←back to thread

310 points speckx | 4 comments | | HN request time: 0s | source
1. Silhouette ◴[] No.45038371[source]
If this report is accurate and the change is made quietly and automatically as it predicts then how does this not end up with the mother of all lawsuits? We have several clients in sensitive industries and contractually it is very clear that we must not upload data for those projects anywhere. Surely many others do as well. Anyone working in industries like healthcare or security could get in a lot of trouble for uploading data even once.
replies(1): >>45038723 #
2. staticman2 ◴[] No.45038723[source]
If you are working in Healthcare or security wouldn't Onedrive be disabled and therefore it can't autosave to the cloud?
replies(2): >>45040230 #>>45063198 #
3. Silhouette ◴[] No.45040230[source]
Within a dedicated organisation you probably would disable it. If you're a supplier working with multiple clients then each might have their own policies on confidentiality and data sharing. Some of them might want you to manage information using an account they provide on a cloud system they use. Others might completely prohibit external transfers. A third category are OK with using online systems in principle but for legal or regulatory reasons they need to make sure that the data doesn't leave a certain geographic area so you can only use systems that provide that guarantee.

A reasonable policy for dealing with this variety is to default to not transferring anything you're working on outside the relevant parts of your organisation - including use of cloud services - and then enable specifics on a per-client basis according to need. It's like the principle of least privilege. But if you operate that way then any software that quietly starts sharing things without explicit permission is a big problem.

And if this change will affect home users who don't have professionally managed systems as well then the same moral hazard applies. I don't think it's OK to push people into sharing their personal data online without understanding what they're doing and the potential consequences.

4. hulitu ◴[] No.45063198[source]
No. IT is an external company those days.