4 ms·
Totally agreed they have the right to monitor your network traffic, but I still think in most cases employees should try to push back on this. At least from my
by ckuehl 10y ago
Totally agreed they have the right to monitor your network traffic, but I still think in most cases employees should try to push back on this.
At least from my view, it's not so much that I don't want my company to know what I'm doing, as that I don't trust their software to securely MITM all of my traffic. This thread doesn't fill me with confidence about the competency of these corporate MITM proxies. And the recent Cloudflare news doesn't help either -- they're effectively the world's largest MITM proxy, and even they couldn't avoid leaking a huge amount of "secure" traffic.
There are surely sectors where it's necessary for a company to MITM all traffic, but I think most companies will do better security-wise by not messing with TLS. It's just too hard to get right.
- theluketaylor 10y agoAt my workplace where we have to do tls inspection for regulatory purposes we provide an internet-only wifi network for employee personal use where we don't intercept TLS. This network is fully isolated from the corporate network and corporate devices join a different, more monitored network. I believe this strikes the best balance between regulatory compliance and employee privacy. People can still use personal email or do online banking while at the office without inspection, but no corporate data can be moved en mass off company servers.
- HappyTypist 10y agoPerfectly sensible and reasonable. Difficult to have any objections.
- FireBeyond 10y ago> but no corporate data can be moved en mass off company servers. How so? 1. Connect to Corp Wifi 2. git clone companyapp.git 3. Connect to Employee Personal Wifi 4. Email tgz'ed companyapp ?
- theluketaylor 10y agoWhen connecting a corporate device to any non-corporate network (including the employee wifi) you can't go anywhere until the vpn is connected. The vpn routes you through all the same inspection points as being on premise.
- semi-extrinsic 10y agoIs both SSH and USB key / USB DVD burner usage completely disabled on your corporate devices? If not, obvious workaround is obvious.
- rocqua 10y agoEven a full mitm solution doesn't MitM the sneakernet.
- Intermernet 10y agoAh yes, but a literal MitM solution could!
- ptaipale 10y agoThat obvious workaround doesn't give you a 24/7 hole from the Internet. To copy information, you need a person to knowingly do it. This decreases the attack surface tremendously.
- buzer 10y agoSo you cannot access the portal page that quite a few more or less public wifi networks require you to access in order to gain internet access?
- ptaipale 10y agoThe VPN clients offer a "hotspot login" or such functionality so that you can open the access. It doesn't work for other use, just opening that VPN so that your company computer can connect to company network.