kidskmfk.blogg.se

Hubstaff for linux
Hubstaff for linux








hubstaff for linux

Given that the software takes screenshots and logs keystrokes it potentially needs very little code injection to represent a very real threat. So whilst it (likely) isn't the intent to be malicious the absence of verification means it could easily contain an exploit that permits a hostile attack. I contacted Hubstaff and whilst they are confident about the security of the software my searches didn't identify that the script has gone through any formal verification process by a third party (i.e Canonical, RedHat, Slackware). The script in question can be found here īoth the the comment " I probably wouldn't have chosen to work here if the software was malware" and the complete lack of documentation or evidence of independent verification by a linux community rang alarm bells. The script is huge and I'm not keen on installing software that tracks when it hasn't or appears not to have been verified by a Linux community. You may also be interested in reading our privacy policy, which can be found here: Most of those features can be disabled by the organization's owner in the organization settings, so if any of those features make you uncomfortable, you may want to talk to your organization's owner about it and see if they can disable it for you. Our software isn't malware or spyware, we're very open about the type of activity that our software can track. That being said, Hubstaff does have some activity tracking features that you can read about here: I know that may not mean a lot given that I work for Hubstaff, but security is something that I've always cared a lot about and I probably wouldn't have chosen to work here if the software was malware. "We have a lot of users that use the Linux version of our app, I myself use it regularly whenever I work on dev items for Hubstaff. Ones compounded by the request to install it on my own personal PC.Ĭommunication from the vendor didn't inspire me with confidence either. Designed to monitor staff activity it raises serious ethical issues. There is virtually no documentation on this script which on face value appears to be spyware. However the service requires the installation of a shell script (Hubstaff-1.2.8-4ec96dd.sh) which is 11.5mb in size. Apologies if I'm posting this in the wrong forumĪs part of the arrangement for some contractual work I was asked to sign up to










Hubstaff for linux