#surveillance

Posts mentioning hashtag #surveillance

Below are all the posts — topics as well as replies — that mention the hashtag #surveillance.

Mention #surveillance in your post to continue the discussion!

Activity Monitoring discussion coming from a manager near you.

In case you weren't aware, they're also looking at activity levels-- So now they're expecting you to click and email and teams and what the f**k else they're looking at to complain about you. And naturally nothing has been communicated, you know know how they measure or what they measure.

F this company.


Apple alerts exploit developer that his iPhone was targeted with government spyware

Earlier this year, a developer was shocked by a message that appeared on his personal phone: “Apple detected a targeted mercenary spyware attack against your iPhone.”

“I was panicking,” Jay Gibson, who asked that we don’t use his real name over fears of retaliation, told TechCrunch.

Gibson, who until recently built surveillance technologies for Western government hacking tools maker Trenchant, may be the first documented case of someone who builds exploits and spyware being themselves targeted with spyware.

“What the he-l is going on? I really didn’t know what to think of it,” said Gibson, adding that he turned off his phone and put it away on that day, March 5. “I went immediately to buy a new phone. I called my dad. It was a mess. It was a huge mess.”

At Trenchant, Gibson worked on developing iOS zero-days, meaning finding vulnerabilities and developing tools capable of exploiting them that are not known to the vendor who makes the affected hardware or software, such as Apple.

“I have mixed feelings of how pathetic this is, and then extreme fear because once things hit this level, you never know what’s going to happen,” he told TechCrunch.

But the ex-Trenchant employee may not be the only exploit developer targeted with spyware. According to three sources who have direct knowledge of these cases, there have been other spyware and exploit developers in the last few months who have received notifications from Apple alerting them that they were targeted with spyware.

Apple did not respond to a request for comment from TechCrunch.

The targeting of Gibson’s iPhone shows that the proliferation of zero-days and spyware is starting to ensnare more types of victims.

Spyware and zero-day makers have historically claimed their tools are only deployed by vetted government customers against criminals and te------ts. But for the past decade, researchers at the University of Toronto’s digital rights group Citizen Lab, Amnesty International, and other organizations have found dozens of cases where governments used these tools to target dissidents, journalists, human rights defenders, and political rivals all over the world.

The closest public cases of security researchers being targeted by hackers happened in 2021 and 2023, when North Korean government hackers were caught targeting security researchers working in vulnerability research and development.

Two days after receiving the Apple threat notification, Gibson contacted a forensic expert who has extensive experience investigating spyware attacks. After performing an initial analysis of Gibson’s phone, the expert did not find any signs of infection, but still recommended a deeper forensic analysis of the exploit developer’s phone.

A forensic analysis would have entailed sending the expert a complete backup of the device, something Gibson said he was not comfortable with.

“Recent cases are getting tougher forensically, and some we find nothing on. It may also be that the attack was not actually fully sent after the initial stages, we don’t know,” the expert told TechCrunch.

Without a full forensic analysis of Gibson’s phone, ideally one where investigators found traces of the spyware and who made it, it’s impossible to know why he was targeted or who targeted him.

But Gibson told TechCrunch that he believes the threat notification he received from Apple is connected to the circumstances of his departure from Trenchant, where he claims the company designated him as a scapegoat for a damaging leak of internal tools.

Apple sends out threat notifications specifically for when it has evidence that a person was targeted by a mercenary spyware attack. This kind of surveillance technology is often invisibly and remotely planted on someone’s phone without their knowledge by exploiting vulnerabilities in the phone’s software, exploits that can be worth millions of dollars and can take months to develop. Law enforcement and intelligence agencies typically have the legal authority to deploy spyware on targets, not the spyware makers themselves.

Sara Banda, a spokesperson for Trenchant’s parent company L3Harris, declined to comment for this story when reached by TechCrunch before publication.

A month before he received Apple’s threat notification, when Gibson was still working at Trenchant, he said he was invited to go to the company’s London office for a team-building event.

When Gibson arrived on February 3, he was immediately summoned into a meeting room to speak via video call with Peter Williams, Trenchant’s then-general manager who was known inside the company as “Doogie.” (In 2018, defense contractor L3Harris acquired zero-day makers Azimuth and Linchpin Labs, two sister startups that merged to become Trenchant.)

Williams told Gibson the company suspected he was double employed and was thus suspending him. All of Gibson’s work devices would be confiscated and analyzed as part of an internal investigation into the allegations. Williams could not be reached for comment.

“I was in shock. I didn’t really know how to react because I couldn’t really believe what I was hearing,” said Gibson, who explained that a Trenchant IT employee then went to his apartment to pick up his company-issued equipment.

Around two weeks later, Gibson said Williams called and told him that following the investigation, the company was firing him and offering him a settlement agreement and payment. Gibson said Williams declined to explain what the forensic analysis of his devices had found, and essentially told him he had no choice but to sign the agreement and depart the company.

