT&T would've just had access to this data as a carrier.
mike_d•about 2 hours ago
At any large employer you sign an agreement to follow the employee handbook and internal policies. They all say the same thing: don't violate the policies even if directed to by your manager.

In this case Apple's legal department had identified the serials and IMEIs as PII.

This is why the case is in civil court and not criminal (because Apple didn't violate any "laws" as you claim). It is a contract dispute.

applfanboysbgon•about 2 hours ago
There's a non-zero chance that Apple might settle if this gets sufficient media coverage, rather than letting it drag on for years making headlines and causing PR damage that exceeds what it would take to buy him off. Even if not illegal, this is surely not the kind of headline Apple wants to be in the news for.
wmf•about 2 hours ago
Yeah, it's almost always better to settle than to go to court. But he's going to get less than he's asking for. And I bet he really wants an apology which he won't get.
loeg•about 2 hours ago
That sounds better for him than dropping it?
codedokode•about 2 hours ago
This is why you should use open-source firmware where there is no registration and customer IDs. Also, the software should allow overwrite IMEI to a random value daily.

> Boardman believed the meeting would finally address both issues.

> Apple fired him the next day.

This is a reminder that being honest with a company doesn't benefit you.

chasil•about 2 hours ago
The apparent takeaway is that Apple devices on AT&T have reduced privacy.

This may change, obviously. Likely for the worse.

hilbert42•about 1 hour ago
There are two laws missing that allow such privacy violations to occur.

First is strong and enforceable law that makes it unlawful to violate one's privacy. The second is to prosecute violators directly—that is, employees cannot hide behind corporate walls and allow the corporate entity to take the blame.

Irrespective of what employers demand, employees have a responsibility to obey the law. Risk of individual employees being chucked in the slammer would change corporate culture overnight.

Fining corporations alone is a waste of time, they see such fines as the cost of doing business, losing one's freedom for an individual is another matter altogether. Employees must be frightened of the consequences of violating the law or the practice will continue.

rileymat2•about 1 hour ago
The main federal laws that are missing is a formal definition of what data you own and expect privacy and what data on you the company owns. In this case it is specified by contract which may or may not have been breached not law.
tdeck•about 2 hours ago
I have to say this sounds like an extremely believable form of shoddy PII stewardship.
radium3d•about 2 hours ago
AT&T looking for more user data to leak to everyone? Already did the SSNs
sigmonsays•about 2 hours ago
Link to non paywall version?
ryanmerket•about 2 hours ago
we don't monetize yet, it's just email
gortok•about 2 hours ago
But we don’t want to have to give you our email.
ryanmerket•about 1 hour ago
all good, i removed it