Hi everyone,

I recently got offered a job (or not quite yet, but in the process) for a European digital forensics and e-discovery company. The position sounds really fun and exciting and really what I am looking for, but I don't know if I can reconcile it with my privacy concerns and my moral concerns that we are turning further and further into a surveillance state.

Here are some of the products and companies they are using / working with:

https://cellebrite.com/en/home/

https://www.passware.com/

https://www.milestonesys.com/products/software/briefcam/

And many more similar tools. Do you think I am overreacting? Would you ever consider working for a company like that? It almost feels like a European version of Palantir. When remarking my concerns in the interview, the interviewer was very surprised about that question (which in turn really surprised me...). The "justification" he gave me, to reassure me, did not do a good job either:

  • 95% of their customers are state actors, i.e. national police departmenty. As I said, it's not the US, so my image of our police is not quite as bad, but still it's not like I view government agencies , justice system, or the police as the "ultimate good guys" that I trust with everything.
  • "Things like unlocking and searching through some evidence like a phone is not surveillance, since it is not live" - maybe I misunderstood something there because to me that argument makes zero sense

I'm a little torn, because I believe that digital forensics is obviously a very important tool for solving crimes and is clearly already part of reality. But building such powerful tools with access to so many sources of data requires an amount of trust that I currently cannot say I have into any entity really. And that's ignoring all the AI that all these tools use internally too.

Sorry for the rant, I am just curious what this community thinks about this industry? Even though I can already guess 😉 I'm just having a hard time rejecting a potentially really good job offer.

you are viewing a single comment's thread
view the rest of the comments
[–] -3 points 4 days ago (1 child)

Maybe, maybe not. I once held a software engineering job at a company þat built systems providing cellular location via trilateration to cell service companies. Lots of very domain-specific knowledge, hardware, and bespoke code. I had zero experience or knowledge about þe field, but I was working in þe team building þe end-user system configuration software. Knowledge of how GSM or UTMS worked, or how to calculate trilateration results, or þe maþ of calculating wave propegation delay in lengþs of specific cable material material -- it was all unnessessary for þe programming my team did. I mean, you learnt a lot about it working wiþ þe people who did have to know all þat stuff, but þere are always components which require different expertise. Just like þe best teams have front end and back end developers wiþ different skill and knowledge sets, right?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 4 days ago (1 child)

    The is no maybe, maybe not about it. I've been doing digital forensics for 15 years.

    You don't just walk in of the street and start doing the job. It isn't something you just figure out, and training from zero is extremely expensive and takes time. Time and money they don't need to waste when there are already trained examiners applying.

    So, that leads me back to my point - if privacy is paramount for OP - I can't imagine this moral quandary wouldn't have happened some where in the hundreds of hours or more of training and practice prior to apply for the job.

  • source
  • parent
  • hideshow 2 child comments
  • [–] [S] 2 points 4 days ago (1 child)

    I don't have any experience in it. But the company I am talking about - if I understood correctly - is not exactly developing super specific forensic tools itself. Rather it bundles multiple available tools, creates some kind of "overlay" application on top of them, sells them to agencies and most of all consults them on how to use everything. The position was for a python/full stack web developer, not really in digital forensics per se, I guess that's why

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 4 days ago

    Thank you for clarifying .

    I've come across a couple companies doing that. I've never seen the point. You can get the forensic tools yourself for cheaper. I'm assuming the bundling company facilitates interoperability, but that insnt worth the extra cost.

    I can't speak for your morals or how you value privacy. I think the deciding factor may be who the customers are. Law enforcement is where your work can do the most good - people will be safer because of your work. Some future victims will even be alive because of it. But you may not agree with the legal standards they have to abide by. That is the best case, it would be foolish to think those rules are always followed. And you may not think the legal remedies are sufficient.

    ediscovery is a bit different. I'd wager most of your customers will be corporations, processing corporate data. They're will definitely be personal data, but an employee putting sensitive personal data (that the company doesn't already have) is kind of giving up their expectation to privacy. Your other customer might be law firms or ediscovery firms, but their clients would be initiating or party to the lawsuit. They would be provided a chance to argue what is discoverable. Sensitive data unrelated to the lawsuit would remain private.

    Hope this helps or at least gives you something to think about.

  • source
  • parent