Feeling like he had no alternative, Gibson said he went along with the offer and signed.

Gibson told TechCrunch he later heard from former colleagues that Trenchant suspected he had leaked some unknown vulnerabilities in Google’s Chrome browser, tools that Trenchant had developed. Gibson, and three former colleagues of his, however, told TechCrunch he did not have access to Trenchant’s Chrome zero-days, given that he was part of the team exclusively developing iOS zero-days and spyware. Trenchant teams only have strictly compartmentalized access to tools related to the platforms they are working on, the people said.

“I know I was a scapegoat. I wasn’t guilty. It’s very simple,” said Gibson. “I didn’t do absolutely anything other than working my a-s off for them.”

The story of the accusations against Gibson and his subsequent suspension and firing was independently corroborated by three former Trenchant employees with knowledge.

Two of the other former Trenchant employees said they knew details of Gibson’s London trip and were aware of suspected leaks of sensitive company tools.

All of them asked not to be named but believe Trenchant got it wrong.


CONFIMRED - ACTIVITY TRACKED

I was skeptical about the 8 hour office hours before, until I got a warning.

People on this forum also warn about activities been tracked, I did not believe it.

Well today , there was a general email about activities been monitored.
Say you go for doctors appt for 2 hours, when you are back you have to spend extra 2 hours.

In summary, your total online activity must be close to 8 hours.


ATTN STIFEL MINIONS: Protocol Updates

Effective immediately, you will be chained to your desks upon arrival to work. Please plan your wardrobe appropriately to accommodate this change. Upon completion of your work day, please ensure your manager approves your work as being complete for the day so you may be unchained from your desk. You will be given exactly 5 minutes to walk from your desk to your transportation. If you need additional time, you will need a doctor’s note explaining why. Failure to comply will result in you being referred to HR and written up. Please note all bathroom breaks, lunch breaks, or desk-side chats not pertaining to work-related activities will be deducted from your total work time for the day, so plan accordingly.

Further, in addition to the surveillance software already installed on your computing devices that track and read your every typed word and mouse click, we are now introducing new surveillance hardware and software to our environment. There will now be surveillance cameras installed in all cubicles, offices, and conference rooms. There will also be new, state of the art thought monitoring hardware and software installed.

If you are found to have spoken about or thought about layoffs, talking to the media about layoffs, how poorly you are treated at work, updating your resume, interviewing for jobs outside of the firm, or any other matters outside of your work for Stifel, you will be referred to HR and written up.

Last, anyone at the director level or above will be issued a whip. Should your work performance become unsatisfactory, you will be summarily whipped and beaten until you come into compliance with workplace standards. Should you require this beating to be handled privately, a psychiatrist’s note will be required. A woodshed is being built to accommodate this requirement.

Thank you for your prompt attention to this matter, and please remember what a privilege it is to work for such a great employer.

PS. If you've read this far, this post is sarcasm and is in response to the "ATTN STIFEL EMPLOYEES" post that was from yesterday. Enjoy, and have a nice day.


Warning: You’re Being Watched!

A good friend of mine who has inside knowledge shared with me that your company is now 100% monitored.

It's a contracted service, and they are to monitor everything. The threshold for flagging and reporting is at the lowest bar. The service started in October and the service continues to March 2026.

I'm not sure why the sudden mistrust, but it's disturbing to be working under a microscope.

What is the purpose of this?

My source said that I should share with my trusted coworkers, but I don't even know who I can trust anymore.


Facial authentication coming soon.

Just got back from Dreamforce conference in San Francisco. Some of our technology execs were there. New tracking software and authentication software will be rolling out soon. In a nutshell, every device we use for work will have tracking and timestamping abilities.
Don’t get me started with how they’ll be using AI in the company.


RTO reporting , Days in office and Hours on internal network

My understanding is there are two Reports
1) Days in office - Badge swipes.
-some buildings do not have a building exit point.

 - Badge point is not sopisticated enough to log a time, only date? 
    Why is it nessisary for them to sift through thousands of IPs/machine names to   determine 'time in office'?  previously they were only checking for where an emplyess was logged in if they wanted to scrutinize the emploee.

2) Hours in office - network IP and user login

  • many emplyees share a computer. one user could be logged in over night.
    • Considering that may employees share a computer the logged in user or lan id needs to be determined. How is that being done? Probaby by the spyware.

I belive two major flaws exist:
They are sitting on a metric ton of data.
No way to pull meaning reports due to inaccurant data.

So many flaws in these reporting methods. It almost begs to gamed.


Does the company monitor productivity?

I’ve noticed some people seem to have a lot of flexibility like taking walks, longer lunch breaks to go to the gym, playing pool, or spending time on their phones. I’m not saying that’s a bad thing, it’s great they have that balance but I’m just curious how that works here. Does our company track productivity in any specific way?


