4 ms·
Yes. And I guess non-glued usb ports on every computer. And users that put every USB stick in their computer they are handed by strangers in front of the offi
by _Codemonkeyism 9y ago
Yes.
And I guess non-glued usb ports on every computer.
And users that put every USB stick in their computer they are handed by strangers in front of the office. Or they find on the printer. Especially when labeled "Pictures".
Because
CEO: Have we Antivirus installed?
CIO: Yes.
Not
CEO: Are we secure?
How does your risk analysis look like?
Do we internal or perimeter defense?
CIO: ...
- pjmlp 9y agoThey don't need to glue USB ports, because IT is intelligent enough to disable access to them via OS configuration. I never understood the stupidity of some people to glue them instead of using OS policies.
- _Codemonkeyism 9y agoI have never seen a company, large or small, which disabled USB ports. Because convenience is always higher rated than security. Glueing is much easier, can't fail with wrong configurations or roll outs, works if people have too many permissions on Linux and in a myriad of other ways.
- pjmlp 9y agoThe companies I work for, security is always higher rated than convenience. You could buy several houses, or be settled for life, with the costs to cover an eventual security breach.
- _Codemonkeyism 9y agoGreat to hear there are companies that take security seriously. The companies I've consulted with had USB not secured in the Laptops of the marketing departments I've seen - and yes some of them lost several hundred millions of $ b/c of breaches in revenue.
- speedplane 9y agoYou've never worked a large bank. They get attacked all the time, every day, over the network, with social engineering (dropping infected USB drives in the parking garage), and plain old physical theft and con-artistry. Moving any file on or off their system is a huge pain (e.g., e-mail attachments are automatically removed unless you go through a security process).
- teknologist 9y ago"We have a password policy in place that forces our users to change their passwords to something long and random with lots of symbols in it no less than 50 characters every week - we're on the cutting edge of security!"
- _Codemonkeyism 9y agoExactly.