Nathan Davis3 said:Look, I don't claim to be an expert on technical capabilities. I just know I was going through some internal testing, and they flagged a "stepping stone" attack as a potential vulnerability. I assume that means they have the ability to track something like that.
What I really want to understand is the configuration itself. That IT firm in Washington, D.C. explained it that way to me, though I haven't received all the specifics yet. Maybe they weren't strictly talking about port forwarding, but rather NAT, like you suggested.
But let's say there *is* a backdoor on my work computer. How would they tell the difference between me logging in from an IP address in the USA versus using this setup provided by the IT firm? This setup involves connecting to a specific router in America that mirrors or links back to the same router here in the USA, so the IP address remains identical. I'm not trying to hide; I just want to know if they can see—"Aha, his computer isn't actually in the USA, it's somewhere else, and the final destination is just the USA"—or how that mechanism actually works.
The IT firm back in America tells me the only way the US office would ever find out is if my ISP handed over my personal data directly. Is that actually plausible? Or could the folks in the US, looking at my WiFi configuration here in the States, see that I'm not actually where I claim to be? Or is this visibility limited strictly to a backdoor on the computer itself?
I can only say the same thing again.
Everything you're saying is technically possible. But whether it actually applies to your specific situation? Honestly, I don't think anyone on this forum has a clue.
It’s possible there’s a backdoor in place, and it’s equally possible there isn't. If one actually exists, whether they can see everything depends entirely on what kind of backdoor we're talking about. They aren't all built the same. Some give you total access to everything, while others are much more limited in what they can actually sniff out.
If they actually pull this off and merge...
Remote work. It’s funny how much people fight about this lately. You’ve got one side acting like being in an office is the only way to prevent total societal collapse, and the other side treating a home setup like they’ve discovered fire. Personally, I don't see the big deal. I remember back when I was working for a tech firm in Seattle, everyone was obsessed with "office culture." They thought if we weren't all sitting in ergonomic chairs staring at each other's heads, the magic wouldn't happen. Turns out, most of that "magic" was just people pretending to be busy while scrolling through Reddit. Now, everyone's arguing over hybrid models and return-to-office mandates. If you can get your job done from a kitchen table in Austin or a coffee shop in Denver without bothering anyone, why should you have to commute two hours through traffic just to sit in a cubicle? It feels less about productivity and more about middle management wanting to feel like they actually have control over something. It's not perfect, obviously. Sometimes you miss the spontaneous vent sessions with coworkers or having someone to grab lunch with, but I'll take my own coffee and zero commute over a fluorescent-lit breakroom any day. Of course they’re going to see your network card configuration. It’s not exactly rocket science. They’ll also definitely know you’re running a VPN to connect to the USA. But here’s the thing: if they have some sneaky little backdoor that only exfiltrates specific bits of data—stuff that doesn't include your location markers—then they won't see where you actually are. I mean, unless they’ve established a full remote connection to your machine, they're basically flying blind on your physical coordinates.
It’s about time we face the reality that they could basically have a full remote connection to your PC without you ever catching a whiff of it. We aren't even talking about those standard remote desktop tools where a little icon pops up or a notification tells you an admin is currently logged in. I'm talking about the silent kind—the stuff happening entirely behind the scenes while you're just trying to finish your work.
It’s entirely possible they’ll figure out you’re working from the States, and it’s equally possible they won't. There's a chance their payroll provider hands over all your data, or maybe they don't. Honestly, I'd bet on them keeping it quiet. To actually get that kind of info, they’d need a court order. Is this really such a massive deal to them that they’d go through the headache of getting a judge to sign off on it? I don't know, you tell me.
In your specific situation, only the system administrator actually knows what’s going on. Nobody else on this forum has a clue—unless, of course, the admin happens to be hanging out here with us.
Edit:
Alright, let me give you a real-world example.
I occasionally fire up a VPN just to get around those annoying geoblocks. You know the drill—some services won't let you in unless it looks like you're making a "local connection" from within the States.
The big difference here is that my setup wasn't touched by some service admin. I installed everything myself and handled all the configurations from scratch.
There’s zero chance the admins of that service are ever going to figure out where I’m actually logging in from. All they see is that I'm hitting them through a VPN, since my entire digital footprint stops at the VPN provider's exit node. If they really wanted to be difficult and decide to block the VPN itself, then fine—I lose my connection entirely. But they aren't getting my location.
In that case, I guess I'll have to hunt around for a different VPN provider that actually follows the rules.
It’s the same story with you and your admins. If that US service wants to block that VPN, they can. Whether they actually pull the trigger is their call, not ours to make here on the forum. Can they do it? Yeah, absolutely.