CES is no longer required

A reminder for those waiting for the next CES. Your feedback is being collected in realtime. Employees sentiment is monitored by Aware, an AI service that monitors internal dialogue.
If you were wondering why the CES seems diluted, it is because they already have the data they need

https://www.cnbc.com/amp/2024/02/09/ai-might-be-reading-your-slack-teams-messages-using-tech-from-aware.html


Desktop Activity Analytics

Verint is the vendor, they track activity while logged into the network. Not all departments have this, most do not. That probably will change at some point.

Essentially it measures activity, idle and inactive time as well as time in applications. Some activities can be flagged, like people that write a book in MS Word by putting a coffee cup on their keyboard, mouse jigglers, etc. Uncertain about putting yourself in a Teams call meeting or other ways to trick the system.

Check your entitlements for Verint and if you have it, assume your clicks are being tracked in addition to network login and out activity. Again, I assume everyone will have it at some point, but you probably don’t as of now.


Hope you all post through a proxy server

In case you haven't noticed by now Schwab is defintely involved with this site and it's possibly even a trap set by them. They definitely have administrative access based on the number of posts and comments that get removed. Not so much the layoff info - I think they actually want people to see that stuff so they are prompted to leave on their own and Chuck doesn't have to cut them a severance check. Things that makes the company look bad though soon disappear. Notice how anything about the Peak-SoMo situation quickly gets deleted.


Employee logging needs transparency

If professional employees are going to be treated like children and have every second with fingers on keyboard and/or within the walls of the designated workplace tracked and reported, and those things will be used against them (and they will, even beyond the day/hour requirements, don't think they won't), they should at least be able to see their own swipe in/out and network on/off time (both in the office and remotely). "We know something you don't know" is a terrible practice.


Now that the dust has cleared…

Every move made by the former regime was designed to pump up the stock price so that the supreme leader could cash out. Work 9 hours a day? Stock price. Track your whereabouts? Stock price. Every. Single. Move. While this was going on the leader negotiated a government job - one that he didn’t want, was unqualified for, and won’t keep very long. The kicker: he did it to escape capital gains taxes on the stock sale. On your hard work. On your 9 hour days. The stock, by the way, is down over $100 per share since he cashed out. That’s not just down - that’s a crash. He’s laughing. His cronies are, too. Maybe now that the evil has left the building things might start becoming normal again. I hope so. Nothing wrong with a boring company.


Big Brother

We're getting cameras in our trucks so they can watch our every move. I wonder how many will get disciplinary actions or lose their jobs over this. As if they don't have us stressed out enough, which is a safety issue itself decreasing focus on tasks and productivity. Techs worried to death that if something happens, even if they do the right thing, they're almost 100% getting disciplined. Accountability they say? Yeah, for everyone except management. This company is terrible.


CAO Tracking Hours In Office

Just got word from my manager. Ekene is going to start tracking us on days we are in office. One of the things I enjoyed about WF was the flexibility. I went my 3 days, sometimes I went 4, sometimes 5 depending on what was going on. Sometimes 8 hrs, sometimes less. Sometimes I'd take a long lunch, sometimes I wouldn't eat lunch. I got my work done and didn't have to be treated like a child.


I knew it! They are really monitoring this!

The security Veep told a colleague of mine that communications does "monitor" these posts and even shares them with executives and other leaders. It is nice to know that he is talking as much as he does. So if a security danger-thing happens at our workplace and something had not been reported earlier to stop it from happening, we now know that an attorney can demand the emails and prove that they knew there was a problem that would endanger many of us. Thousands of associates on another post liked a post begging for someone to do something. Thousands of us! That was a massive show of support and a cry for help. They did it on layoffs.com because they can't trust to report it internally. He also told a colleague that he and his team now have to report to HR and he doesn't like that because they ask for too much to be done right away while they sit on their a-s. He said they were the ones that "had a part in fu--ing up some of his team's onboarding" which I wasn't sure what that meant. But the main point is we now know they do read these and can be held accountable when it happens.


Sapience gone, Manual Tracking instead

They're now requiring us to record every task we do with a stop clock for 5 days straight. Its starting with a lot of people in our group. they gave us an excel sheet with tasks they claim are a list of everything we do. the list is missing so many items. you then have to select a task and start a stop clock. you can pause the clock and then start again. we asked what this was for and they said it was to help groups perform better. our offshore people said it's being used as performance tracking. we went to our boss and they said "just complete the form". it's very scary. they don't have everything we do and don't understand what our jobs are but using this to measure us? Why did we get rid of Sapience if we now have to manually track everything we do? We're also being rushed to complete this and some people can not use the tracking sheet because it's broken and they had to start all over. Even though they had a reason it was not completed they're getting requests every day asking if it was done. What is going on here? Why are they making everyone track down to the minute when none of this is right compared to what my actual job is? This feels like they're trying to decide who to fire next but doing it with partial information.
Are other groups being asked to do this??