Hi everyone,

I recently got offered a job (or not quite yet, but in the process) for a European digital forensics and e-discovery company. The position sounds really fun and exciting and really what I am looking for, but I don’t know if I can reconcile it with my privacy concerns and my moral concerns that we are turning further and further into a surveillance state.

Here are some of the products and companies they are using / working with:

https://cellebrite.com/en/home/

https://www.passware.com/

https://www.milestonesys.com/products/software/briefcam/

And many more similar tools. Do you think I am overreacting? Would you ever consider working for a company like that? It almost feels like a European version of Palantir. When remarking my concerns in the interview, the interviewer was very surprised about that question (which in turn really surprised me…). The “justification” he gave me, to reassure me, did not do a good job either:

  • 95% of their customers are state actors, i.e. national police departmenty. As I said, it’s not the US, so my image of our police is not quite as bad, but still it’s not like I view government agencies , justice system, or the police as the “ultimate good guys” that I trust with everything.
  • “Things like unlocking and searching through some evidence like a phone is not surveillance, since it is not live” - maybe I misunderstood something there because to me that argument makes zero sense

I’m a little torn, because I believe that digital forensics is obviously a very important tool for solving crimes and is clearly already part of reality. But building such powerful tools with access to so many sources of data requires an amount of trust that I currently cannot say I have into any entity really. And that’s ignoring all the AI that all these tools use internally too.

Sorry for the rant, I am just curious what this community thinks about this industry? Even though I can already guess 😉 I’m just having a hard time rejecting a potentially really good job offer.

  • fyf@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    4 days ago

    The is no maybe, maybe not about it. I’ve been doing digital forensics for 15 years.

    You don’t just walk in of the street and start doing the job. It isn’t something you just figure out, and training from zero is extremely expensive and takes time. Time and money they don’t need to waste when there are already trained examiners applying.

    So, that leads me back to my point - if privacy is paramount for OP - I can’t imagine this moral quandary wouldn’t have happened some where in the hundreds of hours or more of training and practice prior to apply for the job.

    • Drukob@feddit.orgOP
      link
      fedilink
      arrow-up
      2
      ·
      4 days ago

      I don’t have any experience in it. But the company I am talking about - if I understood correctly - is not exactly developing super specific forensic tools itself. Rather it bundles multiple available tools, creates some kind of “overlay” application on top of them, sells them to agencies and most of all consults them on how to use everything. The position was for a python/full stack web developer, not really in digital forensics per se, I guess that’s why

      • fyf@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        4 days ago

        Thank you for clarifying .

        I’ve come across a couple companies doing that. I’ve never seen the point. You can get the forensic tools yourself for cheaper. I’m assuming the bundling company facilitates interoperability, but that insnt worth the extra cost.

        I can’t speak for your morals or how you value privacy. I think the deciding factor may be who the customers are. Law enforcement is where your work can do the most good - people will be safer because of your work. Some future victims will even be alive because of it. But you may not agree with the legal standards they have to abide by. That is the best case, it would be foolish to think those rules are always followed. And you may not think the legal remedies are sufficient.

        ediscovery is a bit different. I’d wager most of your customers will be corporations, processing corporate data. They’re will definitely be personal data, but an employee putting sensitive personal data (that the company doesn’t already have) is kind of giving up their expectation to privacy. Your other customer might be law firms or ediscovery firms, but their clients would be initiating or party to the lawsuit. They would be provided a chance to argue what is discoverable. Sensitive data unrelated to the lawsuit would remain private.

        Hope this helps or at least gives you something to think about.