4 ms·
Just another act of IBM's security theatre, and a testament to their backwards views on employee experience.
by kevinSuttle 8y ago
Just another act of IBM's security theatre, and a testament to their backwards views on employee experience.
- chiph 8y agoYou're not wrong on their poor employee experience, but there's very little theater involved - there's good reason to protect their IP. Any firm that invests multi-millions in original design will want to protect their property from theft. Semiconductors were mentioned, but also think about someone like Pixar.
- kevinSuttle 8y agoThe thing is, what's stopping employees from uploading files to a server? The physical devices are a fraction of a fraction of IP theft. Hence the term "theatre".
- jacquesm 8y agoHopefully a firewall.
- racingmars 8y agoPresumably they use network security devices and can see every bit of data that leaves their network to flag possible exfil. Devices like those in use at a company I used to work for man-in-the-middle all HTTPS traffic (using certificates from a CA that corporate IT pushes to all workstations/phones under corporate control, so they're trusted), man-in-the-middles SSH traffic (presumably assuming users just always answer "yes" to the "is this the right key?" question, or the user says no in which case the connection is effectively blocked, so either way the network security device wins), etc. Data exfiltration via USB key is a very real threat that is largely invisible to the company when it happens... no audit trail or anything to look back at.
- chiph 8y agoA business like this is likely to have a WebSense network appliance, and/or policy enforcement software on the desktops.